Privacy Policy
This Privacy Policy explains how A3E Ecosystem Inc. collects, uses, discloses, and protects your personal information when you use the NeuroTrade platform and related services.
1. Who We Are
A3E Ecosystem Inc. is a corporation incorporated under the laws of Canada, with its principal place of business in Ontario, Canada. We are the data controller responsible for the personal information collected through the NeuroTrade platform.
For all privacy-related inquiries, you may contact our Privacy Officer at:
Email: [email protected]
Subject line: Privacy Inquiry
2. Information We Collect
We collect the following categories of personal information:
2.1 Information You Provide Directly
| Data Type | Purpose |
|---|---|
| Email address | Account creation, authentication, service communications, and billing notifications |
| Name (if provided) | Account personalisation and customer support |
| Password (hashed) | Account authentication; stored only in bcrypt-hashed form and never in plaintext |
| Exchange API Keys | Executing trades on your behalf on your connected exchange accounts |
| Payment information | Processed by Stripe; the Company does not directly store your credit card number or banking details |
2.2 Information Collected Automatically
| Data Type | Purpose |
|---|---|
| Trading activity data | Positions opened, closed, and modified through the Platform; trade outcomes and performance metrics |
| Strategy configuration data | Strategy selections, risk parameters, and backtesting inputs |
| Usage and interaction data | Pages visited, features used, session duration, and navigation patterns |
| Device and browser data | Browser type and version, operating system, screen resolution, and device identifiers |
| IP address | Fraud prevention, security monitoring, and approximate geolocation for service optimisation |
| Cookies and similar technologies | Session management, preference storage, and analytics (see our Cookie Policy) |
2.3 Information from Third Parties
We may receive limited information from third-party services you connect to the Platform, including:
- Cryptocurrency exchanges: Account identifiers, balance snapshots, and trade confirmations returned via exchange APIs in response to your authorised connections
- Payment processor (Stripe): Transaction confirmations, subscription status, and billing-related identifiers
3. How We Use Your Information
We use your personal information for the following purposes:
- Providing and operating the Services: Authenticating your account, executing trades through your exchange API Keys, generating trading signals, and delivering the features of your subscription tier
- Improving the Platform and AI models: Analysing aggregated, de-identified trading data to improve the accuracy and performance of our AI models and strategy algorithms. Individual trade data is never shared externally in identifiable form.
- Communicating with you: Sending transactional emails (account confirmations, password resets, billing receipts), service announcements, security alerts, and, where you have opted in, product updates and educational content
- Billing and payments: Processing subscription payments, issuing receipts, and managing your billing cycle through our payment processor
- Security and fraud prevention: Detecting and preventing unauthorized access, abuse, and fraudulent activity
- Legal compliance: Meeting our obligations under applicable law, responding to legal process, and enforcing our Terms of Service
4. Security of Exchange API Keys
We take the security of your exchange API Keys with the utmost seriousness:
- API Keys are encrypted at rest using AES-256 encryption
- Keys are stored in an isolated, access-controlled database separate from other user data
- API Keys are only used to execute trades and retrieve market data as directed by your configured strategies
- We strongly recommend configuring API Keys with trade-only permissions (no withdrawal capability) on your exchange
- API Keys are permanently deleted within 30 days of account closure
5. Legal Basis for Processing (GDPR)
For users in the European Economic Area (EEA), United Kingdom, or Switzerland, we process your personal data under the following legal bases as defined by the GDPR:
| Legal Basis | Applies To |
|---|---|
| Performance of a contract | Processing necessary to provide the Services you have subscribed to, including account management, trade execution, and billing |
| Legitimate interests | Improving our AI models using aggregated data, preventing fraud, ensuring platform security, and conducting internal analytics |
| Consent | Sending marketing communications and optional product updates; use of non-essential cookies |
| Legal obligation | Complying with applicable tax, anti-money laundering, or other regulatory requirements |
6. Data Sharing and Disclosure
We do not sell your personal information. We share your data only in the following limited circumstances:
- Service providers: We engage trusted third-party service providers who process data on our behalf, including Stripe (payment processing), hosting infrastructure providers, and email delivery services. These providers are contractually obligated to protect your data and use it only for the purposes we specify.
- Cryptocurrency exchanges: When you connect an exchange via API Keys, trade instructions are transmitted to the exchange to execute on your behalf. The exchange processes this data under its own privacy policy.
- Legal requirements: We may disclose your information if required by law, regulation, legal process, or governmental request, or if we believe in good faith that disclosure is necessary to protect the rights, property, or safety of the Company, our users, or the public.
- Business transfers: If A3E Ecosystem Inc. is involved in a merger, acquisition, or sale of assets, your personal information may be transferred as part of that transaction. We will notify affected users before their personal information becomes subject to a different privacy policy.
7. International Data Transfers
Your personal information is primarily stored and processed in Canada. Canada has been recognised by the European Commission as providing an adequate level of data protection under GDPR Article 45.
If we transfer your data to service providers located outside Canada or the EEA, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the European Commission, or reliance on the service provider's compliance with an adequate data protection framework.
8. Data Retention
We retain your personal information for as long as necessary to fulfil the purposes described in this Privacy Policy:
- Active accounts: Personal information is retained for the duration of your account's active status
- After account closure: We retain your data for a period of one (1) year following account closure, after which it is permanently deleted or irreversibly anonymised. This retention period allows for dispute resolution, fraud prevention, and compliance with legal obligations.
- Exchange API Keys: Deleted within 30 days of account closure
- Aggregated analytics data: De-identified, aggregated data that cannot be used to identify you may be retained indefinitely for research and service improvement purposes
- Legal holds: If we are required to retain data pursuant to a legal obligation or active legal proceeding, we will retain the necessary data until the obligation is resolved
9. Your Rights
Under PIPEDA and, where applicable, the GDPR, you have the following rights regarding your personal information:
- Right of access: You may request a copy of the personal information we hold about you
- Right to correction: You may request that we correct inaccurate or incomplete personal information
- Right to deletion: You may request that we delete your personal information, subject to our legal retention obligations
- Right to data portability (GDPR): You may request a machine-readable copy of the personal data you have provided to us
- Right to restrict processing (GDPR): You may request that we limit how we use your data in certain circumstances
- Right to object (GDPR): You may object to data processing based on our legitimate interests
- Right to withdraw consent: Where processing is based on your consent, you may withdraw that consent at any time without affecting the lawfulness of prior processing
To exercise any of these rights, contact us at [email protected] with the subject line "Privacy Rights Request." We will respond within 30 days, as required by PIPEDA, or within one month, as required by the GDPR.
If you are located in the EEA and believe we have not adequately addressed your privacy concern, you have the right to lodge a complaint with your local data protection supervisory authority.
10. Children's Privacy
The Platform is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected personal information from a person under 18, we will take steps to delete that information promptly. If you believe a minor has provided us with personal information, please contact us at [email protected].
11. Security Measures
We implement appropriate technical and organisational measures to protect your personal information, including:
- Encryption of data in transit (TLS 1.2+) and at rest (AES-256)
- Secure password hashing using bcrypt
- Role-based access controls limiting employee access to personal data
- Regular security assessments and vulnerability scanning
- Isolated storage for sensitive credentials (API Keys)
- Logging and monitoring of access to personal data systems
While we strive to protect your personal information, no method of electronic transmission or storage is completely secure. We cannot guarantee absolute security, but we are committed to maintaining industry-standard protections and responding promptly to any security incidents.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, or legal requirements. When we make material changes, we will:
- Update the "Last updated" date at the bottom of this page
- Notify registered users by email at least 14 days before the changes take effect
- Post a notice on the Platform
We encourage you to review this Privacy Policy periodically. Your continued use of the Platform after changes take effect constitutes your acceptance of the revised policy.
13. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
A3E Ecosystem Inc.
Privacy Officer
Ontario, Canada
Email: [email protected]
Website: a3eecosystem.com
For complaints under PIPEDA, you may also contact the Office of the Privacy Commissioner of Canada at priv.gc.ca.
Last updated: April 10, 2026