Logo
Home
Strategies
App
Pricing
Exchange Guide
Get In Touch

Algotitan Privacy Policy

Effective date: 22 June 2026

Controller / companyALGOTITAN INFORMATION CONSULTANCY - FZCO
Privacy contactinfo@algotitan.io
General contactinfo@algotitan.io
Registered addressIFZA Business Park, DDP Premises No. 77414-001, Dubai Silicon Oasis, Dubai, United Arab Emirates
1. Purpose and Scope2. Who We Are and Our Role3. Personal Data We Collect4. Sources of Personal Data5. Why We Use Personal Data and the Applicable Grounds6. Compliance and Special-Category Data7. Exchange Integrations, API Credentials, and Trading Data8. Cookies, SDKs, Local Storage, and Similar Technologies9. How We Share Personal Data10. International Transfers11. Data Retention12. Security Measures13. Data Breach and Incident Response14. Your Privacy Rights and How to Exercise Them15. Marketing Communications16. Automated Processing17. Children and Age Restrictions18. Regional Notices19. Third-Party Links and Services20. Changes to This Privacy Policy21. Contact Us22. Short-Form Privacy Notice for Website or Mini App Footer

1. Purpose and Scope

This Privacy Policy explains how Algotitan collects, uses, discloses, stores, transfers, and protects personal data when you access or use our website, Telegram bot, Telegram Mini App, dashboards, software, APIs, paper-trading environment, automated execution tools, support channels, marketing channels, and related services (collectively, the "Service").

The Service lets eligible users test preset strategy behavior in paper trading, connect supported exchange accounts using API connectivity, subscribe to paid plans, and activate user-authorized automated order instructions in the user's own exchange account. Algotitan does not custody user assets and does not request seed phrases, private keys, wallet recovery phrases, or withdrawal-enabled API credentials.

This Policy does not govern personal data processed by Telegram, exchanges, payment processors, wallet providers, advertising platforms, or other third parties under their own privacy policies, except where they process data for Algotitan as our processors or service providers.

2. Who We Are and Our Role

For most processing described in this Policy, Algotitan is the controller, data controller, personal data controller, or equivalent role under applicable privacy law. This means that we decide why and how personal data is processed for the Service.

Where we process personal data for an institutional customer or other controller under a separate written agreement, we may act as a processor or service provider for the limited activities described in that agreement. If local law requires a data protection officer, local representative, or another designated privacy contact, we will identify that person or entity in the applicable regional notice.

3. Personal Data We Collect

We collect only the data reasonably necessary for the Service, security, legal compliance, support, and the other purposes in this Policy. The exact data collected depends on the features you use, permissions you grant, and information you provide.

3.1 Account, Telegram, and Profile Data

  • Name, username, email address, phone number, country or region, language, timezone, referral code, account status, onboarding status, authentication data, settings, subscription status, plan type, notification preferences, and consent records.
  • Telegram user ID, Telegram username, display name, profile information made available through Telegram, chat ID, bot interaction data, Mini App session identifiers, Mini App initialization data, language settings, and interaction timestamps.

3.2 Identity, Compliance, and Eligibility Data

Where legally required or reasonably necessary for eligibility, fraud prevention, security, or compliance, we may collect legal name, date of birth, nationality, citizenship, residence, address, tax-related information, government identification details, proof of address, beneficial ownership information, sanctions or PEP screening results, source-of-funds or source-of-wealth information, geolocation signals, risk flags, investigation notes, and documents or certifications you provide. We do not collect these categories for every user.

3.3 Exchange Integration and API Data

  • Exchange name, exchange account identifiers, subaccount identifiers, linked-account status, connection timestamps, permission metadata, and, where available, the outcome of API-permission validation. We may also collect API key labels, masked API identifiers, encrypted API secrets or token references, token refresh or revocation status, authentication events, API usage logs, diagnostics, error logs, and permission-failure messages.
  • Exchange balances, positions, open orders, executed orders, fills, order history, trade timestamps, instrument or pair selections, account valuation data, margin or derivatives status, strategy execution logs, profit/loss metrics, and account activity made available through the permissions you grant and needed to provide, secure, monitor, troubleshoot, and improve the Service.

3.4 Trial, Strategy, Product, Payment, Device, and Support Data

  • Selected risk level and strategy, paper-trading activity, backtesting activity, strategy activation, pause, or switch instructions, capital-allocation settings displayed in the interface, alerts, notifications, feature interactions, page views, clicks, scrolls, session activity, referral attribution, campaign data, and support interactions.
  • Plan details, billing country, billing address, invoice data, payment status, payment-processor customer ID, transaction identifiers, renewal dates, chargeback records, refund or credit records, taxes, and collection records. We generally do not store full payment-card numbers unless expressly stated at collection.
  • IP address, device identifiers, browser type, operating system, mobile device model, app version, language, timezone, log files, crash reports, diagnostic data, performance metrics, session IDs, cookies, local storage identifiers, device-reputation signals, duplicate-account indicators, and fraud or security signals.
  • Support tickets, emails, chat records, Telegram messages you send to our bot or support channels, screenshots, attachments, diagnostic files, feedback, survey responses, complaints, and, where permitted and notified, call recordings or transcripts.

4. Sources of Personal Data

  • Directly from you when you register, use the Mini App, start a trial, subscribe, connect an exchange, activate a strategy, contact support, or respond to a survey.
  • Automatically from your device, browser, Telegram session, cookies, logs, and security tools.
  • From Telegram to the extent its platform makes Mini App or bot interaction data available to us.
  • From exchanges and integration providers when you authorize connectivity, and from payment processors and billing partners for subscription administration.
  • From identity, fraud, sanctions, and compliance vendors, affiliates, referral partners, marketing partners, and public or legally available sources, where lawful and relevant.

5. Why We Use Personal Data and the Applicable Grounds

We process personal data only when an applicable law permits us to do so. The legal grounds vary by jurisdiction. Where GDPR-like law applies, the table below identifies the main grounds. Under laws that use different terminology, including UAE law, we rely on the corresponding statutory ground, such as consent, a request by you to enter into or perform a contract, a legal obligation, or another basis recognized by the applicable law.

PurposeMain data categoriesMain legal grounds where GDPR-like law applies
Create and administer accounts, trials, subscriptions, and service communicationsAccount, Telegram, profile, payment and support dataContract performance; steps at your request; legal obligation where relevant.
Deliver paper trading, exchange connectivity, dashboards, alerts, and user-authorized order instructionsExchange/API, strategy, account, trading, and device dataContract performance; explicit action/authorization by you; legitimate interests for service integrity where permitted.
Prevent fraud, misuse, unauthorized access, and security incidentsDevice, security, account, API, payment, and compliance dataLegitimate interests where permitted; legal obligation; consent or another statutory ground where required.
Meet legal, sanctions, AML/CFT, tax, audit, recordkeeping, and dispute obligationsCompliance, identity, payment, account, and transaction dataLegal obligation; establishment, exercise, or defense of legal claims; other statutory grounds where applicable.
Improve the Service and measure product performanceUsage, analytics, diagnostics, support, and aggregated dataLegitimate interests where permitted; consent where required for non-essential cookies or similar technologies.
Send marketing and measure campaignsContact, preference, campaign, and cookie dataConsent or another permission expressly allowed by applicable law. You can opt out at any time.

6. Compliance and Special-Category Data

We may process identity, sanctions, PEP, source-of-funds, source-of-wealth, and related compliance data only where necessary and permitted by law. If data is treated as sensitive or special-category data under an applicable law, we will process it only with explicit consent or another valid legal condition available under that law. We do not use compliance data to make investment-suitability recommendations.

7. Exchange Integrations, API Credentials, and Trading Data

When you connect an exchange account, you instruct us to process the data needed to provide the connected features. This may include API credential references, encrypted secrets, token references, permission metadata, account and trading activity, balances, orders, fills, strategy status, execution logs, and diagnostics.

The Service is designed to operate with trade-only API permissions. We do not ask for seed phrases, private keys, wallet recovery phrases, or withdrawal-enabled API credentials. Where a supported exchange or integration makes permission information available, we may review that information and may warn you, refuse connection, restrict features, or disconnect the integration if withdrawal, custody, or other permissions appear broader than approved. Such controls depend on the information made available by the exchange or integration and may not detect every issue. You remain responsible for reviewing exchange-side permissions and revoking access when appropriate.

Your exchange is a separate controller or independent service provider for personal data it processes under its own terms and privacy notice. Algotitan does not control exchange privacy practices, cybersecurity, API behavior, execution, or retention.

8. Cookies, SDKs, Local Storage, and Similar Technologies

We and our service providers use cookies, pixels, SDKs, local storage, device identifiers, and similar technologies for authentication, session management, security, fraud prevention, remembering preferences, analytics, performance measurement, marketing attribution, and product improvement.

Where consent is required, we will not place or read non-essential cookies or similar technologies before you give consent through a cookie banner or settings center. You can change choices through the settings center, browser controls, device settings, or other tools we provide. The settings center will identify the applicable provider, technology, purpose, and duration. Disabling essential technologies may affect Service functionality.

9. How We Share Personal Data

We do not sell personal data for money. We do not disclose personal data for cross-context behavioral advertising unless we provide any notice, consent, or opt-out mechanism required by applicable law.

9.1 Processors and Service Providers

We may share data with providers of cloud hosting, storage, authentication, cybersecurity, monitoring, analytics, customer support, communications, CRM, billing, payments, fraud prevention, compliance screening, identity verification, logging, and development operations. Where required, these providers process data under written terms requiring appropriate privacy and security safeguards.

9.2 Exchanges, Integration Providers, and Platform Providers

We may share data with exchanges, API orchestration providers, order-routing or monitoring partners, market-data providers, notification providers, webhook providers, Telegram, and other platform providers as needed to deliver the Service you request or activate. These organizations may act as independent controllers for their own services.

9.3 Advisors, Corporate Transactions, and Authorities

We may disclose data to affiliates, auditors, legal counsel, consultants, insurers, and transaction counterparties for internal administration, security, finance, legal claims, financing, merger, acquisition, restructuring, asset sale, insolvency, or business transfer. We may disclose data to regulators, courts, law enforcement, tax authorities, sanctions authorities, exchanges, payment processors, or other parties where necessary to comply with law, respond to a lawful request, enforce agreements, investigate fraud or abuse, or protect rights and safety.

9.4 With Your Direction or Consent

We may share data when you request or authorize sharing, connect an integration, participate in a referral or promotion, or otherwise consent.

10. International Transfers

Algotitan is established in the UAE and may process personal data in the UAE and other countries where our affiliates, vendors, exchanges, payment processors, support teams, or infrastructure providers operate. Those countries may have data-protection laws different from those in your country.

Where applicable law requires a transfer mechanism or additional protection, we will use the mechanism required for the relevant transfer, which may include an adequacy decision, standard contractual clauses or standard contracts, contractual safeguards with enforceable data-subject rights, a transfer impact assessment, encryption, access controls, data minimization, localization measures, or a narrow statutory derogation. You may request information about applicable safeguards by contacting us, subject to confidentiality and security restrictions.

Exchange integrations, Telegram, payment providers, and other independent third parties may conduct their own international transfers under their own policies. Review their notices before using their services.

11. Data Retention

We retain personal data only for as long as reasonably necessary for the purposes in this Policy, unless a longer period is required or permitted for legal, tax, accounting, security, fraud, audit, or claims purposes. The following periods are the standard operational periods, subject to legal holds, backup cycles, and mandatory retention obligations.

Data categoryStandard retention period
Account and profile dataLife of the account plus 90 days after closure, unless earlier deletion is required or longer retention is necessary for law, security, fraud prevention, or a claim.
API credentials and token materialsWhile the connection is active. After disconnection or account closure, active use is disabled promptly and credential materials are deleted or rendered unusable within 30 days, unless necessary for a security incident, dispute, or legal obligation.
Exchange, order-instruction, execution, and strategy logsUp to 5 years after the later of account closure or the relevant execution event, unless a longer period is necessary for law, audit, fraud prevention, or a claim.
Subscription, invoice, payment, tax, and accounting recordsUp to 7 years after the relevant financial period, or longer where applicable law requires.
Security, fraud, compliance, sanctions, and abuse recordsUp to 5 years after the relevant event or closure, unless a longer period is legally necessary.
Support communicationsUp to 3 years after resolution of the request, unless retained longer for a dispute, security incident, or legal obligation.
Raw product analytics and diagnosticsUp to 25 months, then deleted, aggregated, or de-identified where reasonably practicable.
Marketing preferences and suppression recordsUntil you withdraw consent or opt out, and thereafter up to 3 years to honor and evidence the opt-out.

We may delete, anonymize, aggregate, or de-identify data when it is no longer required, subject to backup cycles, technical limitations, legal holds, security needs, and mandatory retention obligations.

12. Security Measures

We use administrative, technical, and organizational measures designed to protect personal data, including access restrictions, role-based access, encryption in transit, encryption at rest where appropriate, credential-protection controls, logging, monitoring, network security, vulnerability management, environment segregation, incident-response procedures, vendor due diligence, and workforce confidentiality obligations.

No system is completely secure. Internet-based services, Telegram, APIs, cloud systems, exchanges, and digital-asset markets involve inherent risks. You are responsible for securing your devices, Telegram account, email account, exchange account, API credentials, passwords, and authentication tools, and for notifying us promptly of suspected unauthorized access.

13. Data Breach and Incident Response

If we become aware of a personal-data breach requiring notification under applicable law, we will notify the competent authority and/or affected individuals within the required timeframe and in the required manner. We may also notify exchanges, payment providers, Telegram, vendors, law enforcement, or other parties where appropriate to investigate, mitigate, or prevent harm.

14. Your Privacy Rights and How to Exercise Them

Depending on applicable law, you may have rights to request access, confirmation of processing, correction, deletion, erasure, anonymization, restriction, blocking, portability, objection, withdrawal of consent, opt-out of direct marketing, opt-out of certain sale, sharing, or targeted-advertising activities, human review of certain automated decisions, and a complaint to a supervisory authority.

To make a request, email info@algotitan.io with the subject line "Privacy Request" and include your name, account email or Telegram username, country of residence, request type, and supporting details. We may request information needed to verify identity and locate the relevant records. We will respond within the timeframe required by applicable law. For example, where GDPR applies, the usual period is one month, subject to any lawful extension; where Türkiye's personal-data law applies, we will respond within the applicable statutory period, generally no later than 30 days.

These rights are not absolute. We may refuse, limit, or delay a request where permitted by law, including where identity cannot be verified, retention is legally required, data is needed for security, fraud prevention, or legal claims, the request is manifestly unfounded or excessive, or fulfilling it would adversely affect others' rights and freedoms.

15. Marketing Communications

Where permitted by law and based on the appropriate permission, we may send onboarding messages, service updates, educational content, newsletters, offers, product announcements, event invitations, and marketing communications. You may opt out of non-essential marketing at any time using an unsubscribe link, in-app settings, Telegram controls where available, or by contacting us.

We may still send transactional or service-related messages, including security alerts, billing notices, legal updates, exchange-connectivity notices, and critical Service communications.

16. Automated Processing

Automated processing is core to the Service. It includes paper-trading simulations, strategy deployment after user activation, exchange synchronization, order-instruction generation and transmission, notification triggers, risk-profile handling within the user-selected Service flow, fraud monitoring, security monitoring, and compliance screening.

We do not use personal data to provide individualized investment suitability advice or to promise a trading outcome. Automated security or compliance signals may lead to account restrictions or further review. Where applicable law gives you rights relating to a solely automated decision with legal or similarly significant effects, you may contact us to request information, contest the decision, and seek human review where required by law.

17. Children and Age Restrictions

The Service is not intended for children or minors. We do not knowingly collect personal data from anyone under 18 or under the age of legal majority in the relevant jurisdiction, whichever is higher. If we learn that we have collected personal data from a minor in violation of applicable law, we may delete the data, suspend the account, disable features, and take other appropriate steps.

18. Regional Notices

UAE: Where UAE data-protection law applies, we process personal data in accordance with applicable controller and processor obligations, data-subject rights, security duties, breach-notification duties, and any applicable impact-assessment or officer requirements.

Türkiye: For users in Türkiye, a Turkish-language privacy notice provided at or before collection supplements this Policy. That notice will identify the required purposes, recipient groups, collection methods, legal grounds, rights, and applicable cross-border transfer safeguards. If there is a conflict, the Turkish notice controls to the extent required by Turkish law.

EEA/UK: At the Effective Date, Algotitan does not offer the Service, including account registration, paper-trading trials, paid subscriptions, exchange connectivity, or live execution, to persons located in or ordinarily resident in the EEA or the United Kingdom. Algotitan does not intentionally target those persons through paid advertising, direct marketing, influencer or referral campaigns, or country-specific sales flows. We may process limited technical data from visits to a public website page for security, fraud prevention, location detection, and enforcement of this restriction, but this does not make the Service available. If Algotitan later offers the Service there or intentionally monitors behavior there, it will implement the applicable transparency, transfer, cookie, representative, and other requirements before doing so.

Other markets: If a law in a market imposes localization, registration, notice, consent, local-representative, transfer, security, breach-notification, or other requirements, we may provide a supplemental notice, implement additional measures, restrict features, or decline service until legal clearance is complete.

If this Policy conflicts with mandatory law that applies to you, mandatory law governs to the extent of the conflict.

19. Third-Party Links and Services

The Service may link to or integrate with exchanges, Telegram, wallets, payment processors, analytics services, support platforms, social media, and other third parties. We are not responsible for their privacy, security, data handling, content, or practices. Review their policies before using them.

20. Changes to This Privacy Policy

We may update this Policy to reflect changes to the Service, integrations, data practices, vendors, laws, regulatory guidance, security practices, or business operations. If we make material changes, we will provide notice through the website, Telegram Mini App, Telegram bot, dashboard, email, or another reasonable method before the change takes effect where required by law. The effective date shows when this Policy was last updated.

21. Contact Us

ALGOTITAN INFORMATION CONSULTANCY - FZCO. Privacy contact: info@algotitan.io. General support: info@algotitan.io. In-app privacy requests: @algotitan_support. Registered address: IFZA Business Park, DDP Premises No. 77414-001, Dubai Silicon Oasis, Dubai, United Arab Emirates.

22. Short-Form Privacy Notice for Website or Mini App Footer

Algotitan processes personal data to provide account access, Telegram Mini App functionality, paper trading, subscriptions, exchange integrations, user-authorized trade-only API-based automated execution, support, security, compliance, analytics, and product improvement. We collect account data, Telegram identifiers, exchange/API metadata, trading and account activity made available through integrations, payment and subscription data, device and usage data, cookies, support communications, compliance data, and marketing preferences. We share data with service providers, exchanges, Telegram and platform providers, payment processors, analytics tools, compliance vendors, affiliates, advisors, and authorities where required. Privacy rights and transfer rules vary by jurisdiction. Contact info@algotitan.io or @algotitan_support in Telegram.

Verified Broker on
Binance
Bybit
Bitget
BingX
OKX
WEEX
GATE.IO
KUCOIN

© 2026 AlgoTitan. All rights reserved.

Cryptocurrency trading involves significant risk.

Automated Crypto Trading Platform

Automated crypto futures with real strategies and risk control.

Navigation

  • Home
  • Strategies
  • App
  • Pricing
  • Exchange Guide
  • About US

Resources

  • About US
  • Blog
  • Contact

Information

  • Privacy Policy
  • Terms of Use