Privacy Policy
Privacy policy for the El Fondo platform
Last updated: July 20, 2026
1. Controller and Contact
The controller responsible for processing your personal data within the meaning of Art. 4 (7) GDPR is:
Fintum Market Intelligence GmbH
Abt-Plazidus Straße 24
97359 Schwarzach am Main
Germany
Email: [email protected] · Contact form: el-fondo.com/contact
Register: Amtsgericht Würzburg, HRB 18562
Managing Director: David Siegl
Data protection contact: Friedrich Rösel, [email protected]
We operate the service "El Fondo" ("the Service", "we", "us").
Change of controller. Until July 2026 the Service was operated by three private individuals based in Peru. It is now operated exclusively by Fintum Market Intelligence GmbH, which has assumed the role of controller for all processing described here.
2. Applicable Law
Because we are established in Germany, the EU General Data Protection Regulation (GDPR) applies to all of our processing, regardless of where you live.
Where you are resident in Brazil, Peru, Mexico or Chile, the LGPD, Ley N° 29733, the LFPDPPP and Ley N° 19.628 apply in addition. Where those laws grant you stronger rights than the GDPR, the stronger right prevails. Section 10 sets out the country-specific additions.
3. Categories of Personal Data
| Category | Examples | Source |
|---|---|---|
| Account data | Email address, password hash, account status | You |
| Identity data | First and last name, country | You |
| Contact data | Phone number (where you use WhatsApp verification) | You |
| Demographic data | Date of birth, self-declared gender | You |
| Investor profile | Experience level, objectives, planned capital, time horizon, risk tolerance, retirement age | You |
| Platform activity | Portfolio simulations, allocations, watchlists, votes, reading lists, leaderboard and contest results | Generated by your use |
| Usage data | Page views, clicks, feature interactions, session duration | Generated by your use |
| Technical data | IP address, device and browser characteristics, device identifier, approximate location derived from IP | Generated automatically |
| Communications | Support requests, feedback, email interactions | You |
| Referral data | Referral code, referring user, campaign and click identifiers | You / campaign source |
We do not knowingly process special categories of personal data within the meaning of Art. 9 GDPR.
4. Purposes and Legal Bases
| Purpose | Legal basis |
|---|---|
| Creating and operating your account; providing simulations, watchlists, voting and reading lists | Art. 6 (1) (b) GDPR - performance of a contract |
| Email and phone verification (including WhatsApp one-time passcodes) | Art. 6 (1) (b) GDPR |
| Age verification (16+ eligibility) | Art. 6 (1) (c) GDPR - legal obligation; Art. 8 GDPR |
| Security, abuse and fraud prevention, session and device management | Art. 6 (1) (f) GDPR - our legitimate interest in a secure, non-manipulated service |
| Error diagnostics and performance monitoring | Art. 6 (1) (f) GDPR - our legitimate interest in a functioning service |
| Product analytics and session replay | Art. 6 (1) (a) GDPR - your consent |
| Advertising measurement, remarketing and campaign attribution | Art. 6 (1) (a) GDPR - your consent |
| Newsletters and marketing emails | Art. 6 (1) (a) GDPR - your consent; § 7 (2) No. 2 UWG |
| Market-intelligence insights (Section 5) | Art. 6 (1) (a) GDPR - your consent |
| Retention for tax and commercial law | Art. 6 (1) (c) GDPR - §§ 257 HGB, 147 AO |
| Asserting or defending legal claims | Art. 6 (1) (f) GDPR |
Where we rely on consent, you may withdraw it at any time with effect for the future (Art. 7 (3) GDPR). Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
Where we rely on legitimate interests, you have a right to object under Art. 21 (1) GDPR. In the case of direct marketing, we will stop processing your data for that purpose immediately and unconditionally (Art. 21 (2), (3) GDPR).
5. Market Intelligence
Part of our business consists of producing aggregated market-intelligence insights that we make available to financial institutions such as asset managers, banks and brokers.
What feeds these insights: your demographic data (age band, self-declared gender), your country, your investor profile, and your platform activity - for example which assets or themes attract attention.
What partners receive: aggregated, statistical results only. Age is shared as a band (for example 25-34), never as a date of birth. Gender is shared as a broad category. Partners receive no name, email address, phone number, account identifier or any other direct identifier, and no individual-level records.
Legal basis: your consent under Art. 6 (1) (a) GDPR, requested separately during registration. You may withdraw it at any time in your account settings or by contacting us; withdrawal removes your data from all future insight production.
Aggregation thresholds: we apply minimum cohort sizes before any figure is released, so that no result can be traced back to an individual user.
Partners only ever receive personal data that identifies you directly if you explicitly request a product or service from them through a "Partner Profile" page - and in that case we tell you before the data is sent.
6. Recipients and Processors
We use the following service providers. Those acting as processors are bound by data processing agreements pursuant to Art. 28 GDPR and may only process data on our instructions.
| Recipient | Purpose | Data |
|---|---|---|
| netcup GmbH | Hosting and infrastructure | All categories |
| Amazon Web Services | Hosting and infrastructure | All categories |
| PostHog | Product analytics, session replay | Usage data, technical data |
| Grafana Labs | Performance monitoring, error logs | Technical data |
| Customer.io | Transactional email, CRM, newsletters | Account, identity, contact data |
| Resend | Delivery of contact-form messages | Name, email address, message content |
| Google Ireland Ltd. / Google LLC | Sign-in with Google; Google Analytics 4; Google Ads | Identity data (sign-in), usage data, technical data |
| Meta Platforms Ireland Ltd. | WhatsApp Cloud API, delivery of one-time passcodes | Phone number |
| Financial Modeling Prep | Market data | Technical data |
| Content delivery networks | Delivery of images and static assets | Technical data |
Beyond this, we disclose personal data only where we are legally obliged to do so, or where it is necessary to assert or defend legal claims.
We do not sell personal data.
7. International Transfers
Our own infrastructure runs in Germany and the European Union, with one region in Brazil. Brazil has held a European Commission adequacy decision since 26 January 2026 (Art. 45 GDPR), so no additional safeguards are required for it.
Three recipients process data in the United States: Google, Meta and Resend.
For those transfers we rely on:
- the EU-US Data Privacy Framework (Art. 45 GDPR) where the recipient is certified, which covers Google LLC and Meta Platforms, Inc.; and
- the Standard Contractual Clauses pursuant to Art. 46 (2) (c) GDPR, supplemented by a transfer impact assessment and additional technical measures, for all remaining transfers.
You may request a copy of the relevant safeguards from us at any time.
Residual risk: despite these safeguards, authorities in third countries may be able to access data, and enforcing your rights there may be harder than within the EU.
8. Retention
We keep personal data only for as long as it is needed for the purpose it was collected for, or for as long as a statutory retention period requires.
| Data | Retention |
|---|---|
| Account data, investor profile, platform activity | For as long as your account exists |
| After you delete your account | Your personal data is anonymised immediately, and your profile is deleted from our email provider first. What remains carries no identifier and cannot be linked back to you. |
| Anonymous votes | 180 days after the last change, then deleted automatically |
| Anonymous watchlists | 180 days without activity, then deleted automatically |
| One-time passcodes | Deleted automatically once expired |
| Server and security logs | Only as long as needed to investigate a security or stability incident |
| Product analytics | For the retention period configured with our analytics provider |
| Consent records | For as long as needed to prove your consent under Art. 7 (1) GDPR |
| Accounting and tax records | 6 or 10 years (§ 257 HGB, § 147 AO) |
| Aggregated market-intelligence results | Indefinitely - these contain no personal data |
9. Your Rights
You have the right to:
- Access the personal data we hold about you (Art. 15 GDPR)
- Rectification of inaccurate or incomplete data (Art. 16 GDPR)
- Erasure (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability - a machine-readable copy (Art. 20 GDPR)
- Object to processing based on legitimate interests (Art. 21 (1) GDPR), and unconditionally to direct marketing (Art. 21 (2) GDPR)
- Withdraw consent at any time with effect for the future (Art. 7 (3) GDPR)
To exercise these rights: [email protected]. We respond within one month (Art. 12 (3) GDPR).
Right to lodge a complaint. You may lodge a complaint with a supervisory authority, in particular in the Member State of your residence, place of work or the place of the alleged infringement (Art. 77 GDPR). The authority responsible for us is:
Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 18, 91522 Ansbach, Germany
www.lda.bayern.de
10. Country-Specific Rights
Brazil (LGPD). Confirmation of processing; access; correction; anonymisation, blocking or deletion of unnecessary or excessive data; portability; information about the entities with which data has been shared; withdrawal of consent. Contact for Brazilian data subjects (Encarregado, Art. 41 LGPD): Friedrich Rösel, [email protected]
Peru (Ley N° 29733). ARCO rights - access, rectification, cancellation and opposition - and the right to complain to the Autoridad Nacional de Protección de Datos Personales.
Mexico (LFPDPPP). ARCO rights, plus the right to limit the use or disclosure of your data and to revoke consent.
Chile (Ley N° 19.628). Access, rectification, cancellation and blocking.
11. Is Providing Data Required?
Providing your email address, name, country, date of birth and gender is necessary to create an account: without them we cannot conclude or perform the user agreement (Art. 13 (2) (e) GDPR). Date of birth also serves to verify the minimum age of 16.
All other data - phone number, investor profile, marketing and market-intelligence consent - is voluntary. Not providing it does not affect your access to the Service.
12. Automated Decision-Making and Profiling
We do not use automated decision-making producing legal effects concerning you or similarly significantly affecting you within the meaning of Art. 22 (1) GDPR.
We do analyse usage behaviour to personalise content and to produce the aggregated insights described in Section 5. This analysis has no automated legal consequences for you, and you can object to it at any time (Section 9).
13. Children
The Service is directed at persons aged 16 and over. We do not knowingly process data of persons under 16. If we become aware of such an account, we will close it and delete the data.
14. Cookies and Tracking
Which cookies and comparable technologies we use, on what legal basis, and how you control them is set out in our separate Cookie Policy.
15. Data Security
We protect your data with encryption in transit (TLS), hashed passwords, access controls, rate limiting and separated environments. Personal identifiers in our telemetry are cryptographically hashed before export.
16. Changes
We will update this Privacy Policy when our processing changes. If a change materially affects your rights, we will notify you by email or through a prominent notice on the Service and, where the change relies on consent, ask for your consent again.