Privacy Policy
GDPR-aligned · Last updated: · Siddani Labs
1. Who we are
Siddani Labs ("we", "us") operates the Siddani portfolio platform. For GDPR purposes, Siddani Labs is the data controller for the personal data described here. Contact: privacy@siddani.example (replace with your domain on deployment).
2. Data we collect
- Account data: email address, password hash (Argon2id), plan, two-factor secret if enabled.
- Trading data: order fills, balances and account metadata pulled on your instruction from venues you connect with read-only API keys, or streamed from your MetaTrader terminal via our EA.
- Exchange credentials: sealed with per-record AES-256-GCM envelope encryption; keys are decrypted in memory only to perform the syncs you request.
- Security data: login timestamps, IP addresses, device strings, and a tamper-evident audit trail of privileged actions.
- AI data: questions you ask and the evidence snapshots used to answer them (you can disable AI logging in settings).
3. What we never collect
- We never request withdrawal permissions on exchange keys.
- We never store bank details, card numbers, or identity documents unless a paid subscription requires billing (then processed exclusively by the payment provider — we store only a customer reference).
- We never sell personal data.
4. Legal bases (GDPR Art. 6)
- Contract — operating your account and syncing the data you connect (Art. 6(1)(b)).
- Legitimate interests — security, fraud prevention, service improvement (Art. 6(1)(f)).
- Consent — optional AI logging and product emails, withdrawable at any time (Art. 6(1)(a)).
5. Processors & sharing
We use a minimal set of processors: hosting/cloud provider, managed database and object storage, email delivery service (verification codes and product emails), payment provider (subscriptions), and the exchange/broker APIs you connect — which receive requests signed with your read-only keys. A current list is available on request.
6. Retention
Account and trading data: kept while your account is active. Audit records: kept 7 years (tamper-evidence and legal defense). Login security records: 12 months. Deleted accounts: personal data erased within 30 days, except records we must keep by law.
7. Your rights
- Access & portability — download a machine-readable export from Account center → Data.
- Rectification — edit your data in the app.
- Erasure — delete your account from Account center; we erase personal data within 30 days and confirm.
- Objection & restriction — contact privacy@siddani.example.
- Complaint — you may complain to your local data-protection authority.
8. Security
Measures include: Argon2id password hashing, Ed25519-signed short-lived access tokens, single-use refresh tokens with reuse detection, TOTP two-factor support, envelope encryption for API credentials, tamper-evident audit logging, TLS in transit, encrypted backups, least-privilege access, and regular dependency vulnerability scanning.
9. Cookies
We use one strictly necessary cookie (your refresh session, HttpOnly, SameSite=Strict) and no tracking or advertising cookies.
10. International transfers
Processors are engaged under EU Standard Contractual Clauses where data leaves the EEA.