Privacy Policy (GDPR & UK GDPR) – PreTrAIde
This Privacy Policy (the “Policy”) explains how PAI INTELLIGENCE LTD, a private limited company incorporated in England and Wales (Company Number: 17409040, Registered Address: 124 City Road, London, EC1V 2NX, United Kingdom) (the “Company”, “we”, “us”) collects and processes personal data in connection with the PreTrAIde platform (“PreTrAIde”, “the Platform”, “the Service”).
We are committed to complying with the United Kingdom General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and, where applicable, the European Union General Data Protection Regulation (EU GDPR) (together referred to in this Policy as “GDPR”).
This Policy applies to visitors, registered users, individual customers, and business users. If you use the Service on behalf of a business, you must ensure that any personal data you provide to us is shared lawfully and that you have the necessary rights and permissions.
1. Data Controller and Contact Details
The data controller responsible for your personal data is PAI INTELLIGENCE LTD.
Privacy contact email: [email protected]. If we appoint a Data Protection Officer (DPO) or dedicated privacy representative, we will publish updated contact details on this page.
2. Scope of This Policy
This Policy covers personal data processed through the website, Platform interfaces, user Account features, customer support, billing, and related communications. It does not cover third-party platforms you may access via links on our site; those are governed by their own privacy policies.
3. Personal Data We Collect
We may collect personal data directly from you, automatically through your use of the Service, or from third parties (such as Stripe) where needed to provide the Service. The categories of data we may collect include:
- Identity and Account Data: name, email address, account identifiers, account settings, authentication metadata.
- Billing and Transaction Data: subscription plan, billing country, billing address (if provided), invoices, payment status, and limited payment metadata. We do not store full payment card data.
- Usage Data: features used, analyses run, timestamps, quotas used, technical diagnostics, error logs.
- Technical Data: IP address, device type, browser type/version, operating system, approximate location derived from IP, referral URLs, and similar telemetry.
- Support and Communications: messages sent to support, feedback, and related metadata.
- User Inputs: basket configurations and preferences you submit for analysis. This may be linked to your Account history.
We do not intentionally collect special category data (such as health data or biometric data). Please do not submit such information through the Platform.
4. Children
The Service is not intended for children. If you are under the age of 18 (or the age of majority in your jurisdiction), you must not use the Service. We do not knowingly collect personal data from children. If you believe a child has provided data to us, contact us so we can delete it.
5. Purposes of Processing
We process personal data for the following purposes:
- to create and administer Accounts;
- to provide, operate, maintain, and improve the Service;
- to process subscriptions and payments;
- to deliver customer support and respond to requests;
- to secure the Platform, prevent fraud, abuse, or unauthorised access;
- to perform analytics and service performance monitoring;
- to comply with legal obligations, enforce Terms, and resolve disputes.
6. Legal Bases for Processing (GDPR Article 6)
We process personal data under one or more of the following legal bases:
- Contract (Art. 6(1)(b)): to provide the Service, manage subscriptions, and administer accounts.
- Legal obligation (Art. 6(1)(c)): to comply with accounting, tax, fraud prevention, and other legal requirements.
- Legitimate interests (Art. 6(1)(f)): to secure and improve the Service, prevent abuse, monitor performance, and protect our business.
- Consent (Art. 6(1)(a)): where required, for optional cookies and certain marketing communications.
Where we rely on consent, you may withdraw consent at any time. Withdrawal does not affect the lawfulness of processing before withdrawal.
7. Processors and Sharing of Personal Data
We may share personal data with service providers acting as processors on our behalf, strictly to operate the Service (e.g., infrastructure hosting, email delivery, monitoring, security tooling, and customer support tools). We require processors to protect personal data and use it only for permitted purposes.
Payments are processed by Stripe. Stripe may process certain data as a controller or processor under its own privacy policy. We do not store full card numbers or card security codes on our servers.
We may also disclose data where required by law, court order, or a valid legal request, or where necessary to protect rights, safety, and security.
8. International Transfers
We may process and store personal data in the UK and may transfer data to countries outside the UK/EEA depending on the location of our service providers. Where transfers occur, we implement appropriate safeguards such as the UK International Data Transfer Agreement (IDTA), the UK Addendum to EU Standard Contractual Clauses, and/or EU Standard Contractual Clauses (SCCs), together with additional technical and organisational safeguards where appropriate.
9. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes described in this Policy, including to provide the Service, maintain your Account, comply with legal obligations (including accounting and tax), resolve disputes, and enforce agreements.
Retention periods vary depending on data type and legal requirements. When data is no longer required, we securely delete or anonymise it.
10. Security
We implement appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. Measures may include access controls, encryption in transit, audit logging, monitoring, and least-privilege policies.
No method of transmission or storage is completely secure. You are responsible for keeping your credentials confidential and for using strong passwords and, where available, multi-factor authentication.
11. Cookies and Similar Technologies
We may use cookies or similar technologies for essential operation, security, preferences, and (where applicable) analytics. Where required by law, we will request your consent for non-essential cookies and provide controls to manage your choices.
For more information, please refer to our cookie information page or cookie banner settings (where implemented).
12. Marketing Communications
Where permitted by law, we may send service communications (e.g., subscription confirmations, important service notices) and, where consent is required, marketing communications. You may opt out of marketing emails at any time using the unsubscribe link or by contacting us.
Service communications that are necessary for account administration and security may still be sent even if you opt out of marketing.
13. Automated Decision-Making (GDPR Article 22)
The Platform provides automated outputs (including GO/NO-GO indicators) for decision-support purposes. These outputs are not legal decisions, do not produce legally binding effects on you, and do not constitute profiling intended to significantly affect you within the meaning of Article 22.
You remain free to ignore outputs and make independent decisions. If you have concerns about automated processing, you may contact us using the details above.
14. Your Rights (GDPR Articles 12–23)
Subject to legal limitations and verification of identity, you have the following rights:
- Right of access (Art. 15): obtain confirmation and access to personal data we process about you.
- Right to rectification (Art. 16): correct inaccurate or incomplete data.
- Right to erasure (Art. 17): request deletion where applicable.
- Right to restriction (Art. 18): request limitation of processing in certain cases.
- Right to data portability (Art. 20): receive certain data in a structured, commonly used, machine-readable format.
- Right to object (Art. 21): object to processing based on legitimate interests and to direct marketing.
- Right to withdraw consent: where processing is based on consent, you can withdraw at any time.
To exercise your rights, contact [email protected]. We may request additional information to verify your identity. We will respond within the timeframes required by GDPR.
15. Complaints
If you have concerns about our data practices, please contact us first so we can try to resolve the matter. You also have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO). If you are located in the EEA, you may also lodge a complaint with your local supervisory authority.
16. Changes to This Policy
We may update this Policy from time to time. Where changes are material, we will provide notice through the Platform or by email where appropriate. The updated version becomes effective when published.