Privacy Policy
Document version: 0.1 (DRAFT — pending solicitor / DPO review) Effective date: [EFFECTIVE_DATE] Last updated: [EFFECTIVE_DATE]
This Privacy Policy explains how [COMPANY_LEGAL_NAME] (company number [COMPANY_NUMBER]), registered in [JURISDICTION] at [REGISTERED_ADDRESS] ("PIZQ", "we", "us", "our"), collects, uses, shares, and protects personal data when you use the PIZQ platform, websites, applications, and APIs (the "Service").
PIZQ is the data controller of the personal data described here. This Policy should be read together with our Terms of Service.
We comply with the UK GDPR and the Data Protection Act 2018, and, in respect of individuals in the European Economic Area (EEA), the EU GDPR. Where other privacy laws apply to you (for example, US state privacy laws), the relevant section below applies in addition.
Summary (not a substitute for the full Policy): We collect the data needed to run your account, process payments, secure the platform, and provide features like backtesting and AI Quant. We store core user data in the European Union. We do not sell your personal data. We use a small set of trusted sub-processors. You have rights over your data, including access and deletion.
1. Who we are and how to contact us
- Controller: [COMPANY_LEGAL_NAME], [REGISTERED_ADDRESS]
- Privacy contact / data protection enquiries: [PRIVACY_EMAIL]
- EU/EEA representative (if appointed under Article 27): [EU_REP_DETAILS or "not currently appointed — see note"]
- Supervisory authority: the UK Information Commissioner's Office (ICO) is our lead authority while we are a UK-established controller.
2. The personal data we collect
2.1 Data you provide
- Account & identity: name (if provided), email address, password (stored only as a secure hash), country of residence, and authentication data such as multi-factor settings and a trading PIN (stored hashed).
- Billing: subscription plan and billing records. Card/payment details are collected and processed directly by our payment processor (Stripe) — we do not store full card numbers.
- Content: strategies, algorithms, code, parameters, notes, and prompts you create or upload.
- AI Quant interactions: the prompts and conversation content you submit to the AI Quant assistant.
- Broker connection settings: the broker credentials you choose to connect, which we hold in encrypted form to enable connectivity you request.
- Support communications: messages you send us.
2.2 Data we collect automatically
- Usage & device data: log data, feature usage, timestamps, browser/device and app version information.
- IP address and approximate location: used for security, fraud prevention, and to apply geographic and sanctions-based access controls. We derive approximate country from IP using an offline geolocation database; we do not use IP-based location for advertising.
- Cookies and similar technologies: see Section 9.
2.3 Data from third parties
- Payment status from our payment processor (for example, whether a payment succeeded), without full card data.
- Connected Broker data that you authorise us to receive to provide the Service (for example, account status, positions, or order results), used only to deliver features you request.
2.4 Data we deliberately avoid
- We do not intentionally collect special-category data (such as health, biometric, or political data) and ask you not to submit it.
- We do not require government-ID documents at signup.
- AI Quant is not given access to your broker balances or holdings for the purpose of generating personalised investment advice.
3. How and why we use your data (purposes and lawful bases)
| Purpose | Examples | Lawful basis (UK/EU GDPR) |
|---|---|---|
| Provide the Service | Create and run your account; run backtests; operate AI Quant; transmit instructions to your Connected Broker | Contract (Art. 6(1)(b)) |
| Process payments | Billing, renewals, invoices, refunds | Contract (Art. 6(1)(b)); Legal obligation for tax/accounting records (Art. 6(1)(c)) |
| Service communications | Security alerts, billing notices, important changes | Contract (Art. 6(1)(b)); Legitimate interests (Art. 6(1)(f)) |
| Security, fraud & abuse prevention | Authentication, rate limiting, brute-force and anomaly detection, sanctions/geo controls | Legitimate interests (Art. 6(1)(f)); Legal obligation for sanctions compliance (Art. 6(1)(c)) |
| Maintain & improve the Service | Diagnostics, debugging, reliability, aggregate analytics | Legitimate interests (Art. 6(1)(f)) |
| Improve the Service & train our AI | Using prompts/Content/User Strategies in aggregated/de-identified form to improve features and models — opt-out (see §4A) | Legitimate interests (Art. 6(1)(f)) |
| Marketing to existing users | Product updates to current customers (soft opt-in) | Legitimate interests (Art. 6(1)(f)), with opt-out |
| Marketing to prospects | Newsletters/opt-in marketing | Consent (Art. 6(1)(a)) |
| Legal & compliance | Respond to lawful requests; enforce Terms; establish/defend legal claims | Legal obligation (Art. 6(1)(c)); Legitimate interests (Art. 6(1)(f)) |
Where we rely on legitimate interests, we have balanced those interests against your rights; you may object as described in Section 7. Where we rely on consent, you may withdraw it at any time without affecting prior processing.
We do not carry out solely-automated decision-making that produces legal or similarly significant effects on you without a lawful basis and appropriate safeguards.
4. AI Quant and your prompts
- Prompts and conversation content you submit to AI Quant are processed to generate responses and to maintain continuity of your sessions (Contract, Art. 6(1)(b)).
- AI Quant is powered by a third-party large-language-model provider acting as our sub-processor. Your AI Quant content is sent to that provider solely to return a response to you.
- We instruct our AI provider not to use your content to train their general models, to the extent provided for in our agreement with them.
- Please do not paste sensitive personal data or third-party personal data into AI Quant.
4A. Using your content to improve PIZQ (including AI training)
We use content on the Service — including your prompts, your Content, and your User Strategies — to maintain, secure, and improve the Service, and to train and improve our AI features and models.
- Lawful basis — legitimate interests (Art. 6(1)(f)). Our interest is in improving the Service and our AI; we have weighed it against your rights and apply the safeguards below. We do not rely on this basis for broker credentials or other sensitive credentials, which are excluded from this use.
- You can opt out at any time — and it changes nothing about your access. Turn this off in [Settings → Privacy → "Improve PIZQ"] or by emailing [PRIVACY_EMAIL]. This is your right to object under Art. 21, and we honour it. Once you opt out, we exclude your content from future model training and from this improvement use. (Opting out does not oblige us to retrain models already built before your opt-out — but the safeguards below are designed so that no individual strategy can be reproduced in any event.)
- How we protect your edge (safeguards):
- We use your content in aggregated and/or de-identified form, stripping identifiers before it is used for training.
- We apply controls designed to stop the model memorising or reproducing any individual user's strategy, and we never expose one user's strategy to another user.
- We do not sell your strategies, do not trade them for our own account, and do not use them to compete with you.
- What we never do without your separate, explicit choice: publish your strategies or share them with other users (for example, this only happens if you choose to publish to the Marketplace).
5. Who we share data with (sub-processors and recipients)
We share personal data only as needed to run the Service. We do not sell your personal data. Our recipients fall into these categories:
Sub-processors (process data on our behalf under Article 28 data-processing agreements). We describe them here by category of recipient (as permitted by Article 13(1)(e) UK/EU GDPR). A current list of the specific named sub-processors behind these categories is available on request to [PRIVACY_EMAIL]:
| Category of recipient | Purpose | Data involved |
|---|---|---|
| Cloud hosting & infrastructure provider (EU regions) | Hosting, storage, compute, and managed database | All categories, at rest/in transit |
| Payment processor | Payment processing & billing | Billing/payment data |
| AI processing provider | AI Quant model inference | AI Quant prompts/conversation content |
| Email delivery provider | Transactional email delivery | Email address, message content |
| IP-geolocation database provider | Security/geo controls | IP address (processed locally; database is downloaded, not queried per-user externally) |
| Bot/abuse-protection provider | Bot/abuse protection at signup/login | IP, challenge interaction data |
| Market-data & financial-news providers | Market data and news content | Not personal data in normal use |
| Error/performance-monitoring provider | Error and performance monitoring | Diagnostic logs (may include user IDs) |
Other recipients:
- Connected Brokers you choose to connect — to provide connectivity you request (they are independent controllers under their own terms).
- Professional advisers (lawyers, accountants, auditors) under confidentiality.
- Authorities/third parties where required by law, regulation, or valid legal process, or to protect rights, safety, or the integrity of the Service.
- Acquirers in connection with a merger, acquisition, financing, or sale of assets, subject to confidentiality and this Policy.
6. International data transfers
We store core user data within the European Union (EU regions), which is favourable for EEA/UK users. Some sub-processors (for example, certain AI, payment, or monitoring providers) may process limited data outside the UK/EEA. Where personal data is transferred to a country without a UK/EU adequacy decision, we rely on appropriate safeguards — principally the UK International Data Transfer Agreement / Addendum and the EU Standard Contractual Clauses — and apply additional measures where needed.
You can request details of the safeguards for a specific transfer by contacting [PRIVACY_EMAIL].
7. Your rights
Subject to applicable law, you have the right to:
- Access — obtain a copy of the personal data we hold about you;
- Rectification — correct inaccurate or incomplete data;
- Erasure — request deletion of your data ("right to be forgotten");
- Restriction — ask us to limit processing in certain circumstances;
- Portability — receive certain data in a structured, machine-readable format, and have it transmitted to another controller where technically feasible (see the scope note below);
- Object — object to processing based on legitimate interests, and to direct marketing at any time;
- Withdraw consent — where we rely on consent, withdraw it at any time;
- Not be subject to solely-automated decisions with legal or similarly significant effects, where applicable.
Scope note — portability and your strategies. Your right to portability and export covers your personal data and your backtest results, performance metrics, and account data, which you can export where the Service provides that function. It does not extend to the source code or executable artifacts of your algorithms/strategies ("User Strategies"): as explained in the Terms of Service (clause 10.5), these are built on and incorporate PIZQ's proprietary technology and trade secrets, are not separable from the platform, and are not exportable. This reflects the limit in UK/EU GDPR Article 20 that portability must not adversely affect the rights and freedoms of others, including our trade secrets and intellectual property.
To opt out of the Service-improvement / AI-training use, see §4A — you can do it in Settings or by objecting under Art. 21; it does not affect your access.
To exercise any right, contact [PRIVACY_EMAIL] or use the in-product account controls (including the "Delete my account" and data-export features where available). We will respond within one month (extendable by two further months for complex requests, with notice). We may need to verify your identity.
Exercising these rights is free in most cases. If you are unhappy with how we handle your data, you may complain to the ICO (ico.org.uk) or, if you are in the EEA, your local supervisory authority — but we'd appreciate the chance to resolve it first.
8. Data retention
We keep personal data only as long as necessary for the purposes described, then delete or anonymise it. General guidelines:
| Data | Typical retention |
|---|---|
| Account data | While your account is active, then deleted/anonymised within [RETENTION_ACCOUNT, e.g. 90 days] of account closure, subject to legal holds |
| Content (strategies, code) | While your account is active; deleted on account deletion or earlier on request |
| AI Quant conversation history | For the period needed to provide continuity, then up to 5 years or until you delete it (the period the platform's retention job is configured to enforce; aligned with financial-services record-keeping — confirm with counsel) |
| Content used for Service/AI improvement | Held in aggregated/de-identified form per [RETENTION_TRAINING]; opt-out excludes future use (see §4A) |
| Billing & tax records | As required by law (commonly 6–7 years) |
| Security & access logs | [RETENTION_LOGS, e.g. up to 12 months], longer where needed to investigate an incident |
| Backups | Rotated on a rolling basis; residual copies purged within the backup cycle |
9. Cookies and similar technologies
We use cookies and similar technologies that are strictly necessary to run the Service (for example, to keep you signed in and to protect against abuse). Where we use any non-essential cookies (for example, optional analytics), we will request your consent and provide controls. We default to the most privacy-protective option and do not use advertising/tracking cookies for third-party ad targeting. Full details of the cookies we use, and how to manage them, are in our Cookie Policy.
10. How we protect your data
We apply technical and organisational measures appropriate to the risk, including: encryption in transit (TLS) and encryption of sensitive data such as broker credentials at rest (authenticated AES-256-GCM with key versioning); hashed passwords and PINs; multi-factor authentication; least-privilege access; network and request-size controls; rate limiting and brute-force protection; security logging and monitoring; and a documented incident-response process. No system is perfectly secure, but we work to protect your data and to notify you and the relevant authority of a qualifying breach as required by law (within 72 hours to the supervisory authority where the breach is likely to risk your rights).
11. Children
The Service is not directed to anyone under 18, and we do not knowingly collect data from children. If you believe a child has provided us data, contact [PRIVACY_EMAIL] and we will delete it.
12. US state privacy rights (where applicable)
If you are a resident of California or another US state with a comprehensive privacy law, you may have rights to know, access, correct, delete, and limit the use of your personal information, and to opt out of "sale" or "sharing" of personal information. We do not sell or share personal information as those terms are defined under those laws. To exercise any right, contact [PRIVACY_EMAIL]. We will not discriminate against you for exercising your rights.
13. Changes to this Policy
We may update this Policy. If a change is material, we will give reasonable notice (for example, by email or in-app notice) before it takes effect. The "Last updated" date reflects the current version. Continued use after the effective date constitutes acceptance of the updated Policy.
14. Contact
Questions or requests about privacy: [PRIVACY_EMAIL] [COMPANY_LEGAL_NAME], [REGISTERED_ADDRESS]
This document is a draft prepared for internal review and must be reviewed and approved by a qualified solicitor and (where appointed) a data protection officer before publication. It is not legal advice.