Legal entity details: To Be Announced (TBA). For data protection matters in the meantime, you may contact us at: support@ufobot.ai. This Privacy Policy applies to all users of the UFOBOT.AI platform and website.
We collect the minimum data necessary to provide our platform: • Account data: email address, hashed password, account preferences. • Billing data: subscription tier and payment history. Payment card details are processed exclusively by Stripe and are never stored on our servers. • Exchange API keys: encrypted at rest using AWS KMS (FIPS 140-2 validated). Decrypted only in-memory for the milliseconds required to execute a trade. • Trading activity: trade logs, bot performance metrics, and execution history associated with your account. • Technical data: server-side request logs (IP address, timestamps) retained transiently by our infrastructure for security and abuse prevention. Not stored in user profiles.
We process your personal data under the following legal bases: • Contract performance (Art. 6.1.b): Processing necessary to provide the subscription service you signed up for. • Legitimate interests (Art. 6.1.f): Security monitoring, fraud prevention, and platform integrity. • Legal obligation (Art. 6.1.c): Compliance with applicable laws including anti-money laundering (AML) and financial record-keeping regulations. • Consent (Art. 6.1.a): Where you have explicitly opted in (e.g., newsletter subscriptions).
Your data is used exclusively to: • Operate and maintain your automated trading bots. • Process your subscription payments via Stripe. • Send service communications (system alerts, downtime notices, security warnings). • Comply with legal and regulatory obligations. We do NOT use your data for third-party advertising, data brokering, or any purpose unrelated to the operation of UFOBOT.AI.
Your exchange API keys are subject to the highest level of protection we offer: • Encrypted at rest using AWS KMS (FIPS 140-2 validated) in our eu-central-1 (Frankfurt) region. • Decrypted only in-memory at the precise moment of trade execution — never written to disk in plaintext. • API keys are configured with read/trade permissions only. Withdrawal permissions are explicitly prohibited and enforced at the platform level. • We cannot withdraw, transfer, or access your exchange funds in any way.
We do not sell or rent your personal data. We share information only with essential service providers who comply with strict data protection standards: • Stripe (payment processing) — governed by Stripe's Privacy Policy and PCI-DSS compliant. • Amazon Web Services (hosting and key management) — EU region (Frankfurt), AWS DPA in place. • No other third parties have access to your personal data or API keys.
Your data is stored and processed in the European Union (AWS eu-central-1, Frankfurt, Germany). If data is transferred outside the EU for essential service provision (e.g., Stripe), such transfers are governed by Standard Contractual Clauses (SCCs) approved by the European Commission, ensuring an adequate level of protection.
We retain your data for as long as your account is active or as required to provide services. Specifically: • API keys: deleted immediately upon account deletion or Emergency Ejection. • Trading logs: retained for up to 24 months for performance reporting, then anonymized or deleted. • Billing records: retained for 7 years as required by Spanish tax law (Ley 58/2003 General Tributaria). • Account data: deleted within 30 days of account deletion request.
As a user in the European Union, you have the following rights: • Right of Access (Art. 15): Request a copy of all personal data we hold about you. • Right to Rectification (Art. 16): Correct inaccurate or incomplete data. • Right to Erasure (Art. 17): Request permanent deletion of your data ("Right to be Forgotten"). Use the Emergency Ejection feature in Settings for immediate API key deletion, or contact support@ufobot.ai for full account deletion. • Right to Restriction (Art. 18): Request limitation of processing in specific circumstances. • Right to Data Portability (Art. 20): Receive your data in a structured, machine-readable format. • Right to Object (Art. 21): Object to processing based on legitimate interests. • Right to Lodge a Complaint: You have the right to file a complaint with the Spanish Data Protection Agency (AEPD) at www.aepd.es. To exercise any of these rights, contact us at: support@ufobot.ai
UFOBOT.AI uses only essential session cookies required for authentication and platform operation. We do not use tracking cookies, advertising cookies, or third-party analytics cookies. No cookie consent banner is required as we only use strictly necessary cookies.
We may update this Privacy Policy from time to time. When we do, we will update the "Last Updated" date at the top of this page and notify active subscribers by email of any material changes. Continued use of the platform after notification constitutes acceptance of the updated policy.