Effective date: 22 June 2026
Controller / Company: ALGOTITAN INFORMATION CONSULTANCY - FZCO
Effective date: 01.06.2026
Privacy contact: info@algotitan.io
General contact: info@algotitan.io
Registered address: IFZA Business Park, DDP Premises No. 77414 - 001 Dubai Silicon Oasis, Dubai, United Arab Emirates, 00000, Dubai, U.A.E.
This Privacy Policy explains how Algotitan collects, uses, discloses, stores, transfers, and protects personal data when you access or use our website, Telegram bot, Telegram Mini App, dashboards, software, APIs, paper-trading environment, automated execution tools, support channels, marketing channels, and related services (collectively, the "Service").
The Service enables eligible users to test preset automated execution strategies in a paper-trading environment, connect supported exchange accounts using API connectivity, subscribe to paid plans, and activate automated order instructions in the user's own exchange account. Algotitan does not custody user assets and does not ask for seed phrases, private keys, wallet recovery phrases, or withdrawal-enabled API credentials.
This Privacy Policy does not apply to personal data processed by Telegram, cryptocurrency exchanges, payment processors, analytics providers, wallet providers, identity-verification vendors, advertising platforms, or other third parties under their own privacy notices, except to the extent they process personal data for Algotitan as our processors or service providers.
For most processing described in this Privacy Policy, Algotitan acts as the controller, data controller, personal data controller, or equivalent role under applicable privacy law. Where we process personal data on behalf of a partner, institutional customer, enterprise client, or other controller under a separate agreement, we may act as a processor, service provider, or equivalent role for limited processing activities.
If local law requires appointment of a data protection officer, local representative, data protection contact, or similar role, we will identify the relevant contact in this Privacy Policy, a supplemental notice, or an in-product notice.
full name, username, email address, phone number, country or region, language, timezone, referral code, account status, onboarding status, and authentication data;
Telegram user ID, Telegram username, display name, profile information made available through Telegram, chat ID, bot interaction data, Mini App session identifiers, Mini App initialization data, language settings, and interaction timestamps;
account settings, subscription status, plan type, notification preferences, support preferences, and consent records.
Where legally required or operationally necessary, we may collect legal name, date of birth, nationality, citizenship, residence, address, tax-related information, government identification details, proof of address, beneficial ownership information, sanctions screening results, PEP screening results, source-of-funds/source-of-wealth information, geolocation signals, risk flags, investigation notes, and documents or certifications you provide.
exchange name, exchange account identifiers, subaccount identifiers, linked account status, connection timestamps, permissions metadata, API key labels, masked API identifiers, encrypted API secrets or token references, token refresh/revocation status, authentication events, API usage logs, diagnostics, error logs, and permission-failure messages;
whether withdrawal permissions appear to be enabled or disabled, where this information is made available through the exchange or integration layer;
exchange balances, positions, open orders, executed orders, fills, order history, trade timestamps, instrument or pair selections, account valuation data, margin or derivatives status, strategy execution logs, profit/loss metrics, and account activity needed to provide, secure, monitor, troubleshoot, and improve the Service, subject to the permissions you grant and the exchange's capabilities.
We may collect selected risk level, selected strategy, paper-trading activity, backtesting activity, strategy activation/pause/switch instructions, capital allocation settings available in the interface, watchlist or asset preferences, alerts, notifications, feature interactions, page views, clicks, scrolls, session activity, referral attribution, campaign data, and support interactions.
We may collect plan details, billing country, billing address, invoice data, payment status, payment processor customer ID, transaction identifiers, renewal dates, chargeback records, refund or credit records, taxes, and collection records. We generally do not store full payment card numbers unless expressly stated at the point of collection.
We may collect IP address, device identifiers, browser type, operating system, mobile device model, app version, language, timezone, log files, crash reports, diagnostic data, performance metrics, session IDs, cookies, pixels, SDK data, local storage identifiers, device reputation signals, duplicate-account indicators, and fraud/security signals.
If you contact us or interact with our channels, we may collect support tickets, emails, chat records, Telegram messages you send to our bot or support channels, screenshots, attachments, diagnostic files, feedback, survey responses, complaints, and call recordings or transcripts where permitted.
directly from you when you register, use the Mini App, start a trial, subscribe, connect an exchange, activate a strategy, contact support, or respond to surveys;
automatically from your device, browser, Telegram session, cookies, logs, and security tools;
from Telegram, to the extent Telegram makes Mini App or bot interaction data available to us;
from exchanges and integration providers when you authorize connectivity;
from payment processors and billing partners for subscription administration;
from identity, fraud, sanctions, and compliance vendors where applicable;
from affiliates, referral partners, marketing partners, and service providers where lawful; and
from public or legally available sources, including sanctions lists, court records, public blockchain data, internet sources, or regulator notices where relevant and lawful.
Account administration: create and manage accounts, authenticate users, verify account ownership, maintain settings, administer trials and subscriptions, and send service communications.
Service delivery: connect exchanges, verify API permissions, operate paper trading, deploy strategies you activate, transmit authorized order instructions, calculate metrics, deliver dashboards and alerts, synchronize account data, troubleshoot connectivity, and manage strategy status.
Billing and commercial operations: process payments, renewals, invoices, taxes, refunds, chargebacks, collections, promotions, and plan changes.
Security and fraud prevention: secure accounts, credentials, integrations, systems, and APIs; detect unauthorized access, suspicious activity, abuse, malware, credential misuse, fraud, sanctions exposure, and payment risk.
Compliance and legal obligations: perform legal, regulatory, sanctions, AML/CFT, tax, consumer-protection, recordkeeping, audit, dispute, law-enforcement, regulator-response, and legal-claim activities.
Support: respond to requests, verify identity, investigate bugs and incidents, resolve complaints, and improve support quality.
Analytics and product improvement: understand feature usage, assess onboarding, measure conversion, evaluate exchange reliability, improve strategy-monitoring flows, build aggregated insights, and improve performance and security.
Marketing: send product updates, educational materials, newsletters, offers, event invitations, and retargeting or attribution communications where permitted by law and your preferences.
Depending on your location and the applicable privacy law, we rely on one or more of the following legal bases:
performance of a contract or steps requested before entering into a contract, including account creation, paper trading, subscription management, exchange connectivity, and strategy execution you activate;
legitimate interests, including securing the Service, preventing fraud, improving functionality, analyzing product usage, enforcing terms, responding to incidents, and protecting Algotitan, users, exchanges, and third parties;
legal obligations, including tax, accounting, sanctions, AML/CFT, fraud prevention, regulatory, court, law-enforcement, and recordkeeping obligations;
consent, where required for marketing, cookies, cross-border transfers, sensitive data, certain automated processing, or other activities under applicable law;
establishment, exercise, or defense of legal claims; and
vital interests or public interest where recognized by applicable law and relevant to security or legal compliance.
Where local law requires a specific notice, consent, transfer mechanism, data localization measure, or additional disclosure, we may provide supplemental regional notices or in-product consents.
When you connect an exchange account, you instruct us to process the data required to provide the connected features. This may include API credential references, encrypted secrets, token references, permissions metadata, account and trading activity, balances, orders, fills, strategy status, execution logs, and related diagnostics.
The Service is designed to operate with trade-only API permissions. We do not ask for seed phrases, private keys, wallet recovery phrases, or withdrawal-enabled API credentials. If withdrawal permissions appear to be enabled, we may warn you, refuse connection, restrict features, or disconnect the integration. You remain responsible for reviewing exchange-side permissions and revoking access when appropriate.
Your exchange is a separate controller or independent service provider for data it processes under its own terms and privacy notice. Algotitan does not control exchange privacy practices, exchange cybersecurity, exchange API behavior, exchange execution, or exchange data retention.
We and our service providers may use cookies, pixels, SDKs, local storage, device identifiers, and similar technologies for authentication, session management, security, fraud prevention, remembering preferences, analytics, performance measurement, marketing attribution, and product improvement.
Where required by law, we will request consent for non-essential cookies or similar technologies. You may manage choices through our cookie banner, settings center, browser controls, device settings, or other tools we provide. Disabling some technologies may affect Service functionality.
We may share data with providers of cloud hosting, storage, authentication, cybersecurity, monitoring, analytics, customer support, communications, CRM, billing, payments, fraud prevention, compliance screening, identity verification, logging, and development operations, subject to appropriate contractual and security safeguards where required.
We may share data with exchanges, API orchestration providers, order-routing or monitoring partners, market data providers, notification providers, and webhook providers as needed to provide the Service you activate.
If you use the Service through Telegram, certain identifiers, interaction data, and technical data may be exchanged with Telegram or processed through Telegram's platform. Telegram processes data under its own policies and terms. We are not responsible for Telegram's independent data practices.
We may disclose data to affiliates, auditors, legal counsel, consultants, insurers, and transaction counterparties in connection with internal administration, security, finance, legal claims, financing, merger, acquisition, restructuring, asset sale, insolvency, or business transfer, subject to appropriate safeguards.
We may disclose data to regulators, courts, law enforcement, tax authorities, sanctions authorities, exchanges, payment processors, or other parties if we believe disclosure is necessary to comply with law, respond to lawful requests, enforce agreements, investigate fraud or abuse, protect rights and safety, or preserve the integrity of the Service.
We may share data when you request or authorize sharing, connect an integration, participate in a referral or promotion, or otherwise consent.
We do not sell personal data in the ordinary meaning of that phrase. If a jurisdiction defines "sale," "sharing," or targeted advertising more broadly, we will provide any required notice or opt-out mechanism where applicable.
Algotitan is established in the UAE and may process personal data in the UAE and other countries where we, our affiliates, vendors, exchanges, payment processors, support teams, or infrastructure providers operate. These countries may have data protection laws that differ from those in your country.
Where required by applicable law, we will take steps intended to support lawful international transfers, which may include contractual safeguards, standard contractual clauses or standard contracts where available, transfer impact assessments, access controls, encryption, data minimization, consent mechanisms, localization measures, and supplemental regional notices.
Your use of exchange integrations may independently involve international transfers by the exchange, payment provider, Telegram, or other third parties under their own policies and systems.
We retain personal data for as long as reasonably necessary for the purposes described in this Privacy Policy, including to provide the Service, maintain accounts, process subscriptions, secure systems, investigate incidents, resolve disputes, comply with tax/accounting/legal/regulatory obligations, enforce agreements, and establish, exercise, or defend legal claims.
| Data category | Typical retention approach |
|---|---|
| Account and profile data | For the life of the account and a reasonable period after closure, unless earlier deletion is required or longer retention is legally necessary. |
| Subscription, invoice, payment, tax, and accounting records | For the legally required tax, accounting, audit, and commercial recordkeeping period. |
| API connection metadata and execution logs | For as long as needed to provide the Service, investigate incidents, support users, resolve disputes, comply with law, and preserve audit trails. |
| Security, fraud, compliance, sanctions, and abuse records | For as long as needed to protect the Service, comply with law, prevent abuse, and defend legal claims. |
| Support communications | For as long as needed to resolve the matter, improve support, maintain records, and defend claims. |
| Marketing preferences and suppression records | Until you change preferences or as needed to honor opt-outs and legal obligations. |
We may delete, anonymize, aggregate, or de-identify data when it is no longer required, subject to backup cycles, technical limitations, legal holds, security needs, and mandatory retention obligations.
We use administrative, technical, and organizational measures designed to protect personal data, including encryption in transit, encryption at rest where appropriate, credential protection controls, access restrictions, role-based access, logging, monitoring, network security, vulnerability management, environment segregation, incident response procedures, vendor due diligence, and workforce confidentiality obligations.
No system is completely secure. Internet-based services, Telegram, APIs, cloud systems, third-party exchanges, and digital asset markets involve inherent risks. You are responsible for securing your devices, Telegram account, email account, exchange account, API credentials, passwords, and authentication tools, and for promptly notifying us of suspected unauthorized access.
If we become aware of a personal data breach that requires notification under applicable law, we will notify the competent authority and/or affected individuals within the timeframe and in the manner required by applicable law. We may also notify exchanges, payment providers, Telegram, vendors, law enforcement, or other parties where appropriate to investigate, mitigate, or prevent harm.
Depending on applicable law, you may have rights to request access, confirmation of processing, correction, deletion, erasure, anonymization, restriction, blocking, portability, objection, withdrawal of consent, opt-out of direct marketing, opt-out of certain sale/share/targeted advertising activities, human review of certain automated decisions, and complaint to a supervisory authority.
These rights are not absolute. We may refuse, limit, or delay a request where permitted by law, including where we cannot verify identity, retention is legally required, data is needed for security/fraud/legal claims, the request is excessive or unfounded, or fulfilling the request would affect the rights of others.
To submit a request, contact info@algotitan.io with your name, account email or Telegram username, country of residence, request type, and supporting details. We may ask for information to verify identity and locate the relevant records. We will respond within the timeframe required by applicable law or, where no specific deadline applies, within a reasonable period.
Where permitted by law, we may send service updates, onboarding messages, educational content, newsletters, offers, product announcements, event invitations, and marketing communications. You may opt out of non-essential marketing at any time using the unsubscribe link, in-app settings, Telegram controls where available, or by contacting us. We may still send transactional or service-related messages, such as security alerts, billing notices, legal updates, exchange connectivity notices, and critical Service communications.
Automated processing is core to the Service. This includes paper-trading simulations, strategy deployment after user activation, exchange synchronization, order-instruction generation and transmission, notification triggers, risk-profile handling within the user-selected Service flow, fraud monitoring, security monitoring, and compliance screening.
The Service does not create a promise of trading outcomes, profitability, loss limitation, or uninterrupted execution. Where applicable law gives you rights relating to automated decisions with legal or similarly significant effects, you may contact us to request information, contest the decision, or seek human review where required by law.
The Service is not intended for children or minors. We do not knowingly collect personal data from anyone under 18 or under the age of legal majority in the relevant jurisdiction, whichever is higher. If we learn that we have collected personal data from a minor in violation of applicable law, we may delete the data, suspend the account, disable features, and take other appropriate steps.
Where UAE data protection law applies, we process personal data in accordance with applicable controller and processor obligations, data subject rights, security duties, breach notification duties, and any applicable data protection officer or impact assessment requirements.
Where Turkiye's Law No. 6698 and related guidance apply, additional notice, explicit consent, special-category data, data controller registry, retention, cross-border transfer, standard contract, and data subject rights requirements may apply. We may provide a Turkiye-specific notice or consent mechanism where required.
If laws in CIS or other markets impose localization, registration, notice, consent, local representative, transfer, security, breach notification, or other requirements, we may implement supplemental measures, restrict features, or decline service in that market until legal clearance is complete.
If we offer goods or services to individuals in the EU/UK or monitor behavior there, additional obligations may apply, including transparency requirements, legal bases, data subject rights, cookie consent, transfer safeguards, and representative/DPO requirements where applicable. We may provide supplemental notices or restrict access as needed.
If this Privacy Policy conflicts with mandatory law that applies to you, the mandatory law governs to the extent of the conflict.
The Service may link to or integrate with exchanges, Telegram, wallets, payment processors, analytics services, support platforms, social media, and other third parties. We are not responsible for their privacy, security, data handling, content, or practices. Review their policies before using them.
We may update this Privacy Policy to reflect changes to the Service, integrations, data practices, vendors, laws, regulatory guidance, security practices, or business operations. If we make material changes, we may notify you through the website, Telegram Mini App, Telegram bot, dashboard, email, or other reasonable means. The effective date shows when this Privacy Policy was last updated.
ALGOTITAN INFORMATION CONSULTANCY - FZCO
Privacy contact: info@algotitan.io
General support: info@algotitan.io
Registered address: IFZA Business Park, DDP Premises No. 77414 - 001 Dubai Silicon Oasis, Dubai, United Arab Emirates, 00000, Dubai, U.A.E.
In-app privacy requests: @algotitan_support