Privacy Policy
Last updated: [DATE]
In short: we collect the account and billing information needed to run your subscription. We do not collect, store, or analyze the trading strategies or data you submit to Elenchos to test — that’s yours, it stays yours, and keeping our hands off it is both the right thing to do and, frankly, not something we have any use for.
1. Who we are
Jeremy Andre, a micro-entrepreneur registered in France (SIRET [SIRET number]), [registered address], is the sole data controller for personal data processed through Elenchos.
[TODO: if B (as an independent service provider — e.g. maintaining the website, or handling certain technical tasks) has access to any personal data in the course of that work, B acts as a data processor / sub-processor on [COMPANY NAME]’s behalf, under a data processing agreement (DPA), not as a joint controller. List B here only if that’s actually the case, e.g.: "Website maintenance: [B’s business name] (SIRET [B’s SIRET]), acting under our instructions as a processor."]
2. What we collect
2.1 From the website (account, billing, and contact)
- Account data: name, email, company name, billing details
- Payment data: processed by our payment provider ([e.g. Stripe]); we don’t store full card numbers
- Technical/website data: log files, device/browser info, and basic usage of the marketing site and account areas (e.g. pages visited, login activity)
- Cookies: see our Cookie Policy
2.2 From the Service itself (your strategy data): we do not collect it
When you use Elenchos to test whether a strategy is trustworthy, the data and strategy details you submit are processed only transiently, in real time, to generate your result. We do not store, log, review, analyze, or reuse that data once your session ends, and we do not use it to train models, benchmark other users, or for any purpose beyond producing your immediate output.
We take this position deliberately: this data is often sensitive and proprietary to you, collecting or retaining it would create risk without any legitimate upside for you, and it wouldn’t meaningfully benefit us either — so we simply don’t.
[TODO: confirm this matches your actual architecture exactly. In particular: is anything you submit ever written to disk or logs even briefly (e.g. for debugging, error monitoring, or crash reports)? If yes, say so explicitly and give a retention period (e.g. "error logs may briefly capture request data for up to 24 hours, automatically deleted after, and never manually reviewed") — an absolute "we never collect it" claim that turns out to be technically inaccurate is a real regulatory and reputational risk (misleading commercial practice / inaccurate privacy claim). If it’s genuinely never persisted anywhere, this section can stand as written.]
3. Why we process it (legal basis)
This section concerns the account, billing, and website data described above — not your strategy data, which we don’t collect in the first place.
- To provide the Service and manage your subscription (performance of contract)
- To process payments and comply with tax/accounting obligations (legal obligation)
- To maintain and secure the website and account system (legitimate interest)
- Marketing emails, if any (consent — with an easy opt-out)
4. Who we share it with
We share account, billing, and website data with service providers who help us run the Service (hosting, payment processing, analytics, customer support tools), under contracts that require them to protect your data. We don’t sell personal data. Since we don’t collect your strategy data (see Section 2), there’s nothing of that kind to share in the first place.
[TODO: list your actual subprocessors here once chosen, e.g. hosting provider, Stripe, analytics tool — many privacy regulators expect this to be concrete, not generic.]
5. International transfers
Some providers may be located outside the EU. Where that’s the case, we rely on Standard Contractual Clauses or an equivalent safeguard recognized under GDPR.
6. Retention
We keep personal data for as long as your account is active, plus [X years] afterward for legal/accounting obligations, unless you request earlier deletion (subject to those same obligations).
7. Your rights (GDPR)
You have the right to access, correct, delete, or export your data, restrict or object to processing, and withdraw consent at any time. Contact [privacy@yourcompany.com] to exercise these rights. You can also lodge a complaint with the CNIL (France’s data protection authority) at cnil.fr.
8. Security
We use industry-standard technical and organizational measures (encryption in transit, access controls, etc.) to protect your data.
9. Children
The Service is not directed at anyone under 18, and we don’t knowingly collect data from minors.
10. Changes
We’ll notify you of material changes to this policy by email or in-app notice.
11. Contact
[privacy@yourcompany.com] — [Data Protection Officer, if appointed: name/contact]
