Privacy Policy
This policy explains which personal data we process when you visit festgeldkompass24.com, send us an enquiry through our form, or use our client portal at portal.festgeldkompass24.com – why we process it, and what rights you have.
We are a comparison and introducer service for fixed-term deposits („Festgeld“) at European partner banks. We are not a bank and we do not hold client money. Your deposit is held at the partner bank; we record the key details of that deposit so that you can view them in the portal. The partner bank is the controller for the processing that takes place at the bank.
This is a translation for convenience. The German version of this policy is the authoritative one.
1. Controller
The controller within the meaning of Art. 4(7) GDPR is:
- CHECK24 Vergleichsportal Karten & Konten GmbH
- Erika-Mann-Str. 62–66, 80636 München, Deutschland
- Represented by: Jan Schauhuber
- E-mail: support@festgeldkompass24.com
- Telephone: not yet provided
- Register court: Amtsgericht München, register number: HRB 231529
- VAT identification number: DE310935564
Data protection officer
If a data protection officer has been appointed, you can reach them at: Joachim Heer
2. What data we process and why
2.1 The enquiry form („Angebote anfordern“ / „Request offers“)
When you request offers on our website, we process the details you enter in the form: your name, e-mail address and telephone number, together with the amount and the term you selected in the deposit calculator. These details are stored in our database.
We use them solely to handle your enquiry, to put together suitable fixed-term deposit offers and to contact you about them.
Legal basis: Art. 6(1)(b) GDPR (steps taken at your request prior to entering into a contract, and performance of that contract).
2.2 The account created automatically
When you submit the enquiry, we automatically create a user account for you and e-mail you a link so that you can set your own password. The account lets you view your recorded deposits in the portal later on.
The account holds your name, e-mail address, password and the account role (for example client or staff member). Your password is stored only as a cryptographic hash (scrypt) – we never see it in plain text and cannot recover it.
Legal basis: Art. 6(1)(b) GDPR.
2.3 Recorded fixed-term deposits
If you have opened a fixed-term deposit at a partner bank through us, our staff record the key details of that deposit so that you can see them in the portal. We record:
- the partner bank
- the amount invested
- the interest rate
- the term, together with the start date and the maturity date
- the contract reference
- the bank's deposit-guarantee wording
- an internal note
- which member of staff entered the record
Legal basis: Art. 6(1)(b) GDPR (performance of our contract with you); for the retention of these records also Art. 6(1)(c) GDPR together with commercial and tax retention duties.
2.4 Account activity log
For every account we keep a log of account events (for example sign-ins, changes to the account, and the creation or amendment of a deposit record). This lets us trace what happened, investigate faults and protect your account against unauthorised access.
Legal basis: Art. 6(1)(f) GDPR (our legitimate interest in secure and auditable operation); where the log serves the performance of the contract, also Art. 6(1)(b) GDPR.
2.5 Identity verification (KYC) through Didit
Identity verification is carried out by the provider Didit (verification.didit.me). It works as follows:
- You are directed to a page operated by Didit.
- There you photograph your identity document and take a selfie.
- Didit automatically checks that the capture is of a live person (liveness), compares the selfie with the photograph on the document (face match), and reads the document's data by machine (OCR).
Important, and stated plainly: the images of your identity document and your selfie are not stored on our own servers. What we store is only the outcome of the verification and a session identifier for it. Authorised staff can view the images when they need to; in that case the images are streamed directly from the provider through an access-controlled endpoint and are not cached.
Identity documents and biometric features are particularly sensitive. The face match processes biometric data within the meaning of Art. 9(1) GDPR; it takes place at the provider.
Legal basis: Art. 6(1)(c) GDPR together with the duties of the German Money Laundering Act (Geldwäschegesetz, GwG) where identification is required by law; otherwise Art. 6(1)(b) GDPR, because without verification the deposit cannot be opened at the partner bank.
2.6 Security, abuse prevention and server logs
To protect our systems against overload and abuse (for example automated sign-in attempts) we keep rate-limit records. Operating the website also generates technical server logs (including IP address, time, the address requested, the status code and the browser type).
Legal basis: Art. 6(1)(f) GDPR (our legitimate interest in IT security, stability and abuse prevention).
3. Recipients and processors
We pass on your data only where this is necessary for the purposes described above. Besides the partner bank you choose, we use the following service providers:
3.1 Didit – identity verification
Didit operates the verification page at verification.didit.me and in doing so receives the image of your identity document, your selfie and the data read from them.
3.2 Resend – sending our e-mails
Our transactional e-mails (account creation, password setup, verification notices) are sent through the service Resend (api.resend.com). Resend receives your e-mail address and the content of the message. The sending region we observe in use is the EU region (eu-west-1).
3.3 Hostinger – hosting (server in the United Kingdom)
Our website and portal run on infrastructure provided by Hostinger International Limited. The server in use is physically located in Manchester, United Kingdom. All data you send us is therefore processed on a server outside the EU and the EEA.
The United Kingdom is a third country for the purposes of the GDPR. The European Commission has adopted an adequacy decision for the United Kingdom under Art. 45 GDPR, and the transfer is based on that decision. An adequate level of protection is therefore established without the need for further safeguards.
3.4 Google Fonts – web fonts on the public website
Our public website currently loads its web fonts directly from fonts.googleapis.com and fonts.gstatic.com. When you open a page, your browser therefore connects to Google and your IP address is transmitted to Google. Without this embedding, no such transfer would be necessary.
3.5 Other recipients
Beyond this, we disclose data where we are legally obliged to or where it is necessary to pursue legal claims – for example to public authorities, courts, tax advisers or auditors. We do not sell your data and we do not pass it to third parties for advertising purposes.
4. Cookies
We use only a small number of cookies, and they exist solely to operate the website and the portal:
- fgk_consent – stores your choice in the cookie banner. Lifetime: 1 year. Necessary so that we do not have to ask again on every visit.
- fgk-lang – stores the language you selected (German or English).
- Session cookies with the prefix „fgk“ (Better Auth) – keep you signed in to the portal. They are set httpOnly (not readable by JavaScript) and use SameSite=Lax. Strictly necessary.
- Theme preference (light/dark) – stores whether you chose the light or the dark appearance.
We use no analytics cookies, no tracking pixels and no advertising cookies. There is no web analytics and no profiling for advertising purposes, neither by us nor by third parties.
Legal basis: for strictly necessary cookies, § 25(2) no. 2 TDDDG (technically necessary storage) together with Art. 6(1)(b) and (f) GDPR; for any non-necessary cookies and comparable technologies, your consent under § 25(1) TDDDG and Art. 6(1)(a) GDPR, which you may withdraw at any time through the cookie banner with effect for the future.
5. Retention periods
We keep personal data only for as long as it is needed for the relevant purpose or for as long as statutory retention duties require. The following periods apply:
- Enquiries that do not lead to a contract: deleted no later than 6 months after the last contact.
- Account data: for as long as the account exists; removed within 30 days of its deletion, unless a retention duty prevents this.
- Recorded deposits and related correspondence: 6 or 10 years from the end of the calendar year in which the matter was completed (§ 257 HGB, § 147 AO).
- Identity verification data (outcome and session identifier): 5 years after the end of the business relationship, at most 10 years (§ 8(4) GwG). The images themselves are held by the provider and are subject to the provider's own retention period.
- Account activity log: 12 months.
- Rate-limit records: short-lived, usually a few hours.
- Server logs: 14 days.
6. Your rights
You have the following rights in respect of your personal data:
- Access (Art. 15 GDPR) – to find out whether and what data we process about you, and to receive a copy.
- Rectification (Art. 16 GDPR) – we must correct inaccurate data and complete incomplete data.
- Erasure (Art. 17 GDPR) – you may ask us to delete your data, unless a retention duty prevents it.
- Restriction of processing (Art. 18 GDPR) – for instance while the accuracy of data is being checked.
- Data portability (Art. 20 GDPR) – to receive the data you provided in a common, machine-readable format.
- Objection (Art. 21 GDPR) – see the separate notice below.
- Withdrawal of consent (Art. 7(3) GDPR) – you may withdraw any consent at any time with effect for the future. This does not affect the lawfulness of processing carried out before the withdrawal.
How to exercise your rights: an informal message to support@festgeldkompass24.com or to Erika-Mann-Str. 62–66, 80636 München, Deutschland is enough. We reply without undue delay and within one month at the latest. So that we do not hand your data to the wrong person, we may need to ask you for further details to identify you; exercising your rights is free of charge.
Right to complain to a supervisory authority
Independently of the above, Art. 77 GDPR gives you the right to lodge a complaint with a data protection supervisory authority – in particular in the EU Member State of your residence, your place of work or the place of the alleged infringement. The authority responsible for us is: Erlaubnis nach § 34c GewO, erteilt durch die Landeshauptstadt München, Kreisverwaltungsreferat, Ruppertstraße 19, 80466 München
7. Right to object
You have the right, on grounds relating to your particular situation, to object at any time to processing of your personal data that is based on Art. 6(1)(f) GDPR (in our case: the account activity log, rate limiting, server logs and IT security). We will then stop processing that data unless we can demonstrate compelling legitimate grounds that override your interests, or the processing serves to establish, exercise or defend legal claims (Art. 21(1) GDPR).
Where we were to process your data for direct marketing, you may object at any time and without giving reasons; we would then stop using your data for that purpose (Art. 21(2) and (3) GDPR).
Please send your objection informally to support@festgeldkompass24.com.
8. Automated decision-making
We do not take automated decisions producing legal effects concerning you within the meaning of Art. 22 GDPR. We operate no scoring and no profiling.
We must, however, disclose the following: the identity verification described in section 2.5 runs automatically at the provider. Liveness detection, face match and document reading are performed by machine, and the verification outcome is generated automatically. That outcome is not a final determination on our side: authorised staff can review the case and assess it manually, and you may at any time write to support@festgeldkompass24.com to request review by a human, put your point of view and contest the outcome.
9. Whether you have to provide the data
Providing your contact details in the enquiry form is neither required by law nor by contract, but without them we cannot deal with your enquiry. The identity verification data is required by law wherever the Money Laundering Act calls for identification; without it the business relationship cannot be entered into.
10. Data security
Traffic between your browser and our servers is encrypted throughout with TLS (HTTPS). Passwords are stored only as a scrypt hash. Access to client and verification data is limited to authorised staff and is logged; verification images are retrieved through an access-controlled endpoint with no caching.
11. Changes to this policy
We update this policy when our services, the providers we use or the legal position change. The version published on this page is the one that applies.