Data protection and privacy
1. The principle
In two lines
Your accounts do not leave your computer. We do not see them, we do not store them, we could not produce them if we were asked to.
The only personal data we process is that of the licence and of support. At no point do we have any knowledge of your payment details.
Who is responsible for what
Your accounting data is never transmitted to us. We are neither its data controller nor its processor: it stays on your machine, under your control alone.
The licence and support data — your name, your email address, your order, your computer's fingerprint, the code issued — is processed under the responsibility of Pierre Magnard e.U., Viktor Adler Strasse 57, 2345 Brunn am Gebirge, Austria.
Invoicing and payment fall to our official seller, Paddle Payments Ltd, The Academy, 42 Pearse Street, Dublin, D02 YX88, Ireland — registration number 572448, VAT number IE 3395826PH. They are the data controller for the data they collect on that occasion.
Contact: desk@baleinecash.com
2. The software installed on your machine
Where your data is
In local files, on your disk. For your accounts there is no central server, no online account, no external synchronisation.
We do run a server, but it serves only to issue and track licences. It holds no accounting data — see What the purchase and the renewal transmit.
What leaves your machine
The program works offline. It sends no accounting, technical or statistical data, and opens a connection in three cases only:
1. on purchase or activation, to transmit your order and fetch your licence code;
2. at the expiry of a renewing subscription, to check that a renewal code exists;
3. at your explicit request, to refresh the ISIN prices of your portfolio.
A permanent licence or a firm annual licence never brings about the second case: once the code is issued, nothing more leaves your machine on account of the licence.
None of those three cases transmits your entries, your accounts or your balances. Each is described below.
Outside those three cases, nothing goes out. The program opens in your browser at the address 127.0.0.1, which means your own computer and nothing else.
The licence check is local
Your licence code is cryptographically signed and stored on your computer. The program checks its signature and its date there, with an embedded public key.
That daily check triggers no network call, neither at start-up nor afterwards. We know neither whether you use the software, nor when, nor how.
A permanent licence is thus never checked online again, at any point.
What the purchase and the renewal transmit
The purchase, and where applicable the renewal, are the only operations that send licence information out of your machine.
On that occasion, your computer's fingerprint accompanies the order, so that the code issued is tied to that machine. What is kept is your name, your email address, the order reference, that fingerprint, the code issued and the date of the exchanges:
- on our server, at our host World4You Internet Services GmbH, Linz, Austria;
- at our official seller, Paddle Payments Ltd.
This information serves to issue your licence and to keep track of it. It serves nothing else.
The machine fingerprint is not an identifier that names you, and says nothing about what you do with the software. Associated with your order, it is nonetheless treated as personal data.
The end of a firm annual licence
A firm annual licence carries its end date in the code stored on your computer. The program reads it there and warns you as expiry approaches. No connection takes place, neither for those reminders nor at expiry itself. Nothing renews and nothing is taken from you: if you want to carry on, you buy again, whenever you wish.
Renewing the subscription
If you subscribe, the official seller renews your subscription automatically — that is what a subscription is for; your phone contract does not stop every month waiting for you to extend it either. They tell you before expiry, which leaves you time to cancel within the deadlines. That relationship is theirs: see How to cancel.
Once payment is made, a code covering the new period is issued. You have two ways of getting it:
- you let the program handle it. At expiry, it asks our server whether a code exists for your fingerprint. That is the only network call it makes on its own initiative; it concerns your licence, never your data;
- you do it by hand. The code is also sent to you by email from desk@baleinecash.com — remember to check your junk folder — and you paste it into the licence management screen.
The program has fourteen days from expiry for that retrieval, and retries at every start. During that grace period, nothing changes for you. Once it has passed without a valid code, only the keying in of new entries is blocked; the program goes on checking at every start, and a code obtained later reopens keying in.
Refreshing ISIN prices
You can trigger the refresh of your prices from within the program. It queries Yahoo Finance, and only when you set it off.
The request is made security by security: the program asks for the price of one ISIN code on one date, and nothing else. No account is opened at Yahoo, no identifier accompanies the request, and nothing on our side links one request to the next.
Transmitted are neither your quantities, nor your amounts, nor your purchase or sale prices, nor your transaction dates, nor the composition or the spread of your portfolio, nor your chart of accounts, nor your identity. What goes out is a request for a price, not a portfolio.
As with any request to a website, it leaves your computer with your IP address. We cannot vouch for what an operator of that size is able to deduce from what it sees going past; we vouch for what we send, and we send only that.
On the same occasion the program picks up the information published on the security — geographical zone, sector, type of instrument — to feed your spread analyses. If you prefer that nothing goes out, do not launch the refresh: that composition can be maintained by hand.
Banking credentials
The program does not connect to your bank and holds no credentials. You download your statements yourself from your bank's site, and you import them from your disk.
Encryption and password
Your databases are not encrypted. The program's password protects access to your user, not the content of the files.
On a shared machine, it is your system's disk encryption that really protects you.
3. The purchase and support
What we keep of your purchase
Your name, your email address, the order reference, the machine fingerprint and the licence code issued. This data serves to issue the licence, to keep track of it and to answer your requests.
We keep it for the duration of the contractual relationship, then seven years from your last transaction — the retention period for accounting records imposed by Austrian law.
Payment
The sale and the payment are handled by our official seller, Paddle Payments Ltd, who is the data controller for the billing data it collects. Your card details are entered with them: we never have access to them and we keep none.
Established in Ireland, they process this data under their own privacy policy. Where group entities located outside the European Union are involved, those transfers are covered by the safeguards provided for that purpose.
From them we receive only your name, your email address and the fact that a purchase has taken place — which is what we need in order to issue your licence code and keep track of it.
Support exchanges
If you write to us, your message and its content are kept for as long as it takes to deal with the request and to answer any later questions. We pass them on to nobody.
If you send us a file of your data for diagnosis, it is deleted once the problem has been dealt with.
What we do not do
Your data is neither sold, nor rented, nor exchanged, nor shared for commercial or advertising purposes, whether for payment or not — whatever definition the law of your country adopts for that.
Who your data may be passed to
To three categories of recipient, and to no other:
- our official seller, Paddle Payments Ltd, for the sale and the invoicing;
- our host, World4You Internet Services GmbH, which hosts the licence server and our mail, and which is bound to confidentiality;
- an authority making a request on a legal basis.
4. The website
No cookies
The BaleineCash site is made of static pages. It sets no cookie, does not follow you from one page to the next, and therefore needs no consent banner.
Everything a page displays — text, images, icons, fonts — is served from our own server. Nothing is loaded from a third-party site, and so no third party sees you go by.
Your browser keeps some of those files in memory so as not to download them again at every visit. That memory belongs to it, it stays on your machine, and it tells us nothing.
No audience measurement
We use neither Google Analytics nor any other audience measurement or advertising tool. We do not count your visits.
The activation page
Only one page of the site expects anything of you: the one that lets you fetch your licence code when you have paid from a device other than your working computer.
There you enter the email address of your order and your computer's fingerprint. Those two pieces of information serve solely to find your order and issue the matching code; they join the data described above. No account is created, no password is asked for, no cookie is set.
The host's logs
Like any site, ours is served by a host that technically records the requests it receives: IP address, date, page requested, browser. Those logs serve the security and the proper running of the server, and are not matched with your identity.
Host: World4You Internet Services GmbH, Linz, Austria.
The payment page
The purchase takes place on a page hosted by our official seller, Paddle, which is not our site. That page has its own cookies and its own privacy policy.
The emails we send
The address you give at the time of purchase is used to send you your licence code, your invoice and the information relating to your order.
We may tell you about updates to the software. A word is enough to receive no more of that, without it affecting your licence or your right to support.
Links to third-party sites
Our site may point to sites we do not run. They have their own privacy rules, for which we do not answer.
Minors
BaleineCash is addressed to adults. We do not knowingly collect data concerning a minor.
If you find that a minor has sent us data, write to us: we will delete it.
5. Your rights
What you can ask for
You have rights of access, rectification, erasure, restriction, portability and objection over the data we hold.
A simple request by email is enough, with your name and email address.
One useful point: we can give you back nothing of your accounts, since we have never had them. They are on your disk, and the program lets you export them whenever you wish.
Legal bases
Performance of the contract for the sale, the licence and its follow-up; legal obligation for the retention of accounting records; legitimate interest for the security of the server and for dealing with your support requests.
Complaint
If you consider that the processing of your data breaches the regulation, write to us. You may also refer the matter to the competent data protection authority — in Austria, the Datenschutzbehörde.
Wherever you live
We apply the same rules to all our customers, in every country. The European data protection regulation serves as our benchmark, including where you live outside the European Union.
If the law of your country grants you further rights, write to us: we will seek to give effect to them.
Write to us
desk@baleinecash.com
Pierre Magnard e.U., Viktor Adler Strasse 57, 2345 Brunn am Gebirge, Austria.