Information on the collection and processing of personal data pursuant to Art. 13 and 14 GDPR.
CFOProof™ offers two explicit, transparent privacy modes. You choose which mode to activate on your first visit. You can switch modes at any time.
CFOProof — Ali Najafzadeh
Bockkellerstraße 6/1, 1190 Vienna, Austria
Email: [email protected]
A Data Protection Officer has not been appointed pursuant to Art. 37 GDPR, as the legal requirements for mandatory appointment are not met.
When you visit our website, our hosting provider (e.g. Cloudflare/Vercel) automatically collects server log files (IP address, browser, timestamp), which are necessary to ensure the operation and security of the website (Art. 6(1)(f) GDPR). This data is deleted after a few days.
We do not use any marketing or tracking cookies (such as Google Analytics or Meta Pixel).
We use your browser's local storage (Local Storage / IndexedDB) for the following purposes:
In Server Private Mode, session cookies are used for authentication (Supabase Auth).
When you choose Server Private Mode, your financial data is encrypted and stored in our EU-hosted PostgreSQL database (Supabase, Frankfurt region).
Access control is provided by:
Legal basis: Art. 6(1)(b) GDPR (contract performance) and Art. 6(1)(f) GDPR (legitimate interest in secure data processing).
For payment processing we use Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland.
When you purchase a report, your payment data is transmitted directly to Stripe. We do not store complete credit card data. Processing is based on Art. 6(1)(b) GDPR (contract performance).
Local Private Mode: Since no data is stored on our servers, we cannot provide information about or delete such data. You retain full control of your data through your browser.
Server Private Mode: You have the right to access, rectification, erasure, or restriction of processing under GDPR. Contact us at [email protected].
For complaints, you may contact the Austrian Data Protection Authority (DSB), Barichgasse 40-42, 1030 Vienna.
| Subprocessor | Purpose | Data | Location |
|---|---|---|---|
| Supabase (Server Mode) | Database, Auth, Storage | Financial data, user profiles | Frankfurt, Germany (EU) |
| Stripe Payments Europe, Ltd. | Payment processing | Billing data only | Dublin, Ireland (EU) |
| Vercel / Cloudflare | Hosting / CDN | Standard web server logs | EU endpoints |
In Local Private Mode, no financial data is transmitted to sub-processors. In Server Private Mode, all data is processed exclusively within the EU.
Local Private Mode:
CSV Upload → Browser RAM → Web Worker → Analysis → IndexedDB / localStorage
↓
PDF Generation (client-side)
╔════════════════════════════════════════════════════════════════╗
║ No data leaves the browser. ║
╚════════════════════════════════════════════════════════════════╝Server Private Mode:
CSV Upload → API Route → PostgreSQL (Frankfurt)
↓
Server-Side Analysis → Opportunities → PostgreSQL
↓
PDF Generation (server-side)
╔════════════════════════════════════════════════════════════════╗
║ All data within the EU. RLS per organisation. ║
║ Audit log for every action. ║
╚════════════════════════════════════════════════════════════════╝Diese Analyse stellt keine Steuer-, Rechts- oder Wirtschaftsprüfungsleistung dar und ersetzt keine Beratung gemäß WTBG, RAO oder UGB. Gerichtsstand Wien; es gilt österreichisches Recht unter Ausschluss des UN-Kaufrechts. Die Haftung ist auf den Auftragswert beschränkt; ausgenommen Vorsatz und grobe Fahrlässigkeit (§ 1324 ABGB). [Vorläufig — wird durch geprüfte AGB ersetzt]