Legal

Privacy Policy

Last Updated: 31 August 2026  | Effective Date: 1 January 2024

This Privacy Policy applies to TradeFIQ LTD and describes how we collect, use, store, share, and protect your personal data when you use our platform, website, and related services.

1. About Us and Data Controller

TradeFIQ LTD ("TradeFIQ", "we", "us", or "our") is the data controller responsible for personal data collected through our algorithmic trading platform, website at tradefiq.com, APIs, mobile applications, and any related services (collectively, the "Services").

TradeFIQ LTD is a company incorporated in England and Wales. Our registered address is:
71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom

For privacy-related inquiries, you may contact us at:
Email: privacy@hello.tradefiq.com
Data Protection Officer (DPO): data-protection@hello.tradefiq.com

2. Scope and Who This Policy Applies To

This Privacy Policy applies to all individuals who interact with TradeFIQ, including:

  • Registered users of the TradeFIQ platform (free and paid subscribers)
  • Visitors to our website and marketing pages
  • Individuals who contact us for support, sales, or general enquiries
  • Beta testers, research participants, and members of our community

If you are accessing TradeFIQ on behalf of a company or organisation, this policy also applies to the personal data of individual employees or representatives whose data you provide to us. You warrant that you have the authority and appropriate legal basis to share such data.

This policy does not apply to third-party websites, services, or products that may be linked from our platform. We encourage you to review their privacy policies independently.

3. Personal Data We Collect

We collect the following categories of personal data, depending on how you interact with our Services:

3.1 Identity Data

Full name, email address, username or display name, profile photograph (if provided), date of birth (where required for age verification or KYC compliance), and, where KYC/AML obligations apply, government-issued identification documents and a live selfie or short video used to verify that the document belongs to you ("liveness check"). This liveness check involves processing an image of your face, which is special category biometric data under GDPR Article 9; see Section 4.5 for the legal basis on which we process it.

3.2 Financial and Trading Data

Exchange API keys and secrets (encrypted at rest using AES-256; we never store unencrypted credentials), trading history, open and closed positions, portfolio balances reported by connected exchanges, strategy parameters and configurations, backtest results, and transaction records relating to your TradeFIQ subscription payments.

Your trading capital remains on your connected exchange accounts at all times; we do not have custody of it. Separately, we do hold a Platform Wallet balance on your behalf for deposits, promotional credits, and managed-portfolio copy fees; see Section 6.2 for the payment and identity-verification providers involved, and our Terms of Service (Section 6A) for how the Platform Wallet works.

3.3 Technical Data

IP address, device type and identifiers, operating system, browser type and version, time zone setting, language preferences, screen resolution, referring URL, session identifiers, authentication tokens, error logs and crash reports, and application performance metrics.

3.4 Usage Data

Pages and features accessed, clicks and interactions within the platform, strategy creation and execution events, time spent on features, search queries within the platform, feature adoption patterns, and aggregated behavioural analytics used to improve the platform.

3.5 Communications Data

Content of support tickets submitted through our help desk, emails and messages sent to our team, live chat transcripts (where applicable), survey responses and product feedback, and records of consent and opt-in/opt-out preferences for marketing communications.

3.6 Data We Do Not Collect

We do not collect special category data (as defined under GDPR Article 9), such as data revealing racial or ethnic origin, political opinions, religious beliefs, genetic data, or health data. The one exception is the biometric liveness-check data described in Section 3.1, collected only where KYC/AML obligations require identity verification, on the legal basis described in Section 4.5, not consent.

4. Legal Basis for Processing (GDPR Article 6)

For users in the European Economic Area (EEA), United Kingdom, and other jurisdictions with similar legal frameworks, we rely on the following lawful bases for processing your personal data:

4.1 Performance of a Contract (Article 6(1)(b))

Processing your data is necessary to provide the Services you have subscribed to, including account creation and management, authenticating your sessions, executing algorithmic trading strategies on connected exchanges, managing your subscription and billing, and providing customer support.

4.2 Legitimate Interests (Article 6(1)(f))

We process certain data based on our legitimate business interests, provided these interests are not overridden by your rights and freedoms. These interests include: fraud prevention and platform security, improving the performance and reliability of our Services, understanding how users interact with our platform to develop better features, sending service-related communications (e.g. downtime alerts, security notices), and enforcing our Terms of Service.

You have the right to object to processing on this basis. See Section 9 for how to exercise your rights.

4.3 Consent (Article 6(1)(a))

Where we rely on consent (such as for optional marketing emails or non-essential cookies), we will obtain your clear, affirmative, and freely given consent before processing. You may withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal. To withdraw consent, contact us at privacy@hello.tradefiq.com or use the unsubscribe link in any marketing email.

4.4 Legal Obligation (Article 6(1)(c))

We process personal data when required to comply with applicable laws, regulations, court orders, or lawful requests from competent authorities. This includes anti-money laundering (AML) obligations, tax reporting requirements, and responding to regulatory inquiries.

4.5 Special Category (Biometric) Data

Where identity verification requires a liveness check (Section 3.1), we process the resulting biometric data on the basis of Article 9(2)(g): processing necessary for reasons of substantial public interest, specifically our legal obligation to prevent money laundering and terrorist financing under applicable AML regulations. This data is processed by our identity-verification provider (Section 6.2A) and is not used for any other purpose.

5. How We Use Your Personal Data

We use your personal data for the following purposes:

  • Account management: Creating and maintaining your account, authenticating your identity, managing your subscription tier and billing cycle.
  • Trade execution and strategy management: Connecting to your authorised exchange APIs to execute algorithmic strategies, fetching market data, and reporting on execution performance.
  • Fraud prevention and security: Detecting and preventing unauthorised access, suspicious activity, or abuse of the platform; enforcing rate limits; monitoring for account takeover attempts.
  • Platform analytics and improvement: Analysing aggregated and anonymised usage patterns to improve existing features and develop new functionality. We use self-hosted analytics tools that do not share data with third parties.
  • Communications: Sending transactional emails (trade alerts, execution reports, billing receipts), service notifications (planned maintenance, security advisories), and, with your consent, product updates and marketing communications.
  • Customer support: Processing your support requests, troubleshooting technical issues, and maintaining records of our interactions.
  • Legal compliance: Meeting our obligations under applicable financial regulations, data protection laws, tax laws, and anti-money laundering frameworks.
  • Dispute resolution: Retaining records necessary to resolve disputes, enforce our Terms of Service, and defend against legal claims.

6. How We Share Your Personal Data

We do not sell, rent, or trade your personal data to any third party. We share data only in the circumstances described below, and only to the extent necessary:

6.1 Exchange Integrations

When you connect a cryptocurrency or financial exchange to TradeFIQ, you authorise us to use your API credentials to interact with that exchange on your behalf. Data transmitted to exchanges (e.g. order parameters) is governed by your agreement with the relevant exchange. We pass only the minimum data required to execute your instructions.

6.2 Payment Processors

Card and bank payments are processed by Paystack and Lemon Squeezy; cryptocurrency payments (deposits and withdrawals) are processed by NowPayments. TradeFIQ does not store your full card details. These processors' privacy policies are available at paystack.com/privacy, lemonsqueezy.com/privacy, and nowpayments.io/privacy-policy. We receive confirmation of successful payment and limited billing or transaction data from each processor for account and Platform Wallet management purposes. For cryptocurrency payments, this includes the sending/receiving wallet address and the on-chain transaction, which is inherently public on the relevant blockchain.

6.2A Identity Verification Provider

Where KYC/AML obligations apply, we share your identification documents and liveness-check data (Section 3.1) with Didit, our identity-verification provider, solely to confirm your identity and screen against sanctions and politically-exposed-person lists. Didit processes this data as our processor, under a data processing agreement, and does not use it for any purpose of its own.

6.3 Cloud Infrastructure Providers

We host our Services on cloud infrastructure provided by Amazon Web Services (AWS) and/or Google Cloud Platform (GCP). These providers process personal data solely to provide infrastructure services to us and are subject to data processing agreements that comply with GDPR Article 28 requirements.

6.4 Analytics

We use self-hosted analytics tools (such as Plausible Analytics or Matomo) that process anonymised or pseudonymised usage data on infrastructure we control. We do not use Google Analytics or any analytics tool that sends user-level data to third-party advertising networks.

6.5 Legal Authorities and Regulators

We may disclose personal data to courts, law enforcement agencies, regulatory authorities, or other public bodies where we are legally required to do so, or where disclosure is necessary to: protect the rights, property, or safety of TradeFIQ, our users, or the public; detect, prevent, or address fraud, security, or technical issues; or comply with applicable law or legal process.

Where permitted, we will notify affected users before disclosing their data to authorities.

6.6 Business Transfers

In the event of a merger, acquisition, sale of assets, or corporate restructuring, your personal data may be transferred to the relevant successor entity. We will notify you via email or prominent notice on our website prior to any such transfer, and the successor entity will be bound by equivalent privacy commitments.

7. International Data Transfers

TradeFIQ is based in the United Kingdom. Your personal data may be transferred to, stored in, or processed in countries outside the UK and the European Economic Area (EEA), including the United States and other countries where our service providers operate.

Whenever we transfer personal data internationally, we ensure an adequate level of protection is in place through one or more of the following safeguards:

  • Adequacy decisions: Transfer to countries recognised by the UK ICO or European Commission as providing an adequate level of data protection.
  • Standard Contractual Clauses (SCCs): Use of the International Data Transfer Agreement (IDTA) approved by the UK ICO, or the European Commission's SCCs, with appropriate technical and organisational supplementary measures where required following the Schrems II ruling.
  • UK–US Data Bridge / EU–US Data Privacy Framework: Where applicable and where our partners are certified under the relevant framework.
  • Binding Corporate Rules: Where our group entities are involved.

You may request details of the specific transfer mechanisms in place for your data by contacting privacy@hello.tradefiq.com.

8. How Long We Keep Your Data

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law. Our standard retention periods are:

  • Account and identity data: Retained for the duration of your account, and for 7 years following account closure (to comply with financial, tax, and AML record-keeping obligations).
  • Trading and execution logs: Retained for 5 years following the date of the relevant trade or event, in accordance with applicable financial recordkeeping requirements.
  • Payment and billing records: Retained for 7 years to comply with tax and accounting obligations.
  • Support communications: Retained for 3 years after resolution of the relevant matter, or longer if the matter relates to a dispute or legal claim.
  • Marketing preferences and communications: Retained until you withdraw consent or opt out, plus a short period thereafter to honour suppression lists and prevent re-subscription.
  • Technical and usage logs: Retained for up to 90 days in detailed form; aggregated and anonymised analytics may be retained indefinitely.

When data is no longer required, it is securely deleted or anonymised in accordance with our data disposal procedures.

9. Security Measures

We take the security of your personal data seriously and implement appropriate technical and organisational measures to protect it against unauthorised access, alteration, disclosure, or destruction. Our security measures include:

  • Encryption at rest: All sensitive data, including exchange API keys and personal identifiers, is encrypted at rest using AES-256 encryption.
  • Encryption in transit: All data transmitted between your browser or app and our servers is protected using TLS 1.2 or higher (HTTPS).
  • Two-factor authentication (2FA): We offer and encourage 2FA for all user accounts to prevent unauthorised access.
  • Access controls: Internal access to personal data is restricted on a need-to-know basis. All access is logged and audited.
  • Audit logs: We maintain comprehensive audit trails of access to and modifications of sensitive data.
  • Penetration testing: We conduct periodic third-party penetration testing and vulnerability assessments of our platform.
  • Incident response: We maintain a documented data breach response procedure. In the event of a breach that is likely to result in risk to your rights and freedoms, we will notify you and the relevant supervisory authority within the timeframes required by law (72 hours under GDPR/UK GDPR).
  • Vendor due diligence: All third-party processors are assessed for security compliance before engagement and are subject to data processing agreements.

No security measure is 100% infallible. If you believe your account has been compromised, please contact us immediately at security@hello.tradefiq.com.

10. Your Data Protection Rights

Subject to applicable law and certain exceptions, you have the following rights in relation to your personal data:

10.1 Right of Access

You have the right to request a copy of the personal data we hold about you and information about how we use it. We will provide this within 30 days of a valid request (or within 1 calendar month under GDPR/UK GDPR, extendable to 3 months in complex cases with notice).

10.2 Right to Rectification

You have the right to request that we correct any inaccurate personal data we hold about you, or complete any incomplete personal data.

10.3 Right to Erasure ("Right to be Forgotten")

You may request that we delete your personal data in certain circumstances, for example, where the data is no longer necessary for the purpose it was collected, or where you have successfully withdrawn consent and no other lawful basis applies. This right is not absolute and is subject to our legal obligations (e.g. record-keeping requirements).

10.4 Right to Data Portability

Where processing is based on consent or contract performance and carried out by automated means, you have the right to receive your personal data in a structured, commonly used, machine-readable format, and to have it transmitted to another controller where technically feasible.

10.5 Right to Restriction of Processing

You have the right to request that we restrict the processing of your personal data in certain circumstances, for example, while you contest its accuracy, or while we verify whether our legitimate interests override your objection.

10.6 Right to Object

You have the right to object, on grounds relating to your particular situation, to processing based on legitimate interests (Article 6(1)(f)). You also have an absolute right to object to direct marketing at any time. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests, or where processing is necessary for legal claims.

10.7 Right to Withdraw Consent

Where processing is based on your consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing prior to withdrawal.

10.8 Right to Lodge a Complaint

If you are dissatisfied with how we handle your personal data, you have the right to lodge a complaint with your relevant supervisory authority:

  • UK: Information Commissioner's Office (ICO) ico.org.uk
  • EU: Your local Data Protection Authority (DPA). A list is available at edpb.europa.eu
  • Switzerland: Federal Data Protection and Information Commissioner (FDPIC)

We ask that you first try to resolve any concern by contacting us directly, as we are committed to addressing your concerns promptly and fairly.

To exercise any of these rights, please submit a written request to privacy@hello.tradefiq.com. We may ask you to verify your identity before processing your request. There is no charge for exercising your rights, unless requests are manifestly unfounded or excessive.

11. California Residents: CCPA / CPRA Rights

If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), grants you the following additional rights:

  • Right to Know: You may request that we disclose the categories and specific pieces of personal information we have collected about you, the categories of sources, the business purpose for collection, and the categories of third parties with whom we share it.
  • Right to Delete: You may request deletion of personal information we have collected about you, subject to certain exceptions.
  • Right to Correct: You may request correction of inaccurate personal information.
  • Right to Opt-Out of Sale or Sharing: TradeFIQ does not sell personal information and does not share personal information for cross-context behavioural advertising. No opt-out is required, but we honour any Global Privacy Control (GPC) signal.
  • Right to Limit Use of Sensitive Personal Information: We do not use sensitive personal information for any purpose beyond what is necessary to provide the Services.
  • Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights.

To exercise California privacy rights, contact us at privacy@hello.tradefiq.com or write to us at 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom.

We have not sold personal information in the preceding 12 months. We do not have actual knowledge that we sell personal information of consumers under 16 years of age.

12. Canadian Residents: PIPEDA Rights

If you are a resident of Canada, the Personal Information Protection and Electronic Documents Act (PIPEDA), and applicable provincial legislation (including Quebec Law 25), governs how we handle your personal information.

Under PIPEDA, you have the right to:

  • Access the personal information we hold about you and obtain an account of its use and disclosure;
  • Challenge the accuracy and completeness of your personal information and have it amended where appropriate;
  • Withdraw consent to collection, use, or disclosure of your personal information, subject to legal or contractual restrictions and reasonable notice;
  • Lodge a complaint with the Office of the Privacy Commissioner of Canada at priv.gc.ca.

We will retain Canadian users' data only as long as necessary for identified purposes and will not transfer personal information outside Canada without appropriate protections in place. Our Privacy Officer for Canadian data matters is reachable at privacy@hello.tradefiq.com.

13. Australian Residents: Australian Privacy Act 1988

If you are located in Australia, the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) apply to our handling of your personal information.

Under Australian law, you have the right to:

  • Access the personal information we hold about you;
  • Request correction of personal information that is inaccurate, out of date, incomplete, irrelevant, or misleading;
  • Make a complaint to us, which we will acknowledge and resolve within 30 days;
  • Lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au if you are not satisfied with our response.

We will not use personal information collected from Australian residents for direct marketing unless you have consented or it is impracticable to obtain consent, and we will always include an opt-out mechanism.

We will not disclose personal information to overseas recipients unless we have taken reasonable steps to ensure the overseas recipient does not breach the Australian Privacy Principles, or you have consented to the disclosure.

14. Cookies and Tracking Technologies

We use cookies and similar technologies to operate our Services and improve your experience. For a full description of the cookies we use, their purposes, durations, and how to manage them, please refer to our Cookie Policy.

We do not use advertising or marketing cookies. We do not participate in cross-site tracking or interest-based advertising networks.

15. Children's Privacy

The TradeFIQ platform is not directed at, and is not intended for use by, persons under the age of 18 years. We do not knowingly collect personal data from anyone under 18. If you are a parent or guardian and believe that your child has provided personal data to us without your consent, please contact us immediately at privacy@hello.tradefiq.com and we will take steps to delete such data as soon as practicable.

16. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or the way we operate. When we make material changes, we will:

  • Update the "Last Updated" date at the top of this page;
  • Notify registered users by email at least 30 days before the new policy takes effect;
  • Display a prominent notice on the platform or website where appropriate.

We encourage you to review this policy periodically. Your continued use of the Services after the effective date of the revised policy constitutes your acceptance of the changes. If you do not agree to the updated policy, you should cease using the Services and may close your account.

17. Contact Us

If you have any questions, concerns, or requests relating to this Privacy Policy or our data practices, please contact us:

We will endeavour to respond to all legitimate requests within 30 days. Occasionally it may take us longer if your request is particularly complex or if you have made a number of requests; in this case we will notify you and keep you updated.