Statutory Framework, Data Controller Standing & Global Scope
Institutional governance, legal controller standing, jurisdictional boundaries, and protection of minors.
1.1Legal Data Controller Identification
ZyroPilot Technologies Ltd. ('ZyroPilot', 'the Company', 'we', 'us', or 'our') acts as the statutory data controller for all personal information, behavioral telemetry, and transaction metadata gathered across the ZyroPilot web terminal, trading interfaces, mobile portals, and proprietary API gateways.
1.2Material & Territorial Scope
This Privacy Policy applies to every registered trader, evaluation applicant, institutional partner, affiliate participant, and platform visitor. It governs all personal data processing activities conducted under the European Union General Data Protection Regulation (GDPR), the UK Data Protection Act, and applicable global data sovereignty frameworks.
1.3Voluntary Assent & Condition Precedent
Furnishing the personal data, identity dossiers, and network telemetry specified herein constitutes an indispensable condition precedent to opening an account, executing evaluation challenges, and receiving performance-split allocations. If you decline to provide required compliance details, ZyroPilot cannot grant access to the ZyroPilot trading ecosystem.
1.4Strict Protection of Minors
ZyroPilot maintains an absolute prohibition against registration by any individual under eighteen (18) years of age, or below the statutory age of contractual majority in their home jurisdiction. We do not knowingly solicit, process, or archive data from minors. Any discovered minor profile is purged immediately alongside permanent account termination.
Categories of Collected Data & Verification Dossiers
Account credentials, government identity dossiers, biometric liveness telemetry, and cryptocurrency ledger addresses.
2.1Account Registration Credentials & Profile Metadata
During profile creation and authentication, we record your verified email address, cryptographically hashed passwords, country of residence, preferred terminal language, and assigned unique platform identifier (UID).
2.2Identity Verification (KYC) Dossiers & Biometric Telemetry
Prior to authorizing live account balance withdrawals or evaluation performance payouts, traders must submit mandatory Customer Due Diligence (KYC) records. These comprise:
- Government-issued photo identification (International Passport, National Identity Card, or Driver's License in crisp, unedited color).
- Proof of residential address dated within the preceding ninety (90) days (bank statement, utility invoice, or local council tax assessment).
- Real-time biometric facial telemetry (3D liveness detection vectors and facial contour mapping) to verify identity authenticity and defeat automated deepfakes.
2.3Financial Ledger Records & Cryptocurrency Addresses
For balance deposits and performance fee settlements, we record public blockchain destination addresses (e.g. TRON TRC-20, BSC BEP-20, Bitcoin, Ethereum), transaction hashes (txHash), network confirmation timestamps, and ledger balances. ZyroPilot never requests, collects, or holds private keys, seed phrases, or custodial wallet credentials.
2.4Communications & Operational Desk Records
All interactions with our 24/7 compliance desk, technical support tickets, live chat dialogues, and email inquiries are recorded and retained to facilitate dispute resolution, quality assurance, and audit traceability.
Automated Device Telemetry, Networking & Anti-Fraud Logs
IP routing metadata, hardware fingerprints, browser signatures, and terminal interaction telemetry.
Automated device telemetry is continuously cross-referenced to protect trader balances from account takeovers, identify unauthorized bot deployments, and detect coordinated multi-account arbitrage rings.
3.1Network Identifiers & Geolocation Telemetry
When you access the ZyroPilot terminal, our infrastructure captures your public Internet Protocol (IP) address, Autonomous System Number (ASN), Internet Service Provider (ISP), connection port, and approximate geographic coordinates. This data is monitored in real time to enforce jurisdictional exclusions and block malicious proxy or VPN abuse.
3.2Hardware Fingerprinting & Client Signatures
We collect non-personally-identifying device signatures, including your operating system version, browser engine, screen resolution, WebGL renderer metrics, system time zone, and language preferences. These parameters form an ephemeral device token used to authenticate sessions and flag unauthorized login attempts.
3.3Terminal Interaction & Trading Latency Diagnostics
To ensure order execution transparency and diagnose execution inquiries, our servers log client-side round-trip WebSocket latency, order placement button timestamps, tick sequence numbers, and interface rendering anomalies.
Lawful Grounds for Personal Data Processing
Contractual performance, statutory AML compliance, institutional legitimate interests, and explicit consent grounds.
4.1Performance of Contractual Obligations
Processing account registration details, trading orders, evaluation performance metrics, and balance payout transfers is legally necessary to fulfill our master contractual agreement with you.
4.2Compliance with Statutory Mandates & AML Regulations
We process identity verification dossiers, liveness scans, and financial transaction logs to satisfy binding anti-money laundering (AML), counter-terrorist financing (CTF), international sanctions screening (OFAC/FATF), and corporate accounting obligations.
4.3Legitimate Institutional Interests
We process diagnostic telemetry, risk telemetry, and order behavior under our legitimate commercial interest in preserving platform integrity, preventing algorithmic latency exploitation, halting coordinated hedging schemes, and securing infrastructure against cyber attacks.
4.4Voluntary User Consent
Where we dispatch non-essential marketing newsletters, promotional challenge updates, or opt-in educational webinars, we rely strictly on your unambiguous, freely given consent, which may be revoked at any time.
Statutory Lawful Grounds Mapping Matrix
| Data Category | Primary Processing Purpose | Statutory Lawful Basis | Mandatory / Discretionary |
|---|---|---|---|
| Account Credentials | Session auth & profile management | GDPR Art. 6(1)(b) Contract Performance | Mandatory for access |
| KYC Identification | AML / CTF & Sanctions compliance | GDPR Art. 6(1)(c) Legal Obligation | Mandatory for withdrawals |
| Biometric Telemetry | Liveness verification & anti-spoofing | GDPR Art. 9(2)(a) Explicit Consent | Mandatory for KYC approval |
| Blockchain Addresses | Settlement of payout distributions | GDPR Art. 6(1)(b) Contract Performance | Mandatory for payouts |
| Device & IP Telemetry | Anti-fraud, anti-bot & security | GDPR Art. 6(1)(f) Legitimate Interest | Mandatory automated collection |
| Marketing Newsletters | Product announcements & offers | GDPR Art. 6(1)(a) Voluntary Consent | Optional / Trader opt-in |
Cryptographic Safeguards, Vault Archival & Architecture
AES-256 encryption at rest, TLS 1.3 in transit, Argon2id password hashing, and role-based access segregation.
ZyroPilot infrastructure operates under an immutable security covenant: user cryptographic private keys are never requested, stored, or held. All on-chain transfers interface with user-controlled external non-custodial or exchange wallets.
5.1Institutional Encryption Standards
All identity dossiers, proof of residency files, and sensitive database tables are encrypted at rest using military-grade Advanced Encryption Standard (AES-256-GCM) with automated cryptographic key rotation. All communications between client terminals and backend engines are secured via Transport Layer Security (TLS 1.3).
5.2Password & Credential Hashing Architecture
Trader passwords are never stored in plaintext. Passwords are cryptographically salted and hashed utilizing high-work-factor Argon2id and bcrypt algorithms. Authentication session tokens are hashed with SHA-256 before storage in distributed caching tiers.
5.3Role-Based Access Control (RBAC) & Immutable Logs
Access to KYC verification documents is restricted strictly to vetted compliance officers on a need-to-know basis. Every document inspection, approval, or rejection generates an immutable audit record logging the administrator ID, timestamp, IP address, and inspection justification.
5.4Threat Detection & Anti-DDoS Circuit Breakers
Our cloud infrastructure employs automated intrusion detection systems, enterprise web application firewalls (WAF), distributed rate-limiting micro-services, and automated circuit breakers that throttle anomalous request velocity.
OTC Engine Settlement & Public Ledger Transparency
Server-authoritative execution records, pseudonymous leaderboards, and quantitative research aggregation.
6.1Server-Authoritative Execution Integrity
All trading orders, strike price calculations, algorithmic execution parameters, and trade expiration results are timestamped and archived on server-authoritative databases. These execution records provide verifiable mathematical audit trails in the event of trade settlement inquiries.
6.2Pseudonymous Leaderboards & Trader Anonymity
To promote community competition, ZyroPilot publishes platform leaderboards showcasing top challenge performers, profit split ratios, and win-rate statistics. Such rankings display solely pseudonymous trader handles. Your real legal name, email, and balance records remain strictly confidential.
6.3Anonymized Quantitative Model Refinement
We may aggregate anonymized, de-identified order books and volatility metrics to train risk management algorithms and refine platform pricing stability. Such quantitative research never includes identifiable trader data.
Authorized Third-Party Processors & Zero Commercial Sale
Absolute ban on selling user data, verified third-party infrastructure processors, and legal compliance disclosures.
7.1Absolute Prohibition on Commercial Data Sale
ZyroPilot upholds an uncompromised institutional commitment: we NEVER sell, lease, monetize, license, or trade your personal information, trading history, or contact details to third-party data brokers, advertising networks, or lead generators under any circumstances.
7.2Vetted Infrastructure & Service Processors
We engage reputable, contractually bound technology providers to deliver essential platform functionality. All third-party processors execute strict Data Processing Agreements (DPAs) guaranteeing data confidentiality:
- Tier-IV Cloud Hosting & CDN Networks: Resilient distributed cloud server clusters (e.g. AWS, Cloudflare) for terminal availability and DDoS shielding.
- Certified Identity Verification Vendors: Automated biometric verification providers evaluating liveness telemetry and checking sanctions databases.
- Transactional Blockchain RPC Providers: High-speed blockchain query infrastructure verifying on-chain transaction hash confirmations.
- Transactional Email & Alert Services: Secure enterprise delivery services used to dispatch critical security alerts, 2FA codes, and payout notifications.
7.3Statutory Law Enforcement Inquiries
We disclose personal data solely when mandated by binding court orders, valid judicial subpoenas, or verified statutory requests issued by competent financial intelligence units conducting lawful AML/CTF investigations.
7.4Corporate Restructuring Contingencies
In the event of a merger, acquisition, corporate reorganization, or sale of company assets, trader data will be transferred solely under ongoing confidentiality obligations equal to or exceeding this Privacy Policy.
Statutory Retention Schedules & Five-Year AML Archival
Active account lifecycle, non-derogable 5-year AML archival, and ephemeral telemetry rolling deletion windows.
8.1Active Account Retention Duration
We retain your active profile credentials, trading terminal configurations, and transaction records for as long as your ZyroPilot account remains active and in good standing.
8.2Five-Year Statutory AML & Financial Archival
Following profile closure, evaluation termination, or voluntary departure, statutory regulations mandate that we retain verified KYC identity dossiers, biometric verification reports, and financial transaction ledgers for not less than five (5) consecutive years from the official deactivation date.
8.3Rolling Deletion of Ephemeral Telemetry
Raw network access logs, transient IP telemetry, diagnostic WebSocket latency dumps, and session traces that are not associated with security investigations are purged automatically on rolling thirty (30) to ninety (90) day schedules.
Institutional Data Retention Schedule
| Data Class | Active Account State | Post-Termination Archival | Destruction Methodology |
|---|---|---|---|
| Account Profile & Credentials | Duration of active service | 12 Months (dormancy grace) | Cryptographic erasure from master DB |
| KYC Dossiers & Photo IDs | Duration of active service | 5 Years (Statutory AML Mandate) | Secure vault shredding & key deletion |
| Biometric Liveness Models | Verification period only | 3 Years (Identity dispute limit) | Vector array cryptographic purging |
| Blockchain Transaction Ledgers | Permanent operational ledger | 7 Years (Statutory tax & audit) | Cold archive cryptographic segregation |
| Technical Diagnostic Logs | 30 to 90 rolling days | Purged automatically | Automated log rotation overwrite |
Exercise of Data Subject Rights & Regulatory Requests
Access, rectification, erasure (right to be forgotten), data portability, and restriction of processing rights.
9.1Right of Access & Machine-Readable Portability
You possess the statutory right to request a comprehensive copy of your personal data held by ZyroPilot. We provide structured, standardized, and machine-readable data packages (JSON/CSV) encompassing your profile history, ledger transactions, and trade logs.
9.2Right to Rectification & Profile Correction
If any personal information in our records is inaccurate, incomplete, or out of date, you have the right to request immediate rectification. Correcting legal names following KYC verification requires transmitting updated government documentation.
9.3Right to Erasure ('Right to Be Forgotten') & Statutory Limits
You may submit an account erasure request at any time. Upon receipt, ZyroPilot will permanently purge active marketing entries, operational profiles, and terminal preferences. However, statutory AML regulations prohibit the premature deletion of KYC dossiers and financial transaction histories prior to the expiry of the mandatory 5-year retention period.
9.4Right to Restrict or Object to Processing
You hold the right to object to or restrict processing grounded in legitimate interests, or to revoke consent for non-essential communications. Revoking consent does not impact the lawfulness of processing carried out prior to withdrawal.
9.5Submission Protocol & 30-Day Response Standard
All data subject requests must be submitted in writing to our Data Protection Desk at [email protected]. To safeguard account confidentiality, identity re-verification is required. We fulfill verified requests within thirty (30) calendar days at zero administrative cost.
Authentication Cookies & Client Storage Architecture
Essential security cookies, local storage for terminal charts, and zero cross-site behavioral tracking cookies.
10.1Essential First-Party Security Cookies
ZyroPilot utilizes strictly necessary first-party cookies to manage secure user sessions, maintain cross-subdomain authentication, and protect against Cross-Site Request Forgery (CSRF). These cookies are configured with HttpOnly, Secure, and SameSite=Strict attributes.
10.2Local Storage for Terminal Customization
Our web trading terminal uses HTML5 LocalStorage to preserve your chart layout preferences, indicator configurations, selected currency pairs, and visual theme settings directly on your device without transmitting unnecessary cookies over the network.
10.3Strict Ban on Cross-Site Tracking Pixels
We do not embed third-party tracking pixels, invasive behavioral surveillance cookies, or cross-domain ad-tech beacons. Your browsing patterns within our ecosystem are never monetized or shared with external ad networks.
10.4Browser Cookie Management & Disabling
You can disable or delete cookies via your browser settings. However, disabling essential first-party cookies will prevent secure login and terminal order execution.
Cross-Border Data Transfers & International Safeguards
Cloud node distributions, Standard Contractual Clauses (SCCs), and jurisdictional data protections.
11.1Cross-Border Infrastructure Logistics
To deliver ultra-low-latency trading and real-time tick distribution across five continents, personal data and encrypted verification dossiers may be processed on secure cloud clusters located outside your sovereign country of residence.
11.2Standard Contractual Clauses (SCCs) & Adequacy Safeguards
Where personal data originates in the European Economic Area (EEA), United Kingdom, or Switzerland and is transferred internationally, ZyroPilot enforces standard contractual clauses approved by the European Commission, along with supplemental technical encryption safeguards, to ensure an equivalent level of protection.
11.3Enforceable Third-Party Safeguards
Every foreign service provider, identity verification partner, or technical node operator is bound by strict contractual confidentiality mandates and is legally prohibited from processing data for independent purposes.
Supervision, Data Protection Officer & Escalation Desk
Direct contact channels for our Data Protection Officer (DPO), regulatory escalation, and policy update procedures.
12.1Designated Data Protection Officer (DPO)
ZyroPilot has appointed a dedicated Data Protection Officer to supervise regulatory compliance, monitor vault security, and serve as the direct contact point for supervisory authorities and traders. You may contact our DPO directly at [email protected].
12.2Supervisory Authority Complaint Rights
If you believe our processing of your personal data violates statutory regulations and our Data Protection Desk has not resolved your concern satisfactorily, you hold the legal right to lodge a formal complaint with your national data protection supervisory authority.
12.3Policy Amendments & Advance Notice Protocol
ZyroPilot reserves the right to amend this Privacy Policy periodically to reflect technical enhancements or statutory updates. Material changes will be communicated via terminal banner notices or registered email at least fourteen (14) calendar days prior to becoming effective.
12.4Conclusive Institutional Authority
ZyroPilot's legal compliance and risk departments retain sole and definitive authority regarding the operational interpretation of this Policy, subject to binding statutory legislation.
