Version 6 · effective 6 August 2026
Moatkeep ("Moatkeep", "we", "us") is operated by LGConsult LDA, a limited liability company, Registered in Portugal.
We are the controller of the personal data described in this policy, within the meaning of Regulation (EU) 2016/679 (the "GDPR").
Moatkeep is a research and data platform for everyone interested in such data. It provides company fundamentals, market prices, valuation metrics, editorial and research content that is AI-assisted and human-reviewed, and automatically generated news summaries that are published without prior editorial review (see § 3a). Moatkeep does not provide investment advice, portfolio management, or any regulated advisory service. Nothing on the platform is a recommendation to buy, sell, or hold any security, or can be construed as such in any instance.
This policy covers personal data processed when you visit moatkeep.com, register an account, subscribe to a paid plan, or contact us. Most of the company financial data we publish is information about companies, not about people.
It also covers one case where we process personal data about someone who is not a Moatkeep user: our news summaries name individuals — typically executives, directors and spokespeople — who appear in published financial news. If you are named in one of our news items, § 3a tells you what we do, why, where we got it, and how to object.
| Category | Data | Purpose | Retention (see § 8) |
|---|---|---|---|
| Account data | Email address, name, title, password (as a hash), account preferences, tier | Creating and operating your account; authentication; providing the service | Life of the account + 14-day deletion grace period |
| Optional onboarding profile | Self-described investing experience, goals, how you found us (a single, skippable screen) | Understanding our audience; improving the product | Life of the account; deleted on erasure |
| Ad-click attribution | If you arrive from one of our Google Search ads: the ad-click identifier from the URL (a "gclid", "gbraid" or "wbraid" parameter), when you arrived, which of our campaigns/keywords the click belonged to, and — if you register — the link between that click and your account | Measuring whether our own advertising works (which searches lead people to register and, in aggregate, subscribe); reporting a registration back to Google as an ad conversion (see § 6, Google). Legal basis: your consent (Art 6(1)(a)) where you accept the ad-arrival notice, which is what sets the cookie described in § 5; otherwise our legitimate interest in measuring our own advertising (Art 6(1)(f)), for which an assessment is on file. You can object at any time (Art 21) by emailing support at moatkeep.com | Click identifier deleted ~60 days after capture; the resolved campaign/keyword reference (which contains nothing identifying) is retained for reporting; the attribution record is deleted with the account (§ 8, § 9) |
| Phone number | Phone number, verification status | One-time SMS verification at account activation, to deter automated and abusive sign-ups. Verification is delivered by a third party; | Life of the account; deleted on erasure |
| Payment and billing data | See § 4 — Stripe is the merchant of record | Charging subscriptions; invoicing; refunds | See § 4 and § 8 |
| Security and abuse-detection data | Authentication events (logins, failures, verifications) on a 90-day rolling log: event type and outcome; full IP address only on security events, kept ≤ 30 days; a truncated (subnet-level) IP for rate analysis; a one-way hashed, server-side device fingerprint (HMAC of passive connection characteristics with a rotating server-held key — no fingerprinting script runs in your browser); coarse geolocation derived locally; a deterministic risk score | Detecting credential-stuffing, account takeover, sign-up abuse, and impossible-travel logins; account lockout and step-up challenges | Identifying fields anonymised at ≤ 30 days; de-identified events purged at 90 days |
| Your content | Watchlists, price/metric alerts, private notes, favourites | Providing the features you use | Life of the account; deleted on erasure |
| Alert emails | Your email address and the alert digests we send you (delivered via Resend) | Sending the alert digest emails you configure; every digest carries a one-click unsubscribe | Delivery metadata per Resend's processing terms; alert configuration lives with your account |
| PDF download records | A log of each research-report PDF you download, including the forensic watermark identifier embedded in the file | Deterring and investigating unauthorised redistribution of paid content | Retained; de-identified on erasure (the record survives with the user link removed) |
| Legal-acceptance records | Which published version of the Terms/Privacy Policy/Subscription Terms you accepted, when, and the IP at acceptance; the withdrawal-waiver consent record at checkout (wording version, timestamp, IP, confirmation-email reference) | Proving what you agreed to (defence against repudiation; consumer-law record-keeping) | See § 8; IP is deleted on erasure |
| Error and diagnostics data | Application error reports and operational telemetry. No email address, session IP, or raw device signals are sent to any outside tools — only opaque identifiers. | Detecting and fixing faults; keeping the service reliable | Per tool retention defaults; no directly identifying fields by design |
| Correspondence | Emails you send to support at moatkeep.com | Answering you; handling rights requests and complaints | kept for two years |
| People named in news summaries | Name, job title/role, employer, and what public reporting attributes to that person (a quote, a statement, an appointment, a departure); and the bylined journalist of a source article, where the source names one. Together with the source we took it from — publisher, headline, URL and publication date. No contact details, no identifiers, no special-category data (see § 3a) | Publishing short, attributed summaries of business news about the companies we cover, so readers can follow a company they research on Moatkeep | Legitimate interests — Art 6(1)(f); a Legitimate Interests Assessment (LIA) is on file (see § 3a) |
What we do not do: we run no third-party analytics and no cross-site tracking, and we load no advertising trackers on this site. We do advertise Moatkeep on Google Search; if you arrive from such an ad we measure that arrival ourselves, first-party (see the ad-click attribution row above) — no Google tag, pixel or analytics script runs on this site, and nothing here tracks you across other sites. We do not sell or rent personal data. We do not use your personal data to train AI models, and no user personal data is sent to our AI provider.
Moatkeep publishes short news summaries about the companies we cover. They are written automatically by an AI system, from named and linked public sources, and they sometimes name individuals — typically executives, directors and spokespeople whose statements or appointments are reported in the business press. If that is you, this section is the information Article 14 GDPR requires us to give you, and we are the controller (see § 1).
What we process. Your name; your job title or role and the company you are associated with; and what the source reported about you in your professional capacity — for example a quoted statement, an appointment, or a departure. If you are the journalist bylined on a source article, we also show your name next to the attribution and the link, so that credit for the original reporting is visible. We do not collect your contact details, and we do not build a profile of you: we hold no record about you at all — only the text of individual items, which we never link together by person. We do not knowingly publish special-category data (Article 9) or criminal-offence data (Article 10) about named individuals, and our publication pipeline holds items back for human review when it detects them.
Where we got it. Never from you. Every item names the source publication and links to the original, on the item itself, together with the source's own publication date where the source states one (and says so plainly where it does not). We deliberately do not reproduce the source's headline — our summaries are written in our own words. Those pages were publicly accessible when we read them: we do not use material obtained by circumventing a paywall or a login.
Why we do it, and on what legal basis. Our legal basis is legitimate interests, Article 6(1)(f). The interests we pursue are: informing our subscribers about developments at companies they research on our platform; providing an accurate, attributed, source-linked pointer to the original reporting; and keeping a public record of what we published, when, so our own output can be checked. We are not relying on any journalistic exemption. We have carried out and documented a Legitimate Interests Assessment weighing those interests against your rights — in particular against what you can reasonably expect from an automatically generated aggregator, which is not the same as what you expect from the publication you originally spoke to. It is available on request at support at moatkeep.com.
How long we keep it. For as long as the item stays published. We do not silently delete published items; where we must remove personal data we redact the item in place, so the record that an item existed on a date, and which sources it came from, survives without your details.
Where it goes. News items are published on moatkeep.com and are readable by the public, and — because they are ordinary public web pages listed in our sitemap — search engines can index them, so an item naming you may appear in search results. We do not sell, licence or syndicate them, we send them to no other recipient, we do not use them to train AI models, and they are stored on our infrastructure in the European Union.
Automated processing. The summary itself is generated by an AI system without a person reviewing it before publication — which is why the news surfaces carry a visible "AI-generated" label at the point you first see an item. This is not automated decision-making under Article 22: nothing about the item produces a legal effect on you or similarly significantly affects you. It is publication, and if it is wrong we correct it.
Your rights, and how to use them. You have the rights in § 9 — access, rectification, erasure, restriction and portability — against us for this data as well. To use any of them, write to support at moatkeep.com. We aim to reply within 72 hours and will reply within one month at the latest (Article 12(3)). Because we cannot recognise you from an email address alone, we will ask you for proportionate proof of identity before we change or remove anything — only what is needed to be reasonably sure the request is yours (Article 12(6)). We keep a record that this check was carried out, and we do not keep the proof itself for longer than the request takes to handle.
Your right to object
You have the right to object, at any time, to our publication of a news summary that names you — on grounds relating to your particular situation — because we rely on legitimate interests (Article 21(1) GDPR). You do not need to give a reason beyond your situation, and objecting costs you nothing.
If you object, we stop unless we can show compelling legitimate grounds that override your interests, rights and freedoms. In practice we will either redact your details from the item, withdraw the item, or — if we believe the public interest in an accurate, sourced record outweighs the objection — tell you so, in writing, with our reasons, so that you can complain to a supervisory authority or go to court.
To object: email support at moatkeep.com with "Objection" in the subject line and a link to the item.
Why we are telling you here rather than emailing you. Article 14(5)(b) GDPR allows us not to contact every individual named in a news item where doing so would be impossible or a disproportionate effort — which it is, since we hold no contact details for you and obtaining them would mean collecting more of your personal data than we publish. That exemption is conditional on us making this information publicly available instead, which is what this section is. It is published at /legal/privacy, linked from every page of the site, and not gated behind an account.
Payments run on Stripe under Stripe's Managed Payments service, with Stripe as the merchant of record.
Your purchase contract for the paid subscription is with Stripe (contracting through Stripe Payments Europe, Limited, Ireland — "SPEL"), which acts as the merchant of record and reseller of Moatkeep subscriptions. Stripe is an independent controller of the payment data it collects at checkout (card details, billing address, tax location) and issues receipts and handles refunds under its own privacy notice (stripe.com/privacy). Moatkeep never receives your full card number; we receive subscription status, tier, and limited billing metadata needed to grant access. Statement descriptors and receipts are issued by Stripe/Link under this model.
Stripe's EU contracting entity is SPEL (Ireland), and Stripe's group may transfer personal data to Stripe, LLC (US) and other affiliates under the 2021 EU Standard Contractual Clauses incorporated in Stripe's Data Transfers Addendum, with Stripe's EU–US Data Privacy Framework certification also referenced (see § 7). Stripe's checkout sets cookies on the checkout page only (see § 5).
We mirror your subscription status (active/cancelled/etc., tier, period dates) in our own systems to control access. If you exercise your right of erasure, we cancel any active Stripe subscription and retain the subscription record in anonymised (de-identified) form (see § 9).
Moatkeep uses strictly necessary cookies, plus one optional cookie that exists only if you arrive from one of our ads and accept the one-line notice shown on that arrival. We set no analytics or cross-site tracking cookies, and load no third-party fonts or trackers. This page (together with the dedicated cookie notice at /cookies) provides the required transparency.
Cookies we set: CSRF/security token; Cloudflare related bot management and security; Turnstile cookies; Stripe session cookies strictly necessary for payments; and, only if you arrive from one of our Google Search ads and accept the one-line notice shown then, mk_gclid (the ad-click identifier, kept 30 days) and mk_ad_notice (your accept/decline answer, kept 12 months, so we don't ask again). Lifetime as strictly required to assure the application's correct functioning, except the two ad-related cookies just named, which follow the durations stated above.
Stripe's scripts load only on the checkout page, and Turnstile loads only on the registration page; neither runs elsewhere on the site.
We use the following service providers. Each processes personal data only on our documented instructions under a data-processing agreement (GDPR Art 28), except where marked as an independent controller.
| Provider | Role | What they process | Location of processing |
|---|---|---|---|
| Hetzner Online GmbH | Hosting (all application data, databases, backups) | All categories in § 3 | Germany / Finland (EU) |
| Cloudflare, Inc. | Network/CDN, DDoS protection, bot management, Turnstile, object storage for data-export bundles | Connection metadata (IP, headers) in transit; security cookies; temporary data-export archives | Global edge network; EU–US transfers per § 7 |
| Stripe (SPEL, Ireland / Stripe, LLC, US) | Payments — independent controller as merchant of record (see § 4); processor role limited to account-servicing data | Payment and billing data (§ 4) | EU (SPEL) with possible US transfer (§ 7) |
| Resend, Inc. | Transactional email (verification emails, alert digests, billing confirmations) | Email address, message content | US-based provider |
| Twilio, Inc. | SMS phone verification | Phone number, verification metadata | United States; transfer per § 7 |
| Functional Software | Application error monitoring | Error reports with opaque identifiers; scrubbed of email/IP/device signals | ingest endpoint Germany. US parent company |
| Operational Telemetry | Operational telemetry (metrics, logs, traces), PII-redacted before shipping | Opaque operational identifiers only | EU region |
| Anthropic, PBC | AI model provider for content generation | None of your personal data. Our AI agents draft editorial and research content from public financial data (regulatory filings, market prices, economic series) under human review. No account data, usage data, or any user personal data is sent to Anthropic | US — but not a processor of user personal data; listed for transparency |
| Google Ireland Limited | Advertising conversion measurement — independent controller. When a person who arrived from one of our Google ads registers, we report the conversion to Google so our advertising account reflects it. Exactly what we send: the ad-click identifier Google itself issued, the time of the registration, which conversion type it was (free registration, or — reported separately and without any amount attributable to you personally beyond the subscription price — a later paid subscription), and an internal reference number of ours. We never send your name, email address, phone number, or any hashed version of them. Google processes this under its own Ads data-protection terms | The ad-click identifier + conversion event described in § 3 | EU (Google Ireland) with possible US transfer (§ 7) |
Not processors: our market- and fundamentals-data suppliers (e.g. SEC EDGAR, Databento, FRED) supply public financial data about companies to us; they do not receive or process any personal data about our users and are therefore not sub-processors.
We are established in Portugal and host all core application data in the EU (Hetzner, Germany/Finland). Some providers involve transfers to the United States:
| Data | Retention |
|---|---|
| Account, profile, content (watchlists, alerts, notes, favourites) | Life of the account, then deleted via the erasure process (§ 9) after the 14-day grace period |
| Authentication/security events | Identifying fields (full IP, hashed fingerprint, geo) anonymised at ≤ 30 days; de-identified events hard-deleted at 90 days |
| Ad-click identifier (gclid/gbraid/wbraid) | Deleted (nulled) ~60 days after capture by an automated daily job; the resolved campaign/ad-group/keyword reference survives without any identifier; the attribution record itself is deleted with the account |
| Full IP on security events | ≤ 30 days |
| Data-export bundles (§ 10) | Short-lived download (expires automatically); the archive is deleted on expiry and always deleted on erasure |
| Subscription/billing mirror | Life of subscription; de-identified (anonymised) on erasure; underlying tax/accounting records kept as required by law |
| Withdrawal-waiver consent record | Subscription life + the longest applicable limitation period |
| Legal-acceptance stamps (which Terms/Privacy version you accepted) | Retained indefinitely as legal proof, de-identified on erasure (user link and IP removed) |
| Audit log (admin and sensitive account actions) | Retained (tamper-evident log); actor identifiers anonymised on erasure |
| PDF download / watermark log | Retained; de-identified on erasure |
| Backups | Encrypted backups on EU infrastructure with point-in-time recovery. Erased data may persist in backups until backup rotation completes; during that window it is put beyond use (never restored to production except in disaster recovery, in which case erasure is re-applied) |
| Personal details inside a published news summary | Kept while the item is published; redacted in place on erasure or a successful objection (the item's existence, date, and source links survive without the personal details) |
You have the rights of access, rectification, erasure, restriction, portability, and objection (GDPR Arts 15–21), and the right to withdraw any consent at any time without affecting prior processing.
Most rights are self-service, built into the product:
What survives erasure, in de-identified form (no name, email, IP, or user link):
Where we have reported an ad conversion to Google (§ 6) and you later exercise erasure, we delete our copy of the click identifier and the link to your account, and we notify recipients as Art 19 requires where feasible. The conversion remains in Google's aggregate advertising statistics under Google's own controllership.
To exercise any right, or if anything self-service fails, email support at moatkeep.com. We respond within one month.
We do not make decisions based solely on automated processing that produce legal effects or similarly significantly affect you.
For transparency: our abuse-detection system computes a deterministic risk score from security signals (§ 3). Its effects are limited to security friction — logging, an additional human-verification challenge, or a temporary, automatically-expiring login lockout — and no account is permanently blocked or terminated by the score alone; adverse actions are reviewed by a human administrator and automated lockouts are reversible.
Moatkeep is a research platform for adults. It is not directed at children, and we do not knowingly process data of anyone under 18.
If you believe we have processed your data unlawfully, please contact support at moatkeep.com first — we will try to resolve it.
This policy is versioned. Each published version is immutable and carries its effective date; when we make material changes we will publish a new version here and, where the change affects you significantly, notify you by email. The version history is auditable.