ZyroPilot Launches $400,000 Binary Funded Challenges

Get Funded
ZyroPilot
ChallengesRulesTerminalDemo PracticeBlogFAQContact
Sign InStart Challenge
  • 1. Scope & Controller
  • 2. Data Categories
  • 3. Automated Telemetry
  • 4. Lawful Grounds
  • 5. Security & Vaults
  • 6. Engine & Ledger
  • 7. Third-Party Disclosures
  • 8. Retention Schedules
  • 9. Data Subject Rights
  • 10. Cookies & Storage
  • 11. Global Transfers
  • 12. Governance & DPO
Back to Home
Home/Legal/Privacy policy

Privacy Policy & Data Protection Covenant

How ZyroPilot collects, encrypts, processes, and safeguards personal dossiers, biometric liveness scans, and trading records in strict accordance with statutory standards. Promulgated October 14, 2023.

Z
ZyroPilot Compliance(Data controller)
•Updated Nov 18, 2024•10 min read•12 articles
AES-256Vault encryption for identity records
0Third-party data sales or commercial sharing
5 YearsStatutory AML data retention limit
GDPRFull data portability & right to erasure

All biometric verification vectors and identification documents are stored in zero-knowledge encrypted vaults with continuous audit logging.

Article 01·General & Governance

Statutory Framework, Data Controller Standing & Global Scope

Institutional governance, legal controller standing, jurisdictional boundaries, and protection of minors.

1.1Legal Data Controller Identification

ZyroPilot Technologies Ltd. ('ZyroPilot', 'the Company', 'we', 'us', or 'our') acts as the statutory data controller for all personal information, behavioral telemetry, and transaction metadata gathered across the ZyroPilot web terminal, trading interfaces, mobile portals, and proprietary API gateways.

1.2Material & Territorial Scope

This Privacy Policy applies to every registered trader, evaluation applicant, institutional partner, affiliate participant, and platform visitor. It governs all personal data processing activities conducted under the European Union General Data Protection Regulation (GDPR), the UK Data Protection Act, and applicable global data sovereignty frameworks.

1.3Voluntary Assent & Condition Precedent

Furnishing the personal data, identity dossiers, and network telemetry specified herein constitutes an indispensable condition precedent to opening an account, executing evaluation challenges, and receiving performance-split allocations. If you decline to provide required compliance details, ZyroPilot cannot grant access to the ZyroPilot trading ecosystem.

1.4Strict Protection of Minors

ZyroPilot maintains an absolute prohibition against registration by any individual under eighteen (18) years of age, or below the statutory age of contractual majority in their home jurisdiction. We do not knowingly solicit, process, or archive data from minors. Any discovered minor profile is purged immediately alongside permanent account termination.

Article 02·Data Collection

Categories of Collected Data & Verification Dossiers

Account credentials, government identity dossiers, biometric liveness telemetry, and cryptocurrency ledger addresses.

2.1Account Registration Credentials & Profile Metadata

During profile creation and authentication, we record your verified email address, cryptographically hashed passwords, country of residence, preferred terminal language, and assigned unique platform identifier (UID).

2.2Identity Verification (KYC) Dossiers & Biometric Telemetry

Prior to authorizing live account balance withdrawals or evaluation performance payouts, traders must submit mandatory Customer Due Diligence (KYC) records. These comprise:

  • Government-issued photo identification (International Passport, National Identity Card, or Driver's License in crisp, unedited color).
  • Proof of residential address dated within the preceding ninety (90) days (bank statement, utility invoice, or local council tax assessment).
  • Real-time biometric facial telemetry (3D liveness detection vectors and facial contour mapping) to verify identity authenticity and defeat automated deepfakes.

2.3Financial Ledger Records & Cryptocurrency Addresses

For balance deposits and performance fee settlements, we record public blockchain destination addresses (e.g. TRON TRC-20, BSC BEP-20, Bitcoin, Ethereum), transaction hashes (txHash), network confirmation timestamps, and ledger balances. ZyroPilot never requests, collects, or holds private keys, seed phrases, or custodial wallet credentials.

2.4Communications & Operational Desk Records

All interactions with our 24/7 compliance desk, technical support tickets, live chat dialogues, and email inquiries are recorded and retained to facilitate dispute resolution, quality assurance, and audit traceability.

Article 03·Data Collection

Automated Device Telemetry, Networking & Anti-Fraud Logs

IP routing metadata, hardware fingerprints, browser signatures, and terminal interaction telemetry.

Anti-Sybil & Account Security Telemetry

Automated device telemetry is continuously cross-referenced to protect trader balances from account takeovers, identify unauthorized bot deployments, and detect coordinated multi-account arbitrage rings.

3.1Network Identifiers & Geolocation Telemetry

When you access the ZyroPilot terminal, our infrastructure captures your public Internet Protocol (IP) address, Autonomous System Number (ASN), Internet Service Provider (ISP), connection port, and approximate geographic coordinates. This data is monitored in real time to enforce jurisdictional exclusions and block malicious proxy or VPN abuse.

3.2Hardware Fingerprinting & Client Signatures

We collect non-personally-identifying device signatures, including your operating system version, browser engine, screen resolution, WebGL renderer metrics, system time zone, and language preferences. These parameters form an ephemeral device token used to authenticate sessions and flag unauthorized login attempts.

3.3Terminal Interaction & Trading Latency Diagnostics

To ensure order execution transparency and diagnose execution inquiries, our servers log client-side round-trip WebSocket latency, order placement button timestamps, tick sequence numbers, and interface rendering anomalies.

Article 04·Processing & Grounds

Lawful Grounds for Personal Data Processing

Contractual performance, statutory AML compliance, institutional legitimate interests, and explicit consent grounds.

4.1Performance of Contractual Obligations

Processing account registration details, trading orders, evaluation performance metrics, and balance payout transfers is legally necessary to fulfill our master contractual agreement with you.

4.2Compliance with Statutory Mandates & AML Regulations

We process identity verification dossiers, liveness scans, and financial transaction logs to satisfy binding anti-money laundering (AML), counter-terrorist financing (CTF), international sanctions screening (OFAC/FATF), and corporate accounting obligations.

4.3Legitimate Institutional Interests

We process diagnostic telemetry, risk telemetry, and order behavior under our legitimate commercial interest in preserving platform integrity, preventing algorithmic latency exploitation, halting coordinated hedging schemes, and securing infrastructure against cyber attacks.

4.4Voluntary User Consent

Where we dispatch non-essential marketing newsletters, promotional challenge updates, or opt-in educational webinars, we rely strictly on your unambiguous, freely given consent, which may be revoked at any time.

Statutory Lawful Grounds Mapping Matrix

Data CategoryPrimary Processing PurposeStatutory Lawful BasisMandatory / Discretionary
Account CredentialsSession auth & profile managementGDPR Art. 6(1)(b) Contract PerformanceMandatory for access
KYC IdentificationAML / CTF & Sanctions complianceGDPR Art. 6(1)(c) Legal ObligationMandatory for withdrawals
Biometric TelemetryLiveness verification & anti-spoofingGDPR Art. 9(2)(a) Explicit ConsentMandatory for KYC approval
Blockchain AddressesSettlement of payout distributionsGDPR Art. 6(1)(b) Contract PerformanceMandatory for payouts
Device & IP TelemetryAnti-fraud, anti-bot & securityGDPR Art. 6(1)(f) Legitimate InterestMandatory automated collection
Marketing NewslettersProduct announcements & offersGDPR Art. 6(1)(a) Voluntary ConsentOptional / Trader opt-in
Article 05·Security & Encryption

Cryptographic Safeguards, Vault Archival & Architecture

AES-256 encryption at rest, TLS 1.3 in transit, Argon2id password hashing, and role-based access segregation.

Zero Private Key Exposure Invariant

ZyroPilot infrastructure operates under an immutable security covenant: user cryptographic private keys are never requested, stored, or held. All on-chain transfers interface with user-controlled external non-custodial or exchange wallets.

5.1Institutional Encryption Standards

All identity dossiers, proof of residency files, and sensitive database tables are encrypted at rest using military-grade Advanced Encryption Standard (AES-256-GCM) with automated cryptographic key rotation. All communications between client terminals and backend engines are secured via Transport Layer Security (TLS 1.3).

5.2Password & Credential Hashing Architecture

Trader passwords are never stored in plaintext. Passwords are cryptographically salted and hashed utilizing high-work-factor Argon2id and bcrypt algorithms. Authentication session tokens are hashed with SHA-256 before storage in distributed caching tiers.

5.3Role-Based Access Control (RBAC) & Immutable Logs

Access to KYC verification documents is restricted strictly to vetted compliance officers on a need-to-know basis. Every document inspection, approval, or rejection generates an immutable audit record logging the administrator ID, timestamp, IP address, and inspection justification.

5.4Threat Detection & Anti-DDoS Circuit Breakers

Our cloud infrastructure employs automated intrusion detection systems, enterprise web application firewalls (WAF), distributed rate-limiting micro-services, and automated circuit breakers that throttle anomalous request velocity.

Article 06·Retention & Ledger

OTC Engine Settlement & Public Ledger Transparency

Server-authoritative execution records, pseudonymous leaderboards, and quantitative research aggregation.

6.1Server-Authoritative Execution Integrity

All trading orders, strike price calculations, algorithmic execution parameters, and trade expiration results are timestamped and archived on server-authoritative databases. These execution records provide verifiable mathematical audit trails in the event of trade settlement inquiries.

6.2Pseudonymous Leaderboards & Trader Anonymity

To promote community competition, ZyroPilot publishes platform leaderboards showcasing top challenge performers, profit split ratios, and win-rate statistics. Such rankings display solely pseudonymous trader handles. Your real legal name, email, and balance records remain strictly confidential.

6.3Anonymized Quantitative Model Refinement

We may aggregate anonymized, de-identified order books and volatility metrics to train risk management algorithms and refine platform pricing stability. Such quantitative research never includes identifiable trader data.

Article 07·Processing & Grounds

Authorized Third-Party Processors & Zero Commercial Sale

Absolute ban on selling user data, verified third-party infrastructure processors, and legal compliance disclosures.

7.1Absolute Prohibition on Commercial Data Sale

ZyroPilot upholds an uncompromised institutional commitment: we NEVER sell, lease, monetize, license, or trade your personal information, trading history, or contact details to third-party data brokers, advertising networks, or lead generators under any circumstances.

7.2Vetted Infrastructure & Service Processors

We engage reputable, contractually bound technology providers to deliver essential platform functionality. All third-party processors execute strict Data Processing Agreements (DPAs) guaranteeing data confidentiality:

  • Tier-IV Cloud Hosting & CDN Networks: Resilient distributed cloud server clusters (e.g. AWS, Cloudflare) for terminal availability and DDoS shielding.
  • Certified Identity Verification Vendors: Automated biometric verification providers evaluating liveness telemetry and checking sanctions databases.
  • Transactional Blockchain RPC Providers: High-speed blockchain query infrastructure verifying on-chain transaction hash confirmations.
  • Transactional Email & Alert Services: Secure enterprise delivery services used to dispatch critical security alerts, 2FA codes, and payout notifications.

7.3Statutory Law Enforcement Inquiries

We disclose personal data solely when mandated by binding court orders, valid judicial subpoenas, or verified statutory requests issued by competent financial intelligence units conducting lawful AML/CTF investigations.

7.4Corporate Restructuring Contingencies

In the event of a merger, acquisition, corporate reorganization, or sale of company assets, trader data will be transferred solely under ongoing confidentiality obligations equal to or exceeding this Privacy Policy.

Article 08·Retention & Ledger

Statutory Retention Schedules & Five-Year AML Archival

Active account lifecycle, non-derogable 5-year AML archival, and ephemeral telemetry rolling deletion windows.

8.1Active Account Retention Duration

We retain your active profile credentials, trading terminal configurations, and transaction records for as long as your ZyroPilot account remains active and in good standing.

8.2Five-Year Statutory AML & Financial Archival

Following profile closure, evaluation termination, or voluntary departure, statutory regulations mandate that we retain verified KYC identity dossiers, biometric verification reports, and financial transaction ledgers for not less than five (5) consecutive years from the official deactivation date.

8.3Rolling Deletion of Ephemeral Telemetry

Raw network access logs, transient IP telemetry, diagnostic WebSocket latency dumps, and session traces that are not associated with security investigations are purged automatically on rolling thirty (30) to ninety (90) day schedules.

Institutional Data Retention Schedule

Data ClassActive Account StatePost-Termination ArchivalDestruction Methodology
Account Profile & CredentialsDuration of active service12 Months (dormancy grace)Cryptographic erasure from master DB
KYC Dossiers & Photo IDsDuration of active service5 Years (Statutory AML Mandate)Secure vault shredding & key deletion
Biometric Liveness ModelsVerification period only3 Years (Identity dispute limit)Vector array cryptographic purging
Blockchain Transaction LedgersPermanent operational ledger7 Years (Statutory tax & audit)Cold archive cryptographic segregation
Technical Diagnostic Logs30 to 90 rolling daysPurged automaticallyAutomated log rotation overwrite
Article 09·Rights & Requests

Exercise of Data Subject Rights & Regulatory Requests

Access, rectification, erasure (right to be forgotten), data portability, and restriction of processing rights.

9.1Right of Access & Machine-Readable Portability

You possess the statutory right to request a comprehensive copy of your personal data held by ZyroPilot. We provide structured, standardized, and machine-readable data packages (JSON/CSV) encompassing your profile history, ledger transactions, and trade logs.

9.2Right to Rectification & Profile Correction

If any personal information in our records is inaccurate, incomplete, or out of date, you have the right to request immediate rectification. Correcting legal names following KYC verification requires transmitting updated government documentation.

9.3Right to Erasure ('Right to Be Forgotten') & Statutory Limits

You may submit an account erasure request at any time. Upon receipt, ZyroPilot will permanently purge active marketing entries, operational profiles, and terminal preferences. However, statutory AML regulations prohibit the premature deletion of KYC dossiers and financial transaction histories prior to the expiry of the mandatory 5-year retention period.

9.4Right to Restrict or Object to Processing

You hold the right to object to or restrict processing grounded in legitimate interests, or to revoke consent for non-essential communications. Revoking consent does not impact the lawfulness of processing carried out prior to withdrawal.

9.5Submission Protocol & 30-Day Response Standard

All data subject requests must be submitted in writing to our Data Protection Desk at [email protected]. To safeguard account confidentiality, identity re-verification is required. We fulfill verified requests within thirty (30) calendar days at zero administrative cost.

Article 10·Transfers & Cookies

Authentication Cookies & Client Storage Architecture

Essential security cookies, local storage for terminal charts, and zero cross-site behavioral tracking cookies.

10.1Essential First-Party Security Cookies

ZyroPilot utilizes strictly necessary first-party cookies to manage secure user sessions, maintain cross-subdomain authentication, and protect against Cross-Site Request Forgery (CSRF). These cookies are configured with HttpOnly, Secure, and SameSite=Strict attributes.

10.2Local Storage for Terminal Customization

Our web trading terminal uses HTML5 LocalStorage to preserve your chart layout preferences, indicator configurations, selected currency pairs, and visual theme settings directly on your device without transmitting unnecessary cookies over the network.

10.3Strict Ban on Cross-Site Tracking Pixels

We do not embed third-party tracking pixels, invasive behavioral surveillance cookies, or cross-domain ad-tech beacons. Your browsing patterns within our ecosystem are never monetized or shared with external ad networks.

10.4Browser Cookie Management & Disabling

You can disable or delete cookies via your browser settings. However, disabling essential first-party cookies will prevent secure login and terminal order execution.

Article 11·Transfers & Cookies

Cross-Border Data Transfers & International Safeguards

Cloud node distributions, Standard Contractual Clauses (SCCs), and jurisdictional data protections.

11.1Cross-Border Infrastructure Logistics

To deliver ultra-low-latency trading and real-time tick distribution across five continents, personal data and encrypted verification dossiers may be processed on secure cloud clusters located outside your sovereign country of residence.

11.2Standard Contractual Clauses (SCCs) & Adequacy Safeguards

Where personal data originates in the European Economic Area (EEA), United Kingdom, or Switzerland and is transferred internationally, ZyroPilot enforces standard contractual clauses approved by the European Commission, along with supplemental technical encryption safeguards, to ensure an equivalent level of protection.

11.3Enforceable Third-Party Safeguards

Every foreign service provider, identity verification partner, or technical node operator is bound by strict contractual confidentiality mandates and is legally prohibited from processing data for independent purposes.

Article 12·General & Governance

Supervision, Data Protection Officer & Escalation Desk

Direct contact channels for our Data Protection Officer (DPO), regulatory escalation, and policy update procedures.

12.1Designated Data Protection Officer (DPO)

ZyroPilot has appointed a dedicated Data Protection Officer to supervise regulatory compliance, monitor vault security, and serve as the direct contact point for supervisory authorities and traders. You may contact our DPO directly at [email protected].

12.2Supervisory Authority Complaint Rights

If you believe our processing of your personal data violates statutory regulations and our Data Protection Desk has not resolved your concern satisfactorily, you hold the legal right to lodge a formal complaint with your national data protection supervisory authority.

12.3Policy Amendments & Advance Notice Protocol

ZyroPilot reserves the right to amend this Privacy Policy periodically to reflect technical enhancements or statutory updates. Material changes will be communicated via terminal banner notices or registered email at least fourteen (14) calendar days prior to becoming effective.

12.4Conclusive Institutional Authority

ZyroPilot's legal compliance and risk departments retain sole and definitive authority regarding the operational interpretation of this Policy, subject to binding statutory legislation.

Document:Ref ZP-PRV-2023-V2Effective Oct 14, 2023Amended Nov 18, 2024DPO: [email protected]
FAQ

Privacy & data governance FAQ

Direct clarifications regarding vault encryption, identification data storage, erasure requests, and GDPR rights.

Does ZyroPilot sell, monetize, or license personal data to third parties?

Never. ZyroPilot operates under an institutional covenant prohibiting the sale, commercial lease, or monetization of trader information, contact records, or trading patterns to any third-party advertisers or data brokers under any circumstances.

How are my KYC identity documents and biometric liveness scans encrypted?

All government identification dossiers and biometric vectors are secured in an isolated compliance vault utilizing AES-256-GCM encryption with automated key rotation. Access is strictly restricted to vetted compliance officers via role-based access control (RBAC).

Can I request complete erasure of my personal data under GDPR or CCPA?

Yes. You may submit an erasure request to [email protected]. Operational accounts and marketing registries will be purged immediately. However, statutory Anti-Money Laundering (AML) regulations mandate that identification dossiers and financial ledgers be archived for five (5) years following profile closure.

Are my trading strategies and orders visible to other users?

No. Individual order parameters, position sizes, and trade timing are strictly confidential. Our public leaderboards display only pseudonymous trader handles and aggregate performance ratios, never revealing your legal identity or proprietary strategy details.

Does ZyroPilot collect or store my cryptocurrency private keys or seed phrases?

No. ZyroPilot only records public destination addresses and transaction hashes (txHash) for balance deposits and performance fee distributions. We never request, store, or hold private keys or seed phrases.

How do I contact the Data Protection Officer (DPO) or submit an official data request?

You can write directly to our designated compliance desk at [email protected]. Data subject access and portability requests are processed free of charge within thirty (30) calendar days.

Start Trading Binary Options
with Institutional Capital

Prove your disciplined strategy from only $3, access up to $400,000 funded capital, and keep up to 90% of your profits.

Start Challenge
Instant setup • Guaranteed 24h payouts
ZyroPilot Dashboard UI Mockup
ZyroPilot

Institutional binary options proprietary trading firm. Access up to $400,000 in funded capital with sub-second OTC fills and guaranteed 24-hour cryptocurrency payouts.

Challenges
Evaluation TiersTrading Rules$3 Mini ChallengeInstant FundingFunded Accounts
Platform
Trading TerminalDemo PracticeTrader ReviewsExecution EngineSettlements
Company
About ZyroPilotPartner ProgramContact DeskHelp CenterProp Firm FAQ
Legal
Terms of ServicePrivacy PolicyAML & KYC PolicyRisk DisclosureRestricted Countries

Regulatory & Risk Disclaimer: Trading binary options, OTC contracts, and financial derivatives carries a high level of risk and may not be suitable for all participants. ZyroPilot Technologies Ltd. is a proprietary trading evaluation firm; all challenge accounts operate in a simulated trading environment with synthetic OTC liquidity feeds. We do not accept retail deposits, manage third-party funds, or provide investment advice. Past simulated performance does not guarantee future results, and services are unavailable in restricted or sanctioned jurisdictions.

Copyright © 2026 ZyroPilot Technologies Ltd. All rights reserved.
Payments:AMEXPayPay₿₮
Home
3 $
Challenges
Research
Support
Trade