QuanterLab
Articles Research Desktop Follow the research

Privacy Policy

Last updated: July 2026

This Privacy Policy explains how QuanterLab ("we", "us", "our") collects, uses, stores, and protects your personal data when you use our platform at quanterlab.com. We are committed to protecting your privacy in accordance with the EU General Data Protection Regulation (GDPR), the German Federal Data Protection Act (Bundesdatenschutzgesetz, BDSG), and the German Telecommunications Digital Services Data Protection Act (Telekommunikation-Digitale-Dienste-Datenschutz-Gesetz, TDDDG).

QuanterLab is currently operated as a closed beta. Paid subscriptions, billing, and payment processing are not yet active; the relevant sections will be added to this policy before any payment processing begins, and you will be notified by email.

1. Data Controller

QuanterLab UG (haftungsbeschränkt)
Jurastraße 27/1
72072 Tübingen
Germany
Registergericht: Amtsgericht Stuttgart, HRB 807236
Represented by the managing director (Geschäftsführer): Serhat Girgin
Email: contact@quanterlab.com

The company replaced the founder as data controller upon its entry in the commercial register; nothing about what data is collected, stored or shared changed with that transition. See the Impressum for the full registration details.

Because of the limited scale and nature of the processing carried out, no Data Protection Officer is required under Art. 37 GDPR / §38 BDSG. All data-protection inquiries are handled directly by the controller at the email address above.

2. Data We Collect

2.1 Account Data

When you register for an account, we collect:

  • Email address
  • Password (stored only as a salted, one-way hash (PBKDF2); we never store or have access to your plaintext password)
  • Account creation date
  • Email verification status

2.2 Platform Usage Data

As you use QuanterLab, we store:

  • Strategy configurations and backtest parameters
  • Paper trading instances and trade logs
  • Portfolio compositions and settings
  • Saved reports and analysis results

This data is stored exclusively to provide the service and is associated with your account.

2.3 Technical Data

Our servers automatically collect:

  • IP address (recorded in server access logs; retained for a limited period — see Section 5)
  • Browser type and version (from the HTTP User-Agent header)
  • URL of pages visited and timestamps
  • Referring URL

This data is collected via server access logs and is used solely for security monitoring, abuse prevention, and debugging.

3. Legal Basis for Processing

Data Category Legal Basis (GDPR) Purpose
Account data Art. 6(1)(b) — Contract performance Required to provide the service
Platform usage data Art. 6(1)(b) — Contract performance Storing your strategies, portfolios, and trades
Technical data Art. 6(1)(f) — Legitimate interest Security, abuse prevention, and debugging
Transactional email Art. 6(1)(b) — Contract performance Verification, password reset, service notifications

4. Third-Party Processors

We share personal data only with the following processors, each bound by a data processing agreement (Auftragsverarbeitungsvertrag) pursuant to Art. 28 GDPR:

Processor Purpose Data Shared Location / Safeguards
Hetzner Online GmbH Server hosting and database All platform data Germany (Nuremberg) — EU/EEA, no third-country transfer
Anthropic PBC AI assistant (“Quantin”) and the optional Claude connector (MCP) The chat messages you send and the on-screen research context you submit — which may include your saved backtests, strategy configurations, portfolio holdings, tickers and profit/loss figures. Only sent when you use the assistant. United States — transfer covered by EU Standard Contractual Clauses (SCCs)
Resend (Resend, Inc.) Transactional email delivery (verification, password reset, trade and daily-digest emails) Email address and email content — including, for trade and portfolio digest emails, tickers, positions, prices and profit/loss figures United States — transfer covered by EU Standard Contractual Clauses (SCCs) and the EU-US Data Privacy Framework
Financial Modeling Prep (FMP) Market data and fundamentals API No user data shared — API requests carry only an account-wide API key United States

Where data is transferred outside the EU/EEA, we ensure adequate safeguards through EU Standard Contractual Clauses (SCCs) or, where applicable, the EU-US Data Privacy Framework. You may request a copy of the relevant safeguards by emailing us at contact@quanterlab.com.

5. Data Retention

  • Account data: retained for the duration of your account. Upon account deletion, personal data is removed within 30 days, except where statutory retention obligations apply.
  • Platform usage data (strategies, backtests, paper-trading logs): deleted within 30 days of account closure.
  • Server access logs: automatically purged after 90 days, unless required for the investigation of a specific security incident.
  • Email delivery records: retained by Resend for 30 days for deliverability diagnostics.

6. Your Rights

Under the GDPR, you have the right to:

  • Access — request a copy of all personal data we hold about you (Art. 15)
  • Rectification — correct inaccurate personal data (Art. 16)
  • Erasure — request deletion of your personal data ("right to be forgotten") (Art. 17)
  • Restriction — restrict processing of your data (Art. 18)
  • Data portability — receive your data in a structured, machine-readable format (Art. 20)
  • Objection — object to processing based on legitimate interest (Art. 21)
  • Withdrawal of consent — where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing (Art. 7(3))

You can exercise the most common rights yourself, at any time, from Settings: Download my data gives you a complete, machine-readable copy of your personal data (Access and Portability), and Delete account erases it — your account is locked immediately and all data is permanently removed within 30 days.

To exercise any other right, email us at contact@quanterlab.com. We respond within 30 days as required by Art. 12(3) GDPR. Identification is verified through the email address associated with your account.

7. Cookies

We use only strictly necessary cookies required for the platform to function (session, cookie consent acknowledgement). We do not use advertising, tracking, or analytics cookies. For details, see our Cookie Policy.

8. Marketing and Newsletters

We do not send marketing emails. All emails you receive from us are transactional — account verification, password reset, security notifications, and material changes to these legal documents. If a marketing programme is introduced in the future it will be strictly opt-in and you will be able to unsubscribe at any time.

9. Automated Decision-Making and Profiling

We do not use your personal data for automated decision-making or profiling within the meaning of Art. 22 GDPR. The quantitative tools available on the platform operate on the market data and configurations you choose; they do not produce personal scores or rankings about you.

10. Data Security

We implement appropriate technical and organizational measures to protect your data:

  • All traffic to quanterlab.com is encrypted over HTTPS/TLS
  • Passwords are stored only as a salted, one-way hash (PBKDF2) and never in plaintext
  • Database access is restricted and all traffic is encrypted in transit; the database is not reachable from the public internet
  • Servers are kept current with security updates and are monitored for unusual activity
  • Database backups are created daily and retained only for the period needed for disaster recovery

11. Children's Privacy

QuanterLab is not intended for use by individuals under the age of 18. We do not knowingly collect personal data from minors. If we become aware that we have collected data from a person under 18, we will delete it promptly.

12. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email to registered users at least 30 days before they take effect. The "Last updated" date at the top of this page reflects the most recent revision.

13. Supervisory Authority

You have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority competent for our location is:

Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg
Lautenschlagerstraße 20, 70173 Stuttgart, Germany
www.baden-wuerttemberg.datenschutz.de

You may also contact the supervisory authority of your habitual residence or place of work in the EU/EEA.

Impressum Terms of Service Cookie Policy Financial Disclaimer
QuanterLab Articles About Research feed Pricing Impressum Privacy Policy Terms Cookie Policy Disclaimer
QuanterLab · quantitative research platform. Educational content only; nothing here is investment advice.
QuanterLab - Design, validate and forward-test market strategies | Product Hunt

This site uses essential cookies for authentication and security. See our Cookie Policy.