1. Data Controller
[LEGAL_ENTITY] is the controller of personal data collected via copytolive.com. DPO: [email protected].
2. Data We Collect
- Account: email, hashed password (bcrypt), display name, country (from IP).
- Authentication: TOTP 2FA secret (encrypted), session tokens, login IP+timestamp.
- Trading: Hyperliquid API key (AES-256-GCM encrypted), wallet address, trade history, PnL.
- Payment: subscription history, NOWPayments transaction IDs (we do not store crypto wallet of user).
- Usage: page views (GA4 with anonymized IP), feature flags, error logs (Sentry).
3. Legal Basis (GDPR Art. 6)
- Contract performance (delivering the Service)
- Legitimate interest (security, fraud prevention)
- Consent (analytics, marketing — opt-in)
- Legal obligation (tax, AML)
4. Data Processors (Sub-processors)
- NOWPayments (payments) — Estonia
- Cloudflare (CDN, DDoS) — Global
- Sentry (error tracking) — US/EU
- Resend / SendGrid / Postmark (transactional email) — US/EU
- MaxMind (geo-IP) — US
- Bunny.net / Cloudflare Stream (video learning hub) — Global
5. International Transfers
Data may be processed outside your jurisdiction. We rely on Standard Contractual Clauses (EU-approved) with sub-processors.
6. Retention
- Account data: until deletion request + 30-day grace.
- Trade audit log: 7 years (tax/compliance).
- Email logs: 90 days.
- Backups: 30 days daily + 12 months monthly.
7. Your Rights (GDPR Art. 15-22)
- Access & portability — export all data via /account/privacy → "Export my data"
- Rectification — edit profile in /account
- Erasure — request via /account/privacy → "Delete my account" (irreversible after 30 days)
- Restriction / Object — email [email protected]
- Lodge complaint — your local data protection authority
8. Cookies
We use only essential cookies (session, CSRF). Optional analytics cookies require opt-in via cookie banner.
9. Security
Encryption in transit (TLS 1.3) and at rest (AES-256). Passwords bcrypt-hashed. API keys AES-256-GCM. Optional 2FA TOTP. Rate limiting and DDoS protection via Cloudflare.
10. Children
Service is not for users under 18. Detected accounts will be deleted.
11. Changes
Material changes notified via email and /changelog 30 days in advance.