Privacy policy
As of: September 2026 · This is a translation for your convenience. The German version is legally binding.
1. Controller
The controller responsible for processing personal data on budgentis.com is:
Mark Dannenberg
Nachtweide 6a
76744 Wörth am Rhein
Germany
Email: dannenberg.mark@gmail.com
No data protection officer has been appointed, as there is no legal obligation to do so.
2. Principles
budgentis is built to collect as little data as possible. There is no tracking, no analytics services, no advertising and no embedding of external content (e.g. fonts, maps or videos from third parties). All pages and fonts are loaded directly from our server. The connection is encrypted via SSL/TLS (recognisable by “https://”).
3. Visiting the website – server log files
With every request, the web server automatically stores technical access data: date and time, requested page, amount of data transferred, status code, browser and operating system, referrer URL and the IP address. The IP address is stored only in shortened (anonymised) form, so that it can no longer be attributed to a person.
Purpose: secure and stable operation of the website, detection of faults and attacks. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in secure operation). The log files are deleted automatically by the host after a short time.
4. Hosting
The website and database are operated by ALL-INKL.COM – Neue Medien Münnich, owner René Münnich, Hauptstraße 68, 02742 Friedersdorf, Germany, on servers in Germany. A data processing agreement pursuant to Art. 28 GDPR has been concluded with the host. The host processes the data exclusively on our instructions.
5. User account
An account is required to use budgentis. For this we process:
- Email address – as user name and for resetting the password,
- Password – exclusively as an encrypted hash (bcrypt), never in plain text; nobody – not even the operator – can read it,
- Time of registration and of the last login.
Purpose: providing your personal account. Legal basis: Art. 6(1)(b) GDPR (contract of use). Providing an email address and password is required for use; without them no account can be created. Storage period: until you delete your account.
6. The financial data you enter
Everything you enter in budgentis – income and expenses, account balances, investments (e.g. purchases of stocks, ETFs, cryptocurrencies or precious metals) and loans – is stored in the database, assigned to your account. This data is used exclusively to display it to you and to perform calculations for you. It is not analysed, not passed on to third parties and not used for advertising. You decide yourself which information you enter – online banking credentials, IBANs or account numbers are not required and should not be entered.
Legal basis: Art. 6(1)(b) GDPR. Storage period: until you delete the data or your account. Backup copies made by the host are overwritten on a regular basis.
7. Cookies
budgentis uses only technically necessary cookies:
- “budgentis” – contains a random session ID so that you stay logged in after logging in. It is deleted when you close the browser or log out; in addition, the session ends automatically after 12 hours of inactivity.
- “bg_lang” and “bg_theme” – are only set if you change the language (German/English) or the theme (light/dark/automatic) yourself, and store only this choice (value e.g. “en” or “dark”) for one year. They contain no identifier and are not analysed.
The legal basis for storing the cookies is Section 25(2) no. 2 TDDDG (strictly necessary for the service you requested or the setting you chose); for the processing, Art. 6(1)(b) GDPR. No consent is required for this. No tracking or marketing cookies are used.
8. Protection against misuse
To protect against password guessing, we store the IP address, the email address entered and the time for login, registration and “forgot password” attempts. After several failed attempts, login is temporarily blocked. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the security of the accounts). These entries are deleted after 24 hours at the latest.
9. Forgot password (sending emails)
If you request a new password, we send an email with a link to your registered address. For this, a one-time code (only as a hash) with an expiry time is stored. The link is valid for one hour; the data is deleted after use or at the latest one day after expiry. The email is sent via our host’s mail server (see no. 4). Legal basis: Art. 6(1)(b) GDPR.
10. Price data
To display current prices, our server (not your browser) requests prices from CoinGecko (cryptocurrencies) and Yahoo Finance (stocks and ETFs). Only the respective symbol or ISIN of the security or coin is transmitted – no personal data about you, not even your IP address.
11. Contact by email
If you send me an email, I process your details (email address, content of the message) to handle your request. Legal basis: Art. 6(1)(b) or (f) GDPR. The message is deleted once the request has been dealt with and no statutory retention obligations apply. Emails are received via Google Mail (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland).
12. No automated decision-making
There is no automated decision-making, including profiling, within the meaning of Art. 22 GDPR. Calculations in budgentis (e.g. totals, holding periods) serve only your own overview.
13. Your rights
You have the right at any time to
- access the data stored about you (Art. 15 GDPR),
- rectification of inaccurate data (Art. 16 GDPR),
- erasure (Art. 17 GDPR) – you can delete your account including all data yourself at any time under “Account”,
- restriction of processing (Art. 18 GDPR),
- data portability (Art. 20 GDPR) – via “Download backup” you can get all your data as a file (JSON) at any time,
- object to processing based on Art. 6(1)(f) GDPR on grounds relating to your particular situation (Art. 21 GDPR).
An email to the address above is sufficient to exercise your rights.
14. Right to lodge a complaint
You can lodge a complaint with a data protection supervisory authority. The competent authority is:
Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Rheinland-Pfalz
Hintere Bleiche 34, 55116 Mainz, Germany
Email: poststelle@datenschutz.rlp.de · www.datenschutz.rlp.de
15. Minimum age
budgentis is intended for persons aged 16 and over.
16. Changes
This privacy policy will be adapted if budgentis or the legal situation changes. The version published here applies.
Back