Privacy and Cookies Policy

Last updated: 18 June 2025

Privacy Policy

1. Introduction

Invest Viable Global AB (“InvestViable,” “we,” “us,” “our”) operates InvestViable.com and provides automated valuation, due-diligence and educational tools for publicly traded equities. We respect your privacy and are committed to protecting your personal data in accordance with:

Regulation (EU) 2016/679 (“GDPR”) and Sweden’s supplementary legislation.

California Consumer Privacy Act / California Privacy Rights Act (“CCPA/CPRA”).

Applicable privacy statutes in other jurisdictions where we offer services.

2. Data Controller

Invest Viable Global AB

Org. no. 559499-1597

Filipstadsbacken 50, 123 43 Farsta, Stockholm, Sweden

E-mail: support@investviable.com

For privacy inquiries: supporty@investviable.com

3. Personal Data We Collect

Category Examples Purpose Legal Basis* Retention**

Account Data name, email, password (hash), country, time-zone create & secure user account Contract active + 3 yrs Profile & Subscription tier, billing address, VAT/Tax ID administer paid plans Contract / Legal Obligation active + 7 yrs (acctg.) Usage & Log Data IP, device ID, browser, interaction events, error logs service performance, fraud prevention Legitimate Interest 24 months Valuation Inputs user-entered assumptions, notes provide core functionality Contract user-deleted or account deletion Marketing & Comms newsletter opt-ins, campaign engagement send updates, offers Consent until opt-out Cookies & Analytics GA4 client ID, referrer, session stats site analytics, UX optimisation Consent (where required) / Legitimate Interest see Cookies Policy Payment Data (future) last 4 digits of card, transaction ID (via Stripe/PayPal) process payments, detect fraud Contract / Legitimate Interest as per processor terms

* Additional bases: compliance with legal obligations; protection of vital interests (security). ** We may anonymise data for statistical purposes after the specified period.

4. How We Use Your Data

Service delivery – authenticate, personalise dashboards, compute valuations.

Security – monitor for suspicious logins, enforce one-user-per-account rule.

Product improvement – aggregate usage patterns to refine algorithms.

Communications – transactional e-mails (password resets, policy changes); marketing with your consent.

Legal compliance – bookkeeping, tax, regulatory requests.

5. Sharing and International Transfers

We never sell personal data. We disclose only to:

Recipient Type Purpose Safeguard

Cloud hosting (e.g., AWS EU-West) infrastructure GDPR-compliant DPA Alpha Vantage (USA) market-data requests (may include IP) Standard Contractual Clauses (“SCCs”) Analytics providers (Google Analytics 4, Hotjar) site metrics SCCs / user consent Payment processors (future) subscription billing PCI-DSS + SCCs Professional advisers & authorities legal, audit, tax confidentiality & statutory duties

Data leaving the EEA is protected by SCCs, adequacy decisions, or other lawful transfer mechanisms (Art. 46 GDPR).

6. Your Rights (GDPR, UK GDPR, CCPA/CPRA)

You can exercise:

Access – obtain a copy of personal data.

Rectification – correct inaccurate data.

Erasure – “right to be forgotten” where applicable.

Restriction – limit processing in certain cases.

Portability – receive data in machine-readable form.

Objection / Opt-out – to marketing or processing based on legitimate interest.

Automated decision-making safeguards – we do not engage in profiling that produces legal effects.

Non-discrimination (CCPA) – no adverse treatment for exercising privacy rights.

Submit requests to privacy@investviable.com. We respond within 30 days (GDPR) / 45 days (CCPA). You have the right to lodge a complaint with Integritetsskyddsmyndigheten (IMY) or your local supervisory authority.

7. Security

We implement industry-standard safeguards: TLS encryption in transit, AES-256 at rest, least-privilege IAM, routine penetration tests, and 24/7 monitoring. Users must keep credentials confidential and are liable for activity under their account.

8. Children

Our services are not directed to minors under 18. We do not knowingly collect data from children. If you believe a minor has provided personal data, contact us for deletion.

9. Changes to This Policy

We may modify this Privacy Policy. Material changes will be announced via e-mail or prominent notice. Continued use after the effective date signifies acceptance.

10. Contact

Questions?
E-mail support@investviable.com or write to the address above.

Cookies

1. What Are Cookies?

Cookies are small text files placed on your device by websites you visit. They enable core functionality (e.g., log-in), remember preferences, and collect analytic data. Cookies in this policy include similar technologies such as localStorage, pixels, and SDKs.

2. Who Sets Cookies?

First-party cookies – set by InvestViable.com.

Third-party cookies – set by service providers (e.g., Google, Stripe). We do not control these providers and their policies may differ.

3. Categories of Cookies We Use

Category Purpose Example Cookies Legal Basis

Strictly Necessary Enable core features (log-in, CSRF protection, subscription checkout). Cannot be disabled. iv_session, csrf_token Contract / Legitimate Interest Preferences Store language, theme, time-zone. iv_locale, dark_mode Consent Analytics Gather usage statistics to improve UX (aggregated, pseudonymised). _ga, _gid (Google Analytics 4) Consent Marketing Track newsletter sign-ups, measure campaign ROI, retarget ads (if enabled). fbp, gcl_au Consent

We do not use invasive fingerprinting or sell behavioral data.

4. Cookie Consent & Management

Upon first visit, you see a cookie banner:

Accept all – enables analytics and marketing cookies.

Customize – granular toggles by category.

Reject non-essential – keeps only strictly necessary cookies.

You can revisit choices anytime via “Cookie Settings” in the site footer.

Browser Controls

Most browsers allow blocking or deleting cookies. Refer to:

Chrome: chrome://settings/cookies

Firefox: Preferences > Privacy & Security

Edge: Settings > Site permissions > Cookies
Blocking necessary cookies may impair site functionality.

5. Third-Party Cookies

We use trusted providers:

Provider Purpose Opt-out Information

Google Analytics 4 Site usage analytics https://tools.google.com/dlpage/gaoptout Stripe (future) Secure card payments https://stripe.com/cookies-policy/legal Meta Pixel (optional, marketing) Ad attribution https://www.facebook.com/settings/?tab=ads

6. Updates

We may update this Cookies Policy to reflect technical or legal changes. Date stamps will be updated and, where required, a fresh consent banner will appear.

7. Contact

For cookie-related questions, e-mail support@investviable.com.

© 2024 INVESTVIABLE. All rights reserved.