CEE Analytics

Privacy Policy

GDPR (Regulation (EU) 2016/679) — Last updated: 2026-04-27

1. Data Controller

CEE Analytics, c/o Impact Hub Vienna, Lindengasse 56, 1070 Wien, Austria.
Contact: [email protected]

2. Data We Process

CEE Analytics is a market data analytics platform. We do not require user accounts to access public market dashboards. The site processes:

  • Technical request data (IP address, browser user-agent, timestamp, requested URL) collected by our edge layer for security, abuse prevention, and aggregate traffic analysis. Retention: 30 days.
  • Email correspondence when you contact us at [email protected], retained for the duration of the inquiry and up to 12 months thereafter.

We do not use third-party analytics, ad trackers, or social media pixels. We do not sell or rent personal data.

3. Legal Basis

  • Art. 6(1)(f) GDPR — legitimate interest in operating, securing, and improving the service.
  • Art. 6(1)(b) GDPR — handling inquiries you initiate.

4. Hosting and Sub-Processors

The platform is hosted on Railway (Railway Corp., 548 Market St, San Francisco, CA, USA), which provides ISO 27001-aligned infrastructure within EU and US regions. Network traffic is protected by Cloudflare (DDoS mitigation, TLS termination). Both processors operate under GDPR-compliant Data Processing Agreements with Standard Contractual Clauses (SCCs) for any transfer outside the EEA.

5. Cookies and Local Storage

CEE Analytics uses browser local storage only for non-tracking purposes: remembering your sidebar preference and (for admin users only) a locally-stored access token. No third-party cookies are set.

6. Your Rights (GDPR)

You may at any time exercise the following rights:

  • Right of access (Art. 15)
  • Right to rectification (Art. 16)
  • Right to erasure (Art. 17)
  • Right to restriction of processing (Art. 18)
  • Right to data portability (Art. 20)
  • Right to object (Art. 21)
  • Right to lodge a complaint with the Austrian Data Protection Authority (Datenschutzbehörde, dsb.gv.at)

To exercise any of these rights, write to [email protected]. We will respond within 30 days.

7. Security

All connections are encrypted in transit via TLS 1.3. The application enforces strict HTTP security headers (HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy) and is served exclusively over HTTPS. Backend access is restricted to authenticated administrators.

8. Changes to this Policy

Material changes will be reflected here with an updated revision date. Continued use of the site after changes constitutes acceptance.