Privacy Policy
Last updated: August 2026 · Beta version
1. Introduction
This Privacy Policy describes how naroc ("we", "our", "us") collects, uses and protects personal information during this closed Beta. naroc is currently operated by a private individual, not by a registered company — see the Imprint for operator details.
2. Controller
The data controller for naroc is the private individual named in the Imprint. Once naroc is operated by a registered company (e.g. a GmbH), this section and the Imprint will identify that company as the controller instead.
3. Data we collect
Account data
- Name and email address
- Password (stored as a hash, never in plain text)
- Account preferences, watchlists and tracked companies
Authentication and security data
- Authentication session identifier
- Trusted-device token, if you choose to trust a device
- Login history, including IP address and browser/device information, for security purposes
- Two-factor authentication (2FA) codes and password-reset tokens, stored as hashes
- A pseudonymous administrative audit trail of security-relevant actions (e.g. account suspension), identified by account ID only — never by name or email address
Application and security logs
naroc's server components produce technical application logs used to operate, debug and secure the service (for example, failed login attempts or rate-limit events). These logs may include your IP address for a limited time. Logs are processed exclusively within naroc's own hosting infrastructure (see section 7) and are not shared with any external logging or monitoring service.
4. Cookies
naroc uses only the following strictly necessary or functional cookies. We do not use analytics, advertising or tracking cookies, and we do not show a cookie consent banner because no non-essential cookies are set.
- naroc_auth — keeps you signed in (session cookie)
- naroc-td — recognizes a trusted device so you are not asked for a 2FA code every time
- .AspNetCore.Culture — remembers your language preference (English/German)
5. Retention
- Sessions: expire after 30 minutes of inactivity, or after 30 days at the latest
- Trusted devices: expire after 30 days
- Login history: kept for 365 days
- Email verification / 2FA codes: expire after 5 minutes
- Password-reset tokens: expire shortly after being issued or used
- Administrative audit trail: kept for 180 days
- Application logs: console output is captured by the server's operating system, and the background worker's file-based logs are rotated after 30 days
Retention periods for account, watchlist and preference data have not yet been formally defined and will be established as part of ongoing operator policy.
6. Email delivery
naroc sends account-related emails (such as verification codes, password resets and notifications) via SMTP through STRATO, which also hosts the naroc platform. No other email service is currently used to deliver these emails.
7. Hosting
naroc is hosted on a server operated by STRATO GmbH, located within the European Union. STRATO also provides naroc's outbound email delivery described in section 6.
8. Market data providers
naroc uses Twelve Data to retrieve market data (such as prices and fundamentals) and OpenFIGI to retrieve instrument identifiers. Both are one-way, read-only integrations: naroc requests data from these providers and receives data in return. naroc does not transmit your name, email address, account information or any other personal data to Twelve Data or OpenFIGI.
9. Payments
naroc does not currently process any payments. Payment functionality is planned for after the Beta phase and will, at that point, be handled through Stripe. Stripe is not currently integrated or active, and no payment data is collected or transmitted at this time.
10. Backups
naroc does not currently use a separate backup provider or maintain an established backup service. Backup infrastructure will be reviewed and put in place as part of the operator's ongoing infrastructure planning.
11. Processors (sub-processors)
naroc uses the following categories of processors to operate the service. Each is described in more detail in the corresponding section above.
- Email delivery: STRATO (see section 6)
- Hosting: STRATO (see section 7)
- Payment processor Stripe — planned only for future paid functionality after the Beta; not currently active or integrated (see section 9)
A data processing agreement (Art. 28 GDPR) with STRATO will be reviewed and, where not already in place, put in place as part of the legal review before external Beta users are invited. A separate agreement with Stripe will be established if and when paid functionality is introduced.
12. International data transfers
naroc's hosting and email infrastructure (STRATO) is located within the European Union. Twelve Data and OpenFIGI are used only to retrieve market and instrument data, and no personal data is transmitted to them, so this does not constitute an international transfer of personal data. naroc does not currently transfer personal data outside the EU/EEA. Should this change in the future, naroc will rely on an appropriate safeguard recognised under the GDPR, such as the EU Standard Contractual Clauses, and will update this section accordingly.
13. Your rights
Under the GDPR, you have the following rights regarding your personal data. During this Beta, requests are handled manually — contact us using the details below and we will respond within a reasonable time.
- Access — request a copy of the personal data we hold about you (Art. 15 GDPR)
- Rectification — request correction of inaccurate or incomplete data (Art. 16 GDPR)
- Erasure — request deletion of your data (Art. 17 GDPR)
- Restriction — request that we limit how we use your data (Art. 18 GDPR)
- Objection — object to certain processing of your data (Art. 21 GDPR)
- Data portability — receive your data in a structured, machine-readable format (Art. 20 GDPR)
- Withdraw consent — not currently applicable, as naroc does not process personal data on the basis of consent
- Lodge a complaint with a supervisory data protection authority (Art. 77 GDPR)
14. Security measures
naroc applies technical and organisational measures appropriate to the risk, including: password hashing, the ability to revoke sessions and trusted devices at any time, access-controlled administrative actions with an audit trail, encrypted transport (HTTPS/TLS), and automatic enforcement of the retention periods described above.
15. Changes to this policy
We may update this Privacy Policy from time to time, for example to reflect changes to the application or its infrastructure. The "last updated" date above indicates when this policy was last revised.
16. Contact
For privacy-related questions or requests, contact us at chris@naroc.de.
This policy reflects the current Beta implementation and confirmed production architecture of naroc, and will be revised if the underlying infrastructure or processing activities change.