Skip to content
Generavio

Generavio · Legal

Privacy notice

Information about personal-data processing at Generavio.

Last updated: 6 September 2026

1. Controller and contact

Generavio.com Dorfstrasse 21a 6800 Feldkirch Austria

Privacy and support requests: support@generavio.com

2. Data we process

  • account data such as email address, display name, language preference, verification and session data
  • family memberships and roles
  • adult-created nicknames, colours or avatars for child profiles
  • simulated portfolios, contributions, ETF purchases and values derived from them
  • invitation, security, audit and technical error data
  • support messages, export and deletion operations
  • necessary cookie/language settings and consent records

3. Purposes and legal bases

Data is processed to provide accounts and family areas, enforce permissions, calculate the simulated financial history correctly, provide support, prevent abuse and comply with legal obligations.

Accounts and family areas are provided for the performance of the service agreement. Security and abuse-prevention measures rely on legitimate interests. Processing that requires consent takes place only after consent; legal duties are fulfilled on the applicable statutory basis.

4. Children's data

Children do not have their own account or credentials. An adult Family Owner manages the family and provides only a nickname and optional presentation attributes. A child's date of birth, birth year, address, school and location are not required.

5. Recipients and service providers

Generavio uses Neon for database and authentication, Vercel for hosting, Cloudflare for DNS and email routing, and Resend for transactional email. Providers receive only the data required for their respective task. Where data is processed outside the European Economic Area, the safeguards provided for that transfer by the relevant provider are used.

6. Retention

A statutory duty or documented legal matter may require a different period for the affected records.

  • unaccepted invitations: expire after 7 days; delete personal invitation data after a further 30 days
  • routine application logs: 30 days; security logs: generally 90 days
  • critical audit events and reduced deletion metadata: generally 12 months
  • closed support correspondence: generally 12 months
  • temporary export files: no more than 24 hours; direct transfer is preferred
  • inactive accounts: notice after 18 months and scheduled deletion after 24 months with at least 30 days' warning
  • backups: rolling maximum of 30 days

7. Rights and withdrawal

Data subjects may request access, rectification, erasure, restriction, portability and, where applicable, object to processing. Consent may be withdrawn at any time for the future without making core access dependent on optional advertising. Requests can be sent to support@generavio.com.

A complaint may be lodged with the competent data protection authority. For the Austrian controller, this is generally the Austrian Data Protection Authority, Barichgasse 40–42, 1030 Vienna, dsb.gv.at.

8. Cookies and advertising

Necessary authentication, security and language settings are separated from optional advertising. No advertising scripts are currently loaded. There is no advertising in authenticated family, child, portfolio or transaction areas, and family or financial data is not sent to advertising providers.

9. Security and changes

Generavio uses server-side authorization, tenant isolation, Row Level Security, encrypted transport and logging of critical operations. No technical measure can guarantee absolute security.

Material changes will be versioned and communicated transparently before they take effect.