Privacy Policy
Latest revision: July 4, 2026
1. Who We Are
Findx ("the Service") is operated by Privacore ApS ("Privacore", "we", "us"), Bakkekammen 44, DK-4300 Holbaek, Denmark, CVR 36479604. Privacore ApS is the data controller for the personal data described in this policy.
You can reach us about anything in this policy at hi@findx.com.
2. Personal Data We Collect
2.1 Account Data
When you register we collect your email address and a password. The password is stored only as a salted cryptographic hash; we cannot read it. We also store account status and timestamps such as registration date, email verification and last login.
2.2 Content You Create
Portfolios and their transactions, watchlists, screeners, notes, custom P/E values and earnings estimates that you save in the Service are stored against your account and are visible only to you.
2.3 Payment and Subscription Data
Payments are processed by Paddle.com as merchant of record. Your card details are entered directly with Paddle; we never receive or store card numbers or any other card data. The free trial does not require a payment card.
From Paddle we receive your subscription status (for example active, past due or canceled), your plan (monthly or annual) and the current billing-period date (your next renewal, or a scheduled cancellation date). We use these to grant or withdraw paid access and to show you your plan and renewal date on your billing page. To let you manage your subscription, we open a Paddle-hosted portal where you can update your payment method, download invoices and cancel; that portal is provided directly by Paddle.
2.4 Device and Security Data
When you request a free trial we collect a device fingerprint (a technical identifier computed from browser and connection characteristics, provided by ThumbmarkJS). It is used solely to enforce the one-trial-per-device limit and to assess fraud risk at that moment; it is not used to track your browsing.
We record IP addresses in short-lived security logs used for login rate limiting and signup throttling. The registration form is protected by Cloudflare Turnstile, which processes technical browser data to distinguish people from bots.
3. Purposes & Legal Bases
We process your data for the following purposes, on the following GDPR legal bases:
- Providing the Service (your account, subscription, and the tools you use): performance of a contract, Art. 6(1)(b).
- Fraud and trial-abuse prevention (device fingerprinting at trial start, the card-derived identifier, IP-based rate limiting, Turnstile): our legitimate interest in preventing abuse of free trials and protecting the Service, Art. 6(1)(f).
- Service security and operations (security logs, session management): our legitimate interest in running a secure service, Art. 6(1)(f).
- Transactional email (verification links, account and billing notices): performance of a contract, Art. 6(1)(b). We do not send marketing email without your consent.
4. Third Parties & Processors
We share personal data only with the parties needed to run the Service:
- Paddle.com Market Ltd: payment processing as merchant of record. For payments, Paddle is itself a data controller; see the Paddle privacy policy.
- Cloudflare, Inc.: content delivery, security filtering and the Turnstile bot check.
- Thumbmark: computation of the trial device fingerprint described in section 2.4.
- Hosting providers: the servers the Service runs on.
We do not sell personal data, and we do not share it with data brokers or advertisers. Market data shown in the Service comes from S&P Global Market Intelligence; no personal data flows to them.
5. Cookies
The Service uses strictly necessary cookies only:
- findx_session: keeps you logged in (up to 7 days).
- findx_csrf and one-shot form tokens: security tokens that protect your account against cross-site request forgery.
We set no advertising or cross-site tracking cookies. Third-party components (the Paddle checkout, Cloudflare Turnstile) may set their own strictly necessary cookies when you use them.
6. Data Retention
Account data and the content you create are kept for as long as your account exists and are deleted with it. Security logs are short-lived (login and signup throttling records are deleted within hours). Trial and subscription records are kept while your account exists.
Billing records held by Paddle as merchant of record are retained by Paddle in accordance with bookkeeping and tax law.
7. Your Rights
Under the GDPR you have the right to access the personal data we hold about you, to have it rectified or erased, to restrict or object to processing (including the legitimate-interest processing described in section 3), and to receive your data in a portable format.
To exercise any of these rights, contact us at hi@findx.com. You also have the right to lodge a complaint with the Danish Data Protection Agency, Datatilsynet (www.datatilsynet.dk).
8. Security
All traffic to the Service is encrypted with TLS. Passwords are stored as salted hashes, payment details never touch our servers, and access to production systems is restricted. No system is perfectly secure; if we become aware of a breach affecting your personal data we will notify you as required by law.
9. Changes to This Policy
We may update this policy from time to time. When we do, we will update the date at the top of this document. Material changes will be communicated in the Service or by email.
10. Contact
If you have questions about this policy or how we handle your data, please contact us at:
Privacore ApS
Bakkekammen 44, DK-4300 Holbaek, Denmark
hi@findx.com