Privacy Policy

Last updated: June 2026

Data controller

MALA GESTION (SAS), SIREN 994 483 477, 1C Impasse des Osiers, 57100 Thionville, France.
Contact: contact@fireflyer.net

Data collected

Purposes and legal basis

Retention

Portfolio data is retained while the account is active and permanently deleted upon account deletion.

Technical logs (access, errors, security events) are retained for a maximum of 90 days at Railway Inc. (infrastructure) and Sentry Inc. (monitoring). No financial values or portfolio data are present in these logs.

Security

Sensitive fields (asset names, notes, institutions) are encrypted at rest (AES-128-CBC via Fernet). All communications are secured by HTTPS (TLS 1.2+). Access to data is strictly limited to the authenticated user.

Data sharing

No personal data is sold, rented or shared with third parties for commercial purposes. Data is processed only by the following sub-processors:

Your rights (GDPR)

Under Regulation (EU) 2016/679 (GDPR), you have the following rights:

You may also lodge a complaint with your national supervisory authority (in France: the CNIL).

Third-party data sources

To fetch financial asset prices, FireFlyer queries:

These services receive no personally identifiable data: only security identifiers (ISIN, ticker symbols) are sent in requests.

Cookies

FireFlyer uses only strictly necessary cookies:

No tracking, advertising or analytics cookies are placed without your explicit consent.

Data Processing Agreement (DPA)

Professional users wishing to enter into a Data Processing Agreement may submit a request to contact@fireflyer.net.

Contact

For any questions regarding your personal data: contact@fireflyer.net