Legal

Privacy Policy

This policy explains how Pearlixa collects, uses, and protects information when you interact with our products and services.

Last Updated: 12 July 2026

At a Glance

What We Promise

  • To use your information responsibly and transparently
  • To secure data with high security measures and ongoing reviews
  • To honour your GDPR and other privacy rights, including the right to lodge a complaint
  • To set non-essential cookies only with your consent

What We Will Not Do

  • We do not sell personal data
  • We do not promise investment performance or returns
  • We do not share user-level trading activity with third parties for advertising

This policy also covers cookies & tracking technologies, international data transfers, data retention, and your full rights under the GDPR — see the dedicated sections below.

Information We Collect

Account & Contact Data

  • Name, email address, authentication credentials, and organisation details you provide when creating an account
  • Billing information processed through third-party payment providers (we do not store your full payment card details)
  • Support requests, survey responses, or other communications you send to us

Usage & Device Data

  • API usage logs including endpoints accessed, timestamps, and metadata required for security and billing
  • Log files, IP address, browser type, operating system, and device identifiers gathered for diagnostics and fraud prevention
  • Cookie identifiers or similar technologies used to maintain sessions and remember preferences

Optional Integrations

  • Data you choose to import via integrations with exchanges, brokers, or other partners is processed solely to deliver the requested feature
  • We require proof that you have the right to share any third-party data with us

How We Use Information

Provide & Maintain the Service

  • Authenticate users, deliver dashboards, and process API calls
  • Operate customer support channels and respond to enquiries
  • Manage subscriptions, invoicing, and account notifications

Improve & Secure the Platform

  • Monitor performance, identify bugs, and improve model quality
  • Detect, investigate, and prevent security incidents or abuse
  • Analyse aggregate usage trends to guide product decisions

Comply With Legal Obligations

  • Maintain records required by tax, accounting, and regulatory frameworks
  • Respond to lawful requests from authorities when permitted or required by law

How We Share Information

Service Providers

  • Trusted vendors assisting with hosting, communications, payment processing, analytics, and security operate under written contracts
  • These providers may access personal data only to perform contracted services for us and must safeguard it appropriately

Legal & Safety

  • We may disclose information if required to comply with law, court orders, or to protect the rights, property, or safety of our users or the public
  • We will notify you of such disclosures when legally permissible

Business Transfers

  • If we engage in a merger, acquisition, or asset sale, we will ensure continued protection of personal data and provide notice before personal data is transferred or becomes subject to a different policy

No Sale of Personal Data

  • We do not sell or rent personal information to third parties for marketing or any other commercial purpose

Security & Retention

High Security Operations

  • Use of encryption in transit and at rest, segmented infrastructure, and principle-of-least-privilege access controls
  • Documented security policies, employee training, and change-management procedures
  • Regular internal reviews and independent security assessments as appropriate

Retention & Deletion

  • Account data is retained while an account remains active and for a limited period thereafter to comply with legal obligations
  • API logs may be retained for up to 24 months for billing, fraud prevention, and troubleshooting
  • You may request deletion of personal data; we will honour such requests unless retention is required for legitimate business or legal purposes

International Transfers

Cross-Border Processing

  • We operate from multiple jurisdictions. Your data may be processed outside of your home country by us or our service providers
  • Where required, we implement appropriate safeguards such as Standard Contractual Clauses (SCCs) or equivalent mechanisms approved by relevant authorities
  • Our primary infrastructure runs on AWS in the European Union (eu-central-1, Frankfurt). Where a service provider processes data outside the EU/EEA, we rely on Standard Contractual Clauses
  • We conduct Transfer Impact Assessments for high-risk data transfers as required by GDPR guidance post-Schrems II

Subprocessors & Third Parties

Infrastructure & Hosting

  • Amazon Web Services (AWS) — Cloud infrastructure, data storage, and compute, with our primary region in the EU (eu-central-1, Frankfurt). AWS processes data under the AWS Data Processing Addendum and Standard Contractual Clauses where transfers outside the EU/EEA occur.
  • PostgreSQL — Database hosting for persistent account and usage data

Payment Processing

  • Stripe — Payment processing and subscription management. We do not store full card details; Stripe handles all payment data under their own privacy policy at stripe.com/privacy
  • Stripe processes payments under the Stripe Privacy Policy and is certified to PCI DSS standards

Analytics (with consent only)

  • Google Analytics (Google LLC) — Website analytics to understand traffic patterns and product usage. Google Analytics cookies are only activated with your explicit consent. Data may be transferred to Google servers in the US under Standard Contractual Clauses. Google's privacy policy: policies.google.com/privacy
  • Analytics data is used solely for product improvement and is not linked to individual user identities for advertising purposes

CRM & Marketing (with consent only)

  • HubSpot (HubSpot Inc.) — Customer relationship management, marketing emails, and contact tracking. HubSpot cookies and tracking are only activated with your explicit consent. Data may be transferred to HubSpot servers in the US under Standard Contractual Clauses. HubSpot's privacy policy: legal.hubspot.com/privacy-policy
  • HubSpot processes contact and interaction data to manage customer communications and support requests

Communications

  • Email service providers for transactional and support communications
  • All subprocessors are bound by data processing agreements requiring equivalent security measures to those we apply

Data Breach Response

Incident Detection & Response

  • We maintain 24/7 monitoring for security incidents and unauthorized access attempts
  • Our incident response team is trained to assess, contain, and remediate security events promptly

Notification Timeline

  • In the event of a personal data breach that poses risk to your rights and freedoms, we will notify affected users within 72 hours of becoming aware of the breach (as required by GDPR)
  • We will notify relevant supervisory authorities within the same 72-hour timeframe where legally required
  • Notifications will include: nature of the breach, categories of data affected, approximate number of users affected, likely consequences, and measures taken to address the breach
  • For US users, we comply with state-specific breach notification laws which may require notification within 30-60 days depending on jurisdiction

Data Retention Schedule

Specific Retention Periods

  • Account profile data: Retained while account is active, plus 30 days after account deletion to allow for reactivation
  • API usage logs: 24 months for billing reconciliation, security analysis, and fraud prevention
  • Payment records: 7 years as required by tax and accounting regulations
  • Support communications: 3 years from resolution for quality assurance and legal compliance
  • Marketing preferences: Until you opt out or delete your account
  • Security logs: 12 months for threat analysis and incident investigation

Data Destruction

  • When data reaches the end of its retention period, it is securely deleted or anonymized within 90 days
  • Backup data is purged according to our backup rotation schedule (maximum 30 days for most data)
  • You may request earlier deletion; we will comply unless legal obligations require retention

California Privacy Rights (CCPA/CPRA)

Your Rights Under California Law

  • RIGHT TO KNOW: You can request disclosure of what personal information we collect, use, disclose, and sell about you
  • RIGHT TO DELETE: You can request deletion of your personal information, subject to certain exceptions
  • RIGHT TO OPT-OUT: You can opt out of the "sale" or "sharing" of your personal information. Note: We do NOT sell or share personal information for cross-context behavioral advertising
  • RIGHT TO CORRECT: You can request correction of inaccurate personal information
  • RIGHT TO NON-DISCRIMINATION: We will not discriminate against you for exercising your privacy rights

Categories of Information Collected

  • Identifiers (name, email, account ID, IP address)
  • Commercial information (subscription history, API usage)
  • Internet activity (browsing history on our site, interactions with our services)
  • Geolocation data (approximate location from IP address)
  • We do NOT collect: biometric data, precise geolocation, protected classifications, or sensitive personal information as defined by CPRA

How to Exercise Your Rights

  • Submit requests via email to privacy@pearlixa.com with subject line "CCPA Request"
  • We will verify your identity before processing requests
  • Authorized agents may submit requests with proper documentation
  • We respond to verified requests within 45 days (may be extended by additional 45 days for complex requests)

Biometric & Sensitive Data

What We Do NOT Collect

  • We do NOT collect biometric identifiers (fingerprints, facial geometry, voiceprints, iris scans)
  • We do NOT collect health or medical information
  • We do NOT collect precise geolocation data (only approximate location from IP address)
  • We do NOT collect social security numbers, driver's license numbers, or government IDs (except as required for identity verification in specific cases)
  • We do NOT collect information about racial or ethnic origin, political opinions, religious beliefs, or sexual orientation

Your Choices & Rights

Access & Control

  • Update account information directly within the dashboard
  • Request copies of personal data, correction of inaccuracies, or deletion where legally permissible
  • Opt out of marketing communications at any time via unsubscribe links or account settings

Data Protection Requests

  • Contact privacy@pearlixa.com to exercise privacy rights or raise concerns
  • We respond to verified requests within the timeframes required by applicable law

Email Marketing & CAN-SPAM / CASL Compliance

Marketing Email Practices

  • We send marketing emails only to users who have opted in during signup or through account settings
  • Every marketing email includes: clear identification of Pearlixa as sender, an honest subject line, our physical postal address (Meisenweg 3, 73249 Wernau (Neckar), Germany), and a clear unsubscribe link
  • We comply with the US CAN-SPAM Act for all commercial email communications sent to US recipients
  • For Canadian recipients, we comply with CASL and send commercial messages only with express or implied consent

Opting Out of Marketing Emails

  • You may unsubscribe from marketing emails at any time via the unsubscribe link in any email
  • You can also manage email preferences in your account dashboard under Settings → Notifications
  • Opt-out requests are processed within 10 business days
  • Opting out of marketing does NOT stop transactional emails (receipts, security alerts, account notifications) which are necessary to perform your subscription contract

Children's Privacy (COPPA)

Not Directed at Children

  • Pearlixa is not directed at children under 13 years of age and does not knowingly collect personal information from children under 13
  • Our services require users to be at least 18 years old (or the age of majority in their jurisdiction)
  • In compliance with the Children's Online Privacy Protection Act (COPPA), if we discover that a user under 13 has created an account, we will immediately delete their account and all associated personal data
  • If you are a parent or guardian and believe your child under 13 has provided us with personal information, please contact privacy@pearlixa.com immediately

No Investment Guarantees & Regulatory Disclaimer

Information Service Only - NOT Financial Advice

  • Pearlixa is a technology and information service provider ONLY. We are NOT a registered investment adviser, broker-dealer, or financial institution
  • We are NOT registered with the SEC, FCA, or any other financial regulatory authority. We do not hold any financial services licenses
  • Nothing on this website constitutes a recommendation, solicitation, or offer to buy, sell, or hold any cryptocurrency or financial instrument
  • Predictions, metrics, or performance illustrations are informational tools only and do NOT guarantee, predict, or indicate future results
  • You are solely responsible for all investment decisions. Always consult qualified, licensed financial professionals before investing

Risk Acknowledgment

  • Cryptocurrency markets are highly volatile and unpredictable. You may lose all or a substantial portion of your investment
  • Any accuracy percentages or performance metrics shown represent historical data only. Past performance does NOT guarantee future results
  • Our quant models may produce inaccurate predictions. All predictions should be treated as estimates that may be completely wrong

Limitation of Liability

  • Pearlixa is not liable for any losses, damages, or costs arising from reliance on our services, predictions, or content
  • We provide no warranties of any kind, express or implied, regarding accuracy, completeness, or fitness for any purpose
  • Service availability may be affected by maintenance, outages, or external providers and is governed by our Terms of Service

Cookies, Tracking & Similar Technologies

What Are Cookies?

  • Cookies are small text files placed on your device to store information about your usage.
  • We also use similar technologies such as local storage or pixels where appropriate.
  • Cookies help keep your session secure and enable product functionality.
  • We use minimal cookies focused on security, functionality, and user preferences - NOT advertising or tracking.

Types of Cookies We Use

  • ESSENTIAL COOKIES: Required for login, session management, security controls, rate limiting, and fraud prevention. These cannot be disabled without breaking core functionality.
  • PREFERENCE COOKIES: Remember your settings such as theme, persona selection, and UI preferences. Disabling these resets your preferences on each visit.
  • ANALYTICS COOKIES: We use Google Analytics and HubSpot for website analytics and CRM. These cookies are ONLY activated after you give explicit consent via our cookie consent banner. You can withdraw consent at any time.

Consent Management

  • Essential cookies are set automatically as they are strictly necessary for the website to function.
  • Preference cookies are set when you make choices (e.g., selecting a persona). You implicitly consent by making these choices.
  • If we add analytics cookies in the future, we will present a clear consent banner before any are set.
  • Your consent preferences are stored in the "cookie_consent" cookie and honored for 1 year.
  • You can withdraw consent at any time by clearing cookies in your browser settings or contacting us.

Third-Party Cookies

  • STRIPE: Our payment processor Stripe sets cookies for fraud prevention and secure payment processing. These are essential cookies set regardless of consent. See: stripe.com/privacy
  • GOOGLE ANALYTICS: With your consent, Google Analytics sets cookies (_ga, _ga_*) to measure website traffic and user behaviour. Data is sent to Google LLC servers. Google's privacy policy: policies.google.com/privacy
  • HUBSPOT: With your consent, HubSpot sets cookies (hubspotutk, __hstc, __hssc, __hssrc) to track contacts for CRM and marketing. Data is sent to HubSpot Inc. servers. HubSpot's privacy policy: legal.hubspot.com/privacy-policy
  • NO ADVERTISING COOKIES: We do NOT use Facebook Pixel or any advertising/retargeting cookies.
  • NO CROSS-SITE TRACKING: We do not permit any third party to track you across other websites for advertising using cookies set on our platform.
  • Analytics and CRM cookies from Google and HubSpot are only set after you provide explicit consent.

Session Duration & Security

  • Login sessions expire after 24 hours of inactivity for security.
  • If you select "Remember me" during login, sessions may last up to 7 days.
  • Sessions are invalidated immediately when you log out.
  • CSRF tokens are regenerated with each session to prevent request forgery attacks.
  • We use secure, HTTP-only cookies for sensitive tokens to prevent JavaScript access.

Local Storage & Similar Technologies

  • We use browser local storage to store: UI state, cached API responses for performance, and feature flags.
  • Local storage data remains until you clear browser data or we programmatically remove it.
  • We do NOT store sensitive information (tokens, passwords) in local storage.
  • Local storage is used to persist your risk warning acceptance (30 days) to avoid repeated popups.

How to Control Cookies

  • BROWSER SETTINGS: You can configure your browser to refuse all cookies or alert you when cookies are set.
  • DISABLING ESSENTIAL COOKIES: Warning - this will prevent login and break core functionality.
  • CLEARING COOKIES: You can delete all cookies at any time through your browser settings. This will log you out and reset preferences.
  • OPT-OUT OF ANALYTICS: If we implement analytics cookies, you can opt out via our cookie banner or by enabling "Do Not Track" in your browser.
  • Contact privacy@pearlixa.com if you need assistance managing your cookie preferences.

Legal Basis & Regulatory Compliance

  • EU ePRIVACY DIRECTIVE (2002/58/EC): Our cookie practices comply with the EU ePrivacy Directive (Cookie Directive) as implemented across EU member states. Essential cookies are set on the basis of legitimate interest (strictly necessary for the service). All non-essential cookies require your prior informed consent.
  • UK PECR (Privacy and Electronic Communications Regulations 2003): For UK users, we comply with PECR, the UK equivalent of the ePrivacy Directive. The same consent model applies — essential cookies only without consent, all others require opt-in.
  • GDPR ARTICLE 6 BASIS: Where cookies process personal data, the lawful basis is: (a) Consent (Art. 6(1)(a)) for preference cookies; (b) Legitimate interests (Art. 6(1)(f)) for strictly necessary security and fraud-prevention cookies.
  • DO NOT TRACK (DNT): We respect the DNT browser signal. If your browser sends a DNT=1 header, we will not activate any non-essential tracking or preference cookies beyond what is strictly necessary for security.
  • WITHDRAWAL OF CONSENT: You may withdraw your cookie consent at any time by clearing your cookies in browser settings or contacting privacy@pearlixa.com. Withdrawal does not affect the lawfulness of processing before withdrawal.
  • SUPERVISORY AUTHORITY: EU users may lodge a complaint regarding our cookie practices with their national data protection authority. UK users may contact the Information Commissioner's Office (ICO) at ico.org.uk.

GDPR Compliance & Your Rights

Our Commitment to GDPR Compliance

  • Pearlixa designs products and processes with privacy by default and privacy by design principles as required by GDPR Article 25.
  • We maintain comprehensive records of processing activities (ROPA) as required by GDPR Article 30.
  • We conduct Data Protection Impact Assessments (DPIAs) for high-risk processing activities as required by GDPR Article 35.
  • Our legal team regularly reviews processing activities to ensure ongoing compliance with GDPR requirements.
  • We are committed to transparency about how we collect, use, and protect personal data of EU/EEA and UK residents.

Controller vs Processor Role

  • DATA CONTROLLER: For user account data, Pearlixa acts as the data controller. We determine the purposes and means of processing your personal data.
  • DATA PROCESSOR: When processing data on behalf of enterprise customers (e.g., API data they send us), we act as a data processor under their instructions.
  • Enterprise customers who are controllers must enter into a Data Processing Agreement (DPA) with us before processing EU/EEA personal data through our services.
  • As a processor, we only process personal data according to documented instructions from the controller and applicable law.

Lawful Bases for Processing (Article 6)

  • CONTRACT PERFORMANCE (Art. 6(1)(b)): To provide our services, process payments, deliver API access, and respond to support requests.
  • LEGITIMATE INTERESTS (Art. 6(1)(f)): To secure our platform, prevent fraud, improve service quality, and conduct analytics. We balance our interests against your rights through Legitimate Interest Assessments (LIAs).
  • CONSENT (Art. 6(1)(a)): For non-essential cookies, marketing communications, and optional features. You may withdraw consent at any time.
  • LEGAL OBLIGATION (Art. 6(1)(c)): To comply with tax laws, anti-money laundering requirements, and respond to lawful government requests.
  • We do NOT process special category data (Article 9) such as health, biometric, or political opinion data.

Your Rights Under GDPR

  • RIGHT OF ACCESS (Art. 15): You can request a copy of your personal data and information about how we process it.
  • RIGHT TO RECTIFICATION (Art. 16): You can request correction of inaccurate personal data.
  • RIGHT TO ERASURE (Art. 17): You can request deletion of your personal data ("right to be forgotten"), subject to legal retention requirements.
  • RIGHT TO RESTRICTION (Art. 18): You can request we limit processing of your data in certain circumstances.
  • RIGHT TO DATA PORTABILITY (Art. 20): You can request your data in a structured, machine-readable format.
  • RIGHT TO OBJECT (Art. 21): You can object to processing based on legitimate interests or for direct marketing.
  • RIGHTS RELATED TO AUTOMATED DECISION-MAKING (Art. 22): You have the right not to be subject to decisions based solely on automated processing that significantly affect you.
  • We respond to verified requests within 30 days (may be extended by 60 days for complex requests).

International Data Transfers

  • Pearlixa is operated from Germany, with primary data processing on AWS infrastructure in the European Union (eu-central-1, Frankfurt). Some service providers may process personal data outside the EU/EEA.
  • TRANSFER MECHANISM: We use the European Commission's Standard Contractual Clauses (SCCs) - specifically the controller-to-processor and processor-to-processor modules as appropriate.
  • POST-SCHREMS II COMPLIANCE: We conduct Transfer Impact Assessments (TIAs) to evaluate US surveillance laws and implement supplementary measures where necessary.
  • SUPPLEMENTARY MEASURES: We implement encryption in transit and at rest, access controls, and contractual commitments to challenge unlawful government requests.
  • UK DATA: For UK residents, we comply with the UK GDPR and use the UK International Data Transfer Agreement (IDTA) alongside SCCs.
  • Our cloud infrastructure (AWS) runs in the EU (eu-central-1, Frankfurt). Data is not routinely transferred outside the EU/EEA except to the subprocessors listed below.

Subprocessors

  • We engage subprocessors to assist in providing our services. All subprocessors are bound by data processing agreements with equivalent protections.
  • CURRENT SUBPROCESSORS: Amazon Web Services (hosting, EU — Frankfurt), Stripe (payments, US), email service providers.
  • We maintain a current subprocessor list which is available upon request to privacy@pearlixa.com or as an attachment to our DPA.
  • SUBPROCESSOR CHANGES: We notify customers of new subprocessors at least 30 days before engagement. You may object to new subprocessors within 14 days.
  • We conduct security assessments of subprocessors before engagement and periodically thereafter.

Data Retention

  • We retain personal data only as long as necessary for the purposes for which it was collected, as required by GDPR Article 5(1)(e).
  • ACCOUNT DATA: Retained while your account is active, plus 30 days after deletion for reactivation.
  • API LOGS: 24 months for billing, security analysis, and troubleshooting.
  • PAYMENT RECORDS: 7 years as required by tax and accounting regulations.
  • SUPPORT COMMUNICATIONS: 3 years from resolution.
  • When data is no longer needed, it is securely deleted or anonymized within 90 days.
  • See our Privacy Policy for the complete retention schedule.

Security Measures (Article 32)

  • ENCRYPTION: Data is encrypted in transit (TLS 1.3) and at rest (AES-256).
  • ACCESS CONTROLS: Role-based access controls, principle of least privilege, multi-factor authentication for staff.
  • MONITORING: 24/7 security monitoring, intrusion detection, and automated threat response.
  • TESTING: Regular penetration testing and vulnerability assessments.
  • INCIDENT RESPONSE: Documented incident response procedures with defined roles and escalation paths.
  • TRAINING: Regular security and privacy training for all staff handling personal data.
  • We implement appropriate technical and organizational measures considering the state of the art, costs, and nature of processing.

Data Breach Notification (Articles 33-34)

  • We maintain incident detection systems and response procedures to identify breaches promptly.
  • AUTHORITY NOTIFICATION: We will notify the relevant supervisory authority within 72 hours of becoming aware of a personal data breach that poses risk to individuals (Article 33).
  • INDIVIDUAL NOTIFICATION: We will notify affected individuals without undue delay when a breach is likely to result in high risk to their rights and freedoms (Article 34).
  • DOCUMENTATION: We document all breaches, including facts, effects, and remedial actions taken.
  • CUSTOMER NOTIFICATION: For enterprise customers, we notify them of breaches affecting their data within 48 hours.
  • Contact security@pearlixa.com immediately if you suspect unauthorized access to your account.

Data Protection Officer

  • While not legally required to appoint a DPO, we have designated a privacy lead responsible for GDPR compliance.
  • DATA PROTECTION CONTACT: privacy@pearlixa.com
  • Our privacy team monitors regulatory developments and updates our practices accordingly.
  • You may contact our privacy team for any questions about how we handle your personal data.

Right to Lodge a Complaint

  • If you believe we have not complied with our data protection obligations, you have the right to lodge a complaint with a supervisory authority.
  • EU residents: Contact your local Data Protection Authority (DPA)
  • UK residents: Contact the Information Commissioner's Office (ICO) at ico.org.uk
  • List of EU DPAs: edpb.europa.eu/about-edpb/about-edpb/members_en
  • We encourage you to contact us first at privacy@pearlixa.com so we can address your concerns directly.

Questions or Requests?

Contact our privacy team and we will respond as soon as possible.

Email: privacy@pearlixa.com

Data Protection Officer: privacy@pearlixa.com