QTSurfer beta

Privacy notice

Draft privacy notice for the QTSurfer service.

Draft template. This notice must be reviewed, completed and approved before QTSurfer is made available to users. It is not legal advice.

Controller: [legal entity name, registered address and company registration details]
Privacy contact: [privacy email]
Effective date: [to be confirmed]

1. Scope

This notice explains how the controller processes personal data when you visit the QTSurfer website, create an account or use the service. It must be completed with the controller’s final details, the actual vendors used and the jurisdictions in which the service operates.

2. Personal data we may process

Depending on how you use QTSurfer, this may include:

  • Account and contact information, such as your name, email address and account settings.
  • Authentication, security and technical information, such as login events, IP address, browser, device and service logs.
  • Service content, such as strategy metadata, configurations, backtest inputs and outputs, and support requests.
  • Billing and subscription information, where paid plans are offered. Payment card information should normally be processed by a payment provider rather than stored by QTSurfer.

Do not submit personal data to strategy code, strategy parameters or other service content unless it is necessary and you have a lawful basis to do so.

3. Why we use personal data

We may process personal data to provide and secure the service, create and manage accounts, respond to requests, prevent misuse, comply with legal obligations, improve the service and communicate material service or policy changes. The final notice must identify the applicable legal bases for each purpose, including performance of a contract, legitimate interests, consent or legal obligation.

4. Sharing and service providers

We may use carefully selected providers for hosting, databases, authentication, email, analytics, payment processing, support and infrastructure monitoring. The final notice must name or categorise the actual providers, describe the relevant safeguards and state whether personal data is disclosed to any other recipients.

We do not sell personal data. Any future advertising, marketplace or data-sharing activity requires separate legal review and an update to this notice.

5. International transfers

If personal data is transferred outside the country or region where you are located, we will use the transfer mechanism and safeguards required by applicable law. The final notice must describe those mechanisms and identify relevant destination countries or regions where required.

6. Retention

We keep personal data only for as long as needed for the purposes described above, including account operation, security, dispute resolution and legal compliance. The final notice must state concrete retention periods or the criteria used to determine them.

7. Your rights

Depending on applicable law, you may have rights to access, correct, delete, restrict or object to processing of your personal data, receive it in a portable format, withdraw consent, and complain to a supervisory authority. Contact us using the details above to exercise your rights. We may need to verify your identity before responding.

8. Security

We use technical and organisational measures designed to protect personal data. No system is completely secure, so the final notice must avoid promises that cannot be made and should describe the security commitments that are actually in place.

9. Changes and contact

We may update this notice as the service or law changes. We will publish the current version and, where required, provide additional notice. Contact [privacy email] with questions or requests.