Privacy Policy
Effective date: April 21, 2026
This Privacy Policy describes how Bincoti, S.A. ("we", "us"), the operator of TradeAssi (tradeassi.com), collects, uses, and protects your personal data.
1. Data We Collect
- Account data: email, name, hashed password, language preference.
- Usage data: IP address, device/browser, pages viewed, actions performed.
- Trading data: strategies, alerts, backtests, journal entries you create.
- Exchange API keys: encrypted at rest (AES-GCM); we never store withdrawal-enabled keys.
- Payment data: handled by our processor (Paddle, NowPayments). We receive only transaction metadata — no full card numbers.
2. How We Use Data
- Operate the Service (execute strategies, deliver alerts, compute backtests).
- Process payments and prevent fraud.
- Send service emails (verification, billing, security notices). Marketing emails only with opt-in.
- Improve reliability and detect abuse via aggregated analytics.
3. Legal Basis (GDPR)
We process data on the basis of: (a) contract performance (delivering the Service), (b) legitimate interest (security, analytics), (c) consent (marketing, optional features), and (d) legal obligation (tax, AML where applicable).
4. Data Sharing
We do not sell personal data. We share only with:
- Payment processors (Paddle as Merchant of Record, NowPayments for crypto).
- Infrastructure providers (AWS — Tokyo region).
- Communication providers (Telegram, email delivery, push services) for notifications you enable.
- Authorities, when required by valid legal process.
5. Data Retention
Account data is retained while your account is active and for up to 12 months after deletion for legal/tax purposes. You may request earlier deletion by emailing bincoti.sa@gmail.com — we will comply subject to legal retention requirements.
6. Your Rights
Depending on your jurisdiction, you have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. Exercise these rights by contacting bincoti.sa@gmail.com. EEA/UK residents may also lodge a complaint with their local data-protection authority.
7. Security
We use industry-standard safeguards: TLS in transit, encrypted API keys at rest, isolated production infrastructure, and least-privilege access. No system is perfectly secure; notify us immediately at bincoti.sa@gmail.com of any suspected compromise.
8. International Transfers
Our primary infrastructure is in AWS Tokyo (Japan). Data may be transferred to and processed in jurisdictions where our service providers operate. We apply appropriate safeguards (e.g., Standard Contractual Clauses) where required.
9. Cookies
We use essential cookies for authentication and preferences. We do not use third-party advertising cookies.
10. Children
The Service is not directed to children under 18. We do not knowingly collect data from minors. Contact us to remove such data.
11. Changes
We may update this Policy. Material changes will be announced at least 14 days in advance.
12. Contact
Bincoti, S.A. — privacy: bincoti.sa@gmail.com