Privacy policy · Datenschutzerklärung
Privacy
Welcome. This policy explains which personal data we process when you visit marketzeitgeist.com and its subdomains, for which purposes, on which legal basis, and which rights you have. It applies to the website, the Cycles IQ onboarding at cyclesiq.marketzeitgeist.com, and contact by e-mail. The research newsletter on Substack and the tools and API have their own notices where indicated.
1. Controller
WhenToTrade, owner Lars von Thienen
Bredbeekskoppel 6
21266 Jesteburg, Germany
E-mail: lars@marketzeitgeist.com
MarketZeitgeist is a brand of WhenToTrade, a registered sole proprietorship of Lars von Thienen. No data protection officer is appointed, as none is required by law.
2. Your rights
You have the right to obtain confirmation whether we process personal data about you and, if so, access to that data (Art. 15 GDPR); to rectification (Art. 16); to erasure (Art. 17); to restriction of processing (Art. 18); to data portability (Art. 20); to object to processing based on legitimate interests (Art. 21); and to withdraw consent at any time with effect for the future (Art. 7 (3)). You may exercise these rights free of charge by e-mail to the address above. You also have the right to lodge a complaint with a supervisory authority (Art. 77), for example the one responsible for us: Die Landesbeauftragte für den Datenschutz Niedersachsen, Prinzenstraße 5, 30159 Hannover, Germany, lfd.niedersachsen.de.
3. Data security
All pages are delivered over HTTPS. Data is stored on Microsoft Azure in the EU (region West Europe) with access restricted to the controller. We take technical and organisational measures appropriate to the risk to protect your data against loss, misuse and unauthorised access.
4. Automated decision-making
We do not use automated decision-making or profiling within the meaning of Art. 22 GDPR.
5. Visiting the website: hosting and server logs
The website is hosted on Microsoft Azure Static Web Apps (Microsoft Ireland Operations Ltd., One Microsoft Place, Dublin 18, Ireland). When you access a page, the platform processes the data your browser transmits: IP address, date and time, requested page, referrer, browser and operating system. This is technically necessary to deliver the page and to keep the service secure. Legal basis: Art. 6 (1) f GDPR (legitimate interest in a functioning, secure website). Platform logs are retained by Microsoft for a short period for security purposes; we do not evaluate them personally. Fonts are served from our own server; no request is made to Google or other font providers.
6. Cookies and analytics
The website marketzeitgeist.com sets no cookies of its own and uses no analytics or tracking services. Where a page uses browser storage for your convenience (for example to remember your position in the onboarding questionnaire), this stays in your browser and is not transmitted to us.
7. DNS and edge services: Cloudflare
Our domains use the DNS service of Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA. For some hostnames Cloudflare also acts as a reverse proxy and protects against attacks; in that case your requests pass through Cloudflare's network, which processes your IP address and request data for security and delivery. Legal basis: Art. 6 (1) f GDPR. Cloudflare is certified under the EU-US Data Privacy Framework; transfers rely on Art. 45 GDPR.
8. Cycles IQ onboarding questionnaire
Prospects who receive a personal invitation link can answer a questionnaire at cyclesiq.marketzeitgeist.com. We process the data you enter (name, e-mail address, your answers, whether you agree to sign an NDA), the invitation source, and technical data (IP address, browser) to prepare an individual Cycles IQ offer and to arrange an introductory call. Legal basis: Art. 6 (1) b GDPR (pre-contractual measures at your request). The data is stored in Microsoft Azure Table Storage in the EU and is deleted at the latest twelve months after the last contact if no membership follows, or as required by statutory retention periods if it does. The following services are involved:
- Cloudflare Turnstile protects the form against automated submissions. It processes technical browser data and your IP address to distinguish humans from bots, without tracking you across sites. Legal basis: Art. 6 (1) f GDPR.
- Calendly (Calendly LLC, 271 17th St NW, Atlanta, GA 30363, USA) is embedded to book the introductory call. When you book, Calendly processes your name, e-mail address and the chosen time under its own privacy policy. Calendly is certified under the EU-US Data Privacy Framework. Legal basis: Art. 6 (1) b GDPR.
- Microsoft 365 sends the notification and confirmation e-mails from our mailbox and hosts the introductory call on Microsoft Teams. Legal basis: Art. 6 (1) b GDPR.
9. Contact by e-mail
If you contact us by e-mail, we process your e-mail address, name and the content of your message to answer your enquiry. Our mailboxes are hosted with Microsoft 365 in the EU. Legal basis: Art. 6 (1) b GDPR for enquiries relating to a contract, otherwise Art. 6 (1) f GDPR. Messages are deleted when the matter is closed, unless statutory retention obligations apply.
10. Research newsletter (Substack)
The research newsletter is published on Substack (Substack Inc., 548 Market St, San Francisco, CA 94104, USA) and reached via research.marketzeitgeist.com. Subscribing, reading and unsubscribing are handled by Substack under its own privacy policy; Substack acts as an independent controller for the subscriber relationship. We receive the e-mail addresses of subscribers to publish the newsletter. Legal basis: Art. 6 (1) a GDPR (your consent when subscribing), revocable at any time via the unsubscribe link.
11. Tools, API and member accounts
The analyzer, the scanner pages, the Cycles API and the MCP server are separate services with their own registration. When you create an account, we process the data required to operate it (name, e-mail address, sign-in identifier, plan, API keys, usage statistics) to provide the service and to bill it. Legal basis: Art. 6 (1) b GDPR. Sign-in is provided by Auth0 (Okta, Inc., 100 First Street, San Francisco, CA 94105, USA; EU tenant hosted in the EU), which processes your sign-in identifier, password hash or social login and technical sign-in data as our processor; Okta is certified under the EU-US Data Privacy Framework. Use of the services is governed by our Terms of Service. Usage data of the API is retained as long as needed for billing, throttling and abuse prevention.
12. Recipients and international transfers
We pass personal data to processors only where named above (Microsoft, Cloudflare, Calendly, Substack), each bound by data processing agreements or acting as independent controllers as stated. Where a provider is located in the USA, the transfer relies on the EU-US Data Privacy Framework (Art. 45 GDPR) or on standard contractual clauses (Art. 46 GDPR). We do not sell personal data and do not pass it to third parties for their own marketing.
13. Retention
We keep personal data only as long as necessary for the purposes stated above or as required by statutory retention periods (in particular commercial and tax law, up to ten years for accounting records). Afterwards the data is deleted or anonymised.
14. Changes
We update this policy when the services or the legal situation change. The version published here applies. Last updated: 12 September 2026.