This Privacy Notice explains how we collect, use and protect your Personal Data, and describes the rights available to you under the General Data Protection Regulation (EU) 2016/679 ("GDPR"). We review and update this Notice periodically to reflect changes in our practices and in applicable law.
This Privacy Notice explains, in the order set out below:
- Definitions
- Who We Are
- How to Contact Us
- What Personal Data We Process, the Purposes, the Legal Basis and the Retention Period
- Disclosure of Your Personal Data, including International Transfers
- Your Rights and How to Exercise Them
- Children's Personal Data
- Security Measures
- Links to Other Websites
- Updates to This Privacy Notice
- Right to Lodge a Complaint
1. Definitions
For the purposes of this Privacy Notice, the following terms have the meaning set out below.
Controller means AXIS SOCIETY FLD SRL, a Romanian company, with its registered office at 27-33 Nerva Traian Street, Entrance B, 1st Floor, District 3, Bucharest, 031044, Romania, registered with the Trade Registry under no. J2025065290005, having tax identification code 52410879 ("Controller", "we", "our" or "us"), operating Axis Terminal at https://www.axis-terminal.com/ (the "Platform"). The Controller determines the purposes and means of the Processing of your Personal Data.
Supervisory Authority means the independent public authority responsible for monitoring the application of the GDPR in the Controller's home Member State, established pursuant to Article 51 GDPR.
Personal Data means any information relating to an identified or identifiable natural person ("Data Subject"); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
Data Subject means the identified or identifiable natural person to whom Personal Data relates.
Processing means any operation or set of operations performed on Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission or otherwise making available, alignment or combination, restriction, erasure or destruction.
Restriction of Processing means the marking of stored Personal Data with the aim of limiting its Processing in the future.
Processor means a natural or legal person, public authority, agency or other body which Processes Personal Data on behalf of the Controller.
Representative means a natural or legal person established in the European Union who is designated by the Controller in writing, pursuant to Article 27 GDPR, to represent the Controller in relation to its GDPR obligations, where the Controller itself is not established in the European Union.
Recipient means a natural or legal person, public authority, agency or another body to which Personal Data is disclosed, whether a Third Party or not. Public authorities which may receive Personal Data in the framework of a particular inquiry are not regarded as Recipients.
Third Party means a natural or legal person, public authority, agency or body other than the Data Subject, Controller, Processor, and persons who, under the direct authority of the Controller or Processor, are authorized to Process Personal Data.
Consent means any freely given, specific, informed and unambiguous indication of your wishes by which you, by a statement or by a clear affirmative action, signify agreement to the Processing of your Personal Data.
Data Breach means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data.
2. Who We Are
For the purposes of the GDPR, in relation to the Personal Data Processed through the Platform, we act as the Controller, and our visitors and users are Data Subjects.
We are committed to protecting your Personal Data and to Processing it only for specific, explicit and legitimate purposes, in line with the principles of the GDPR.
Data Protection Officer. At this time, Axis Terminal has not appointed a Data Protection Officer, as it is not currently required to do so under the GDPR.
3. How to Contact Us
If you have any question about this Privacy Notice or about how we Process your Personal Data, please contact us at contact@axissoc.com.
4. What Personal Data We Process, the Purposes, the Legal Basis and the Retention Period
We place a high priority on protecting your Personal Data. Wherever possible, we collect Personal Data directly from you, giving you greater control over the information you share with us, and we Process it only for the specific purposes described below.
Personal Data includes any information that could, directly or indirectly, identify you. Some information — for example, your professional skills or education — is not, on its own, Personal Data, because it could not directly lead to your identification; however, combined with other information such as your name, username or e-mail address, it could eventually identify you.
For each category of Personal Data we Process, the purpose, the legal basis relied upon, how it is collected, and the applicable retention period are set out below. The legal basis is referenced by letter, corresponding to Article 6(1) GDPR: (a) your consent; (b) performance of a contract to which you are a party, or steps taken at your request before entering into one; (c) compliance with a legal obligation; (d) protection of vital interests; (e) performance of a task carried out in the public interest; (f) our legitimate interests, or those of a Third Party, provided these are not overridden by your interests or fundamental rights — where (f) is used, the specific legitimate interest is stated.
Category 1 – Account Registration and Management
- Personal Data processed: e-mail and any other Personal Data you choose to share with us.
- Legal basis: Art. 6(1)(b) GDPR – Processing is necessary for the performance of the contract with you, including the creation, authentication and management of your account.
- Collection method: directly from you, when you create and use your account on the Platform.
- Retention period: for as long as your account remains active and, following its closure, for the period necessary to comply with applicable legal obligations or to establish, exercise or defend legal claims.
Category 2 – My Portfolio
- Personal Data processed: information regarding your investment portfolio, including financial instruments or holdings, ticker symbols, number of shares, average acquisition cost, cash balance, transactions, dividends, fees, stock splits, transaction history, portfolio value, realised profit or loss and other information resulting from the Processing of your portfolio data.
- Legal basis: Art. 6(1)(b) GDPR – Processing is necessary in order to provide the My Portfolio functionality requested by you as part of the Platform.
- Collection method: directly from you, either by manually entering information into the Platform or by uploading broker files in .xlsx or .csv format.
- Retention period: for as long as you use the My Portfolio functionality and maintain an active account, and for a period of 18 (eighteen) months after your subscription expires, is cancelled or otherwise ceases to be active, so that your account and the information previously stored therein may be restored if you subsequently renew your subscription. The relevant data may be deleted earlier if you delete such data or your account, unless further retention is necessary to comply with Applicable Law or to establish, exercise or defend legal claims.
Category 3 – Website Visitors
- Personal Data processed: IP address, browser type and version, operating system, pages accessed, referrer URL, date and time of visit, and other data collected through cookies (see our Cookie Policy).
- Legal basis: Art. 6(1)(b) GDPR for the strictly necessary cookies that sign you in and keep you signed in, and Art. 6(1)(a) GDPR – your consent, expressed through your own action, for the preference cookies described in the Cookie Policy. The Platform places no advertising or tracking cookies; usage measurement runs without storing cookies or identifiers on your device, on the basis of Art. 6(1)(f) GDPR – our legitimate interest in understanding and improving how the Platform is used, using aggregated data hosted in the European Union.
- Collection method: automatically, when you access the Platform.
- Retention period: as set out for each cookie in our Cookie Policy.
Category 4 – Social Media and Correspondence
- Personal Data processed: your social media account details; any information you choose to share when contacting us by e-mail or on our social media profiles; comments and/or posts on our profiles.
- Legal basis: Art. 6(1)(f) GDPR – our legitimate interest in responding to enquiries and providing support.
- Collection method: directly from you, when you contact us.
- Retention period: 1 year from the last interaction, unless a longer period is required by applicable law.
Category 5 – Patreon Subscription Verification
- Personal Data processed: your e-mail address, Patreon membership status and tier, pledge and charge status, and the dates your subscription started, renewed or lapsed.
- Legal basis: Art. 6(1)(b) GDPR – Processing is necessary to verify, grant and maintain your access to the Platform, which is conditional upon an active subscription through the Patreon Account.
- Collection method: from Patreon, when you subscribe to the Patreon Account and periodically for as long as your account remains linked to the subscription.
- Retention period: together with your account data under Category 1.
Category 6 – Marketing Communications
- Personal Data processed: your e-mail address and your marketing preference.
- Legal basis: Art. 6(1)(a) GDPR – your consent, given through the marketing e-mails option in your account settings. We send marketing communications only to members who have enabled this option.
- Collection method: directly from you, when you enable the option.
- Retention period: until you withdraw your consent — you can disable the option at any time from your account settings or through the preferences link included in every such e-mail — or until your account is deleted. Withdrawing consent does not affect service e-mails required to operate your account (such as confirmation or password-reset e-mails).
Category 7 – Testimonials
- Personal Data processed: the display name you choose, the text of your testimonial and the date of your consent.
- Legal basis: Art. 6(1)(a) GDPR – your consent to the public display of your testimonial under the chosen display name, given when you submit it.
- Collection method: directly from you, through the testimonial form on the Platform.
- Retention period: until you withdraw your testimonial or delete your account. A testimonial is displayed publicly only after review by us, and you may withdraw it at any time, after which it is no longer displayed.
Category 8 – Platform Activity and Personalisation
- Personal Data processed: activity events generated as you use the Platform while signed in (for example, companies viewed and features used) and the statistics derived from them.
- Legal basis: Art. 6(1)(f) GDPR – our legitimate interest in operating, improving and personalising the Platform, including personal statistics shown only to you (for example on your Investor Card) and community statistics shown only in aggregated form that does not identify you.
- Collection method: automatically, as you use the Platform while signed in.
- Retention period: together with your account data under Category 1.
Investor Card verification. Each member account is assigned a serial number, shown on the member's Investor Card. The card carries a verification link and QR code leading to a public page which confirms only whether that serial number was issued, whether the corresponding membership is currently active, and the month in which the membership began. The page displays no name and no other Personal Data. This limited disclosure is based on Art. 6(1)(f) GDPR – our legitimate interest, shared with our members, in allowing a shared or printed card to be verified as genuine.
Personal Data is retained only for as long as necessary for the purpose for which it was collected, after which it is deleted or irreversibly anonymized. We take appropriate steps to ensure the timely deletion of Personal Data once retention is no longer necessary.
Where a category above relies on Art. 6(1)(b) or Art. 6(1)(c) GDPR, providing the corresponding Personal Data is a contractual or statutory requirement. If you do not provide it, we may be unable to enter into or perform the relevant contract, or to comply with the relevant legal obligation.
5. Disclosure of Your Personal Data, including International Transfers
In the ordinary course of our business, we do not disclose or transfer your Personal Data to Third Parties for their own direct marketing purposes, regardless of their location.
Our Employees. Employees who have access to Personal Data are trained to observe its security and confidentiality, and their access is limited to what is required to perform their specific tasks.
Processors and Suppliers. We work with service providers to carry out certain technical or administrative tasks on our behalf, such as e-mail hosting, data storage, server hosting, and legal services. Our principal service providers currently include Supabase (authentication and database hosting, in the European Union – Frankfurt), Vercel (application hosting and delivery) and Resend (e-mail delivery). Patreon, as the subscription platform and merchant of record, acts as an independent controller of the data it processes for its own purposes, under its own privacy policy. Our market-data provider (Financial Modeling Prep) does not receive your Personal Data. Where a Processor is not established in the European Economic Area ("EEA"), engaging them may involve the disclosure of your Personal Data outside the EEA. We only engage Processors that provide sufficient guarantees to implement appropriate technical and organizational measures in compliance with the GDPR, and we enter into a data processing agreement with each Processor as required by Article 28 GDPR.
International Transfers. Where your Personal Data is transferred outside the EEA, we ensure that this takes place on the basis of Standard Contractual Clauses under Art. 46 GDPR and, where applicable, an adequacy decision under Art. 45 GDPR pursuant to the EU-U.S. Data Privacy Framework. You may request a copy of the relevant safeguard by contacting us as set out in Section 3.
Legal Requirements. Your Personal Data may be disclosed to governmental authorities or law enforcement agencies where required by applicable law.
6. Your Rights and How to Exercise Them
We implement appropriate technical and organizational measures to ensure that your rights as a Data Subject are observed, as follows.
Right of Access. You have the right to obtain confirmation as to whether Personal Data concerning you is being Processed by us and, where that is the case, access to your Personal Data and information on how it is Processed.
Right to Data Portability. You have the right to receive the Personal Data you have provided to us in a structured, commonly used and machine-readable format, and to transmit that data to another controller without hindrance from us, where technically feasible.
Right to Object. You have the right to object to the Processing of your Personal Data where Processing is necessary for the performance of a task carried out in the public interest, or for the purposes of legitimate interests pursued by us. You have the right to object at any time where your Personal Data is Processed for direct marketing purposes.
Right to Rectification. You have the right to obtain from us, without undue delay, the rectification of inaccurate Personal Data concerning you. The rectification will be communicated to each Recipient to whom the data was sent, unless this proves impossible or involves disproportionate effort.
Right to Erasure ("Right to Be Forgotten"). You have the right to obtain from us the erasure of Personal Data concerning you without undue delay, and we have the obligation to erase it without undue delay, where: it is no longer necessary for the purposes for which it was collected; you withdraw consent and there is no other legal ground for the Processing; you object to the Processing and there are no overriding legitimate grounds; it has been unlawfully Processed; erasure is required for compliance with a legal obligation; or it was collected in relation to the offer of information society services. You can also delete your account and the associated data at any time from the Account page of the Platform.
Right to Restriction of Processing. You have the right to obtain from us Restriction of Processing where: you contest the accuracy of your Personal Data, for a period enabling us to verify its accuracy; the Processing is unlawful and you oppose erasure, requesting restriction instead; we no longer need your Personal Data, but you require it for the establishment, exercise or defence of legal claims; or you have objected to Processing pending verification of whether our legitimate grounds override yours.
Right to Withdraw Consent. Where the Processing of your Personal Data is based on your consent, you have the right to withdraw it at any time, without affecting the lawfulness of Processing carried out before the withdrawal. You can withdraw your consent by contacting us, by adjusting the relevant option in your account settings (for marketing e-mails and testimonials) or by adjusting your cookie preferences.
Right Not to Be Subject to a Decision Based Solely on Automated Processing. You have the right not to be subject to a decision based solely on automated Processing, including profiling, which produces legal effects concerning you or similarly significantly affects you. We do not use applications, algorithms, artificial intelligence or automated processes to make decisions, without human intervention, that produce legal effects concerning you.
You can exercise any of these rights at any time by writing to us using the contact details in Section 3. To protect your Personal Data, we may ask you to verify your identity before responding. We will respond within one month of receipt, or notify you if we need to extend this by up to two further months due to the complexity or number of requests. Exercising your rights is generally free of charge; however, we may charge a reasonable fee, or decline to act, where a request is manifestly unfounded or excessive.
7. Children's Personal Data
We do not knowingly collect Personal Data from children under the age of 16. If you are under this age, please do not submit any Personal Data to us. Please also note that, under our Terms of Use, the Services are available only to persons who are at least 18 years of age.
8. Security Measures
We have implemented appropriate technical and organizational measures to protect the privacy and security of your Personal Data, and to protect it from damage, loss, misuse, unauthorized access, alteration, destruction or disclosure, including the following.
- Access to our filing system is limited to individuals nominated by us, who use individual accounts and passwords that are changed periodically.
- All employees, collaborators and service providers who have access to Personal Data must act in accordance with our data protection principles and policies. They have been informed of, and have undertaken to comply with, the GDPR, whether by signing a data processing agreement or as an effect of law.
- Employees and collaborators access Personal Data only to perform their professional duties and only in accordance with the stated purpose of collection.
- Computers used to access the filing system are password-protected and equipped with up-to-date antivirus, antispam and firewall protection.
- Personal Data is printed only by authorized users, and only where necessary to perform our activity or to fulfil a legal obligation.
We also encourage you to think carefully about what Personal Data you share with us. No method of transmission over the internet or by e-mail can be guaranteed to be completely secure.
9. Links to Other Websites
Our Platform may contain links to other organizations' websites. This Privacy Notice does not cover the Personal Data Processed by them.
If you access another organization's website, we encourage you to read its privacy notice, generally available at the bottom of that website.
Where we integrate a third-party purchase on the Platform, that third party acts as the Controller for that specific feature/operation, with no direct involvement from us. Please read the applicable privacy notice before proceeding, available on their websites.
10. Updates to This Privacy Notice
As our services evolve, we will update this Privacy Notice accordingly, and we always publish the latest version on our website. We encourage you to check back from time to time. If you have any questions, please contact us using the details in Section 3.
11. Right to Lodge a Complaint
If you believe that our Processing of your Personal Data infringes the GDPR, you have the right to lodge a complaint with a Supervisory Authority — in particular in the Member State of your habitual residence, place of work, or the place of the alleged infringement — without prejudice to any other administrative or judicial remedy.
National Supervisory Authority for Personal Data Processing (ANSPDCP)
28-30 G-ral Gheorghe Magheru Boulevard, District 1, 010336 Bucharest, Romania
E-mail: anspdcp@dataprotection.ro · Phone: +40 31 805 9211 / +40 31 805 9212 · Website: www.dataprotection.ro