Legal
Prospectus & Holdings Alignment Privacy Policy
- Version
- 1.0
- Effective date
- 28 August 2026
- Controller
- AP Digital Solutions GbR
- Contact
- info@apdigitalsolutions.eu
Privacy at a glance
AP Digital Solutions GbR (AP Digital, we, us or our) provides a business-to-business service that compares information in U.S. fund prospectuses and other official filings with publicly reported holdings information.
- The fund and filing information analysed by the Service is obtained principally from official, publicly available SEC EDGAR records. We do not need private investor records or non-public portfolio data to provide the standard Service.
- We nevertheless process personal information when a person visits the website, creates or uses a business account, buys a subscription, generates an API key, connects an AI assistant, requests support or contacts us.
- The standard Service is not designed for confidential datasets or personal information about investors, employees, customers or other individuals. Please do not submit that information.
- We do not sell personal information, share it for cross-context behavioural advertising, use it for targeted advertising, or use it to make decisions producing legal or similarly significant effects about individuals.
- We provide privacy rights to U.S. residents as described in Section 14, including a specific California notice in Section 15.
This Privacy Policy explains how we collect, use, disclose, retain and protect personal information in connection with the Prospectus & Holdings Alignment website, accounts, subscriptions, application programming interfaces, model-context-protocol connector, outputs, communications and related support (together, the Service).
1. Who we are and how to contact us
AP Digital Solutions GbR is the controller or business responsible for the personal information described in this Privacy Policy.
AP Digital Solutions GbR
Schultestraße 25
57076 Siegen
Germany
Email: info@apdigitalsolutions.eu
Please put Privacy Request in the subject line when exercising a privacy right, and Privacy Appeal in the subject line when appealing a decision on a request.
2. Scope and roles
2.1 Information covered
This Privacy Policy applies to personal information processed through or in connection with the Service, including information about:
- website visitors;
- prospective and current business customers;
- account administrators and authorised users;
- persons who contact us or request a demonstration;
- suppliers, advisers and business contacts; and
- persons named in public regulatory filings that the Service retrieves or analyses.
It does not apply to a third party's independent processing, including processing by a payment provider, an AI assistant selected by the user, the SEC, a linked website or another third-party service. Those parties provide their own privacy notices.
2.2 Controller and processor roles
For the standard Service, AP Digital determines why and how account, website, subscription, security, support and service-usage information is processed and acts as a controller or business.
The standard Service is designed to analyse public filing information rather than personal datasets supplied by a customer. AP Digital does not agree to act as a processor or service provider for customer-controlled personal datasets merely because a user enters a query or uses an integration. If a separately signed enterprise agreement requires AP Digital to process personal data on a customer's documented instructions, the parties must enter into appropriate data-processing terms before that data is submitted.
2.3 Business-only service
The Service is intended for business and professional users who are at least 18 years old. It is not directed to consumers for personal, family or household purposes, or to children.
3. Public filing information
3.1 Sources and use
The Service retrieves and analyses information from official public sources, principally SEC EDGAR, including prospectuses, registration statements, shareholder reports and public N-PORT holdings information. Public filings may contain fund, issuer and portfolio information and may also identify directors, officers, signatories, advisers or other professional contacts.
We use Public Source Data to:
- locate and retrieve relevant filings;
- extract and normalise stated policies, objectives, classifications and holdings;
- generate and reproduce scorecards and source-linked Outputs;
- maintain auditability, source provenance and methodology testing;
- identify filing changes, corrections or inconsistencies; and
- improve extraction accuracy and the reliability of the Service.
We do not use names or business contact details appearing in public filings to build consumer profiles, conduct targeted advertising, determine an individual's eligibility for a product or service, or enrich the filings with non-public consumer data.
3.2 Effect of public availability
Some U.S. privacy laws exclude information lawfully made available from federal, state or local government records from their definition of personal information. Where such an exclusion applies, the statutory rights described below may not apply to the relevant public filing information.
Public availability is not, however, a universal exemption under every privacy law. We therefore describe this processing transparently, limit it to the Service purposes above and provide a contact route for concerns. We may retain a public record, source citation or factual correction where reasonably necessary to preserve the accuracy, provenance and reproducibility of an Output or to establish, exercise or defend legal claims.
4. Personal information we collect
The information we collect depends on how a person interacts with the Service. We may collect the following categories.
4.1 Identity, contact and professional information
This may include:
- name;
- work email address and business telephone number;
- employer or organisation, job title, department and professional role;
- business address, country and time zone;
- team size and purchasing or account authority; and
- information included in a demonstration request, contact form, order or business communication.
4.2 Account, authentication and security information
This may include:
- account and user identifiers;
- password hashes and authentication information;
- multi-factor authentication status and recovery information;
- sign-in timestamps, session identifiers and access history;
- IP address, device and browser attributes used for authentication or fraud prevention;
- account permissions, team membership and administrator actions; and
- API-key identifiers, creation and revocation dates, scopes, last-used information and related security logs.
We do not intend to receive a user's plaintext password. Credentials are handled through authentication controls designed to protect them.
4.3 Subscription, transaction and billing information
This may include:
- selected plan, seats, billing interval and subscription status;
- business billing name and address, tax status and tax identifiers where required;
- invoice, payment, refund and cancellation history;
- transaction identifiers and limited payment-card metadata, such as card brand, expiry month and last four digits, received from the payment provider; and
- records of acceptance of recurring-payment terms.
Our payment provider, rather than AP Digital, is intended to collect and process complete payment-card numbers and card verification values. Its processing is governed by its own privacy notice and terms.
4.4 Service inputs, usage and Output information
This may include:
- fund names, tickers, CIKs, filing selections and analysis instructions;
- Reviews requested, feature use, plan consumption and timestamps;
- generated scorecards, classifications, source links, exports and saved history;
- annotations, feedback and non-confidential messages entered into the Service;
- API requests and responses, MCP request metadata and integration events;
- user-selected settings and preferences; and
- diagnostic information associated with an error or support request.
The standard Service does not require personal information about investors, employees or other individuals. Users must not submit confidential holdings, material non-public information or sensitive or regulated personal information.
4.5 Device, network and website information
This may include:
- IP address;
- browser type and version, operating system and device type;
- referring page, pages viewed, links selected and navigation events;
- session timing, language and display settings;
- approximate location derived from IP address, such as country or region, but not precise GPS location;
- cookie, local-storage and similar technical identifiers; and
- performance, crash, security and fraud signals.
4.6 Communications and support information
This may include correspondence, call or meeting details, support tickets, feedback, survey responses, and information reasonably needed to investigate or resolve a request.
4.7 Inferences
We may infer limited information needed to operate the Service, such as likely business region, plan needs, account risk, preferred features or whether activity appears automated or abusive. We do not create sensitive consumer profiles or use these inferences to make decisions producing legal or similarly significant effects about an individual.
4.8 Sensitive personal information
Account credentials and authentication information may constitute sensitive personal information under some laws. We use that information only to provide, authenticate, secure and administer the Service and for other purposes permitted without a separate right to limit use.
We do not seek to collect Social Security numbers, government identification numbers, precise geolocation, biometric templates, health information, genetic information, racial or ethnic origin, religious beliefs, sexual orientation, union membership, contents of private consumer communications, or similar highly sensitive information through the standard Service. Do not submit such information.
5. How we collect personal information
We collect information:
- directly from the individual, such as during registration, checkout, use of the Service, a support request or a contact form;
- from the relevant organisation, such as when an administrator creates or manages an account or an employer identifies an authorised user;
- automatically from devices and systems, through logs, cookies, local storage, authentication controls and security or diagnostic tools;
- from service providers, such as authentication, hosting, payment, communication, security and support providers;
- from user-directed integrations, such as an MCP-compatible AI assistant or API client;
- from official public sources, principally SEC EDGAR; and
- from lawful business sources, such as professional directories, event registrations, referrals or publicly available company websites, where relevant to a business relationship.
6. Why we use personal information
We use personal information for the following purposes.
6.1 Provide and administer the Service
We use information to register users, authenticate access, manage teams and permissions, process Reviews, generate and save Outputs, enable exports and integrations, administer API keys, provide support and perform our agreement with the customer.
6.2 Manage subscriptions and transactions
We use information to present plans, process payments, issue invoices and tax records, manage renewals and cancellations, prevent payment fraud and maintain evidence of subscription authorisation.
6.3 Secure the Service
We use information to protect accounts, credentials, Public Source Data, systems and users; detect abuse, malware, suspicious access or policy violations; investigate incidents; enforce rate limits and plan restrictions; and maintain logs and backups.
6.4 Maintain, test and improve functionality
We use usage, diagnostic and feedback information to understand performance, correct errors, test extraction and scoring, develop features and improve usability. We may use aggregated or de-identified statistics for these purposes.
We do not intentionally use private account prompts, saved Review history or customer account data to train a general-purpose third-party AI model unless the customer expressly agrees in writing.
6.5 Communicate
We use contact information to provide service notices, security messages, billing communications, responses to enquiries, demonstrations, customer-success communications and information about relevant AP Digital services. A recipient may opt out of non-essential marketing at any time. Transactional and security messages may still be sent.
6.6 Comply with law and protect rights
We use and preserve information where reasonably necessary to comply with tax, accounting, sanctions, law-enforcement, regulatory and other legal requirements; respond to lawful requests; establish, exercise or defend legal claims; protect individuals and property; and enforce our agreements.
6.7 Corporate transactions
We may use and disclose information to evaluate or complete a financing, reorganisation, merger, acquisition, asset sale or similar transaction, subject to appropriate confidentiality and legal safeguards.
7. Legal bases for processing in the EEA, United Kingdom and similar jurisdictions
Where applicable law requires a legal basis, we rely on one or more of the following:
- contractual necessity, to create and administer an account, provide the Service, process a subscription and respond to requests made before entering into a contract;
- legitimate interests, including operating and improving a secure B2B service, analysing official public filings, supporting customers, preventing misuse, protecting legal rights and carrying out proportionate business communications, balanced against the rights and interests of affected individuals;
- legal obligations, including tax, accounting, sanctions, security, regulatory and lawful-disclosure duties;
- consent, for optional marketing, non-essential cookies or another activity where consent is the appropriate basis; and
- establishment, exercise or defence of legal claims, where relevant.
Where we rely on consent, it may be withdrawn at any time without affecting earlier lawful processing. Where we rely on legitimate interests, an individual may object as described in Section 17.
8. How we disclose personal information
We may disclose personal information to the following categories of recipients for the purposes described in this Policy.
8.1 The customer's organisation
Account administrators and other authorised personnel may see account identity, business contact information, team membership, permissions, activity, saved history, subscription status, support matters and audit information associated with their organisation. A customer is responsible for its own use of information made available through organisational administration functions.
8.2 Service providers and contractors
We may use providers of:
- cloud hosting, storage, content delivery and database services;
- identity, authentication and access management;
- payment processing, invoicing and tax support;
- email, support, customer-relationship and business communications;
- system monitoring, error diagnostics, analytics and product operations;
- security, fraud prevention, logging, backup and incident response; and
- professional services, including legal, accounting, audit and insurance.
These recipients may process information only for contracted purposes, subject to appropriate confidentiality, security and data-protection terms. Where U.S. state law applies, we use service-provider or contractor terms designed to restrict retention, use and disclosure outside the contracted business purpose.
8.3 User-directed AI assistants and integrations
When a user configures the MCP Connector, calls an API through another product or otherwise directs information to a third-party AI assistant or integration, the information necessary to fulfil that request may be transmitted to and processed by that third party. Section 9 explains this processing.
8.4 Authorities and persons involved in legal matters
We may disclose information where reasonably necessary to comply with law or a binding request; protect rights, safety and security; investigate fraud or misuse; enforce agreements; or establish, exercise or defend legal claims.
8.5 Corporate transaction recipients
Information may be disclosed under confidentiality protections to prospective or actual investors, lenders, acquirers, sellers and professional advisers in connection with a corporate transaction. A successor may continue to use information subject to this Policy or provide notice of materially different practices.
8.6 With consent or at the individual's direction
We may disclose information for another purpose explained at the time, with valid consent or at the individual's direction.
9. MCP Connector, APIs and third-party AI services
The Service may allow a user to create an API key and connect the Service to an MCP-compatible client or third-party AI assistant, including a service chosen and controlled by the user.
When such a connection is used:
- the third party may receive the user's prompt, fund identifier, instructions, portions of an Output, source information, request metadata and any other information the user chooses to provide through that third party;
- AP Digital may receive an authenticated request, the information required to process it, technical metadata and the resulting usage record;
- the third party acts under its own terms and privacy notice and may store, review, use or train on information according to the user's account settings and its own practices;
- the customer is responsible for approving the integration, selecting appropriate privacy and training settings, controlling who can use it and ensuring that its use is lawful; and
- users must not place AP Digital API keys, passwords, confidential information, material non-public information or personal information about other individuals into an AI prompt or an insecure location.
AP Digital does not control an independent AI provider's processing. Disconnecting an integration prevents new requests but may not delete information already retained by the third party. Deletion requests concerning that information should also be directed to the relevant third party.
10. Cookies, local storage and tracking preferences
10.1 Technologies we use
The Service may use cookies, local storage, session identifiers and similar technologies that are necessary or reasonably useful to:
- keep a user signed in and maintain a secure session;
- remember privacy, language and display preferences;
- balance traffic and maintain availability;
- prevent fraud and protect accounts;
- measure service reliability, diagnose errors and understand aggregate use; and
- preserve a user's selections during registration or checkout.
At the effective date of this Policy, AP Digital does not use advertising cookies or permit third-party advertising networks to track users across unaffiliated websites for targeted advertising. We do not sell or share personal information for cross-context behavioural advertising.
Where applicable law requires consent for a non-essential cookie or similar technology, we will request consent before using it. A user can also manage cookies through browser settings, although blocking necessary technologies may prevent sign-in or other functions.
10.2 Do Not Track and universal opt-out signals
Some browsers transmit a Do Not Track signal, but there is no single industry standard governing that signal. Because we do not use cross-site advertising tracking, the Service does not currently change its essential operations in response to a Do Not Track setting.
Where required by applicable U.S. state law, we treat a recognised universal opt-out mechanism, such as the Global Privacy Control, as a request to opt out of sale, sharing or targeted advertising for the browser or device from which the signal is received. Because AP Digital does not engage in those activities at the effective date, the signal should not produce a visible change. We will update this Policy and the Service if our practices change.
11. Sale, sharing, targeted advertising and automated decisions
AP Digital does not:
- sell personal information for money or other valuable consideration;
- share personal information for cross-context behavioural advertising as defined by California law;
- process personal information for targeted advertising as defined by applicable U.S. state privacy laws;
- provide personal information to third parties for their own direct marketing; or
- profile individuals in furtherance of decisions producing legal or similarly significant effects concerning access to credit, employment, housing, insurance, education, essential services or another comparable opportunity.
We do not offer a financial incentive, price difference or loyalty programme in exchange for personal information. We do not knowingly sell or share personal information of individuals under 18.
A disclosure to a contracted service provider, the customer's own organisation, or a third party acting at the user's direction is not treated as a sale or targeted-advertising disclosure where applicable law provides an exclusion and the legal conditions are met.
12. Retention
We retain personal information only for as long as reasonably necessary for the purpose for which it was collected, including to provide the Service, preserve security and auditability, comply with legal duties and establish or defend claims. Retention may vary according to the nature and sensitivity of the information, the amount and context of processing, the risk of harm, the user's settings, contractual commitments and legal requirements.
Our intended standard retention periods are:
| Information | Intended standard period |
|---|---|
| Active account, profile and organisation information | For the life of the account or business relationship |
| Closed account information | Normally deleted or de-identified within 24 months after closure, except information needed for legal, security, billing or suppression purposes |
| Saved Reviews, Outputs and user history | While the account is active; normally deleted or de-identified within 90 days after account closure, subject to plan settings, legal holds and backup cycles |
| API, access and audit logs | Normally up to 12 months; shorter operational logs may be retained for less time and security-relevant records may be retained longer when necessary |
| Security and authentication event logs | Normally up to 180 days, or longer where needed to investigate an incident, misuse or legal claim |
| Contact-form, demonstration and ordinary sales enquiries | Normally up to 12 months after the last substantive interaction, unless a business relationship begins or the recipient opts out sooner |
| Support communications | Normally up to 24 months after resolution, or longer where needed for an ongoing account, product issue or claim |
| Billing, invoice, tax and transaction records | For the period required by applicable tax, accounting and commercial law, which may be up to 10 years in Germany |
| Subscription consent, Terms acceptance, privacy requests and opt-out records | Normally five years or the applicable limitation period, whichever is longer where reasonably necessary |
| Public filings, source extracts, provenance and methodology records | For as long as reasonably useful to provide, verify or reproduce the relevant Output, maintain source integrity or resolve a dispute |
| Backups | Cycled out in accordance with the backup schedule, normally within 90 days after deletion from active systems, unless isolated for security or legal reasons |
We may retain a minimal suppression record to respect an opt-out, or information needed to demonstrate compliance. Deletion from active systems may not immediately remove information from encrypted backups; backed-up information is protected, not restored for ordinary use and deleted through the normal cycle.
13. Security and incident response
We use administrative, technical and physical safeguards designed to protect personal information against accidental or unlawful destruction, loss, alteration, unauthorised disclosure and access. Depending on the information and system, these safeguards may include access controls, role-based permissions, credential hashing, multi-factor authentication, encryption in transit and at rest, logging, monitoring, backups, vulnerability management, personnel confidentiality, service-provider review and incident-response procedures.
No online service can guarantee absolute security. Users must protect passwords and API keys, use appropriate endpoint security, revoke credentials that may be compromised and promptly report suspected unauthorised access to info@apdigitalsolutions.eu.
Where a security incident triggers a legal notification duty, we will investigate and provide notices to affected persons and authorities as required by applicable law.
14. U.S. state privacy rights
14.1 Rights we provide
Subject to applicable exceptions, verification and the scope of the relevant law, a U.S. resident may request that we:
- confirm and provide access to personal information we process about the resident;
- correct inaccurate personal information;
- delete personal information;
- provide a portable copy of personal information supplied by or concerning the resident, where required and technically feasible;
- provide information about the categories of personal information, sources, purposes and categories of recipients;
- where required, provide a list of specific third parties to which personal information was disclosed;
- opt the resident out of sale, sharing, targeted advertising or qualifying profiling;
- limit certain uses or disclosures of sensitive personal information, where the right applies;
- withdraw consent for processing based on consent; and
- appeal a refusal or material limitation of a request where applicable law provides an appeal right.
Because AP Digital does not sell personal information, share it for cross-context behavioural advertising, use it for targeted advertising or conduct qualifying profiling, an opt-out request will ordinarily be recorded but will not require a change to those practices.
We generally extend the access, correction, deletion and portability process to U.S. residents even where a particular state law does not require every right. This voluntary extension does not remove an exception, privilege, retention duty or other rule allowed by applicable law.
14.2 How to submit a request
Send an email to info@apdigitalsolutions.eu with the subject Privacy Request and state:
- the request being made;
- the state of residence;
- the email address associated with the account or communication; and
- enough information to locate the relevant records.
Do not send government identification documents unless we specifically and lawfully request them. We may verify identity by confirming control of the relevant email account, checking account information, requesting a signed declaration or using another proportionate method. The verification level will depend on the sensitivity of the information and the risk of harm from unauthorised disclosure or deletion.
An authorised agent may make a request where permitted by law. We may require proof of the agent's authority and may verify the resident's identity or direct confirmation, unless a valid power of attorney removes that requirement.
14.3 Timing, appeals and non-discrimination
We will acknowledge and respond within the period required by applicable law, ordinarily within 45 days. Where permitted, we may extend the response period and will explain the reason. We do not normally charge for a request, but may charge or decline to act where applicable law permits this because requests are manifestly unfounded, excessive or repetitive.
To appeal a decision, email info@apdigitalsolutions.eu with the subject Privacy Appeal within 60 days after receiving the decision and explain the basis of the appeal. We will respond within the legally required period and, where required, explain how to contact the relevant state attorney general.
We will not unlawfully discriminate against a person for exercising a privacy right. This means we will not deny a service, charge a different price or provide a different level of service because a person made a request, except where a difference is reasonably related to the value of information or otherwise permitted by law.
14.4 Exceptions
A request may be limited or denied where permitted by law, including where information is needed to:
- complete a transaction or provide the Service requested;
- protect security, prevent fraud or investigate misuse;
- comply with tax, accounting, recordkeeping or other legal duties;
- exercise free-speech or other legal rights;
- establish, exercise or defend legal claims;
- preserve evidence or comply with a legal hold;
- maintain internal uses reasonably aligned with expectations and law;
- protect another person's rights; or
- retain official public-record information that applicable law excludes from the relevant statutory definition.
We will explain a denial unless law prohibits the explanation.
15. California privacy notice
This Section supplements the rest of this Privacy Policy for California residents and is intended to satisfy the California Consumer Privacy Act, as amended (CCPA), and the California Online Privacy Protection Act (CalOPPA).
15.1 Categories collected, sources, purposes and disclosures
The table describes categories of personal information we may have collected during the preceding 12 months. Whether a category applies to a particular person depends on the interaction with the Service.
| California category | Information, sources and purposes | Disclosures and sale/share status |
|---|---|---|
| Identifiers | Examples: Name, work email, business address, account ID, IP address, online identifiersMain sources: Individual, organisation, device, service providersPurposes: Accounts, Service delivery, support, security, billing, communications, compliance | Business-purpose recipients: Customer administrators; hosting, authentication, payment, communication, support and security providers; advisers and authorities where requiredSold/shared: No |
| Customer-record information under California Civil Code section 1798.80 | Examples: Name, business address, telephone number, payment and billing detailsMain sources: Individual, organisation, payment providerPurposes: Contracting, billing, tax, support, fraud prevention | Business-purpose recipients: Payment, invoicing, tax, support and professional-service providersSold/shared: No |
| Commercial information | Examples: Plan, subscription, transaction, renewal, cancellation, Review and service historyMain sources: Individual, account, payment provider, ServicePurposes: Provide and administer plans, billing, analytics, support and records | Business-purpose recipients: Customer administrators; payment, hosting, support and analytics providersSold/shared: No |
| Internet or other electronic network activity | Examples: Browsing and Service interaction, session and login events, device/browser data, API activity, diagnosticsMain sources: Device, browser, Service and security providersPurposes: Functionality, authentication, security, diagnostics, capacity and improvement | Business-purpose recipients: Hosting, authentication, monitoring, analytics, support and security providersSold/shared: No |
| Geolocation data | Examples: Approximate country or region inferred from IP addressMain sources: Device and network providersPurposes: Security, localisation, tax and fraud prevention | Business-purpose recipients: Hosting, security, payment and tax providersSold/shared: No; no precise geolocation is sought |
| Professional or employment-related information | Examples: Employer, title, department, professional role, work contact informationMain sources: Individual, organisation, public business sourcesPurposes: B2B account administration, support, sales and communications | Business-purpose recipients: Customer administrators; communication, support and professional-service providersSold/shared: No |
| Inferences | Examples: Likely region, plan needs, feature preferences or account-risk indicatorsMain sources: Information above and Service activityPurposes: Security, customer support, product administration and improvement | Business-purpose recipients: Relevant hosting, security, support and analytics providersSold/shared: No |
| Sensitive personal information | Examples: Account log-in credentials and authentication informationMain sources: Individual, authentication provider, ServicePurposes: Account access, authentication, security and fraud prevention | Business-purpose recipients: Authentication, hosting and security providersSold/shared: No; used only for permitted operational purposes |
We may also process official Public Source Data from SEC EDGAR. To the extent that information is lawfully made available from federal government records, it may be excluded from the CCPA definition of personal information. We do not sell or share Public Source Data to profile or target individuals.
During the preceding 12 months, we may have disclosed each applicable category above to the corresponding service-provider, contractor or other recipient categories for the stated business purposes. We have not sold personal information or shared it for cross-context behavioural advertising.
15.2 California rights
California residents may have the right to:
- know the categories and specific pieces of personal information collected;
- know the categories of sources, purposes and recipients;
- correct inaccurate personal information;
- delete personal information, subject to exceptions;
- obtain a portable copy;
- opt out of sale or sharing;
- limit use or disclosure of sensitive personal information where it is used beyond legally permitted purposes; and
- receive equal service and pricing when exercising a right.
AP Digital does not currently engage in sale or sharing and does not use sensitive personal information for purposes that trigger the CCPA right to limit. We therefore do not display a Do Not Sell or Share My Personal Information or Limit the Use of My Sensitive Personal Information link. A California resident may nevertheless submit either request through the method in Section 14, and we will record and act on it as required.
15.3 Notice at collection
At or before collection, we provide a short notice identifying the relevant categories and purposes and a link to this Policy. Appendix A contains the notice text intended for the account-registration, contact and billing interfaces. We do not retain a category for longer than reasonably necessary for the disclosed purposes, subject to Section 12.
15.4 California minors and financial incentives
The Service is not intended for individuals under 18. We do not knowingly sell or share the personal information of anyone under 18. We do not provide a financial incentive or price or service difference in exchange for personal information.
15.5 Direct marketing and tracking disclosures
We do not disclose personal information to third parties for their own direct-marketing purposes. California residents may still contact us regarding California Civil Code section 1798.83 using the details in Section 1.
Section 10 explains our response to browser Do Not Track settings, universal opt-out signals and whether other parties collect information over time and across third-party websites. We do not authorise advertising networks to conduct cross-site targeted advertising through the Service.
16. New York privacy and security information
We extend the request process in Section 14 to New York residents. In addition, we maintain a data-security programme designed to include reasonable administrative, technical and physical safeguards appropriate to the size and complexity of our business, the nature and scope of our activities and the sensitivity of the information processed. This includes proportionate service-provider safeguards and secure disposal practices.
We do not sell personal information, conduct targeted advertising or permit advertising networks to track users across unaffiliated services. We will provide security-incident notices to New York residents and the relevant authorities where required by New York law.
Nothing in this Section limits a right or remedy available under New York law, including laws concerning data security, breach notification, deceptive practices, automatic renewal or cancellation.
17. EEA, United Kingdom and Swiss rights
Depending on applicable law, an individual may have the right to:
- access personal data and receive information about its processing;
- correct inaccurate or incomplete data;
- erase data in specified circumstances;
- restrict processing;
- receive data in a structured, commonly used and machine-readable format and transmit it to another controller;
- object to processing based on legitimate interests, including direct marketing;
- withdraw consent at any time;
- lodge a complaint with a competent supervisory authority; and
- receive safeguards relating to a solely automated decision producing legal or similarly significant effects.
AP Digital does not use personal data through the Service to make solely automated decisions producing legal or similarly significant effects about individuals.
A person in the EEA may complain to the data-protection authority in the country of habitual residence, place of work or alleged infringement. AP Digital's lead local supervisory authority is the data-protection authority for North Rhine-Westphalia, Germany. A person in the United Kingdom may complain to the Information Commissioner's Office, and a person in Switzerland may contact the Federal Data Protection and Information Commissioner.
Where an individual is named in an official filing obtained indirectly, providing a separate notice to every person may be impossible or involve disproportionate effort given the scale and public regulatory context. This published Policy describes the source, purpose and safeguards for that processing. We will consider a specific, substantiated concern and any applicable right, while preserving accurate official records and source provenance where law permits.
18. International data transfers
AP Digital is established in Germany. Personal information may be processed in Germany, elsewhere in the European Economic Area, the United Kingdom, the United States and other countries where AP Digital's providers or a user-directed integration operates.
When personal data is transferred from the EEA, United Kingdom or Switzerland to a country not recognised as providing adequate protection, we use an available lawful transfer mechanism where required. This may include the European Commission's Standard Contractual Clauses, the United Kingdom's international data-transfer addendum or agreement, Swiss adaptations, participation in an approved adequacy framework, or another legally recognised safeguard. Supplementary security and contractual measures are applied where appropriate.
A user who directs information to a third-party AI assistant or integration may cause an additional international transfer under that third party's arrangements. The customer is responsible for approving that service and its transfer settings.
19. Children
The Service is for business users aged 18 and over and is not directed to children. We do not knowingly collect personal information from a child under 13 or intentionally offer the Service to minors.
If you believe a child has provided personal information, contact info@apdigitalsolutions.eu. We will investigate and delete the information where required. We do not condition participation in an activity on a child disclosing more information than reasonably necessary because the Service has no child-directed activity.
20. De-identified and aggregated information
We may create information that is aggregated or de-identified so that it cannot reasonably be linked to an identified or identifiable person. We may use and disclose that information for lawful business purposes, including security, statistics, capacity planning and Service improvement.
Where applicable law regulates de-identified information, we will maintain it in de-identified form, take reasonable measures to prevent re-identification and not attempt to re-identify it except where law permits testing of de-identification controls.
21. Third-party links and SEC sources
The Service may link to SEC EDGAR, official filings, fund or issuer information, documentation, payment pages, AI providers and other third-party websites or services. A link does not mean AP Digital controls or endorses the third party's privacy practices. Users should review the relevant third-party notice before providing information.
22. Changes to this Privacy Policy
We may update this Policy to reflect changes in law, the Service, providers or processing practices. The revised version will show a new effective date and will be posted through the Service.
Where a change materially affects the way we use personal information, we will provide additional notice appropriate to the circumstances, such as an account notice or email, before the change takes effect where required. We will request consent where applicable law requires it rather than applying the change solely through notice.
23. Contact and complaints
Questions, concerns and privacy requests should be sent to:
AP Digital Solutions GbR
Schultestraße 25
57076 Siegen
Germany
Email: info@apdigitalsolutions.eu
We will investigate a substantiated complaint and respond in accordance with applicable law. An individual may also contact the competent regulator or attorney general where that right is available.
Appendix A - U.S. notices at collection
These short notices are intended to be displayed at the relevant collection point with an active link to this Privacy Policy. They should be updated if the fields, providers or purposes change.
A.1 Account registration notice
Privacy notice: AP Digital Solutions GbR collects your name, work email, organisation, account credentials, IP/device information and account activity to create and secure your business account, provide fund analyses, administer your plan, prevent misuse and comply with law. Account login credentials may be sensitive personal information and are used only for authentication and security. We do not sell or share personal information for cross-context behavioural advertising. Retention depends on the life of the account and the periods described in our Privacy Policy.
Recommended adjacent acceptance text:
I confirm that I am at least 18, am acting for business or professional purposes, have authority to bind my organisation where applicable, and agree to the Website and Platform Terms. I acknowledge the Privacy Policy.
The Terms acceptance should be an unchecked, affirmative clickwrap control. The Privacy Policy should be acknowledged as a notice and should not be framed as blanket consent to all processing.
A.2 Contact or demonstration form notice
Privacy notice: AP Digital Solutions GbR collects the contact and professional information you submit, together with basic device and communication information, to respond to your enquiry, arrange a demonstration, assess business requirements, maintain security and keep appropriate business records. Do not submit confidential holdings, material non-public information or personal information about other individuals. We do not sell or share personal information for cross-context behavioural advertising. Enquiry records are normally retained for up to 12 months after the last substantive interaction unless a business relationship begins or law requires longer. See our Privacy Policy.
A.3 Subscription and billing notice
Privacy notice: AP Digital Solutions GbR and its payment provider collect business billing, subscription, transaction, authentication and device information to process payment, administer recurring billing, prevent fraud, provide invoices, manage cancellation and comply with tax and accounting law. The payment provider, not AP Digital, is intended to collect the complete card number and card verification value. We do not sell or share personal information for cross-context behavioural advertising. Billing and tax records are retained for legally required periods. See our Privacy Policy.
Recommended adjacent renewal text:
Your paid subscription renews automatically at the price and billing interval shown until cancelled. You may cancel online at any time; cancellation takes effect at the end of the current paid billing period. By selecting the paid plan, you expressly authorise recurring charges and acknowledge the renewal terms.