{
  "schema": "rv.privacy_processing_inventory.v1",
  "version": "2026-08-28",
  "status": "owner_legal_review_required",
  "controller_ref": "https://rubikvault.com/imprint",
  "supervisory_authority": {
    "name": "State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia",
    "url": "https://www.ldi.nrw.de/"
  },
  "automated_decision_making": {
    "legal_or_similar_significant_effect": false,
    "note": "Market classifications are informational product outputs and do not make decisions about a user."
  },
  "processes": [
    {
      "id": "public_delivery_security",
      "purpose": "Deliver and protect the website and APIs.",
      "legal_basis": "GDPR Article 6(1)(f): secure and reliable service operation.",
      "categories": ["IP address", "request time", "requested resource", "status code", "referrer", "user agent"],
      "data_subjects": ["website visitors"],
      "recipients": ["Cloudflare as hosting and security processor"],
      "third_country": "Provider processing may involve the United States; the current provider transfer mechanism and data-processing terms require owner verification before commercial activation.",
      "retention": "Provider security and access logs are retained according to the configured Cloudflare plan and settings; RubikVault does not create a separate raw visitor log.",
      "required": true,
      "consequence_if_not_provided": "The website cannot be delivered securely."
    },
    {
      "id": "aggregate_product_analytics",
      "purpose": "Measure page areas, actions, channels and coarse errors to improve the product.",
      "legal_basis": "GDPR Article 6(1)(f): privacy-bounded product quality and error detection.",
      "categories": ["allowlisted event", "day", "surface", "element", "channel", "coarse outcome", "coarse error code", "optional campaign", "optional content ID", "optional app version"],
      "data_subjects": ["website and app users"],
      "recipients": ["Cloudflare KV as infrastructure processor"],
      "third_country": "Same Cloudflare processing context as public delivery.",
      "retention": "Anonymous aggregates only; account-linked lifecycle details expire after 90 days.",
      "required": false,
      "consequence_if_not_provided": "No loss of public research access."
    },
    {
      "id": "local_preferences_watchlists",
      "purpose": "Remember explicitly requested device-local preferences and watchlists.",
      "legal_basis": "TDDDG Section 25(2)(2): storage required for the function requested by the user.",
      "categories": ["preferences", "watchlist names", "asset references", "private notes"],
      "data_subjects": ["users choosing local convenience features"],
      "recipients": ["none until the user explicitly enables cloud sync"],
      "third_country": "None for device-local storage.",
      "retention": "Until removed by the user or browser storage is cleared.",
      "required": false,
      "consequence_if_not_provided": "The selected convenience setting is not remembered."
    },
    {
      "id": "account_identity_sync",
      "purpose": "Authenticate an optional account and provide sync, saved content, history, alerts and sessions.",
      "legal_basis": "GDPR Article 6(1)(b): requested account service; Article 6(1)(f) for session security and abuse prevention.",
      "categories": ["Firebase subject", "verified email", "optional display name", "login provider", "account ID", "consent records", "saved items", "watchlists", "alerts", "devices", "sessions", "activity"],
      "data_subjects": ["registered users"],
      "recipients": ["Google Firebase Authentication", "Cloudflare KV"],
      "third_country": "Google and Cloudflare processing may involve the United States; current data-processing terms and transfer safeguards require owner legal verification before commercial activation.",
      "retention": "For the account lifetime; session and one-time records expire automatically; deletion removes allowlisted account data unless statutory retention applies.",
      "required": false,
      "consequence_if_not_provided": "Public research remains available; account convenience features are unavailable."
    },
    {
      "id": "account_feedback_reports",
      "purpose": "Receive voluntary authenticated structured feedback and diagnostics for product improvement.",
      "legal_basis": "GDPR Article 6(1)(a): explicit voluntary submission consent; Article 6(1)(f) for secure review and abuse prevention.",
      "categories": ["pseudonymous RubikVault account ID", "fixed feedback kind/reason/rating", "fixed diagnostic severity/error code", "feature area", "web/iOS/Android surface", "app version", "consent version", "creation and expiry time"],
      "data_subjects": ["authenticated users voluntarily submitting a report"],
      "recipients": ["Google Cloud Firestore as report storage processor", "RubikVault operator"],
      "third_country": "Firestore database region is europe-west3; current Google processing terms and transfer safeguards require owner verification before activation.",
      "retention": "Up to 90 days or until account deletion; reports contain no free text, email, name, raw route, content/ticker identifier, raw IP, user agent, auth token, password, payment, portfolio, brokerage, session or anonymous visitor ID.",
      "required": false,
      "consequence_if_not_provided": "No loss of public research or account access; RubikVault does not receive that feedback or problem report."
    },
    {
      "id": "firebase_crashlytics_private_debug",
      "purpose": "Diagnose crashes in owner-controlled private Debug builds before public release.",
      "legal_basis": "GDPR Article 6(1)(f): secure pre-release quality testing; public release collection remains disabled pending separate legal approval.",
      "categories": ["crash stack", "app version", "operating-system version", "device model", "coarse RubikVault error code"],
      "data_subjects": ["owner and explicitly invited private Debug testers"],
      "recipients": ["Google Firebase Crashlytics", "RubikVault operator through Firebase console"],
      "third_country": "Google processing may involve the United States; current data-processing terms and transfer safeguards require owner legal verification before any public activation.",
      "retention": "Firebase project retention setting for private test diagnostics; remove test data after acceptance. No RubikVault user ID, email, auth token, raw visitor event or custom free-form user text is attached by app code.",
      "required": false,
      "consequence_if_not_provided": "Private crash diagnostics are unavailable; public app functionality is unchanged."
    },
    {
      "id": "premium_billing",
      "purpose": "Create, administer and verify Premium subscriptions.",
      "legal_basis": "GDPR Article 6(1)(b) and Article 6(1)(c) for statutory billing records.",
      "categories": ["customer ID", "subscription or transaction ID", "product ID", "entitlement status", "period end", "billing event ID", "pseudonymous trial reservation or consumed state", "time-bounded account-deletion guard"],
      "data_subjects": ["Premium customers"],
      "recipients": ["Stripe for web billing", "Apple for iOS billing", "Google for Android billing", "Cloudflare KV and Durable Objects"],
      "third_country": "Provider-specific transfer mechanisms and terms require owner verification before activation.",
      "retention": "Entitlement and one-trial state for the account lifetime. Account deletion removes both and does not retain a person-lifetime trial tombstone. A pseudonymous account/customer deletion guard expires after 180 days and exists only to stop delayed signed billing events from recreating deleted account data. Legally required commercial and tax evidence is retained separately for the applicable statutory period.",
      "required": true,
      "consequence_if_not_provided": "Premium cannot be purchased or restored."
    },
    {
      "id": "messages_notifications",
      "purpose": "Deliver requested service messages, double-opt-in newsletters and alerts.",
      "legal_basis": "GDPR Article 6(1)(b) for requested service messages; Article 6(1)(a) for marketing email and push consent.",
      "categories": ["email address", "delivery metadata", "alert preferences", "push subscription or device token"],
      "data_subjects": ["subscribers and users enabling notifications"],
      "recipients": ["owner-approved email provider", "browser push services", "Apple Push Notification service", "Firebase Cloud Messaging"],
      "third_country": "Depends on the activated provider; safeguards and processor terms require owner verification.",
      "retention": "Until consent is withdrawn, the subscription is removed, or bounded delivery evidence expires.",
      "required": false,
      "consequence_if_not_provided": "The selected message or notification cannot be delivered."
    },
    {
      "id": "consumer_contract_actions",
      "purpose": "Receive, execute and prove subscription cancellation, withdrawal and account-deletion declarations.",
      "legal_basis": "GDPR Article 6(1)(b) and Article 6(1)(c): contract administration and statutory consumer/commercial record duties.",
      "categories": ["account ID", "verified email", "request reference", "receipt time", "contract action", "optional reason", "provider action status"],
      "data_subjects": ["account holders and Premium customers"],
      "recipients": ["Cloudflare KV", "transactional email provider", "Stripe, Apple or Google when required to execute the action"],
      "third_country": "Depends on activated infrastructure and payment providers; safeguards and processor terms require owner verification.",
      "retention": "Contract-action evidence is retained for the applicable statutory commercial limitation and record period; the configured maximum is ten years.",
      "required": true,
      "consequence_if_not_provided": "The requested contract action cannot be identified, executed or proven."
    }
  ]
}
