Version française

Privacy: the Trade Manager licence server

Version 1 of [To be completed: publication date].

At a glance

Your right to object

You may object at any time, on grounds relating to your particular situation, to the processing based on our legitimate interest (the check log, the monitoring of slot moves, back-ups: section 3). Write to [To be completed: contact for personal data]. We will stop that processing unless we demonstrate compelling legitimate grounds that override your interests, or unless the data is needed to establish, exercise or defend legal claims.

1. Who is responsible for your data

Controller: Oli Consulting FZE [To be completed: exact name and legal form], Ajman Free Zone (United Arab Emirates), trade licence no. [To be completed], [To be completed: full street address]. Contact for your data: [To be completed: e-mail address for personal data, or the support address].

Representative in the European Union (Article 27 GDPR): [To be completed: name and address of the representative appointed by Oli Consulting FZE]. You may contact the representative about your data, in addition to us or instead of us.

Data protection officer: Oli Consulting FZE has not appointed one.

Technical service provider (processor): Brandon Maestu, a sole trader established in France (SIREN 949 911 713), designs and operates the licence server on behalf of Oli Consulting FZE, following its written instructions.

2. What this notice covers

It covers the data processed by the Trade Manager licence server (https://licence.olinvestprive.fr): when you activate and use Trade Manager, and when the Oli Consulting FZE team creates and manages your key.

It does not cover your payment: that is processed by the payment method you chose with the seller (for example an online payment platform or a bank transfer), under its own rules; our server never receives your banking data. Nor does it cover conversations with support on Telegram, or the olinvestprive.fr website, which have their own rules.

3. What data, why, on what legal basis, for how long

DataPurposeLegal basis (GDPR, Art. 6(1))Retention
Your key (stored as a fingerprint and an encrypted copy, never in clear), the plan, the number of slots, the end dateRun your licence, count the licences soldPerformance of the contract (b); legitimate interest (f): proof of salesFor as long as your key can be used, so with no limit for a lifetime licence (see below)
Your order, if it was entered: your name, your e-mail address, your payment reference, the payment method, the amount, a noteDeliver your key, answer support requests, prove the salePerformance of the contract (b); legitimate interest (f): proof5 years after the last activity of your licence, then erased
Your MetaTrader accounts: account number, broker server name, platform (MT5 or MT4), account type (live, demo, contest), software version, dates of activation, move and last checkApply your licence (slots, moves), answer support requestsPerformance of the contract (b)5 years after the last activity of your licence, then numbers and servers replaced by a fingerprint
Your confirmation at activation: date and time, version of the texts confirmed, account from which you gave itProve that you confirmed the licence agreementLegitimate interest (f): proofWith your key (the account number follows the rule for your MetaTrader accounts)
The check log: for each call from Trade Manager, the date and time, the account (number, server, platform, type), the version, the server's answer and the IP addressSecurity of the service, detection of abuse (random key guessing, shared keys), explaining a refusal when you contact supportLegitimate interest (f): security of the service and fraud prevention6 months
The e-mails we send you, if you gave your e-mail address: your key (if the team chooses to send it by e-mail), the confirmation of your activation, necessary notices (mandatory version, security incident, end of service)Perform the contract and inform youPerformance of the contract (b)Our database only records that an e-mail was sent, without its content. At Brevo, the sending log is kept for [To be completed: period set in the Brevo account, 6 months proposed], without the content of the messages
Back-ups: an encrypted copy of the database, made every night and kept outside the databaseBeing able to restore everything after an incidentLegitimate interest (f): security and continuity of the service[To be completed: 30 days proposed], then erased by the technical service provider
The host's technical logs: the requests received, including the IP addressRun and secure the serviceLegitimate interest (f)1 day
Statistics: number of calls per day, per answer and per platform, with no personal dataMonitor the activity of the serviceAnonymous dataNo limit

What these periods mean. The fingerprint and the encrypted copy of your key, and the history of its slots, stay in the database for as long as your key can be used: that is what makes it work and what counts the licences sold; for a lifetime licence there is therefore no end date, and this is still personal data. The "last activity" of your licence is the latest of these dates: last check by Trade Manager, end of your subscription, deactivation, action by support. Five years is the general limitation period under French law (Article 2224 of the Civil Code): it allows us to prove the sale and the operation of your licence in the event of a dispute. When it expires, your name, e-mail address, payment reference and note are erased, and your account numbers and servers are replaced by a fingerprint (pseudonymised data, which is still personal data); this is done at the latest during the annual review that follows the expiry.

If you are a member of the team using the administration interface: we process your name, e-mail address, role, password (as a fingerprint), second factor (encrypted), sessions, and the log of your sign-ins (date, result, IP address, browser) for 12 months; your name and e-mail address are kept while you have access and for 5 years afterwards, then replaced by an identifier; the log of actions (who did what, and when) is kept for the whole life of the service, then 5 years, to prove sales and the proper management of keys. Legal basis: legitimate interest (f) in securing and tracing the administration.

4. Where this data comes from

5. What is required and what is optional

Your key and your MetaTrader account data are required: without them your licence cannot be checked.

Your name and e-mail address are optional. Without an e-mail address we can neither send you your key or the confirmation of your activation by e-mail, nor warn you by e-mail of a new mandatory version or of an incident. Without a name or e-mail address, support finds you through your key or your account number.

6. Who has access to your data

Licence server data is never used for advertising or marketing, and is never sold.

7. Transfers outside the European Union

To the United Arab Emirates. The Oli Consulting FZE team accesses the data from the United Arab Emirates. That country is not covered by an adequacy decision of the European Commission, and this transfer is not covered, to date, by standard clauses of the Commission suited to our situation (a controller established outside the Union but subject to the GDPR). It relies on: [To be completed after legal advice: transfer instrument chosen and GDPR article]. You can obtain a copy by writing to [To be completed: contact for personal data]. The European Commission is preparing standard clauses for this case; this notice will be updated when they are adopted.

To the United States. Vercel Inc. and Databricks, Inc. (with Neon, LLC) are US companies: although the application and the database are hosted in Frankfurt, they may access data from the United States, for example for maintenance. They are certified under the EU–US Data Privacy Framework, recognised by the European Commission's adequacy decision of 10 July 2023.

By Brevo's service providers. Brevo hosts its data in the European Union, but some of its own service providers are located outside the Union: in the United States (content delivery network and firewall, support tool, dashboards, support and maintenance) and in India (support and maintenance). According to the list published by Brevo, these transfers rely, depending on the provider, on the Data Privacy Framework, on standard contractual clauses of the European Commission or on binding corporate rules.

8. Automated decisions

The server automatically decides whether an account may open orders, by applying the rules of your licence: valid key, end date, slots, software version. No decision is based on profiling. The administration interface only flags to the team the keys whose slots have been moved more than 10 times in 30 days; a person then reviews the situation before taking any measure. If you dispute a decision, write to support: a member of the team will review it and can correct it.

9. Your rights

You may ask to access your data, to have it corrected or erased, to restrict its use, and to receive the data you provided to us in a machine-readable format. You may object to processing based on our legitimate interest (see "Your right to object" at the top of this notice). If you live in France, you may also set instructions on what happens to your data after your death.

Some data is necessary for your licence or to prove the sale: erasing it may make your licence unusable, or may only be possible at the end of the retention period; we will tell you if so.

To exercise your rights, write to [To be completed: contact for personal data], or to the representative in the Union (section 1). We may ask you to prove that the key or account concerned is yours. We reply within one month, which may be extended by two months if the request is complex; we would then tell you why.

You may also lodge a complaint with the data protection authority of the country where you live or work, or where the infringement took place; in France, the CNIL (cnil.fr).

10. Security

The server can only be reached over HTTPS. Your key is never stored in clear: only a fingerprint and an encrypted copy. The server's answers to Trade Manager are signed. The administration interface can only be reached with a personal account, a strong password and a mandatory second factor; sessions are short, attempts are limited, and every action is written to a log that the application can neither modify nor erase. Logs contain no key, password, name or e-mail address. An encrypted back-up is made every night. If a data breach is likely to result in a high risk to you, we will inform you as the law requires.

11. Cookies and files on your computer

The public pages of the licence server (licence, privacy, legal notice) set no cookies and use no trackers. The administration interface, reserved for the team, uses a single session cookie that is strictly necessary for signing in.

Trade Manager stores on your computer, in the MetaTrader common folder, your key (encrypted) and the server's last answer, so that it can work without calling the server all the time. These files are necessary for the service you request.

12. Changes to this notice

We will update this notice if our processing or the law changes; the version date is shown at the top. If there is a significant change, we will announce it on licence.olinvestprive.fr and by e-mail if we have your address.

Contact

Oli Consulting FZE · [To be completed: address] · personal data: [To be completed: contact for personal data] · representative in the Union: [To be completed] · support: [To be completed: Telegram] · [To be completed: support e-mail].