Data protection

Privacy policy

Information pursuant to Articles 13 and 14 GDPR on the processing of personal data in the 100 Vital Years web application. Placeholders in square brackets must be completed by the operator before launch.

1. Controller and contact

Controller within the meaning of Art. 4(7) GDPR: [Legal name of the operator / company], [Street and house number, Postcode City, Germany]. Email: [privacy@your-domain.tld]. Full provider identification is in the imprint.

Data protection officer: [Data protection officer — name and contact, or: not required under Art. 37 GDPR]

2. What we process, why, and on what legal basis

  • Account data (email address, password hash, sign-in provider, sign-in timestamps, optional first name, last name, username, date of birth and profile picture). Purpose: creating and operating your account. Legal basis: performance of a contract, Art. 6(1)(b) GDPR.
  • Portfolio data (projects, loans, interest rates, payments, renovation and running costs, rental income, currency settings). By default this stays on your device in the browser’s local storage. It is only transmitted to our servers if you activate cloud sync or a cloud backup. Legal basis: Art. 6(1)(b) GDPR.
  • Subscription and billing data (plan, trial end date, cancellation date, payment status). Purpose: managing your subscription and meeting commercial and tax record-keeping duties. Legal basis: Art. 6(1)(b) and Art. 6(1)(c) GDPR in conjunction with § 147 AO and § 257 HGB.
  • Service emails (welcome, trial reminder, plan and cancellation confirmations, password reset). Legal basis: Art. 6(1)(b) GDPR.
  • Marketing emails and newsletter — only with your prior confirmed consent (double opt-in). We store the consent, the channel, the time, the source and the wording version as proof (Art. 7(1) GDPR). Legal basis: Art. 6(1)(a) GDPR and § 7(2) no. 2 UWG.
  • Feedback and support messages you send us through the help page. Legal basis: Art. 6(1)(b) and Art. 6(1)(f) GDPR (answering your request).
  • Server log data (IP address, timestamp, requested resource, user agent) generated automatically when the site is called up. Purpose: delivery, stability and security of the service. Legal basis: Art. 6(1)(f) GDPR; our legitimate interest is a secure, functioning service.

Providing account and portfolio data is not a statutory requirement, but without it the service cannot be provided.

3. Local storage and cookies

The application stores your settings and — unless you use cloud sync — your entire portfolio in your browser’s local storage. These entries are strictly necessary to deliver the service you expressly requested, so they do not require consent under § 25(2) no. 2 TDDDG. We do not use advertising cookies, tracking pixels or cross-site profiling. If analytics is introduced later, it will only run after opt-in consent.

4. Recipients and processors

  • Hosting, database and authentication — our infrastructure provider hosts the application, the database and the sign-in service on our behalf under a data processing agreement (Art. 28 GDPR).
  • Email delivery — outbound emails are sent through our managed email infrastructure from the sender domain notify.100vitalyears.com.
  • Google and Apple sign-in — if you choose to sign in with Google or Apple, the respective provider processes the sign-in and transmits your email address and identifier to us. This happens only on your explicit action.
  • Exchange rates — for multi-currency portfolios your browser calls a public exchange-rate service. Only the requested currency pair and technically necessary connection data (including your IP address) are transmitted; no portfolio content is sent.
  • External analysis (optional) — the “analyse with ChatGPT” function only copies a summary of your portfolio to your clipboard and opens the third-party site. Nothing is transmitted automatically; whatever you paste there is processed under that provider’s own terms.
  • Payment processing — [name of the payment provider / merchant of record] processes payments and invoicing on our behalf or as an independent controller. Card details never reach our servers.

5. Transfers to third countries

Where a processor operates outside the European Economic Area, the transfer is safeguarded by an adequacy decision of the European Commission or by the EU Standard Contractual Clauses under Art. 46(2)(c) GDPR, together with supplementary technical measures. You can request a copy of the safeguards from [privacy@your-domain.tld].

6. Retention

  • Account and portfolio data: until you delete your account.
  • Consent records: for the duration of the consent plus three years after withdrawal, to defend against legal claims (§ 195 BGB).
  • Invoices and booking-relevant records: ten years under § 147 AO and § 257 HGB.
  • Server logs: normally deleted or anonymised within 30 days.

7. Your rights

You have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing based on legitimate interests (Art. 21). Where processing is based on consent, you may withdraw it at any time with effect for the future (Art. 7(3)) — this does not affect the lawfulness of processing carried out before the withdrawal.

You can exercise the most common rights yourself in the app: export all of your data as a machine-readable JSON file and delete your account and all associated data under Settings → Your data and rights. For anything else write to [privacy@your-domain.tld]; we answer within one month.

You also have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR), for example: [Competent supervisory authority, e.g. Bayerisches Landesamt für Datenschutzaufsicht, Promenade 27, 91522 Ansbach]

8. Automated decision-making and security

We do not use automated decision-making or profiling within the meaning of Art. 22 GDPR. All calculations shown in the app are simulations based on the values you enter. Traffic is encrypted in transit (TLS); portfolio rows in the database are protected by row-level access rules so that only your own account can read them.

Version 2026-08 · Last updated 2026