Privacy Policy
What data pofinance.xyz processes, on what legal basis, and how the rules of EU GDPR, French data protection law (CNIL), CCPA/CPRA and the IAB Europe Transparency & Consent Framework (TCF) v2.3 apply.
Last updated:
1. Data controller
The data controller is pofinance.xyz (“we”, “us”). For privacy correspondence write to privacy@pofinance.xyz or use the contact page. Verifiable privacy requests are answered within thirty (30) calendar days, in line with GDPR Article 12.
2. What we collect — and what we do not
The retirement calculator processes no personal data and no input value on our servers. Age, savings, income and target spending entered into the form remain in your browser. We do not log, transmit, or store them. Confirm by opening DevTools → Network and observing the absence of outbound requests as you type.
The Service may process the following limited categories of data:
- Server access logs: IP address, user-agent, requested URL, timestamp, HTTP status code. Retention: 30 days.
- Aggregated analytics (page views, country, device class), loaded only after analytics consent.
- Advertising cookies set by Google AdSense and DoubleClick, only after advertising consent.
- Contact-form submissions retained only as long as required to respond — default 12 months.
3. Legal bases
- Legitimate interest (Art. 6(1)(f) GDPR) for security logging.
- Consent (Art. 6(1)(a) GDPR; ePrivacy) for analytics, advertising, and any non-essential cookie.
- Contract / pre-contractual measures (Art. 6(1)(b) GDPR) for contact-form correspondence.
4. Cookies
Three cookie categories. The cookie policy lists each cookie individually with provider, purpose, and retention period.
5. Google AdSense, DoubleClick and personalised advertising
The Service may display advertising delivered by Google AdSense and the DoubleClick
advertising network. With advertising consent granted, Google and certified TCF v2.3
vendors may set and read cookies including __gads, __gpi,
IDE, NID, DSID, and test_cookie;
process IP, user-agent and approximate location; build interest-based advertising
profiles; and share data with TCF v2.3 vendors you authorise.
Manage Google's use of advertising data at adssettings.google.com or opt out network-wide at youronlinechoices.eu.
6. TCF v2.3 consent management
We use an IAB Europe TCF v2.3-compliant Consent Management Platform. On first visit a banner lists the data-processing purposes and the certified vendors. No non-essential cookie is set, and no third-party advertising script is loaded, until you grant or refuse consent on a per-purpose, per-vendor basis. Modify your consent at any time via the “Cookie preferences” link in the footer.
7. International transfers
Some third parties (notably Google) may transfer personal data to the United States. Such transfers rely on the EU–U.S. Data Privacy Framework and Standard Contractual Clauses where applicable.
8. Your rights
Under GDPR, French data protection law, and CCPA/CPRA you may:
- Access personal data we hold about you;
- Request correction or erasure;
- Restrict or object to processing, including profiling for advertising;
- Receive your data in a machine-readable format;
- Withdraw consent at any time;
- Lodge a complaint with the CNIL (France), your supervisory authority (other EU member states), or the California Privacy Protection Agency (US).
California residents may opt out of the “sale” or “sharing” of personal information. We honour the Global Privacy Control (GPC) signal.
9. Children
The Service is not directed at children under 16. We do not knowingly collect personal data from children under 16.
10. Changes
Material changes are flagged on the home page; the “Last updated” date above always reflects the most recent substantive revision.