Privacy Policy
Effective date: 6 September 2026 · Version 1.0
In plain words. We process the data needed to run the Service: who you are (name, e-mail), what your terminals report (account number, balances, positions, orders, trade history, running robots) and what you ask the assistant. We never receive your trading or investor passwords. We do not sell data and we do not run advertising trackers. Your chat messages are processed by an AI provider to produce answers. You can ask us what we hold about you and have it corrected or deleted.
1. Who is responsible
The data controller is MTCodec JSC, Georgia ("MTCodec", "we"). Contact for privacy matters: privacy@algohand.com. Where a business customer (for example a broker or platform) integrates the Service into its own application, that customer is the controller of its end users' data and MTCodec acts as its processor under a data processing agreement; this Policy then describes our processing on the customer's behalf.
2. What we process, why, and on which legal basis
| Data | Where it comes from | Purpose | Legal basis (GDPR, where applicable) |
|---|---|---|---|
| Name, e-mail, company, message you type into a form | Website forms (demo access, business enquiry, early access, EA author application) | Answer your request, send access codes, keep in touch about the Service | Legitimate interest in responding to enquiries; consent where you opt in to updates |
| Account and access data: e-mail, access codes, API keys, enrolment tokens, plan, billing status | You, or the business customer that onboards you | Provide and secure the Service, billing | Performance of a contract |
| Terminal state reported by the Agent: MetaTrader account number and server, broker name, account currency and leverage, balance, equity, margin, floating P&L, open positions and pending orders, closed deals (times, symbols, volumes, prices, profits, magic numbers, comments), running EAs and their settings, chart list, terminal build, connection and AutoTrading status | The Agent on your VPS, from files written by our manager component inside your terminals | Show you the state of your accounts and robots, execute and verify your commands, compute equity curves and performance breakdowns, keep robots running after restarts | Performance of a contract |
| VPS technical data: hostname, operating system, CPU/memory/disk usage, uptime, Agent version, install paths, a machine fingerprint (a hash derived from machine identifiers, used to bind the Agent's credentials to that machine), the VPS's public IP address | The Agent | Operate, secure and update the Agent; detect a copied or moved installation | Performance of a contract; legitimate interest in security |
| Commands: what was requested, by whom, when, the resulting changes and what the terminal reported afterwards | You, the assistant on your instruction, or a business customer's application | Execute commands, show outcomes, provide an audit trail | Performance of a contract; legitimate interest in accountability |
| Chat messages and the assistant's replies | You, in the chat | Understand your request, look up your robots and settings, propose and explain actions | Performance of a contract |
| Server logs: IP address, request path, timestamps, user agent, errors | Your browser, the Agent, API clients | Security, abuse prevention, troubleshooting | Legitimate interest in security and reliability |
| Payment data: plan, amounts, invoices, country, VAT status. Card details are handled by the payment provider and never reach us. | You, via the payment provider | Billing, tax compliance | Performance of a contract; legal obligation |
What we deliberately do not collect: trading passwords, investor passwords, master passwords or any other MetaTrader credentials; card numbers; contents of your VPS beyond the MetaTrader state described above.
3. AI processing
To answer you, the chat sends your messages, the assistant's tool results (state of your robots and accounts) and the conversation context to an AI model provider. Currently this is Anthropic, PBC (USA), through its API, under terms that prohibit the provider from training models on this data. The provider may retain data for a limited period to enforce its usage policies. We do not send your messages to any other AI provider without updating this Policy. Business customers that use their own AI assistant with our API are responsible for their own AI provider.
4. Who receives data
We share data only with providers that help us run the Service, under contracts that restrict them to our instructions, and where the law requires:
- Hosting: Contabo GmbH (Germany) — our servers and database are located in the European Union.
- DNS, TLS and e-mail routing: Cloudflare, Inc. (USA/EU) — network services for algohand.com; e-mail to @algohand.com addresses is forwarded through Cloudflare.
- AI: Anthropic, PBC (USA) — see section 3.
- Payments: a payment provider acting as merchant of record (to be named at the point of purchase) — handles card data, invoices and tax.
- Fonts and libraries: the website loads fonts from Google Fonts and scripts from the cdnjs content delivery network (Cloudflare); when your browser loads them, your IP address is disclosed to those providers.
- Business customers: if you use the Service through a broker or platform, that customer sees the state of your accounts and robots and your commands, because it provides the Service to you.
- Authorities: where required by law, court order or to protect rights, safety or property.
- Business transfer: a successor of our business, with notice to you.
We do not sell personal data and do not use it for third-party advertising.
5. International transfers
Our servers are in the European Union. Some providers (Anthropic, Cloudflare, Google) process data in the United States or other countries. Where the GDPR applies, such transfers rely on the European Commission's adequacy decisions (including the EU–US Data Privacy Framework where the provider is certified) or on standard contractual clauses.
6. How long we keep data
- Terminal state samples (balance/equity per minute): 90 days.
- Trade history, commands and audit trail: while your account is active and for 12 months after it ends, unless you ask for earlier deletion or the law requires longer retention (for example for invoices).
- Chat sessions: kept for the duration of the session on our servers; the AI provider's retention is described in section 3.
- Website enquiries: up to 24 months after the last contact.
- Server logs: 30 days.
- Billing records: as required by tax law (typically 6 years).
7. Cookies and local storage
The website does not use advertising or analytics cookies. The chat stores your access code and a session identifier in your browser's local storage so that you do not have to re-enter them; you can clear them with the "Change access code" button or by clearing site data in your browser. Necessary technical cookies may be set by our providers (for example by Cloudflare for security).
8. Security
The Agent communicates only outbound over TLS to our servers and verifies our certificate against a private certificate authority; no inbound ports are opened on your VPS. Agent credentials are stored encrypted and bound to the machine. Access to production systems is limited to authorised staff with key-based authentication. Data is backed up daily. No system is perfectly secure; if we learn of a breach affecting your data we will inform you and, where required, the supervisory authority without undue delay.
9. Your rights
Depending on your country, you may have the right to access the personal data we hold about you, to have it corrected or deleted, to restrict or object to processing, to receive it in a portable format, and to withdraw consent where processing is based on consent. Write to privacy@algohand.com; we answer within one month. You may also complain to a supervisory authority: in Georgia, the Personal Data Protection Service; in the EU/EEA, the data protection authority of your country; in the UK, the Information Commissioner's Office.
10. Children
The Service is not intended for persons under 18 and we do not knowingly collect their data.
11. Changes
We may update this Policy. Material changes will be announced on the website or by e-mail at least 14 days before they take effect. The version and effective date are shown at the top.
12. Contact
MTCodec JSC, Georgia · privacy@algohand.com · info@mtcodec.com
See also: Terms of Service · Risk Disclosure