1. Controller
The controller responsible for data processing within the meaning of the General Data Protection Regulation (GDPR), other national data protection laws of the member states and other data protection provisions is:
Auras & Bielawski GbR
represented by the partners Wadim Auras and André Bielawski
Eduard-Bäumer-Str. 4
56288 Kastellaun
Germany
Email: hello@tmb-invest.de
Website: https://tmb-invest.de
Contact form
For enquiries about data protection, data subject rights or the processing of your data, you can also use our contact form.
A data protection officer is not required by law. If you have questions about the processing of your data, please use the contact details above.
2. Purpose and scope
This privacy policy informs you about the nature, scope and purpose of the processing of personal data within our online offering tmb-invest.de and the associated functions such as the Library (software shop), DAX Analysis (market analysis tool), Noélee (AI agent for PineScript®), stelaraX (AI chart analysis), customer accounts, contact form, waiting lists and newsletter.
3. Hosting and server logs
Our website is hosted by ALL-INKL.COM – Neue Medien Münnich, Hauptstraße 68, 02742 Friedersdorf, Germany. A data processing agreement pursuant to Art. 28 GDPR is in place with ALL-INKL.COM.
Each time the site is accessed, technically necessary data is stored in so-called server log files:
- IP address (anonymised / truncated after 7 days at most)
- Date and time of access
- URL accessed and amount of data transferred
- Browser type, operating system and referrer URL
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the stability, security and functionality of the website). Retention: 14 days at most, unless security incidents require longer retention.
Further information on data processing by ALL-INKL.COM: all-inkl.com/datenschutzinformationen.
3.1 Audience measurement (TMB Analytics, self-hosted)
If you have consented to the "Statistics" category in the cookie banner, we carry out our own self-hosted audience measurement under the name "TMB Analytics". Data is not transferred to external analytics providers (e.g. Google Analytics, Matomo Cloud); processing takes place exclusively on our own infrastructure at ALL-INKL.COM (see Section 3).
Data processed per page view:
- URL accessed and page title;
- Referrer (referring URL) and referrer domain;
- Device type (desktop/tablet/mobile), browser, operating system (derived from the user agent);
- Screen width;
- UTM parameters (utm_source, utm_medium, utm_campaign), if contained in the URL;
- Country, region and city — via coarse IP-based geolocation (see below);
- Timestamp;
- A pseudonymous visitor ID (
tmb_visitor_id, in the browser's localStorage) and a session ID (tmb_session, sessionStorage, expires after 30 minutes of inactivity). Both identifiers are randomly generated and contain no personal reference whatsoever;
- A SHA-256 hash of your IP address — salted with a secret generated randomly once per site. Your actual IP is never stored in our analytics tables and cannot be recovered from the hash.
Geolocation (third party ip-api.com): For a coarse assignment of country and city, your IP address is transmitted once to the service ip-api.com (operated by Fossabyte LTD, EU/USA). We only receive country, region and city in return; according to its own statements, ip-api.com does not process the request in a personally identifiable way and sets no cookies. We cache the result for 24 hours to avoid repeated requests for the same IP. Privacy information from ip-api.com: ip-api.com/docs/legal.
Legal basis: Art. 6(1)(a) GDPR (consent via our cookie banner) in conjunction with Section 25(1) TDDDG. Consent is voluntary; without consent no analysis takes place. You can withdraw your consent at any time — either via the cookie settings ("Settings" in the footer) or by deleting the local browser data. A withdrawal takes effect from the time of withdrawal.
Retention: Individual page view records are deleted automatically after 365 days (daily cron job). Aggregated evaluations are therefore never older than one year.
Exceptions: Users logged in as administrators (manage_optionspermission) are never recorded — so our own test visits do not distort the statistics.
4. Cookies and similar technologies
We use technically necessary cookies and storage techniques required to operate the site (login session, shopping cart, language selection, CSRF protection). These are set on the basis of Art. 6(1)(f) GDPR and require no consent. In addition, with your consent we use pseudonymous identifiers for the self-hosted audience measurement (see Section 3.1). We currently do not use third-party marketing or tracking cookies.
5. Contact form and email
If you contact us via the contact form or by email, we process your details (first and last name, email, optionally phone, subject, message text) solely to handle your enquiry. If you address a team member directly, the message is forwarded to their assigned email address, with hello@tmb-invest.de in copy for internal follow-up.
Legal basis: Art. 6(1)(b) GDPR (pre-contractual measures) or (f) GDPR. Retention: until the matter is resolved; statutory retention periods (e.g. Section 257 HGB, Section 147 AO) remain unaffected.
6. Customer account and order processing
To purchase products from our Library we create a customer account or use an existing one. The following data is processed:
- Name, email address, password (hashed)
- Billing address: first and last name, optionally company, street, postcode, city, country
- Order data: product(s), price, order number, timestamp, status
- Licence data: licence key, bound MetaTrader 5 account (if activated), activation and download times
- IP address at the time of the order (for fraud prevention)
Legal basis: Art. 6(1)(b) GDPR (performance of a contract). Retention in accordance with commercial and tax law obligations (usually 10 years).
7. Payment processing via Mollie
For payment processing we use the service provider Mollie B.V. (Keizersgracht 313, 1016 EE Amsterdam, Netherlands). When an order is placed, the data required for payment (name, email, order amount, order reference) is transmitted to Mollie. Mollie processes the actual payment data (e.g. credit card, SEPA, PayPal, Apple Pay, Sofort) as an independent controller in accordance with its own privacy policy: https://www.mollie.com/privacy.
Legal basis: Art. 6(1)(b) GDPR. A data processing agreement with Mollie is in place.
7.1 Subscriptions and recurring payments (instaTrader)
For subscriptions (e.g. the instaTrader monthly or yearly plan) we create a customer record at Mollie (name, e-mail address, our customer number). With the first payment you grant Mollie a mandate for recurring payments; the actual payment data (card or account details) remain with Mollie. We only store the Mollie identifiers of the customer record, the mandate and the subscription as well as the term, next due date, amount, payment status and the time of a cancellation in order to manage the charges, invoices and the validity of your licence.
The validity of the software licence is tied to the paid subscription period: the software regularly checks via our servers whether the licence is active and transmits the licence key, a device identifier and the device name (see section 8). If a payment fails or the subscription ends, the licence is marked as expired; we inform you about this by e-mail.
The legal basis is Art. 6 (1) (b) GDPR (performance of a contract) and, with regard to the retention of invoice data, Art. 6 (1) (c) GDPR in conjunction with the retention periods under commercial and tax law (up to ten years). The mandate at Mollie remains in place until you revoke it or the subscription ends; you can revoke it at any time through us or your payment provider.
8. Provision of digital products and licences
After successful payment a licence key is generated automatically and sent by email. Downloads are available after logging in to the customer account. For software that binds a MetaTrader 5 account, the MT5 account number is linked to the licence on first activation to prevent multiple use. This binding serves licence enforcement only; no further processing of the MT5 account data takes place.
9. DAX Analysis and index analyses (market data and AI assessment)
At /tools/dax-analyse/ as well as /tools/dow-jones-analyse/, /tools/nasdaq-analyse/ and /tools/sp500-analyse/ we provide analysis tools that evaluate price and fundamental data of the companies in the DAX 40, Dow Jones 30, Nasdaq 100 and S&P 500 as well as economic news, and derive an AI-supported assessment ("TMB Analysis"). We obtain the market data server-side from Yahoo Finance (Yahoo EMEA Ltd., Ireland) and finanzen.net (finanzen.net GmbH, Karlsruhe); the composition of the US indices from Wikipedia (Wikimedia Foundation, USA) and nasdaq.com (Nasdaq, Inc., USA). The AI assessment is generated via the API of OpenAI (OpenAI Ireland Ltd. or OpenAI, L.L.C., USA) or Anthropic PBC (USA).
No personal data: All queries are made automatically by our server and contain only market data and news – no data of our website visitors. When you open the page, your browser only processes the server log data described in Section 3. If you are logged in, we check on the basis of your user account whether the "Past assessments" area has been unlocked for you (Art. 6(1)(b) GDPR).
We store previous assessments for evidence and transparency purposes (Art. 20 Market Abuse Regulation); these records contain no personal data.
10. Noélee – AI agent for PineScript® / MQL (OpenAI)
At /noelee/ we offer the AI agent Noélee, which helps users program trading software (PineScript® v6 for TradingView and MQL5 for MetaTrader 5). The "PineScript® Indicators" area can be used free of charge within a one-off credit budget; further areas are unlocked via paid bundles.
Technically, Noélee runs on the OpenAI API. The responsible contracting party for users in the EEA is OpenAI Ireland Ltd., 1st Floor, The Liffey Trust Centre, 117–126 Sheriff Street Upper, Dublin 1, D01 YC43, Ireland; technical processing may be carried out by OpenAI, L.L.C. (3180 18th Street, San Francisco, CA 94110, USA). We use a current model of the GPT-4 class (currently GPT-4o) and update it to newer versions when needed.
10.1 Data processed
When you use the chat, the following data is processed:
- Chat content (your requests and the AI's answers), stored separately per area;
- Identifier: for logged-in users the internal user ID of your TMB account; for users who are not logged in a hashed value of your IP address (md5 with server salt, third parties cannot recover the original IP);
- Timestamp of each message;
- Area assignment (e.g. "pine_indicators", "mt5_eas") per chat entry;
- Technical request data (IP address, user agent, timestamp) to enforce the credit budgets in the free tier (10 credits anonymous, 25 credits for logged-in users).
10.2 Transfer to OpenAI (Ireland and USA)
To generate the answer, your chat content (request text and previous conversation, at most the last 30 messages) is transmitted to the OpenAI API and processed there. This may involve a transfer to a third country (USA). The legal basis is Art. 6(1)(b) GDPR (provision of the AI assistance you requested) in conjunction with Art. 49(1)(a) GDPR (explicit consent to the transfer by using the chat after being informed of the risk).
OpenAI has its own privacy policies; according to its own statements, input transmitted via the API is not used to train the models and is stored for up to 30 days to prevent abuse. Details: openai.com/policies/privacy-policy · API Data Usage Policies. OpenAI is certified under the EU-US Data Privacy Framework; standard contractual clauses apply in addition.
Please do not enter any sensitive or personal data (health data, financial account information, passwords, third-party data, etc.) in the Noélee chat.
10.3 Retention of the chat history
To allow you to continue using the service, we store your chat histories in our database:
- Logged-in users: Stored permanently until you delete the chat yourself via the "Clear chat" button or close your account.
- Users who are not logged in: stored linked to your IP hash; the history can only be accessed as long as you use the same IP address. You can delete the history manually at any time.
- Chat histories are stored separately per area (e.g. the PineScript® indicators history separately from the MQL5 EAs history).
Legal basis: Art. 6(1)(b) GDPR (performance of a contract or pre-contractual measures to provide the requested service). For anonymous chats we have no direct link to the user's identity; forced deletion only takes place when the underlying infrastructure is decommissioned.
10.4 Trading Academy (lesson progress and PDF export)
The Noélee "Trading Academy" area provides structured learning modules on trading topics (basics, technical analysis, risk management, psychology, strategy). In addition to the chat content described in Section 10.3, we process the following data for this purpose:
- Lesson progress: For each module we store which lessons you have completed (list of lesson IDs), the lesson currently in progress, the status ("in_progress"/"completed"), and the start and, if applicable, completion time. This data is tied to your user ID (logged in) or to a SHA-256 hash of your IP (not logged in). It serves the seamless continuation of your learning path.
- Thread assignment: Each module gets its own chat thread so that questions and answers about a lesson are kept separate from other conversations. Thread content is stored as described in Section 10.3 and transmitted to OpenAI (Section 10.2).
- Generated PDF summaries (premium feature): After completing a module you can have a personalised PDF summary of your learning path generated in exchange for credits (Academy PDF bundle). The PDF file is stored on our server (directory with a random path); in the database we store the file path, file size, title, module reference, user ID, timestamp and optionally the associated order ID. Once generated, the PDF contains content from the associated chat thread and the lessons you completed.
Legal basis: Art. 6(1)(b) GDPR (performance of a contract or pre-contractual measures to provide the learning service) and – for retaining the PDF transactions – Art. 6(1)(c) GDPR in conjunction with Section 147 AO, Section 257 HGB (tax retention for paid Academy PDFs).
Retention:
- Lesson progress: permanently, until you close your account or request deletion by email to hello@tmb-invest.de.
- Generated PDF files: remain available in your account as long as your account exists. You can delete individual PDFs yourself at any time. The transaction metadata for paid PDF generations is subject to the 10-year retention period for tax-relevant transactions.
- For users who are not logged in we store the lesson progress linked to an IP hash; PDF export is not possible without logging in.
10.5 Premium bundles, credit refills and area unlocks
For the use of paid areas ("premium bundles") and for pure credit top-ups ("credit refills") we additionally process the following data:
- Credit balance: current balance of purchased and used credits, linked to your user ID;
- Area unlocks: list of the premium areas unlocked for your account with the date of unlocking and a reference to the underlying order;
- Transaction log (ledger): chronological record of all credit movements (bundle purchases, refill purchases, usage, manual adjustments) with timestamp and reference to the area. Serves traceability and dispute resolution.
Legal basis: Art. 6(1)(b) GDPR (performance of the bundle/refill contract) and Art. 6(1)(c) GDPR (commercial and tax retention obligations, in particular Section 257 HGB, Section 147 AO).
Retention: This data is kept for the duration of your account use and, after it ends, for the statutory retention periods (usually 10 years for tax-relevant transactions).
10.6 Payment processing for bundle purchases
Bundle purchases are processed via the payment service provider Mollie B.V.. The provisions in Section 7 of this privacy policy apply accordingly. On purchase, the order number, buyer ID and bundle name are recorded for confirmation and linked to the unlocking of the area and the credit top-up.
10.7 Credit budget in the free tier
To enforce fair use in the free tier we manage a one-time credit budget (10 credits for anonymous users, 25 credits for logged-in users). Each request to Noélee consumes one credit from this budget. The budget is persistent and does not regenerate automatically; once used up, paid premium bundles or credit refills are available for topping up (Section 11.5).
Technically, the remaining credit balance is stored server-side — for logged-in users as user meta on the TMB account, for anonymous users as a hashed key value (combined from the IP address and a random UUID generated in the browser). The stored data contains no content, only the numeric credit balance and a timestamp of the initial grant.
For users who are not logged in, the credit budget is additionally anchored to a device-specific, randomly generated identifier ("browser ID"). This ID is a UUID without personal reference and is stored in local storage (localStorage) of your browser. It prevents the budget from being granted again by switching networks (e.g. from Wi-Fi to mobile data). You can delete this ID at any time via your browser settings; your current credit balance is then discarded and a new initial budget is granted on your next visit.
To ward off automated bot requests we use the service Cloudflare Turnstile from Cloudflare, Inc. (101 Townsend St, San Francisco, CA 94107, USA) for users who are not logged in. Turnstile checks in the background, using technical browser characteristics (user agent, header properties, mouse and keyboard behaviour, IP address), whether a real person is present — without a visible captcha task and without tracking. No cookies are set and no personal data is stored permanently. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in protection against abuse). Cloudflare processes data in the USA on the basis of the EU-US Data Privacy Framework. More information: cloudflare.com/privacypolicy.
10.8 Withdrawal and deletion
You can:
- delete the chat history yourself at any time via the "Clear chat" button in Noélee (per area or globally);
- stop using Noélee at any time by no longer opening the page;
- as a logged-in user, request the complete deletion of all Noélee chat data via hello@tmb-invest.de;
- have the credit balance and area unlocks deleted on request — however, this amounts to waiving the purchased services and does not lead to a refund. The retention of the transaction logs for tax reasons (Section 10.5) remains unaffected.
11. stelaraX – AI chart analysis (OpenAI ChatGPT)
At /stelarax/ we offer the completely free service stelaraX. Based on user input (symbol, timeframe, strategy), stelaraX generates an AI-supported analysis proposal with entry, take profit, stop loss, risk-reward ratio and lot size recommendation.
Technical architecture: To provide the service we work with two specialised partners:
- Live market data is obtained server-side via the market data API of Twelve Data Pte. Ltd., 20A Tanjong Pagar Road, Singapore 088443. Only the instrument selected by the user (e.g. EURUSD) and the timeframe are transmitted — no personal user data. The request originates from our server, not from your browser; your IP address is not passed on to Twelve Data.
- Validation and analysis of the setup proposals then takes place via the OpenAI API. OpenAI receives the market data snapshot and your input parameters in order to validate and comment on the setup proposal.
OpenAI's responsible contracting party for users in the EEA is OpenAI Ireland Ltd., 1st Floor, The Liffey Trust Centre, 117-126 Sheriff Street Upper, Dublin 1, D01 YC43, Ireland. OpenAI OpCo, LLC (3180 18th Street, San Francisco, CA 94110, USA) is responsible for US-side processing.
11.1 Data processed
When you use stelaraX, the following data is processed:
- Input to us: selected symbol (e.g. EURUSD, BTCUSD, XAUUSD), timeframe (M15, H1, H4, D1, etc.), strategy selection (e.g. OTE, SMC, Donchian, Fibonacci), optionally risk parameters (account size, risk %, R:R profile);
- Technical metadata (only with us): IP address, user agent, timestamp of the request — for abuse protection and rate limiting. This metadata is not transmitted to Twelve Data or OpenAI.
- To Twelve Data: only symbol and timeframe to retrieve the corresponding price data (no personal details).
- To OpenAI: the parameters chosen by the user (symbol, timeframe, strategy, risk parameters if any) and the market data snapshot obtained from Twelve Data that OpenAI needs for validation and commentary.
- AI result: the signal proposal generated by the OpenAI API with entry/TP/SL/lot size/comment.
For logged-in users the assignment of the request to the user ID is stored; for anonymous use we work with a SHA-256 hash of your IP address.
11.2 Transfer to OpenAI (USA and Ireland)
To validate and comment on the setup, the user input mentioned above and the market data snapshot obtained from Twelve Data are transmitted to OpenAI. OpenAI uses them to generate the final analysis text. Depending on model availability, processing takes place in the EU (via OpenAI Ireland Ltd.) and/or in the USA (via OpenAI OpCo, LLC). This therefore constitutes a transfer to a third country (USA).
Legal basis: Art. 6(1)(b) GDPR (provision of the AI chart analysis you requested) in conjunction with Art. 49(1)(a) GDPR (explicit consent to the transfer by using the service after being informed of the risk) and — where applicable — standard contractual clauses pursuant to Art. 46(2)(c) GDPR. Further information on data processing by OpenAI: openai.com/policies/eu-privacy-policy.
Please do not enter any sensitive or personal data (health data, account information, passwords, third-party data, etc.) in stelaraX. The input fields are designed exclusively for market parameters anyway.
11.3 Storage of generated analyses (opt-in)
stelaraX analyses are not automatically stored by us. You initially see a generated analysis only transiently in your browser session. Only if you actively decide to save it ("Save signal" button) do we store a copy of the analysis with the following details in your TMB user account:
- Symbol, timeframe, selected strategy;
- Entry price, take profit, stop loss, R:R, lot size if any;
- Time of generation, optionally a comment/title you assigned.
Legal basis: Art. 6(1)(a) GDPR (consent by actively saving) or Art. 6(1)(b) GDPR (provision of the requested save function).
Retention period: Saved analyses remain permanently retrievable until you delete them yourself. Deletion is irrevocable and takes place directly in the stelaraX interface per signal or globally via a "Delete all" action. When your TMB account is closed, all saved stelaraX analyses are deleted as well.
11.4 Free service — no billing record
stelaraX is completely free. No payment data, no billing or contract addresses and no credit balances are recorded. Processing is limited to what is technically necessary to provide the analysis (Section 11.1) and – if the save function is used – to what the user actively saves (Section 12.3).
11.5 Abuse protection and rate limiting
To ensure fair access we apply a request limit per IP and hour/day. The counters are kept in a server-side cache (WP transients) for at most 24 hours and contain no content, only timestamps and a hash of the request source. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in protection against abuse).
11.6 Objection and deletion
You can:
- stop using stelaraX at any time by no longer opening the page — transient analysis results that were not saved are discarded as soon as you leave the page;
- delete saved analyses individually or all at once in the stelaraX interface at any time;
- as a logged-in user, request the complete deletion of all stelaraX data via hello@tmb-invest.de.
Data that has already been transmitted to OpenAI is thereafter within OpenAI's area of responsibility; according to its own statements, API input is not used to train the models but may be cached briefly to prevent abuse.
12. Newsletter and marketing emails
If you sign up for our newsletter, we process your email address on the basis of your consent (Art. 6(1)(a) GDPR). We use the double opt-in procedure. You can unsubscribe at any time via the link in every newsletter email or by sending a message to hello@tmb-invest.de.
13. External services and links
stelaraX AI analysis: The stelaraX chart analysis is an internal area of our website for logged-in users. Personal data is processed within the scope of the existing user account and this privacy policy; no transfer to third parties takes place as part of the analysis.
MetaTrader 5 / MQL5: Links to MetaTrader 5 downloads or MQL5 signals lead to offerings of MetaQuotes Software Corp.
Broker links: We link to brokers (e.g. GBE Brokers) as external providers. When you click, you leave our site.
14. Fonts
We use locally embedded fonts (web fonts) that are loaded directly from our server. No connection to Google Fonts or other external font CDNs is made.
15. Recipients and processors
Your data is only transferred to third parties in the following cases:
- To ALL-INKL.COM – Neue Medien Münnich as hosting provider for operating the website
- To Mollie B.V. for processing payments
- To OpenAI (OpenAI Ireland Ltd. / OpenAI, L.L.C., USA) for processing AI chat requests (Noélee, see Section 10), AI chart analyses (stelaraX, see Section 11) and the AI assessment of the DAX Analysis (see Section 9)
- To OpenAI Ireland Ltd. (Ireland) or OpenAI OpCo, LLC (USA) for processing AI chart analysis requests (stelaraX, see Section 12)
- To ip-api.com (Fossabyte LTD) for IP-based geolocation as part of the self-hosted audience measurement, provided you have consented to the statistics category (see Section 3.1)
- To our email delivery service provider (SMTP provider) for delivering system emails
- To tax advisers and authorities, where legally required
We have concluded contracts pursuant to Art. 28 GDPR with processors where the respective arrangement requires it.
16. Transfers to third countries
Transfers to third countries outside the EU/EEA take place in the following cases:
- OpenAI, L.L.C. (USA): for processing Noélee chat requests, see Section 10. Legal basis Art. 49(1)(a) GDPR (consent by use) or standard contractual clauses pursuant to Art. 46(2)(c) GDPR.
- OpenAI OpCo, LLC (USA): for processing stelaraX chart analysis requests, see Section 11. Legal basis Art. 49(1)(a) GDPR (consent by use) or standard contractual clauses pursuant to Art. 46(2)(c) GDPR. The contracting party for EEA users is OpenAI Ireland Ltd.; US-side processing takes place depending on model availability.
- Mollie B.V.: primarily EU processing; for US card payments a transfer to the card networks (USA) may be necessary.
- ip-api.com (Fossabyte LTD, incl. USA): Individual IP lookup requests for rough geolocation as part of the self-hosted audience measurement, see Section 3.1. Only country/region/city are returned. Legal basis: Art. 6(1)(a) GDPR (consent via the cookie banner, "Statistics" category) in conjunction with Art. 49(1)(a) GDPR.
17. Partner program (affiliate)
We run a partner program through which registered affiliate partners can receive a commission for referring customers. Participation is voluntary and requires a TMB Invest user account. As part of the partner program we process the following data:
a) Attribution via cookie
If a person clicks on a partner link (URL parameter ?ref=CODE), we set a technical cookie named tmb_aff with the partner's referral code. Duration: 30 days. Existing assignments are not overwritten (first-touch attribution). The cookie contains no personal information about the visitor, only the public partner code. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in correct partner accounting) and, if an order is placed later, Art. 6(1)(b) GDPR (performance of the contract with the partner).
b) Click log
When a partner link is opened we log: partner code, a SHA-256 hash of the IP address (no plain-text IP), the user agent, the target URL (landing page) and the referrer. The log serves fraud detection only (cookie stuffing, self-purchases, unusual click patterns). Legal basis: Art. 6(1)(f) GDPR (legitimate interest in fraud prevention). Retention: 12 months, then automatic deletion.
c) Commission and payout data
For our own partners (program participants) we additionally process: full name, email address, account holder, IBAN and BIC for paying out commissions, and the time of acceptance of the terms and conditions. For each referred order we store the order ID, gross/net amount, commission amount, status and timestamp. Legal basis: Art. 6(1)(b) GDPR (performance of a contract) and Art. 6(1)(c) GDPR in conjunction with Section 147 AO (tax retention obligation, 10 years).
d) Recipients
Bank details are viewed exclusively by authorised staff of Auras & Bielawski GbR and – within the scope of statutory record-keeping and reporting obligations – by our tax adviser and, where applicable, the competent tax authorities.
e) Objection and deletion
You can object to the setting of the tmb_affcookie at any time by blocking or deleting it in your browser settings. As a registered partner you can have your partner account closed by emailing hello@tmb-invest.de. Commissions already paid out and the associated accounting records are subject to tax retention periods and cannot be deleted before these expire.
17a. Applicant data (careers area)
Via our careers area at /karriere/ you can apply for advertised positions or send an unsolicited application. The application process collects structured data in several steps, which we process to carry out the selection procedure.
a) Data collected
- Contact details (required): full name, email address.
- Contact details (optional): phone number, LinkedIn/portfolio URL, place of residence, country.
- Documents — upload option: CV as a file (PDF, DOC, DOCX or ODT, 8 MB at most) and optionally a cover letter as free text.
- Documents — guided process: free-text answers to up to five open questions (motivation, previous projects, superpower, timeframe/scope, links to your own work).
- Conditions (optional): earliest start date, availability (full-time, part-time, working student, freelance), salary expectation, source of the application (e.g. LinkedIn, referral, social media) and, where applicable, a free-text comment on the source.
- Technical metadata: IP address at the time of submission (to ward off automated abusive submissions), timestamp of submission, reference to the advertised position.
b) Purpose of processing
We process the data mentioned above solely for the purpose of carrying out the application procedure, in particular to assess professional and personal suitability for the advertised or a comparable position, to contact the applicant, to organise introductory interviews, to send trial tasks and — if an employment relationship is established — to transfer the data to the personnel file. It is not used for any other purpose.
c) Legal basis
Processing is based on Section 26(1) sentence 1 BDSG in conjunction with Art. 6(1)(b) GDPR (pre-contractual measures to establish an employment relationship at the applicant's request). Where, exceptionally, special categories of personal data (Art. 9 GDPR) are voluntarily provided as part of an application (e.g. photo, health information), processing is additionally based on Section 26(3) BDSG or on consent pursuant to Art. 9(2)(a) GDPR. Consent is voluntary and can be withdrawn at any time.
d) Retention and deletion
If the application procedure ends without a hire, the application documents including all uploads and metadata are deleted automatically no later than 6 months after the procedure ends. This period follows the case law on possible claims under the German General Equal Treatment Act (Section 15(4) AGG: two-month period for asserting claims) plus a reasonable buffer for any pending proceedings. If you are hired, the documents are transferred to the personnel file and are then subject to the relevant employment and social law retention periods (typically up to 10 years after the end of the employment relationship for payroll records, Section 257 HGB, Section 147 AO).
e) Talent pool (only with explicit consent)
At the applicant's request, the documents can be kept beyond the 6-month period in a talent pool so that we can contact them again about suitable future vacancies. Storage in the pool takes place exclusively on the basis of prior consent given in writing (including by email) pursuant to Art. 6(1)(a) GDPR. Consent is voluntary, can be withdrawn at any time without giving reasons (email to hello@tmb-invest.de) and is deleted automatically after two years unless renewed beforehand.
f) Storage location and access
Application documents are stored exclusively within our WordPress installation at our German host (ALL-INKL.COM, see Section 3). Access is restricted to members of the HR/recruiting team of Auras & Bielawski GbR and the decision-makers responsible for the respective position. Uploaded files (CV, cover letter) are stored as private media attachments and are not accessible via the public media library. No transfer to third parties (e.g. external applicant tracking systems) takes place.
g) Email notifications
After receiving an application we automatically send you a confirmation of receipt to the email address provided. Internal notifications go to hello@tmb-invest.de. Emails are sent via the SMTP service of our host (ALL-INKL.COM, see Section 3); no transfer to external email marketing providers takes place.
h) Withdrawal and deletion on request
You can withdraw your application at any time and request the complete deletion of your application data. An informal email to hello@tmb-invest.de with the keyword "Delete application" is sufficient. Deletion takes place without delay, at the latest within 30 days of receipt of the request. Any employment-law obligations of proof and documentation (e.g. to comply with the AGG) may in individual cases prevent immediate deletion; in this case the data is blocked for the duration of the obligation and then deleted.
i) Automated decision-making
No automated decision-making within the meaning of Art. 22 GDPR (in particular no automated scoring, no algorithmic pre-selection) takes place in the application procedure. All selection decisions are made by people from our team.
j) Abuse protection
To ward off automated submissions (spam bots) we use an invisible honeypot field and nonce-based CSRF protection. The IP address is stored at the time of submission for the purpose of preventing abuse (legal basis: Art. 6(1)(f) GDPR, legitimate interest in a functioning application process). The IP is removed automatically from the application record after 30 days unless a specific suspicion of abuse requires longer retention in an individual case.
18. Your rights as a data subject
You have the following rights at any time:
- Access to the data stored about you (Art. 15 GDPR)
- Rectification of inaccurate data (Art. 16 GDPR)
- Erasure of your data (Art. 17 GDPR), unless statutory retention obligations prevent it
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection to processing (Art. 21 GDPR)
- Withdrawal of consent given, with effect for the future (Art. 7(3) GDPR)
Please send requests to hello@tmb-invest.de.
19. TMB CopyFlow (Windows software)
TMB CopyFlow is a Windows application for copying trade orders between your own MetaTrader 5 accounts. When the software is used, data is processed as follows:
19.1 Processing on your device
The login details of your trading accounts (login number, password, server name), your copy settings, the mapping state of open positions and a log of the copied orders are stored exclusively locally on your computer in the folder %LOCALAPPDATA%\TMBCopyFlow . Passwords are encrypted with the Windows Data Protection API (DPAPI) and are bound to your Windows user account. This data is not transmitted to us.
19.2 Licence check
On start-up and roughly every six hours thereafter, the software checks the validity of your licence via an encrypted connection (HTTPS) to tmb-invest.de. The following is transmitted: your licence key, a device identifier derived from hardware characteristics, the program version and, for technical reasons, your IP address. Purpose: binding the licence to one PC and protection against unauthorised use. Legal basis: Art. 6(1)(b) GDPR (performance of a contract). The device identifier is stored assigned to the licence for as long as the licence exists; the binding can be reset on request when you change devices.
19.3 Optional remote view on a mobile device
If you enable the "Phone via tmb-invest.de" function in the software, your PC sends a status report to our server roughly every three seconds, which forwards it to your paired mobile device. The status report contains: names and login numbers of your accounts, server names, balance and equity, open positions, the latest log lines and the name of your PC. Broker passwords are not transmitted. Commands triggered from the mobile device (e.g. start copying, close position) are stored until collected by the PC, for a maximum of two minutes. The last status report is deleted automatically after 24 hours. When creating accounts via the mobile device, the account password is transmitted end-to-end encrypted; our server cannot read it.
Legal basis: Art. 6(1)(b) GDPR (performance of a contract, additional function requested by you). The function is off by default and can be ended at any time in the software or in the customer account (unpair). Hosting: ALL-INKL.COM as processor (see Section 3).
19.4 Microsoft Store
When you purchase via the Microsoft Store, Microsoft Ireland Operations Ltd. or Microsoft Corporation processes your purchase and account data under its own responsibility. We receive no personal data of buyers from Microsoft, only anonymous sales statistics. Microsoft's privacy statement applies: privacy.microsoft.com.
19.5 No sharing, no analytics
The software contains no third-party advertising or analytics services and sends no usage statistics. Transmission to brokers takes place exclusively via the MetaTrader terminals running on your PC and is subject to the privacy policy of the respective broker.
19.6 Your rights
You have the rights to access, rectification, erasure and restriction described in the "Data subject rights" section. You delete local data yourself by removing the folder %LOCALAPPDATA%\TMBCopyFlow; we delete the server data of the remote view and the device binding on request to hello@tmb-invest.de.
20. AI labelling and transparency (Art. 50 AI Act)
Since 2 August 2026, the transparency obligations of Art. 50 of the EU AI Act (Regulation (EU) 2024/1689) apply. We implement them as follows:
- AI interaction: Our AI services Noélee (AI chat and Trading Academy) and stelaraX (AI chart analysis) are clearly disclosed as AI systems from the very first interaction (Art. 50(1) AI Act).
- AI-generated output: Content generated by Noélee and stelaraX (chat answers, analysis proposals, learning PDFs) is marked as AI-generated. The setup proposals output by stelaraX carry a visible AI notice; Academy PDFs contain a corresponding notice in the document.
- Visible labelling of editorial content: Posts on this website that were created entirely or substantially by artificial intelligence are marked with a clearly perceptible notice directly on the content. AI-generated or AI-altered realistic image, audio or video representations ("deepfakes") are disclosed as such at the first perception (Art. 50(4) AI Act).
- Machine-readable marking: Labelled content additionally receives a machine-readable marking in the source code (meta data and structured data according to the IPTC standard "Digital Source Type"), so that the AI origin is also technically recognisable (Art. 50(2) AI Act).
- AI-assisted content: Content for which AI was used only in a supporting role and which is subject to human editorial review is voluntarily labelled as "AI-assisted".
We answer questions about AI labelling at hello@tmb-invest.de.
21. Right to lodge a complaint
You have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is:
The State Commissioner for Data Protection and Freedom of Information of Rhineland-Palatinate
Hintere Bleiche 34, 55116 Mainz, Germany
Web: www.datenschutz.rlp.de
22. Currency of this policy
Last updated: August 2026. We reserve the right to amend this privacy policy if the legal or technical framework changes. This English version is provided for convenience; the German version is authoritative.