Legal
Privacy Policy
Effective: 2026-07-09Last updated: 2026-07-09Version 1.0
Privacy Policy
Effective date: 2026-07-09 Last updated: 2026-07-09
Table of Contents
- Introduction
- Who This Policy Applies To
- Data Controller
- Categories of Personal Data We Collect
- Legal Bases for Processing
- Purposes of Processing
- Third-Party Sharing and Sub-Processors
- International Data Transfers
- Data Retention
- Your Data-Subject Rights
- How to Exercise Your Rights
- Cookies and Similar Technologies
- Security
- Children
- Changes to This Policy
- Contact
1. Introduction
This Privacy Policy explains how Alphaservus Consulting Services Ltd., trading as "tradesense technologies" ("Tradesense", "we", "us") collects, uses, discloses, and safeguards personal data when you use the Tradesense service made available at app.tradesense.tech (the "Service"). It is drafted with reference to the EU General Data Protection Regulation ("GDPR") and the UK GDPR and applies globally to users of the Service.
2. Who This Policy Applies To
This Policy applies to:
- Broker administrators — individuals acting on behalf of a brokerage organisation onboarded by Tradesense.
- Traders — individual end-users who register via a Broker-specific invite link.
- Visitors — individuals who visit our marketing site or interact with our support channels.
Broker organisations are separately responsible for their own privacy notices to their Traders concerning the trading relationship. This Policy covers processing carried out by Tradesense in respect of the Service.
3. Data Controller
The data controller for personal data processed under this Policy is:
- Alphaservus Consulting Services Ltd. (trading as "tradesense technologies")
- Registered address: 1 Stelios Kazantzides, Cyprus
- Country of incorporation: Cyprus
- Legal contact: support@tradesense.tech
Tradesense has not appointed a formal Data Protection Officer. Data-protection queries should be sent to support@tradesense.tech.
Where Tradesense processes personal data on behalf of a Broker (e.g., data about that Broker's Traders provided by the Broker for administration), Tradesense acts as a processor and the Broker is the controller in respect of that data.
4. Categories of Personal Data We Collect
4.1 Account data - Email address, name, password hash, and role (Broker admin or Trader).
4.2 Broker organisation data - Organisation name, primary contact details, Match-Trader connection credentials (stored encrypted at rest), and risk-cap configuration.
4.3 Trader data - Match-Trader login (mt_login), Match-Trader group (mt_group), the connection through which the Trader was invited, Strategy configurations, and history of Strategy Executions and orders.
4.4 Usage data - Page views, click events, session identifiers, feature usage counters, and similar telemetry captured via internal usage-event logging.
4.5 Communications data - Telegram chat identifier (chat_id) provided by the Trader when linking a Telegram account, and the history of alert messages sent to that identifier.
4.6 Support data - Emails, tickets, screenshots, and other content you send to us in the course of receiving support.
4.7 Technical data - IP address, device and browser information, and diagnostic error data captured for security and troubleshooting.
We do not knowingly collect special-category (sensitive) personal data. Do not submit such data to the Service.
5. Legal Bases for Processing
We process personal data on the following legal bases under Article 6 GDPR:
- Performance of a contract (Art. 6(1)(b)) — to create and maintain your account, provide the Service, execute Strategies you configure, deliver alerts you request, and provide support.
- Legitimate interests (Art. 6(1)(f)) — to secure the Service, prevent fraud and abuse, monitor and improve the Service, produce aggregated analytics, and communicate essential service updates. When we rely on legitimate interests, we balance them against your rights and freedoms.
- Consent (Art. 6(1)(a)) — for optional cookies, marketing communications (if any), and Telegram linking. You may withdraw consent at any time without affecting the lawfulness of prior processing.
- Legal obligation (Art. 6(1)(c)) — to maintain audit trails, respond to lawful requests from public authorities, and comply with financial-services record-keeping obligations that apply to us or that we are required to support for a Broker.
6. Purposes of Processing
- Provide the Service — authenticate users; provision Broker and Trader accounts; execute Strategies and orders against Match-Trader; monitor positions; deliver Telegram alerts.
- Administer and support — respond to your requests, investigate incidents, and manage billing if introduced after beta.
- Secure the Service — detect and prevent abuse, unauthorised access, and fraud; enforce risk caps and kill switches on behalf of Brokers.
- Improve the Service — analyse aggregated usage, prioritise features, and debug errors.
- Comply with law — maintain records required by regulators, respond to lawful requests, and support Brokers' regulatory obligations.
7. Third-Party Sharing and Sub-Processors
We do not sell personal data. We share personal data only in the following circumstances and only to the extent necessary:
- Match-Trader (the trading platform) — Broker connection credentials are used to make API calls on the Broker's behalf. No Tradesense-side user data (e.g., other Brokers' data, Tradesense telemetry) is shared with Match-Trader. Match-Trader is separately responsible for personal data it holds under its own terms.
- Telegram — where a Trader links a Telegram chat to receive alerts, we send the Trader's
chat_idand message text to Telegram's Bot API. This is optional and consent-based. - Sentry (error monitoring) — anonymised or pseudonymised error events, stack traces, and diagnostic context are sent to Sentry for reliability and debugging purposes. We configure Sentry to minimise personal data in event payloads.
- Hosting and infrastructure providers — cloud hosting, managed PostgreSQL database, DNS, CDN, and email-delivery providers acting as our processors under written contracts.
- Professional advisers — auditors, lawyers, and accountants where necessary and subject to confidentiality obligations.
- Authorities and law-enforcement — where required by law, court order, or valid regulatory request.
- Corporate transactions — in connection with a merger, acquisition, or sale of assets, subject to protective safeguards.
The specific sub-processors currently engaged by Tradesense are:
| Sub-processor | Purpose | Data categories | Location | |---|---|---|---| | Hetzner Cloud | Infrastructure hosting (application servers, database, network) | All service data at rest and in transit | Germany / Finland (EU) | | Sentry (Functional Software, Inc.) | Application error tracking and performance monitoring | Error messages, stack traces, anonymised session identifiers (no PII in payload) | United States (SCC-covered) | | Telegram (Telegram FZ-LLC) | Delivery of alert notifications to Traders who voluntarily link a Telegram account | Trader's Telegram chat_id and alert message content | Global (Trader initiates the link) |
For clarity, Match-Trader is not a Tradesense sub-processor. Each Broker maintains its own contractual relationship with Match-Trader and controls the API credentials used to connect the Service to the Broker's Match-Trader environment.
8. International Data Transfers
Where personal data is transferred outside the European Economic Area or the United Kingdom to a country not covered by an adequacy decision, we implement appropriate safeguards, including the European Commission's Standard Contractual Clauses ("SCCs") and, for UK transfers, the UK International Data Transfer Addendum, together with supplementary technical and organisational measures where necessary. You may request a copy of the safeguards in place by contacting support@tradesense.tech or support@tradesense.tech.
9. Data Retention
We retain personal data only for as long as necessary for the purposes described in this Policy:
- Account data — retained while the account is active and for up to seven (7) years after account closure, reflecting typical financial-services record-keeping obligations.
- Trading activity and Execution history — retained for up to seven (7) years after the activity, or longer where a Broker's applicable regulator requires it.
- Usage events and analytics — retained for up to two (2) years.
- Application and access logs — retained for up to ninety (90) days, or longer where an ongoing security investigation requires it.
- Support communications — retained for up to three (3) years after the last correspondence.
This retention period aligns with financial-services regulatory expectations in Cyprus and reflects Brokers' own audit-trail obligations to their national competent authorities.
Where personal data is no longer required, we delete it or irreversibly anonymise it.
10. Your Data-Subject Rights
Subject to applicable law, you have the following rights (GDPR Articles 15–22):
- Right of access — to obtain confirmation of, and a copy of, the personal data we hold about you.
- Right to rectification — to have inaccurate or incomplete data corrected.
- Right to erasure ("right to be forgotten") — to have personal data deleted where legally permitted. This right is subject to exceptions, in particular where retention is required to comply with a legal or regulatory obligation, to establish, exercise, or defend legal claims, or where a Broker (as controller of Trader data it provides to us) instructs retention.
- Right to data portability — to receive personal data you provided to us in a structured, commonly used, machine-readable format, or to have it transmitted to another controller where technically feasible.
- Right to restrict processing — to limit the way we process your data in certain circumstances.
- Right to object — to object to processing based on legitimate interests, including profiling; and an absolute right to object to processing for direct marketing.
- Right to withdraw consent — where processing is based on consent, at any time, without affecting the lawfulness of prior processing.
- Right to lodge a complaint with a supervisory authority in your EU member state of residence, place of work, or place of the alleged infringement, or with the UK Information Commissioner's Office if you are in the UK, or with the competent supervisory authority in Cyprus.
Where you are a Trader and the data in question was provided by your Broker as controller, we may forward your request to your Broker to respond.
11. How to Exercise Your Rights
To exercise any of the rights above, contact us at support@tradesense.tech or support@tradesense.tech. We will acknowledge your request promptly and respond within thirty (30) days of receipt. We may extend this period by a further two months for complex or numerous requests, in which case we will inform you of the extension and its reasons.
We may ask you for information to verify your identity before responding. If we consider a request manifestly unfounded or excessive, we may charge a reasonable fee or refuse to act, in each case explaining our reasoning.
12. Cookies and Similar Technologies
We use cookies and similar technologies as described in the Cookie Policy.
13. Security
We implement appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These measures include:
- Encryption of data in transit (TLS) and encryption at rest for sensitive fields such as Match-Trader connection credentials.
- Role-based access controls and least-privilege principles for internal staff.
- Audit logging of administrative actions.
- Regular review of access rights and dependency vulnerabilities.
- Segregation of production and non-production environments.
No system can be guaranteed 100% secure. In the event of a personal-data breach that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within seventy-two (72) hours of becoming aware of it, in accordance with Article 33 GDPR, and will notify affected individuals without undue delay where required under Article 34 GDPR.
14. Children
The Service is not directed at, and must not be used by, individuals under the age of 18. We do not knowingly collect personal data from persons under 18. If we become aware that we have inadvertently collected such data, we will delete it promptly.
15. Changes to This Policy
We may update this Policy from time to time. Where a change is material, we will give you at least thirty (30) days' notice by email and via an in-app banner before the change takes effect. Non-material changes may take effect immediately. The "Last updated" date at the top of this Policy indicates when it was most recently revised.
16. Contact
Privacy-related questions and requests may be addressed to:
- Data Protection Officer (or privacy contact): support@tradesense.tech
- Legal notices: support@tradesense.tech
- Postal address: Alphaservus Consulting Services Ltd., 1 Stelios Kazantzides, Cyprus
NOTE — Placeholders to fill in
Alphaservus Consulting Services Ltd.— registered legal name of the Tradesense entity1 Stelios Kazantzides, Cyprus— registered address of the Tradesense entityCyprus— country of incorporationsupport@tradesense.tech— e.g., legal@tradesense.techsupport@tradesense.tech— e.g., dpo@tradesense.tech (or remove if no DPO)2026-07-09— publication date of this Policy
NOTE — Open questions flagged in the draft
- Is a DPO appointed (Section 3)? Determines whether
support@tradesense.techremains. - Confirm final sub-processor list (Section 7) — hosting, database, email, monitoring.
- Confirm 7-year retention window (Section 9) against Cyprus financial-services rules and any Broker contract requirements.