Privacy Policy

    Version 1.0 • Effective 2025-09-06

    Explains what personal and sensitive data Algovested collects, how it is used (execution of trades, compliance, analytics), how it is secured, shared, and the rights data principals have under the DPDP Act.

    Key Points

    What we collect (examples)

    • Account and contact information (name, email, phone)
    • Broker identifiers and account numbers (for mapping and reconciliation)
    • Encrypted API credentials / OAuth tokens (stored encrypted; used only to execute trades) — treated as 'sensitive data'
    • Transaction history, balances, holdings, order logs and execution reports
    • Device identifiers, IP addresses, telemetry and logs for security and compliance

    How we use credentials (explicit consent & zero-knowledge statement)

    • You provide API credentials or authorize OAuth. Algovested stores them encrypted using a KMS/HSM system; in normal operations Algovested personnel do not have access to plaintext.
    • You expressly authorize Algovested to use the encrypted credentials to place orders, query balances & holdings, and receive confirmations.
    • If decryption is required for incident response, such actions are logged, limited to authorized personnel, and subject to dual-authorization controls.

    Automated decisions (profiling and algorithmic trading disclosure)

    • Automated trading decisions made by your chosen algos will occur without human intervention unless you select a managed/human-review option.
    • You will be shown (at onboarding) a clear summary of algorithm behavior and risk parameters; black-box algos come with additional disclosures and constraints under exchange rules.

    Security measures (high-level)

    • Encryption in transit (TLS) & at rest (AES-256 or equivalent).
    • KMS/HSM-based key management, rotation policies, separation of duties, audit logging and periodic penetration testing.
    • Access controls: least privilege IAM and multi-factor authentication for admin access.

    Data subject rights & requests

    • How to request access, correction, deletion or portability via the account portal or privacy@algovested.com.
    • Procedure and expected timeframes for responding to requests (per DPDP implementing rules).

    Breach response & notification

    • Algovested has an incident response plan: containment, forensic investigation, assessment of harm, and notification to Data Protection Board and affected principals when required.
    • For major incidents we will: provide a description of the breach, data categories affected, mitigation steps and contact details for follow-up.

    Third-party processors & transfers

    • We only use processors under written contracts with security and confidentiality obligations. Cross-border transfers will comply with applicable law and be disclosed.
    • We do not sell or rent personal data.

    Cookies & tracking

      Contact & DPO