Effective date: 22 June 2026
This Privacy Policy explains how Algotitan collects, uses, discloses, stores, transfers, and protects personal data when you access or use our website, Telegram bot, Telegram Mini App, dashboards, software, APIs, paper-trading environment, automated execution tools, support channels, marketing channels, and related services (collectively, the "Service").
The Service lets eligible users test preset strategy behavior in paper trading, connect supported exchange accounts using API connectivity, subscribe to paid plans, and activate user-authorized automated order instructions in the user's own exchange account. Algotitan does not custody user assets and does not request seed phrases, private keys, wallet recovery phrases, or withdrawal-enabled API credentials.
This Policy does not govern personal data processed by Telegram, exchanges, payment processors, wallet providers, advertising platforms, or other third parties under their own privacy policies, except where they process data for Algotitan as our processors or service providers.
For most processing described in this Policy, Algotitan is the controller, data controller, personal data controller, or equivalent role under applicable privacy law. This means that we decide why and how personal data is processed for the Service.
Where we process personal data for an institutional customer or other controller under a separate written agreement, we may act as a processor or service provider for the limited activities described in that agreement. If local law requires a data protection officer, local representative, or another designated privacy contact, we will identify that person or entity in the applicable regional notice.
We collect only the data reasonably necessary for the Service, security, legal compliance, support, and the other purposes in this Policy. The exact data collected depends on the features you use, permissions you grant, and information you provide.
Where legally required or reasonably necessary for eligibility, fraud prevention, security, or compliance, we may collect legal name, date of birth, nationality, citizenship, residence, address, tax-related information, government identification details, proof of address, beneficial ownership information, sanctions or PEP screening results, source-of-funds or source-of-wealth information, geolocation signals, risk flags, investigation notes, and documents or certifications you provide. We do not collect these categories for every user.
We process personal data only when an applicable law permits us to do so. The legal grounds vary by jurisdiction. Where GDPR-like law applies, the table below identifies the main grounds. Under laws that use different terminology, including UAE law, we rely on the corresponding statutory ground, such as consent, a request by you to enter into or perform a contract, a legal obligation, or another basis recognized by the applicable law.
| Purpose | Main data categories | Main legal grounds where GDPR-like law applies |
|---|---|---|
| Create and administer accounts, trials, subscriptions, and service communications | Account, Telegram, profile, payment and support data | Contract performance; steps at your request; legal obligation where relevant. |
| Deliver paper trading, exchange connectivity, dashboards, alerts, and user-authorized order instructions | Exchange/API, strategy, account, trading, and device data | Contract performance; explicit action/authorization by you; legitimate interests for service integrity where permitted. |
| Prevent fraud, misuse, unauthorized access, and security incidents | Device, security, account, API, payment, and compliance data | Legitimate interests where permitted; legal obligation; consent or another statutory ground where required. |
| Meet legal, sanctions, AML/CFT, tax, audit, recordkeeping, and dispute obligations | Compliance, identity, payment, account, and transaction data | Legal obligation; establishment, exercise, or defense of legal claims; other statutory grounds where applicable. |
| Improve the Service and measure product performance | Usage, analytics, diagnostics, support, and aggregated data | Legitimate interests where permitted; consent where required for non-essential cookies or similar technologies. |
| Send marketing and measure campaigns | Contact, preference, campaign, and cookie data | Consent or another permission expressly allowed by applicable law. You can opt out at any time. |
We may process identity, sanctions, PEP, source-of-funds, source-of-wealth, and related compliance data only where necessary and permitted by law. If data is treated as sensitive or special-category data under an applicable law, we will process it only with explicit consent or another valid legal condition available under that law. We do not use compliance data to make investment-suitability recommendations.
When you connect an exchange account, you instruct us to process the data needed to provide the connected features. This may include API credential references, encrypted secrets, token references, permission metadata, account and trading activity, balances, orders, fills, strategy status, execution logs, and diagnostics.
The Service is designed to operate with trade-only API permissions. We do not ask for seed phrases, private keys, wallet recovery phrases, or withdrawal-enabled API credentials. Where a supported exchange or integration makes permission information available, we may review that information and may warn you, refuse connection, restrict features, or disconnect the integration if withdrawal, custody, or other permissions appear broader than approved. Such controls depend on the information made available by the exchange or integration and may not detect every issue. You remain responsible for reviewing exchange-side permissions and revoking access when appropriate.
Your exchange is a separate controller or independent service provider for personal data it processes under its own terms and privacy notice. Algotitan does not control exchange privacy practices, cybersecurity, API behavior, execution, or retention.
We and our service providers use cookies, pixels, SDKs, local storage, device identifiers, and similar technologies for authentication, session management, security, fraud prevention, remembering preferences, analytics, performance measurement, marketing attribution, and product improvement.
Where consent is required, we will not place or read non-essential cookies or similar technologies before you give consent through a cookie banner or settings center. You can change choices through the settings center, browser controls, device settings, or other tools we provide. The settings center will identify the applicable provider, technology, purpose, and duration. Disabling essential technologies may affect Service functionality.
We do not sell personal data for money. We do not disclose personal data for cross-context behavioral advertising unless we provide any notice, consent, or opt-out mechanism required by applicable law.
We may share data with providers of cloud hosting, storage, authentication, cybersecurity, monitoring, analytics, customer support, communications, CRM, billing, payments, fraud prevention, compliance screening, identity verification, logging, and development operations. Where required, these providers process data under written terms requiring appropriate privacy and security safeguards.
We may share data with exchanges, API orchestration providers, order-routing or monitoring partners, market-data providers, notification providers, webhook providers, Telegram, and other platform providers as needed to deliver the Service you request or activate. These organizations may act as independent controllers for their own services.
We may disclose data to affiliates, auditors, legal counsel, consultants, insurers, and transaction counterparties for internal administration, security, finance, legal claims, financing, merger, acquisition, restructuring, asset sale, insolvency, or business transfer. We may disclose data to regulators, courts, law enforcement, tax authorities, sanctions authorities, exchanges, payment processors, or other parties where necessary to comply with law, respond to a lawful request, enforce agreements, investigate fraud or abuse, or protect rights and safety.
We may share data when you request or authorize sharing, connect an integration, participate in a referral or promotion, or otherwise consent.
Algotitan is established in the UAE and may process personal data in the UAE and other countries where our affiliates, vendors, exchanges, payment processors, support teams, or infrastructure providers operate. Those countries may have data-protection laws different from those in your country.
Where applicable law requires a transfer mechanism or additional protection, we will use the mechanism required for the relevant transfer, which may include an adequacy decision, standard contractual clauses or standard contracts, contractual safeguards with enforceable data-subject rights, a transfer impact assessment, encryption, access controls, data minimization, localization measures, or a narrow statutory derogation. You may request information about applicable safeguards by contacting us, subject to confidentiality and security restrictions.
Exchange integrations, Telegram, payment providers, and other independent third parties may conduct their own international transfers under their own policies. Review their notices before using their services.
We retain personal data only for as long as reasonably necessary for the purposes in this Policy, unless a longer period is required or permitted for legal, tax, accounting, security, fraud, audit, or claims purposes. The following periods are the standard operational periods, subject to legal holds, backup cycles, and mandatory retention obligations.
| Data category | Standard retention period |
|---|---|
| Account and profile data | Life of the account plus 90 days after closure, unless earlier deletion is required or longer retention is necessary for law, security, fraud prevention, or a claim. |
| API credentials and token materials | While the connection is active. After disconnection or account closure, active use is disabled promptly and credential materials are deleted or rendered unusable within 30 days, unless necessary for a security incident, dispute, or legal obligation. |
| Exchange, order-instruction, execution, and strategy logs | Up to 5 years after the later of account closure or the relevant execution event, unless a longer period is necessary for law, audit, fraud prevention, or a claim. |
| Subscription, invoice, payment, tax, and accounting records | Up to 7 years after the relevant financial period, or longer where applicable law requires. |
| Security, fraud, compliance, sanctions, and abuse records | Up to 5 years after the relevant event or closure, unless a longer period is legally necessary. |
| Support communications | Up to 3 years after resolution of the request, unless retained longer for a dispute, security incident, or legal obligation. |
| Raw product analytics and diagnostics | Up to 25 months, then deleted, aggregated, or de-identified where reasonably practicable. |
| Marketing preferences and suppression records | Until you withdraw consent or opt out, and thereafter up to 3 years to honor and evidence the opt-out. |
We may delete, anonymize, aggregate, or de-identify data when it is no longer required, subject to backup cycles, technical limitations, legal holds, security needs, and mandatory retention obligations.
We use administrative, technical, and organizational measures designed to protect personal data, including access restrictions, role-based access, encryption in transit, encryption at rest where appropriate, credential-protection controls, logging, monitoring, network security, vulnerability management, environment segregation, incident-response procedures, vendor due diligence, and workforce confidentiality obligations.
No system is completely secure. Internet-based services, Telegram, APIs, cloud systems, exchanges, and digital-asset markets involve inherent risks. You are responsible for securing your devices, Telegram account, email account, exchange account, API credentials, passwords, and authentication tools, and for notifying us promptly of suspected unauthorized access.
If we become aware of a personal-data breach requiring notification under applicable law, we will notify the competent authority and/or affected individuals within the required timeframe and in the required manner. We may also notify exchanges, payment providers, Telegram, vendors, law enforcement, or other parties where appropriate to investigate, mitigate, or prevent harm.
Depending on applicable law, you may have rights to request access, confirmation of processing, correction, deletion, erasure, anonymization, restriction, blocking, portability, objection, withdrawal of consent, opt-out of direct marketing, opt-out of certain sale, sharing, or targeted-advertising activities, human review of certain automated decisions, and a complaint to a supervisory authority.
To make a request, email info@algotitan.io with the subject line "Privacy Request" and include your name, account email or Telegram username, country of residence, request type, and supporting details. We may request information needed to verify identity and locate the relevant records. We will respond within the timeframe required by applicable law. For example, where GDPR applies, the usual period is one month, subject to any lawful extension; where Türkiye's personal-data law applies, we will respond within the applicable statutory period, generally no later than 30 days.
These rights are not absolute. We may refuse, limit, or delay a request where permitted by law, including where identity cannot be verified, retention is legally required, data is needed for security, fraud prevention, or legal claims, the request is manifestly unfounded or excessive, or fulfilling it would adversely affect others' rights and freedoms.
Where permitted by law and based on the appropriate permission, we may send onboarding messages, service updates, educational content, newsletters, offers, product announcements, event invitations, and marketing communications. You may opt out of non-essential marketing at any time using an unsubscribe link, in-app settings, Telegram controls where available, or by contacting us.
We may still send transactional or service-related messages, including security alerts, billing notices, legal updates, exchange-connectivity notices, and critical Service communications.
Automated processing is core to the Service. It includes paper-trading simulations, strategy deployment after user activation, exchange synchronization, order-instruction generation and transmission, notification triggers, risk-profile handling within the user-selected Service flow, fraud monitoring, security monitoring, and compliance screening.
We do not use personal data to provide individualized investment suitability advice or to promise a trading outcome. Automated security or compliance signals may lead to account restrictions or further review. Where applicable law gives you rights relating to a solely automated decision with legal or similarly significant effects, you may contact us to request information, contest the decision, and seek human review where required by law.
The Service is not intended for children or minors. We do not knowingly collect personal data from anyone under 18 or under the age of legal majority in the relevant jurisdiction, whichever is higher. If we learn that we have collected personal data from a minor in violation of applicable law, we may delete the data, suspend the account, disable features, and take other appropriate steps.
UAE: Where UAE data-protection law applies, we process personal data in accordance with applicable controller and processor obligations, data-subject rights, security duties, breach-notification duties, and any applicable impact-assessment or officer requirements.
Türkiye: For users in Türkiye, a Turkish-language privacy notice provided at or before collection supplements this Policy. That notice will identify the required purposes, recipient groups, collection methods, legal grounds, rights, and applicable cross-border transfer safeguards. If there is a conflict, the Turkish notice controls to the extent required by Turkish law.
EEA/UK: At the Effective Date, Algotitan does not offer the Service, including account registration, paper-trading trials, paid subscriptions, exchange connectivity, or live execution, to persons located in or ordinarily resident in the EEA or the United Kingdom. Algotitan does not intentionally target those persons through paid advertising, direct marketing, influencer or referral campaigns, or country-specific sales flows. We may process limited technical data from visits to a public website page for security, fraud prevention, location detection, and enforcement of this restriction, but this does not make the Service available. If Algotitan later offers the Service there or intentionally monitors behavior there, it will implement the applicable transparency, transfer, cookie, representative, and other requirements before doing so.
Other markets: If a law in a market imposes localization, registration, notice, consent, local-representative, transfer, security, breach-notification, or other requirements, we may provide a supplemental notice, implement additional measures, restrict features, or decline service until legal clearance is complete.
If this Policy conflicts with mandatory law that applies to you, mandatory law governs to the extent of the conflict.
The Service may link to or integrate with exchanges, Telegram, wallets, payment processors, analytics services, support platforms, social media, and other third parties. We are not responsible for their privacy, security, data handling, content, or practices. Review their policies before using them.
We may update this Policy to reflect changes to the Service, integrations, data practices, vendors, laws, regulatory guidance, security practices, or business operations. If we make material changes, we will provide notice through the website, Telegram Mini App, Telegram bot, dashboard, email, or another reasonable method before the change takes effect where required by law. The effective date shows when this Policy was last updated.
ALGOTITAN INFORMATION CONSULTANCY - FZCO. Privacy contact: info@algotitan.io. General support: info@algotitan.io. In-app privacy requests: @algotitan_support. Registered address: IFZA Business Park, DDP Premises No. 77414-001, Dubai Silicon Oasis, Dubai, United Arab Emirates.
Algotitan processes personal data to provide account access, Telegram Mini App functionality, paper trading, subscriptions, exchange integrations, user-authorized trade-only API-based automated execution, support, security, compliance, analytics, and product improvement. We collect account data, Telegram identifiers, exchange/API metadata, trading and account activity made available through integrations, payment and subscription data, device and usage data, cookies, support communications, compliance data, and marketing preferences. We share data with service providers, exchanges, Telegram and platform providers, payment processors, analytics tools, compliance vendors, affiliates, advisors, and authorities where required. Privacy rights and transfer rules vary by jurisdiction. Contact info@algotitan.io or @algotitan_support in Telegram.