Privacy policy

Last updated: 22/05/2025

This Privacy Policy describes how we collect, use, share, and protect your personal data when using the website braintechfinance.com and the web application app.braintechfinance.com (hereinafter, the “Services”).

1. Data controller

1.1 The Data Controller is currently Braintech Finance. For any question or request regarding the processing of personal data, you may contact us at: info@braintechfinance.com

1.2 At this time, Braintech Finance does not fall within the circumstances requiring appointment of a Data Protection Officer (DPO) pursuant to Article 37 GDPR.

2. Personal data collected

The Services are not intended for individuals under 18 years of age. In case of unauthorized registration, we will promptly delete the data pursuant to Article 8 GDPR.

We collect the following User personal data:

  • Identification and contact data: name, surname, date of birth, telephone number, email address.

  • Service data: MT4 account number (MT4 Account), account balance, history of operations executed through Braintech Finance automated Strategies, IDs of active strategies, risk percentage and capital allocation percentage set for each active strategy.


These data are necessary to provide the Services and enable the creation and management of the User account.

3. Legal basis for processing

The processing of your personal data relies on the following legal bases under Regulation (EU) 2016/679 (“GDPR”):

  • Performance of a contract (Art. 6(1)(b) GDPR): personal data (such as name, surname, date of birth, telephone number, email) are necessary for registration, use of the Services, and fulfilment of related contractual obligations.

  • Consent (Art. 6(1)(a) GDPR): the User provides consent by expressly accepting this Privacy Policy and the Terms & Conditions during registration. Where legally required (e.g., for non-technical cookies), consent is free and may be withdrawn at any time without affecting the lawfulness of processing prior to withdrawal.

  • Legitimate interest (Art. 6(1)(f) GDPR): the Controller processes aggregated browsing data (e.g., Google Analytics with IP anonymization) for statistical purposes and abuse prevention, considering its interest overriding the fundamental rights and freedoms of the data subjects.

We do not send newsletters or commercial communications at this time. Any future marketing activities will require a separate, optional consent.

4. Methods and purposes of data use

4.1 Service provision

  • Management and maintenance of the User’s account.

  • Display and management of MT4 account number, balance, and trade history.

  • Sending of technical or functional emails (e.g., registration confirmation, password reset).

4.2 Internal analysis and improvement

  • We use data (in aggregated or, where possible, anonymous form) to improve user experience and resolve technical issues.

4.3 Cookies and Google Analytics

  • Our website uses technical cookies necessary for platform operation.

  • We also use anonymized Google Analytics, which collects aggregated navigation data (e.g., geographic area, visited pages) without directly identifying the User. A dedicated cookie policy may be published in the future. We do not perform personal profiling for commercial or advertising purposes.

Tracking is executed with anonymized IP addresses and aggregated data, in accordance with the Italian Data Protection Authority’s Cookie Guidelines (10/06/2021).

Summary Table – Purpose / Data / Legal Basis

Account management and Service delivery (login, MT4-sync, service emails): identification data, credentials, and MT4 data. Legal basis: Art. 6(1)(b) GDPR – performance of a contract.

Technical session cookies necessary for the functioning of the website/app: session ID and user interface preferences. Legal basis: Art. 6(1)(f) GDPR – legitimate interest.

Google Analytics with anonymized IP (statistics): aggregated browsing data. Legal basis: Art. 6(1)(f) GDPR – legitimate interest.

Possible future direct marketing activities (newsletter, promotions): email and interactions with campaigns. Legal basis: Art. 6(1)(a) GDPR – consent.

Profiling and automated decision-making: not applicable (the service does not perform profiling under Art. 22 GDPR).

5. Data Sharing and Transfer

5.1 Third-party providers
Collected data may be processed on systems operated by third-party providers (e.g., hosting services, Microsoft, Google), possibly located outside the European Union.

5.2 Standard Contractual Clauses (SCC)
For transfers outside the EU, we apply Standard Contractual Clauses (SCC) under the GDPR, as well as additional security measures where necessary, to ensure processing meets European protection standards.

5.3 Legal obligations
In exceptional circumstances, we may share data with public or judicial authorities when required by applicable law.

6. Data Security

6.1 Protection measures
We adopt physical, logical, and organizational security measures (encryption, network protections, personnel training, etc.) to prevent unauthorized access, disclosure, or loss of personal data.

6.2 Limited access
Access to personal data is restricted to authorized personnel and collaborators who need such access for the purposes described.

7. User rights

Under the GDPR, the User may at any time:

  • Access their personal data;

  • Rectify inaccurate or incomplete data;

  • Request deletion (“right to be forgotten”), except where processing is required by law;

  • Request restriction of processing under Article 18 GDPR;

  • Object to processing, where applicable;

  • Request data portability to another Controller, where technically feasible.

To exercise these rights, the User may write to
info@braintechfinance.com with subject: “Privacy rights request”.
A reply will be provided within 1 month of the request, except in cases of particular complexity.

7.1 Right to lodge a complaint
Should the User believe that their personal data is being processed in violation of data protection law, they have the right to lodge a complaint with the Italian Data Protection Authority (www.garanteprivacy.it), without prejudice to any other administrative or judicial remedy.

8. Data retention period

• Tax and accounting documentation: stored for 10 years pursuant to Art. 2220 Civil Code and Art. 22 Presidential Decree 600/1973.

• Marketing consent logs: stored for 24 months from consent withdrawal or last contact, pursuant to the Italian DPA’s provision of 24/02/2005 and Marketing Guidelines 2021.

• Anonymized Analytics Cookies: aggregated data stored for 14 months, as set by the Italian DPA’s Cookie Guidelines (10/06/2021).

All other personal data are stored only for the time strictly necessary to fulfil the purposes described in this policy and then deleted or anonymized, unless a different legal obligation applies.

9. Absence of direct marketing activities

We currently do not send any commercial communications or newsletters to our Users. Any automated emails relate solely to registration steps, password recovery, or essential service communications.

Should direct marketing activities be introduced in the future, a separate and specific consent will be requested from the User.

10. Changes to the privacy policy

Any changes to this Privacy Policy will be communicated to registered Users by email or made publicly available on our website. We invite you to periodically review this page to stay informed of updates.

For any questions or clarification regarding this Privacy Policy, you may contact us at: info@braintechfinance.com