Privacy Policy

How website and app data is handled

Effective date: 27 September 2026   Last updated: 4 October 2026   Version: 2026.10

This notice describes personal-data processing connected with autonomoustrading.io and the Autonomous Trading application when this notice is presented there. The controller is Intuitive Code Lda, at the geographic address stated in Operator and legal identification. Direct privacy contact: sales@autonomoustrading.io.

Information we process and why

Depending on the feature you use, we process the following information for the stated purposes. The legal bases refer to Article 6 GDPR; a separate basis may apply where law requires it.

  • Account and access: email, account identifiers, authentication records, subscription and entitlement status, access dates and one-time free-plan claim records to register, sign in, secure an account and provide eligible access. The app supports email/password and Google sign-in through a self-hosted Supabase service. Base: contract steps/performance (Article 6(1)(b)); security and fraud prevention may rely on legitimate interests (Article 6(1)(f)). Google sign-in also involves Google's own processing.
  • Contact and sales: the contact form collects name, email, phone, company, website, country, profile, product interest, capital range, journey stage and message. The submission may include IP address, user agent and referral information. Purpose: answer an inquiry and prepare a requested commercial discussion. Base: pre-contract steps (Article 6(1)(b)) where requested, or legitimate interests in responding to other inquiries (Article 6(1)(f)). The form sends data through a Hookdeck endpoint; the configured contact workflow stores a submission in Supabase, updates a Mautic contact and sends email notifications.
  • Newsletter: email, optional first name, page URL, signup and confirmation information. Purpose: confirm a subscription and send requested research or product email. Base: consent (Article 6(1)(a)) where required for direct marketing. The website submits through a Hookdeck endpoint; configured workflows maintain a Supabase subscriber record and use Resend for confirmation email. The confirmation page calls a Supabase function. You may withdraw through an unsubscribe link or the privacy contact.
  • Research and AI interaction: questions, selected research or signal context, conversation history and information you choose to provide to the current Flowise Expert. The Expert is delivered through a Flowise chat interface configured with conversation memory, document retrieval and an OpenAI model. Chat messages are stored in the Flowise database. Purpose: respond to a request and preserve useful conversational continuity. Base: contract performance where the feature is provided under an account (Article 6(1)(b)); security logging may rely on legitimate interests (Article 6(1)(f)). Conversation memory can personalize an explanation without itself selecting a transaction as suitable for you. Please avoid submitting unnecessary sensitive personal or financial details.
  • Order and billing: selected product and offer, buyer and billing details, country, tax information, order amount, bank-transfer reference where supplied, order status and access dates. These support an order request, bank-transfer follow-up, access and tax/accounting records. Bases: contract (Article 6(1)(b)) and legal obligation (Article 6(1)(c)). The current in-app order form does not collect card numbers or payment. Bank-transfer instructions and the final amount are communicated separately before payment becomes binding.
  • Technical and security data: IP address, device/browser details, access times, diagnostics and security events generated when using the site or app. Purpose: operate, secure and troubleshoot the service. Base: legitimate interests in reliable and secure operation (Article 6(1)(f)), subject to balancing and applicable terminal-access rules.
  • Optional website analytics and marketing tracking: pageviews and similar identifiers generated by Mautic or configured tags when enabled by your choice. Base: consent (Article 6(1)(a)) where required. The website choices are described in the Cookie Policy. We do not claim analytics data is anonymous. The authenticated app is a separate origin and must present its own applicable controls.

Sources, recipients and service providers

Public Website AI Assistant: after three anonymous answers, we use your email address to send a one-time access code through our transactional email provider, Resend. Verification is only for Assistant access continuity, usage limits and abuse prevention; it does not create a customer account or subscribe you to marketing. The gateway uses a keyed, pseudonymous email identifier for the verified allowance of 20 successful questions per UTC calendar day, resetting at 00:00 UTC. It uses an opaque browser session and a daily rotating, pseudonymous IP identifier for anonymous limits and abuse controls. Email addresses and verification codes are not sent to the Assistant model or knowledge retrieval service. Codes are stored only as a keyed verification hash, expire after ten minutes and can be used once.

Most information comes from you or your device. The observed service path includes self-hosted Supabase for authentication, orders, access and form/newsletter records; Hookdeck for website form endpoints; n8n workflows for routing submissions; Mautic for contact records and optional website measurement; Resend for newsletter confirmation; Flowise and OpenAI for the current Expert; and Google for sign-in and, on the masterclass page after consent, configured tags. Cloudflare delivers the website. Some pages also request Google Fonts, jsDelivr resources or embedded media. Information is shared with a service only as needed for the feature or request involved. We may disclose data to authorities where legally required.

International transfers

Some service providers or their subprocessors may process or access information outside the European Economic Area, depending on the service and its configuration. Any restricted transfer is subject to the applicable GDPR transfer requirements, which may include an adequacy decision, standard contractual clauses or another lawful mechanism. You may ask the privacy contact above for information about the arrangements applicable to your data.

Retention

We keep personal data only for the purposes for which it is needed, subject to applicable legal duties and proportionate dispute or security needs. Account and access information is needed while the account or entitlement remains active; relevant contract records may continue to be needed after access ends. Tax and accounting records are kept for the period required by applicable law. Contact inquiries are kept while we respond and for reasonable follow-up; newsletter addresses are used while subscribed, with limited suppression or consent evidence retained where necessary after withdrawal. Expert conversations are kept while needed for the requested service and conversational continuity. Routine security data is kept only as needed to investigate and prevent misuse. A documented legal claim or statutory duty may require longer retention of the relevant records, and a valid erasure request may lead to earlier deletion where law permits.

Public Website AI Assistant conversations and gateway sessions are subject to approximately daily cleanup targeting seven days. Verification challenge records are removed after expiry, on subsequent gateway activity or daily cleanup. Daily usage counters are removed after two days, session allowance records after seven days, and aggregate operational counters after 30 days. The gateway does not keep plaintext email addresses, codes, raw IP addresses or conversation transcripts for this verification feature. Resend necessarily processes the recipient address and code to deliver the requested email; provider-controlled delivery records and logs may follow separate retention rules.

The configured n8n workflow system makes eligible completed execution data subject to pruning after seven days; that setting does not delete separate contact, subscriber or chat records. Website cookie choices expire after 180 days; see the Cookie Policy. Provider-controlled copies and logs may have different retention rules from operator-controlled records. Ask the privacy contact above about the criteria applicable to a particular record.

AI, profiling and individual decisions

Autonomous Trading's intended service is research, market intelligence and non-personalized recommendations where applicable, not individual suitability assessment. Conversation history may maintain continuity, reference previously discussed research and adjust explanation style. That differs from using your financial circumstances, objectives, individual risk tolerance or capacity for loss to select or present an investment transaction as suitable for you. The planned AI Trading Strategist is not a completed production product. The reviewed order and access flow did not establish solely automated decisions with legal or similarly significant effects under Article 22 GDPR; other app functionality requires a separate assessment before an ecosystem-wide conclusion.

Your rights and choices

Subject to legal conditions, you may request access, rectification, erasure, restriction, portability and objection to processing, including objection to direct marketing. Where processing rests on consent, you may withdraw it at any time without affecting prior lawful processing. You can change website tracking choices at any time through “Cookie settings” in the website footer. Send other privacy requests to the contact given above. We may verify identity before responding and will explain any lawful refusal or limitation. You may complain to Portugal's CNPD or another competent EEA supervisory authority.

Children, security and changes

The investment-focused service is not intended for children. If we learn that a child supplied data without a lawful basis, we will address it under applicable law. We use appropriate organizational and technical safeguards, but no online service can guarantee absolute security. Material changes to this notice will be dated and communicated where legally required. This notice does not ask you to consent merely by reading it.

Related documents: Terms of Service, Cookie Policy and Investment, Research and AI Risk Notice.