Version 4 · effective 14 July 2026
Moatkeep ("Moatkeep", "we", "us") is operated by LGConsult LDA, a limited liability company, Registered in Portugal.
We are the controller of the personal data described in this policy, within the meaning of Regulation (EU) 2016/679 (the "GDPR").
Moatkeep is a research and data platform for everyone interested in such data. It provides company fundamentals, market prices, valuation metrics, and editorial and research content that is AI-assisted and human-reviewed. Moatkeep does not provide investment advice, portfolio management, or any regulated advisory service. Nothing on the platform is a recommendation to buy, sell, or hold any security, or can be construed as such in any instance.
This policy covers personal data processed when you visit moatkeep.com, register an account, subscribe to a paid plan, or contact us. It does not cover the company financial data we publish — that is public-market information about companies, not personal data about you.
| Category | Data | Purpose | Retention (see § 8) |
|---|---|---|---|
| Account data | Email address, name, title, password (as a hash), account preferences, tier | Creating and operating your account; authentication; providing the service | Life of the account + 14-day deletion grace period |
| Optional onboarding profile | Self-described investing experience, goals, how you found us (a single, skippable screen) | Understanding our audience; improving the product | Life of the account; deleted on erasure |
| Phone number | Phone number, verification status | One-time SMS verification at account activation, to deter automated and abusive sign-ups. Verification is delivered by a third party; | Life of the account; deleted on erasure |
| Payment and billing data | See § 4 — Stripe is the merchant of record | Charging subscriptions; invoicing; refunds | See § 4 and § 8 |
| Security and abuse-detection data | Authentication events (logins, failures, verifications) on a 90-day rolling log: event type and outcome; full IP address only on security events, kept ≤ 30 days; a truncated (subnet-level) IP for rate analysis; a one-way hashed, server-side device fingerprint (HMAC of passive connection characteristics with a rotating server-held key — no fingerprinting script runs in your browser); coarse geolocation derived locally; a deterministic risk score | Detecting credential-stuffing, account takeover, sign-up abuse, and impossible-travel logins; account lockout and step-up challenges | Identifying fields anonymised at ≤ 30 days; de-identified events purged at 90 days |
| Your content | Watchlists, price/metric alerts, private notes, favourites | Providing the features you use | Life of the account; deleted on erasure |
| Alert emails | Your email address and the alert digests we send you (delivered via Resend) | Sending the alert digest emails you configure; every digest carries a one-click unsubscribe | Delivery metadata per Resend's processing terms; alert configuration lives with your account |
| PDF download records | A log of each research-report PDF you download, including the forensic watermark identifier embedded in the file | Deterring and investigating unauthorised redistribution of paid content | Retained; de-identified on erasure (the record survives with the user link removed) |
| Legal-acceptance records | Which published version of the Terms/Privacy Policy/Subscription Terms you accepted, when, and the IP at acceptance; the withdrawal-waiver consent record at checkout (wording version, timestamp, IP, confirmation-email reference) | Proving what you agreed to (defence against repudiation; consumer-law record-keeping) | See § 8; IP is deleted on erasure |
| Error and diagnostics data | Application error reports and operational telemetry. No email address, session IP, or raw device signals are sent to any outside tools — only opaque identifiers. | Detecting and fixing faults; keeping the service reliable | Per tool retention defaults; no directly identifying fields by design |
| Correspondence | Emails you send to support at moatkeep.com | Answering you; handling rights requests and complaints | kept for two years |
What we do not do: we run no advertising, no third-party analytics, and no cross-site tracking. We do not sell or rent personal data. We do not use your personal data to train AI models, and no user personal data is sent to our AI provider.
Payments run on Stripe under Stripe's Managed Payments service, with Stripe as the merchant of record.
Your purchase contract for the paid subscription is with Stripe (contracting through Stripe Payments Europe, Limited, Ireland — "SPEL"), which acts as the merchant of record and reseller of Moatkeep subscriptions. Stripe is an independent controller of the payment data it collects at checkout (card details, billing address, tax location) and issues receipts and handles refunds under its own privacy notice (stripe.com/privacy). Moatkeep never receives your full card number; we receive subscription status, tier, and limited billing metadata needed to grant access. Statement descriptors and receipts are issued by Stripe/Link under this model.
Stripe's EU contracting entity is SPEL (Ireland), and Stripe's group may transfer personal data to Stripe, LLC (US) and other affiliates under the 2021 EU Standard Contractual Clauses incorporated in Stripe's Data Transfers Addendum, with Stripe's EU–US Data Privacy Framework certification also referenced (see § 7). Stripe's checkout sets cookies on the checkout page only (see § 5).
We mirror your subscription status (active/cancelled/etc., tier, period dates) in our own systems to control access. If you exercise your right of erasure, we cancel any active Stripe subscription and retain the subscription record in anonymised (de-identified) form (see § 9).
Moatkeep uses strictly necessary cookies only. We set no analytics, advertising, or cross-site tracking cookies, load no third-party fonts or trackers. This page (together with the dedicated cookie notice at /cookies) provides the required transparency.
Cookies we set: CSRF/security token; Cloudflare related bot management and security; Turnstile cookies; Stripe session cookies strictly necessary for payments. Lifetime as strictly required to assure the application's correct functioning.
Stripe's scripts load only on the checkout page, and Turnstile loads only on the registration page; neither runs elsewhere on the site.
We use the following service providers. Each processes personal data only on our documented instructions under a data-processing agreement (GDPR Art 28), except where marked as an independent controller.
| Provider | Role | What they process | Location of processing |
|---|---|---|---|
| Hetzner Online GmbH | Hosting (all application data, databases, backups) | All categories in § 3 | Germany / Finland (EU) |
| Cloudflare, Inc. | Network/CDN, DDoS protection, bot management, Turnstile, object storage for data-export bundles | Connection metadata (IP, headers) in transit; security cookies; temporary data-export archives | Global edge network; EU–US transfers per § 7 |
| Stripe (SPEL, Ireland / Stripe, LLC, US) | Payments — independent controller as merchant of record (see § 4); processor role limited to account-servicing data | Payment and billing data (§ 4) | EU (SPEL) with possible US transfer (§ 7) |
| Resend, Inc. | Transactional email (verification emails, alert digests, billing confirmations) | Email address, message content | US-based provider |
| Twilio, Inc. | SMS phone verification | Phone number, verification metadata | United States; transfer per § 7 |
| Functional Software | Application error monitoring | Error reports with opaque identifiers; scrubbed of email/IP/device signals | ingest endpoint Germany. US parent company |
| Operational Telemetry | Operational telemetry (metrics, logs, traces), PII-redacted before shipping | Opaque operational identifiers only | EU region |
| Anthropic, PBC | AI model provider for content generation | None of your personal data. Our AI agents draft editorial and research content from public financial data (regulatory filings, market prices, economic series) under human review. No account data, usage data, or any user personal data is sent to Anthropic | US — but not a processor of user personal data; listed for transparency |
Not processors: our market- and fundamentals-data suppliers (e.g. SEC EDGAR, Databento, FRED) supply public financial data about companies to us; they do not receive or process any personal data about our users and are therefore not sub-processors.
We are established in Portugal and host all core application data in the EU (Hetzner, Germany/Finland). Some providers involve transfers to the United States:
| Data | Retention |
|---|---|
| Account, profile, content (watchlists, alerts, notes, favourites) | Life of the account, then deleted via the erasure process (§ 9) after the 14-day grace period |
| Authentication/security events | Identifying fields (full IP, hashed fingerprint, geo) anonymised at ≤ 30 days; de-identified events hard-deleted at 90 days |
| Full IP on security events | ≤ 30 days |
| Data-export bundles (§ 10) | Short-lived download (expires automatically); the archive is deleted on expiry and always deleted on erasure |
| Subscription/billing mirror | Life of subscription; de-identified (anonymised) on erasure; underlying tax/accounting records kept as required by law |
| Withdrawal-waiver consent record | Subscription life + the longest applicable limitation period |
| Legal-acceptance stamps (which Terms/Privacy version you accepted) | Retained indefinitely as legal proof, de-identified on erasure (user link and IP removed) |
| Audit log (admin and sensitive account actions) | Retained (tamper-evident log); actor identifiers anonymised on erasure |
| PDF download / watermark log | Retained; de-identified on erasure |
| Backups | Encrypted backups on EU infrastructure with point-in-time recovery. Erased data may persist in backups until backup rotation completes; during that window it is put beyond use (never restored to production except in disaster recovery, in which case erasure is re-applied) |
You have the rights of access, rectification, erasure, restriction, portability, and objection (GDPR Arts 15–21), and the right to withdraw any consent at any time without affecting prior processing.
Most rights are self-service, built into the product:
What survives erasure, in de-identified form (no name, email, IP, or user link):
To exercise any right, or if anything self-service fails, email support at moatkeep.com. We respond within one month.
We do not make decisions based solely on automated processing that produce legal effects or similarly significantly affect you.
For transparency: our abuse-detection system computes a deterministic risk score from security signals (§ 3). Its effects are limited to security friction — logging, an additional human-verification challenge, or a temporary, automatically-expiring login lockout — and no account is permanently blocked or terminated by the score alone; adverse actions are reviewed by a human administrator and automated lockouts are reversible.
Moatkeep is a research platform for adults. It is not directed at children, and we do not knowingly process data of anyone under 18.
If you believe we have processed your data unlawfully, please contact support at moatkeep.com first — we will try to resolve it.
This policy is versioned. Each published version is immutable and carries its effective date; when we make material changes we will publish a new version here and, where the change affects you significantly, notify you by email. The version history is auditable.