Privacy Policy
Effective date: August 28, 2026
1. Controller
The controller pursuant to Article 4(7) GDPR is:
asymmetric.vision GmbH
Kurfürstendamm 194, 10707 Berlin, Germany
Amtsgericht Charlottenburg · HRB 172365 B
Represented by the managing directors Daniel Rumpf and Johannes H. Göttsch
Email: getfunded@asymmetricvision.com
2. Scope
This policy applies to our public website at asymmetricvision.comand to the invite-only Asymmetric Insights platform (the “Portal”). It explains what personal data we collect, how we use it, and the rights you have under the GDPR.
3. Data we collect
- Access request: name, email address, firm, role, and free-form purpose.
- Account data: email address and authentication tokens (via Supabase Auth).
- Consent timestamps: when you accept the Terms, the GDPR consent, the NDA, and confirm accredited-investor status.
- Audit log: each login, report view, and administrative action is recorded with the acting user and timestamp.
- Server logs: standard HTTP request metadata (IP address, user agent, timestamp) retained for operational and security purposes.
4. Purposes and legal bases
- Evaluating and granting access to the Portal — legitimate interest (Art. 6(1)(f) GDPR) and consent (Art. 6(1)(a) GDPR).
- Enforcing confidentiality of Portal content via per-user watermarking and audit logs — legitimate interest in protecting our intellectual property and meeting regulatory expectations.
- Communicating about your account and the investment materials you have access to — performance of pre-contractual or contractual obligations (Art. 6(1)(b) GDPR).
- Sending research-publication notifications when you have explicitly opted in via the onboarding form or account settings — consent (Art. 6(1)(a) GDPR). Consent is confirmed via a double-opt-in email and can be withdrawn at any time via the unsubscribe link in every email or the toggle in Settings.
- Compliance with accounting, tax, and anti‑money‑laundering obligations — legal obligation (Art. 6(1)(c) GDPR).
5. Recipients and data processors
We engage the following processors under written data-processing agreements (Art. 28 GDPR):
- Supabase(Supabase Inc., USA; project hosted on AWS Frankfurt, eu-central-1) — database, authentication, email sign-in links, and document storage.
- Vercel(Vercel Inc., USA) — web hosting. Serverless functions are pinned to Vercel's Frankfurt region (fra1); the CDN serves static responses from the user's nearest edge.
- Google(Google Ireland Ltd., Ireland / Google LLC, USA) — Google Workspace hosts our email, including the delivery of account emails and the research-publication notifications you have opted in to.
Where a processor is located outside the EU/EEA, transfers are safeguarded by the Standard Contractual Clauses (Art. 46(2)(c) GDPR) and supplementary measures where required.
6. Storage location
Personal data is stored in Supabase's Frankfurt region (AWS eu-central-1). Server-side processing (Next.js server actions, API routes, server components) runs in Vercel's Frankfurt region (fra1). Access to operational infrastructure is restricted to authorised personnel and service accounts.
7. Retention
Portal account data is retained for the duration of your co-investor relationship and afterwards only for the period required by applicable law (in particular the German Commercial Code and tax law retention periods of up to 10 years). Audit log records are retained for at least 10 years for regulatory and compliance purposes. You can delete your account at any time; residual records required by law will be blocked for further processing (“Sperrung”) rather than deleted.
8. Your rights
- Access (Art. 15): export your profile and audit history as JSON from the Settings page.
- Rectification (Art. 16): request correction of inaccurate data by writing to us.
- Erasure (Art. 17): delete your account from the Settings page, subject to statutory retention.
- Restriction (Art. 18) and objection (Art. 21) to processing based on legitimate interest.
- Data portability (Art. 20): the JSON export is a portable, structured record.
- Withdrawal of consent (Art. 7(3)): you may withdraw consent at any time with effect for the future.
- Right to lodge a complaint: you may complain to the Berliner Beauftragte für Datenschutz und Informationsfreiheit or to the authority of your habitual residence.
9. Cookies and tracking
We use only strictly necessary cookies for authentication session management (Supabase Auth). We do not use analytics, advertising, or third-party tracking cookies.
10. Security
We use state-of-the-art transport encryption (TLS), row-level security on the database, service-role keys held only on the server, and per-user watermarking on confidential materials. We maintain an audit trail of every access to confidential content.
11. Changes to this policy
We may update this policy to reflect changes in our services or the law. Material changes will be communicated via the Portal or by email where appropriate.
12. Contact for privacy matters
Please direct any request related to this policy to getfunded@asymmetricvision.com.