Person and research

Privacy

What this site processes, and what it deliberately does not.

Controller

Jens-Werner Winkler, Beethovenstraße 11, 32839 Steinheim, Germany. Email: info@winkler-trading.de, phone: +49 171 3272272. The full details are in the legal notice.

This statement covers this website. What the installed software processes on the user's own machine, and where it connects to, is set out in its own privacy statement for the Winkler Trading Station: /docs/wts-datenschutz.pdf.

What is processed

  • Server log: IP address, time, requested address, response status, bytes transferred and user agent. The upstream web server writes this so that faults and attacks can be traced. Legal basis: Art. 6(1)(f) GDPR.

That is all of it, as long as nobody creates an account. There is no contact form, no feedback form, no comments and no search.

Member account

Anyone creating an account for the Trading Station provides: name, email address, login name for the software, a password of their own choosing for this site, and a billing address (street, postcode, city, country; company and VAT ID are optional).

Added to that is the machine-generated password for the software. It has to be displayable in the member area and is therefore held encrypted rather than hashed. The password for this site, by contrast, is stored only as a derivation (PBKDF2) and cannot be recovered.

Also stored: the time of registration, the end of the trial, the plan chosen and a history of what happened to the account (created, plan changed, blocked or released at the licence server).

Legal basis: Art. 6(1)(b) GDPR — without these details neither an account nor an invoice is possible.

Session cookie wex_mitglied: technically necessary, HttpOnly, SameSite=Lax, and Secure over an encrypted connection. It holds the account identifier and an expiry time, both signed, and expires after thirty days.

Transfer to the licence server

So that the software can sign in, the website creates an account on the licence server (hub) when the account is created. What is transmitted is the login name and the generated password — nothing else. Neither name nor address nor email address goes there.

If the trial ends or a payment does not arrive, the account there is blocked; after a payment it is released again. What the licence server processes beyond that — machine identifier, IP address, timestamps — is set out in the privacy statement for the software (/docs/wts-datenschutz.pdf).

Payment

Paid orders run through CopeCart GmbH, Rosenstraße 2, 10178 Berlin, Germany. CopeCart is not a processor but the seller: the contract of sale is concluded with CopeCart (terms, clause 1), and CopeCart processes your order and payment data on its own responsibility as a controller within the meaning of Art. 4(7) GDPR. CopeCart's own privacy statement applies to that.

What this website gives out. A buy button is a link to the product's order page at CopeCart. That link carries the email address of the account — so that it is already filled in on the order form and so that the later order notice can be matched to the right account. The website gives out nothing more: no name, no address, no payment data. Everything else — card or bank details, billing address, address verification, fraud checks — CopeCart collects itself on its own page; the provider sees no payment data and stores none.

What comes back. CopeCart reports every order to the provider: order and transaction number, product, amount including the VAT shown, means of payment, payment status, for recurring payments the next date, and the buyer's name and email address. From that the provider knows which access to unlock and for how long. Legal basis: Art. 6(1)(b) GDPR. Of this, only the order and transaction number as a record, and the end of the paid term, are stored on the account.

CopeCart is established in Germany; for the payment this website transmits nothing to a third country. Which service providers CopeCart uses in turn is set out in CopeCart's privacy statement.

Anyone who only uses the free trial does not come into contact with CopeCart.

Email

Messages to members (credentials, end of trial, payment received) are sent from an unattended address to the address given. Every message is written to an outbox on the server before it is sent, so that what went out stays traceable; it contains the login name and the generated password for the software.

Live trading room

The live trading room in the member area consists of a video stream and a chat. Both exist only for members with a booked access; anyone who merely reads the site is not touched by it.

Stream. The stream runs through YouTube (Google Ireland Ltd., Dublin, Ireland) and is embedded as a frame via youtube-nocookie.com. The frame loads only after the member clicks "Load stream" — before that no request goes to Google, and the room's page needs no foreign source. With the click, YouTube receives the IP address and browser details and may set cookies of its own under its own rules; the detail is in Google's privacy policy. Legal basis: Art. 6(1)(a) GDPR — the consent lies in the click and can be withdrawn at any time by not loading the stream — and Art. 6(1)(b) GDPR for providing the booked service. As far as YouTube stores or reads information on the device, the consent given by the click is also the basis under section 25(1) TDDDG. Google also processes data in the USA; Google is certified under the EU-US Data Privacy Framework.

Chat. Chat messages are stored with the member's login name and the time and shown to all members with access to the room; the real name stays out of it. Only the most recent 1000 messages are kept, older ones are deleted automatically. Individual messages are deleted by the provider on request. Legal basis: Art. 6(1)(b) GDPR.

Payment. Access is paid through CopeCart like the plans — on its own or as the combo together with access to the software, then with one payment for both; the Payment section applies.

Mentoring programme

Anyone booking the mentoring programme receives dates and working material by email to the address held in the account; the Email section applies. Stored on the account are the end of the programme and the term booked; from that the site derives that the five handbooks are available for the term.

The sessions run as video calls over a tool agreed with the member; no tool is prescribed. What is processed there — connection data, picture and sound — is governed by the privacy notice of the chosen provider; this website is not involved in it. The sessions are not recorded unless both sides expressly agree. Legal basis: Art. 6(1)(b) GDPR.

The AI learning platform (WTS AI Coach) is not a service of this website. It consists of a program on the member's own computer and a server of its own; the account, the book knowledge and the learning progress live there, and every question passes through that server to the operator of the language model. What exactly is processed, and for how long it is kept, is described on the AI Coach page. This website learns nothing about the learning progress.

Payment runs through CopeCart; the Payment section applies.

What does NOT happen

No analytics or tracking tools, no advertising cookies, no external fonts, no CDN resources, no social plugins, no profiling, no automated decision-making in individual cases, and no language cookie — the language is in the address.

A transfer to a third country happens at one point only: in the live trading room through YouTube, and there only after the click on "Load stream". Anyone who merely reads the site, uses the free trial or buys something is not affected — CopeCart is established in Germany. The video call of the mentoring programme runs outside this website; whether any data reaches a third country there depends on the tool agreed.

Serving a page makes no request to a foreign server. The fonts are downloaded at build time and served from this host afterwards. The one exception is the live trading room, and even there the YouTube frame loads only after a click — the page itself needs no foreign source.

Retention

  • Server logs: seven days at most, then deleted.
  • Session cookie wex_mitglied: thirty days from sign-in; "Sign out" deletes it at once.
  • Member account: until the account is deleted. A deletion needs no particular form, an email is enough; invoicing data is unaffected while tax retention periods run.
  • Outbox: the messages sent are kept as a record until the account is deleted.
  • Chat in the live room: the most recent 1000 messages; older ones are deleted on the next write.
  • Mentoring programme: end and term stay on the account until the account is deleted.

Your rights

Access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection to processing based on legitimate interests (Art. 21 GDPR). A message to info@winkler-trading.de is enough.

Right to object: where processing rests on Art. 6(1)(f) GDPR — the server log — you may object to it at any time on grounds relating to your particular situation (Art. 21(1) GDPR). A message to info@winkler-trading.de is enough for that as well.

You may lodge a complaint with a data protection supervisory authority, in particular at your habitual residence, your place of work or the place of the alleged infringement. For the provider's registered address that authority is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen, Kavalleriestraße 2–4, 40213 Düsseldorf, Germany.

Hosting

Operated on a rented server at [[HOSTING PROVIDER AND LOCATION]]. The upstream web server terminates the encrypted connection and writes the log described above.

As long as that bracket stands open, so does the rest: a data processing agreement under Art. 28 GDPR is to be concluded with the host, and whether any data reaches a third country depends on where that host sits. Both go in here once the site is deployed — a promise made before the decision would be no promise at all.

Version

5 September 2026.