Google Analytics and cookie preferences
The Google Analytics 4 tag (Google; G-13R1XE9ZTL) loads by default when a web page opens. Before an analytics cookie choice, or when declined, analytics_storage=denied permits cookieless measurement signals; this does not mean that no data is sent to Google. Google may process page URLs/titles, referrers, device/browser information and the connection IP address. The connection may involve processing abroad. Account identifiers, portfolio amounts and calculator inputs are not sent as custom analytics parameters. Advertising storage, advertising user data, ad personalization and Google Signals are disabled.
Cookie Preferences shows necessary cookies as always active. The analytics cookie switch in Settings and Accept All allow _ga and _ga_* cookies for at most 180 days; Reject or switching off clears accessible GA cookies while cookieless measurement continues. GPC/DNT disables measurement; the tag file may still load. metrilume:analytics-consent:v1 stores only the choice and timestamp; the choice is requested again after 180 days. If saving fails, analytics cookies stay off in this tab. Earlier accept/decline records are preserved as cookie choices. Cookie Preferences in the footer reopens the panel. Previously received Google data is not retroactively erased; report retention is managed in Google property settings. Native applications and standalone Lume Embed iframes do not load this web tag. External chart providers’ storage controls are subject to their policies and browser settings.
1. Scope and definition
A subprocessor is a third party that processes for the same service personal data AxelVira received in its capacity as processor on behalf of a business customer. For processing that directly concerns MetriLume consumers, the same supplier may instead be a “processor/service provider”; its role is determined by the actual data flow.
The presence of software in code, its use in testing, or plans to use it in the future does not mean it accesses B2B Customer Data. A supplier is listed as an active B2B subprocessor only after the exact contracting entity, purpose, data, countries, and transfer mechanism are verified for an order that incorporates the DPA. A controller-side provider used by the account-free public service does not become a B2B subprocessor merely because it is disclosed here.
2. Current role record
| Record | Role, service, and purpose | Data categories | Location and verification |
|---|---|---|---|
| Business DPA subprocessor | None — as of this version, there is no active business order that brings the DPA into effect | — | — |
| Cloudflare — public service | Technical provider for DNS, content/network transmission, DDoS and bot/abuse protection, and TLS edge functions in the consumer/public service for which AxelVira acts as controller; this record alone is not authorization for a business DPA subprocessor | IP address, request time, domain/route and protocol headers, and security signals; request/response content only to the extent necessary for transmission | Global edge network; the exact contracting legal entity, access countries, and transfer mechanism will be verified and recorded in an order-specific annex before any B2B processing begins |
| SEC EDGAR — public data source | Official source providing US company and financial-statement records through an API; requests are made from the MetriLume server, and this record is not a B2B DPA subprocessor authorization | General symbol catalog or CIK selected for research and standard server request information; search text and the end user’s browser IP address are not sent directly to the SEC | United States; official SEC EDGAR API use and access rules |
| TradingView — hosted chart and BIST stock screener | Controller-side external service providing a market chart or BIST end-of-day stock screener for display that loads automatically when the web or mobile US Markets Charts module or BIST equities page opens; it is not a B2B DPA subprocessor | IP address, request/network and device-browser information, referring page if sent by the browser, selected symbol, market and widget configuration, and cookie or analytics data under the provider’s own policy; MetriLume sends no account, portfolio, or order data | TradingView’s global service; the provider controls data under its Privacy and Cookie Policies. The connection starts automatically when the web or mobile US Markets Charts module or BIST equities page opens |
The production application and database run on server infrastructure managed by AxelVira. The contractual identity and role of a physical network/data-center or other hosting party are not treated as verified by this public record. Before any B2B processor service is activated, the exact legal entity, role, countries, security obligations, and transfer mechanism of every party able to access Customer Data are completed in an order-specific annex; business processing does not begin until that verification is complete.
3. Inactive integrations
Google and Apple authentication, Turkish mobile-phone verification, passkeys, iyzico, Garanti BBVA, Stripe, and mobile-store purchase flows may exist in code or plans; while their production feature gates are closed and no user data is sent for those purposes, they are not on the active subprocessor list.
When an identity, payment, or store provider is enabled, its role is separately reviewed. A provider may be an independent controller for its own legal purposes in some processing; if so, that fact is disclosed to the user before the transaction, and the provider is not characterized solely as a subprocessor.
4. Engineering and business tools
A source-code, CI/CD, or developer-collaboration tool is not included in this customer-data subprocessor list if it does not ordinarily access production end-user content. If production data must be opened to a supplier for support or incident response, minimization, time-limited access, confidentiality, and, where required, the listing/change process apply.
5. Selection and contractual controls
- Assessment of service necessity, data minimization, and alternatives involving fewer transfers.
- Review of security, incident response, deletion/return, continuity, and independent assurance.
- Confidentiality, processing only on instructions, personnel authorization, and further-subprocessor obligations.
- KVKK/GDPR role, data-center/access countries, and an appropriate international-transfer mechanism.
- Return of data, evidence of deletion, and revocation of access at the end of the contract.
6. Change notice and objection
Unless prevented by a security or urgent service-continuity issue, business DPA customers receive notice through the registered channel at least 15 calendar days before a new subprocessor or a material change of purpose or location. The current version and date are published on this page.
During the notice period, the customer may object at [email protected] on specific data-protection grounds. AxelVira considers supplementary safeguards, an alternative supplier, or narrowing the processing scope. If no reasonable solution can be found, the affected service may be terminated under the DPA.
If advance notice is not possible because of a critical security vulnerability or supplier outage, the change is made only to protect the service; it is notified without undue delay when the review is complete, and the ordinary objection and resolution process applies.
7. Version history
| Date | Version | Change |
|---|---|---|
| September 5, 2026 | 1.3 | Updated automatic TradingView loading in the web and mobile Charts module and the provider’s technical data role. |
| September 4, 2026 | 1.2 | Added the SEC EDGAR server-side data source and the TradingView chart provider role. |
| August 24, 2026 | 1.0 | Published the first bilingual registry, recorded that there is no active B2B subprocessor, and separated the controller-side Cloudflare disclosure from disabled integrations. |
8. Contact
For a subprocessor-notice subscription, security/transfer information about a particular supplier, or an objection, contact [email protected]. Reasonable supporting information is provided while protecting trade secrets and the security of other customers.
Contact and data controller
- AxelVira Teknoloji A.Ş.
- İzmir Trade Registry 271455
- Address
- Adalet Mah. Manas Blv. No:47/B Folkart Plaza D:3509, Bayraklı/İzmir, Türkiye
- Tax identification number
- 0991410303
- MERSİS
- 0099141030300001
- Support
- [email protected] · +90 (850) 840 20 83
- Privacy and data requests
- [email protected] · [email protected]