Privacy notice
This notice describes the website’s current technical setup with a non-public feedback form, but without user accounts, audience measurement, advertising or marketing tracking. Last updated: 29 July 2026.
Controller
Nicolas Schröder und Rasmus Hansen GbR, handelnd unter Gold Update
Neubruchstraße 20
85774 Unterföhring
Germany
Delivery and security through Cloudflare
Gold Update uses Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA, for DNS, CDN delivery, TLS encryption, security filtering, execution of the website as a Cloudflare Worker, the D1 market-data database and Email Routing. When the website is requested, Cloudflare processes technically necessary connection and security data, in particular the IP address, date and time, requested address, HTTP and browser information, status code and Cloudflare Ray ID. The purposes are secure, fast and stable delivery and protection against abuse. The legal basis is Article 6(1)(f) GDPR; our legitimate interests are operational security, availability and abuse prevention. Cloudflare processes data under its Data Processing Addendum. For transfers to the United States, Cloudflare relies on the EU-US Data Privacy Framework and additionally on EU Standard Contractual Clauses.
Logs and retention for website requests
The deployed application has persistent Cloudflare Worker logging disabled and does not configure its own log export. Gold Update therefore stores no complete visitor or access logs of its own. Cloudflare may process connection and security data for as long as necessary to deliver, protect and troubleshoot the service; contractual processing ends once it is no longer necessary for the service. If account-level Cloudflare log features are enabled later, this notice must first be updated with their specific retention period.
Strictly necessary security cookies
The application itself sets no cookies during an ordinary page request. Cloudflare may set strictly necessary cookies only where bot protection is enabled or a specific security check is triggered: __cf_bm supports bot detection and expires after 30 minutes of inactivity; cf_clearance records a successfully completed security check and has a default lifetime of 30 minutes. They are not used for advertising or audience measurement and Gold Update does not combine them into user profiles.
Short-term abuse prevention
The public price interfaces limit unusually frequent requests. The requesting IP address and a counter are processed only in the volatile memory of one server instance and are deleted no later than the end of a one-minute window. They are not combined with other data. The legal basis is Article 6(1)(f) GDPR; the legitimate interest is protection against overload and automated abuse.
Market data providers
Gold API, Frankfurter and the Eurostat interface are called exclusively on the server. The website visitor’s IP address is not sent to these providers. Eurostat supplies only the public monthly consumer-price index for the selected region and it is not connected to visitor profiles. In the Cloudflare D1 market-data tables, Gold Update stores only market values, source timestamps, currencies and technical retrieval states. The separate feedback data is described in the feedback-form section.
Contact by email
When you write to contact@gold-update.com or dataprotection@gold-update.com, Gold Update processes the sender and recipient addresses, time, subject, message and any attachments you provide. Cloudflare Email Routing receives the message and forwards it to the configured destination mailbox. That mailbox is currently provided through Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, and potentially Google LLC in the United States. Google relies, among other safeguards, on the EU-US Data Privacy Framework and, where required, Standard Contractual Clauses. The legal basis is Article 6(1)(b) GDPR for pre-contractual communication, Article 6(1)(c) GDPR for legal obligations and otherwise Article 6(1)(f) GDPR. The legitimate interest is handling genuine enquiries and documenting credible correction notices.
Deletion of emails
Ordinary enquiries are deleted six months after final resolution. They are kept longer only where the particular message qualifies as a business or commercial letter, accounting voucher or other legally retained record. Relevant German retention periods are in particular six years for business correspondence, eight years for accounting vouchers and ten years for certain accounting records. Where a message is required to establish, exercise or defend legal claims, it may be retained until the relevant limitation period expires; the regular German limitation period is three years and generally starts at the end of the relevant year.
Feedback form
Through the non-public feedback form, Gold Update processes the message and, where voluntarily provided, the name and email address, as well as the language, time of receipt and processing status. The email address is intended only for a requested reply. The information is stored in Cloudflare D1 and used solely to review the submission, improve the service and reply where requested. The legal basis is Article 6(1)(f) GDPR; the legitimate interest is user-focused improvement and traceable handling of specific comments. Feedback records are automatically deleted no later than 183 days after receipt. To prevent spam, the IP address is pseudonymised with a secret key. Only this HMAC value, the hourly window and a counter are stored; the raw IP address is not stored in the feedback database. Rate-limit data is deleted no later than two hours after the start of the window. A maximum of five submissions per IP is accepted per hour. Please do not submit sensitive financial information, identity documents or credentials.
No advertising, analytics or profiling
The website currently uses no analytics or advertising services, affiliate technology, social-media plugins or user accounts. Apart from the feedback form described above, there are no interactive submission or community features. The language is part of the URL and is not stored locally. External sources are contacted only when a visitor actively opens the link. Before advertising, affiliate links or audience measurement are introduced, this notice, advertising labels and – where required – consent management will be extended.
Your rights
Subject to the GDPR, you have rights including access, rectification, erasure, restriction, data portability and objection. You may object to processing based on legitimate interests for reasons arising from your particular situation. Send requests to dataprotection@gold-update.com. You may also lodge a complaint with a data protection authority, in particular the Bavarian State Office for Data Protection Supervision, Promenade 18, 91522 Ansbach, Germany.
Required data and automated decisions
There is no legal or contractual obligation to provide personal data merely to use the website, although delivery is impossible without technically necessary connection data. Gold Update carries out neither automated decision-making within Article 22 GDPR nor profiling.