Privacy Policy
1. Controller
Controller within the meaning of the EU General Data Protection Regulation (GDPR):
We Elevate Holding GmbH (in formation)
Gewerbering 19/1/4
3484 Grafenwörth, Austria
Email: office@we-elevate.at
2. Overview
This privacy policy explains which personal data we process when you visit our website we-elevate.at, open a customer account, or use our Elevate App (available on Google Play and the Apple App Store). We process personal data exclusively on the basis of the GDPR and the Austrian Data Protection Act (DSG).
We do not use any analytics or marketing trackers on our website (no Google Analytics, no advertising pixels).
3. Hosting and Server Log Files
Our website and the servers of the Elevate App are operated by Hostinger International Ltd. on servers located in Frankfurt am Main (Germany, EU). When you access the website or the app’s interfaces, connection data is processed for technical reasons (IP address, date and time, requested resource, browser/device identifier). This data is used to deliver the content, ensure stability, and defend against attacks (Art. 6(1)(f) GDPR) and is deleted automatically after a short period.
To protect against abuse, we limit failed login attempts based on the IP address (15-minute lockout after repeated failed attempts).
4. Cookies
We only use strictly necessary cookies: session cookies for logging in to your customer account (Art. 6(1)(b) GDPR). No cookies are set for analytics or advertising purposes; a cookie banner is therefore not required.
5. Registration and Customer Account
A customer account is required to use our services. In this context we process: first and last name, email address, password (stored encrypted), billing address, and where applicable phone number, company name and VAT ID, as well as your chosen plan and contract status. Upon registration we also take your browser language as the default setting for the app content (German/English); you can change this yourself at any time.
The legal basis is performance of the contract (Art. 6(1)(b) GDPR). We retain accounting-related data in accordance with statutory retention periods (Section 132 of the Austrian Federal Fiscal Code (BAO): 7 years).
6. Payment Processing (Stripe)
Payments are processed by Stripe Payments Europe Ltd. (Ireland) and Stripe Inc. (USA). Your payment details (e.g. card data) are entered and processed directly with Stripe; we ourselves never receive or store complete payment data. Transfers to the USA are safeguarded by EU Standard Contractual Clauses; Stripe is also certified under the EU-US Data Privacy Framework. Legal basis: Art. 6(1)(b) GDPR. Further information: stripe.com/privacy.
7. Referral / Partner Program
If you reach us via a partner’s referral link, we process the assignment of your account to the referring partner for commission settlement (Art. 6(1)(b) and (f) GDPR). Partners do not see any of your account data beyond what is required for settlement.
8. The Elevate App
You sign in to the Elevate App with your existing customer account. In addition to the website, the app processes the following data:
8.1 Broadcast Channels
Only our team publishes content in the channels (market analyses, announcements). As a member, you can read posts and react to them with emoji. In doing so, we process your read receipts and reactions (including your display name); these are visible only to our team, never to other members. Members remain anonymous to one another — channel statistics (e.g. “members online”) are displayed exclusively as numbers without names. Legal basis: Art. 6(1)(b) GDPR.
8.2 Push Notifications (Firebase Cloud Messaging)
For notifications about new posts we use Firebase Cloud Messaging provided by Google Ireland Ltd. and Google LLC (USA). For this purpose a device token is processed; the notification text contains the channel name and a preview of the post. You can disable push notifications at any time in the app or in your device settings; when you sign out, the token is deleted. Legal basis: Art. 6(1)(a) GDPR (consent via the operating system permission). Google is certified under the EU-US Data Privacy Framework.
8.3 Crash Reports (Firebase Crashlytics)
To keep the app stable we use Firebase Crashlytics (Google). In the event of a crash, technical data is transmitted (device type, operating system version, crash log, pseudonymous installation ID) — no content and no real name. Legal basis: Art. 6(1)(f) GDPR (reliable operation).
8.4 Voice and Video Content, Translation
Voice and video posts published by our team are stored on our own servers (EU) and transcribed there; no external service is used for transcription. For the automatic translation of team posts (German/English) we use the API of Anthropic PBC (USA), and for voicing translated content the services of ElevenLabs Inc. (USA). Only our team’s editorial content is transmitted to these two services — never any member data.
8.5 Portfolio Feature
You can voluntarily link your accounts at trading venues (e.g. exchanges) using API keys with read-only access. We then retrieve your balances and transactions and store them to display your portfolio and related analytics. The keys are stored encrypted on our servers (EU); trading on your behalf is technically impossible with these keys. You can unlink at any time in the app, which ends the retrieval. Legal basis: Art. 6(1)(b) GDPR. Market prices (e.g. via CoinGecko, Twelve Data) are retrieved by our server without any personal reference — your IP address is never transmitted to these providers.
8.6 Biometric Unlock
The optional unlock via fingerprint or face recognition is performed entirely on your device by the operating system. Biometric data never leaves your device and is at no time accessible to us.
8.7 Fonts
The app loads display fonts from Google Fonts (Google LLC, USA); for technical reasons your IP address is transmitted to Google in the process (Art. 6(1)(f) GDPR).
8.8 App Permissions
The app only requests permissions when the corresponding feature is used: Notifications (push), Photos/Media (only when saving images/videos to your gallery), Microphone (only when the recording feature is used by team members). Every permission can be revoked in your device settings.
9. App Stores
When you obtain the app via Google Play (Google Ireland Ltd.) or the Apple App Store (Apple Distribution International Ltd., Ireland), the respective store operator processes data (e.g. account, download and diagnostic data) under its own responsibility. The privacy policies of Google and Apple apply.
10. Recipients and International Data Transfers
Recipients of personal data are exclusively the processors and service providers named in this policy: Hostinger International Ltd. (hosting, EU), Stripe (payments), Google (push notifications, crash reports, fonts), Anthropic and ElevenLabs (our team’s editorial content only). Where data is transferred to the USA, we rely on EU Standard Contractual Clauses (Art. 46 GDPR) or on the EU-US Data Privacy Framework where the provider is certified. Data is never shared for advertising purposes; we do not sell your data.
11. Retention Periods
We store account data for the duration of the contractual relationship. After the contract ends, the data is deleted or anonymized unless statutory retention obligations (in particular 7 years under Section 132 BAO for invoicing data) require otherwise. Push tokens are deleted when you sign out, server logs after a short period, and technical event data from app synchronization after 24 hours at the latest.
12. Your Rights
You have the rights of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21 GDPR). You may withdraw any consent you have given at any time with effect for the future. To exercise these rights, simply contact office@we-elevate.at.
You also have the right to lodge a complaint with the supervisory authority: Austrian Data Protection Authority (Österreichische Datenschutzbehörde), Barichgasse 40–42, 3484 Grafenwörth, www.dsb.gv.at.
13. Deleting Your Account and Data
You can request the deletion of your account and the associated personal data at any time — by email to office@we-elevate.at sent from the email address registered with us. We will promptly delete or anonymize your account and your app data (device tokens, read receipts, reactions, portfolio links including API keys); invoicing data is retained solely within the scope of statutory retention obligations.
14. Security
All connections are TLS-encrypted. Passwords are stored exclusively as hashes, exchange API keys are stored encrypted. Access to personal data is restricted to the persons responsible for it; security-relevant operations are logged.
15. Changes to This Policy
We will update this privacy policy when our services or the legal situation change. The version published here applies.
Last updated: July 2026