Privacy Policy

Version 2.0 · Last updated: 26 August 2026 · Supersedes the version of 22 August 2026

1. Who is responsible for your data

Controller

Decibest Financial, Spain

Privacy contact

support@decibest.com

Data protection officer

We have not appointed a DPO, as we are not required to under Art. 37 GDPR. Privacy requests go to the address above.

We are the data controller for the personal data described in this policy, under Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 (LOPDGDD).

We operate decibest.com, a stock research terminal. This policy explains what personal data we collect, why, on what legal basis, who we share it with, how long we keep it and what rights you have.

2. Personal data we collect

2.1 Data you give us

Account data

Email address, password hash or federated identity, optional display name, optional profile picture.

Product data you create

Watchlists, alert rules, holdings you enter, decisions you log, custom pillar weights, interface preferences.

Support data

The content of messages you send us and our replies.

Billing data

Name, billing address and country, VAT number where applicable, and the plan you choose. Card numbers are entered directly with our payment processor and never reach our servers.

2.2 Data we receive from third parties

If you sign in using Google, we receive from that provider your email address, a unique identifier and, where you have made them available, your name and profile picture. We do not receive your password. The provider's own privacy policy governs what it does with your data.

2.3 Data generated by your use of the Service

Usage data

Analysis requests and tokens consumed per day, which modules and pages you open, and timestamps. Used for quota enforcement and product analytics.

Approximate location and device context

Country, region and city derived from your IP address by our edge network, plus browser time zone, language, browser and operating system. We do not use precise or GPS location, and we do not store your IP address for the purpose of deriving location.

Acquisition data

The referring website and any campaign parameters (utm_source, utm_medium, utm_campaign) present the first time you arrive.

Subscription data

Plan, status, renewal dates, payment outcomes and invoices.

Technical and security logs

Server, application and error logs. These logs contain your IP address, together with request metadata, user agent and timestamps. We keep them to operate, debug and secure the Service and to detect and investigate abuse. Retention is set out in clause 9.

We do not knowingly collect special categories of personal data under Art. 9 GDPR, and you should not send us any.

3. Whether you have to provide it

Account data and billing data are necessary to enter into and perform our contract with you. If you do not provide them we cannot give you an account or a paid subscription. Everything else is either generated automatically by using the Service or is optional, and declining it does not stop you using the Service — although declining non-essential cookies means we see less about how the product is used.

4. Why we process it, and on what legal basis

Running your account and producing analyses

Performance of a contract — Art. 6(1)(b)

Payments, renewals and invoices

Performance of a contract — Art. 6(1)(b)

Service and transactional emails

Performance of a contract, and our legitimate interest in keeping you informed about a service you pay for — Art. 6(1)(b) and (f)

Security, abuse prevention, quota enforcement

Our legitimate interest in operating a secure service — Art. 6(1)(f)

Server-side aggregate analytics

Our legitimate interest in understanding and improving the product — Art. 6(1)(f). These do not read from or write to your device.

Analytics or personalisation that reads or writes on your device

Your consent — Art. 6(1)(a), with Art. 5(3) of Directive 2002/58/EC as transposed in Spain (Art. 22.2 LSSI)

Non-transactional marketing emails

Your consent — Art. 6(1)(a)

Accounting, tax, invoicing and anti-fraud obligations

Legal obligation — Art. 6(1)(c)

Establishing, exercising or defending legal claims

Our legitimate interest, and legal obligation where applicable — Art. 6(1)(f) and (c)

Where we rely on legitimate interest, we have assessed that interest against your rights and freedoms, and you can object at any time under clause 11. Where we rely on consent, you can withdraw it at any time, as easily as you gave it, without affecting the lawfulness of what we did before you withdrew.

We do not sell your personal data, and we do not share it with third parties for their own marketing.

5. Automated decision-making

5.1 Model outputs are not decisions about you. Scores, verdicts, pillar breakdowns and entry-quality assessments are analyses of financial instruments. They are not decisions about you, do not profile you, and produce no legal or similarly significant effect on you within the meaning of Art. 22 GDPR.

5.2 Automated account controls. Some operational checks are automated — quota enforcement, rate limiting, and detection of credential sharing or abusive use. These can restrict features or, in serious cases, lead to suspension of your account. Where an automated check restricts or suspends your account, you may obtain human review, express your point of view and contest the outcome by emailing support@decibest.com. We will respond within 5 working days.

6. Cookies and local storage

6.1 Strictly necessary. We use cookies and browser local storage that are essential to provide the Service: keeping you signed in, maintaining your session, security and load balancing, and remembering interface state such as recent tickers, chart overlays and collapsed panels. These do not require your consent because you have asked for the Service that needs them.

6.2 Everything else needs your consent. Analytics, measurement and any other non-essential cookie or storage access is only used if you accept it in our cookie notice, which offers Accept and Reject as equally available options. Refusing does not restrict your access to the Service.

6.3 Changing your mind. You can withdraw or change your cookie choices at any time by clearing this site's data in your browser, which makes the cookie notice appear again. Clearing cookies will also sign you out.

6.4 Duration. No cookie we set has a lifespan of more than 24 months. Consent choices are re-requested at least every 24 months, and sooner if our cookie use changes materially.

6.5 What we use

Authentication storage (first party)

Strictly necessary — keeps you signed in between visits. Duration: until sign-out or expiry of the session.

Interface preferences (first party)

Strictly necessary — remembers recent tickers, chart overlays, collapsed panels and menu order. Duration: up to 12 months.

Cookie consent record (first party)

Strictly necessary — records your choice so we do not ask again. Duration: 24 months.

Cached analysis data (first party)

Strictly necessary — speeds up the terminal by caching data you already requested. Duration: up to 7 days.

7. Who we share your data with

We use service providers who process personal data on our documented instructions under a data processing agreement meeting Art. 28 GDPR. We do not disclose your data to anyone else except where required by law or necessary to establish or defend legal claims.

Cloud database and authentication

Hosting, database and authentication for account and product data. EU/EEA hosting; any transfer outside the EEA is covered by adequacy or Standard Contractual Clauses.

Application hosting and edge network

Serves the application and derives approximate location from your IP address. Adequacy decision or Standard Contractual Clauses as applicable.

Stripe

Payment processing: billing and subscription data. EU and US processing under the EU–US Data Privacy Framework and Standard Contractual Clauses.

Transactional email delivery

Delivers account, billing and quota emails: email address and message content.

Market and fundamental data providers

Twelve Data, Financial Modeling Prep and Finnhub receive instrument queries only; requests are proxied by our servers and do not carry your identity.

AI provider

Generates the written explanation of a model output. Receives the instrument data and model output for that request, not your identity.

We keep this list current. Ask us at support@decibest.com if you want details of a specific provider. Our data providers are separate controllers for their own purposes. We do not send them your identity in the ordinary course of operating the Service.

8. International transfers

Some providers process personal data outside the European Economic Area, as shown in clause 7. Where they do, the transfer is covered by an adequacy decision of the European Commission under Art. 45 GDPR, or by the European Commission's Standard Contractual Clauses under Art. 46 GDPR together with a transfer impact assessment and any additional technical and organisational measures that assessment identifies as necessary.

Where a transfer to the United States relies on the EU–US Data Privacy Framework, we also maintain Standard Contractual Clauses with the provider as a fallback, so that transfers remain lawful if the adequacy decision is amended, suspended or annulled. You can request a copy of the relevant safeguards by emailing support@decibest.com.

9. How long we keep it

Account and product data

For as long as your account exists

After account deletion

Erased or anonymised within 30 days; removed from backups within 90 days

Billing, invoicing and accounting records

For the period required by Spanish tax and commercial law — generally 6 years from the end of the relevant financial year, and up to 10 years for anti-money-laundering purposes where applicable

Technical and security logs (including IP addresses)

90 days for general application logs; 12 months for security and abuse-detection logs

Support correspondence

24 months from closure of the ticket

Cookie consent records

24 months, as evidence that consent was obtained

Data relevant to a legal claim

Until the claim and any limitation period is resolved

Where we anonymise rather than erase, the result cannot be linked back to you and is no longer personal data.

10. Security

We apply technical and organisational measures appropriate to the risk under Art. 32 GDPR, including encryption in transit and at rest, access control on a least-privilege basis, hashed credentials, network isolation, logging and monitoring, and regular review of our providers. No system is perfectly secure, and we do not claim otherwise.

If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we notify the Agencia Española de Protección de Datos within 72 hours of becoming aware of it, and we notify you without undue delay where the risk is high.

11. Your rights

You have the right to:

  • Access your personal data and obtain a copy;
  • Rectify inaccurate or incomplete data;
  • Erase your data where one of the grounds in Art. 17 applies;
  • Restrict processing in the circumstances in Art. 18;
  • Data portability — receive the data you provided in a structured, commonly used, machine-readable format, and have it transmitted to another controller where technically feasible;
  • Object to processing based on legitimate interest, on grounds relating to your particular situation. Where you object to direct marketing, we stop, unconditionally and immediately;
  • Withdraw consent at any time, without affecting the lawfulness of processing before withdrawal;
  • Human review of automated account restrictions, as set out in clause 5.2.

How to exercise them. Email support@decibest.com. Most account data can also be viewed, corrected, exported or deleted directly in account settings.

Verification. We may ask you to confirm control of the email address on the account, or for other proportionate information, so that we do not disclose your data to someone else. We do not ask for more than we need.

Timing. We reply within one month. Where a request is complex or where you have made several, we may extend by up to two further months and will tell you why within the first month.

Cost. Free, unless a request is manifestly unfounded or excessive, in which case we may charge a reasonable fee or refuse, and will explain why.

Complaints. You can complain to a supervisory authority — in Spain, the Agencia Española de Protección de Datos, C/ Jorge Juan 6, 28001 Madrid, www.aepd.es. You can also complain to the authority in your country of residence or workplace. We would rather you came to us first, but you are not obliged to.

12. Children

The Service is not directed at people under 18, and we do not knowingly collect their personal data. If you believe a minor has given us data, contact support@decibest.com and we will delete it.

13. Changes to this policy

We may update this policy. We publish the new version with an updated date, and we announce material changes in the app or by email before they take effect. Where a change requires your consent, we ask for it.

14. Contact

Questions, requests or complaints: support@decibest.com. See also our Terms of Service.

Back to sign in