Tradyr.ai Privacy Notice

Version: 1.1.0 | Date: 2026-04-30

Overview

Tradyr.ai collects and processes information needed to operate the application, authenticate users, provide requested integrations, support billing, deliver emails, and maintain security and auditability.

Information We Process

We may process:

Broker credentials and AI-provider keys supplied by users are stored encrypted at rest by the application.

How We Use Information

We use information to:

User Activity Audit Logging

For security, troubleshooting, abuse prevention, and compliance with applicable regulatory regimes (including, where applicable, GDPR Article 32 and NIST 800-53 AU controls), Tradyr.ai records an audit entry for every authenticated request the application receives. Each entry captures the action category and verb, request path and HTTP method, outcome (ok / client_error / blocked / error), HTTP status code, request duration, originating IP address, user-agent string, and a redacted summary of the request payload.

Sensitive payload fields — including but not limited to password, token, api_key, cookie, and authorization headers — are auto-redacted before any audit row is written to durable storage. The redaction occurs at capture time and is re-applied at read time as a defense-in-depth measure; the original sensitive values are never written to disk by the audit subsystem.

User activity audit data is retained for five (5) years from the date of capture, after which entries are removed automatically by a scheduled retention sweep. Independently captured probe / security event records (e.g. SQL-injection, XSS, or path-traversal patterns observed in request payloads) are retained for three (3) years.

Self-Service Access ("My Activity")

Authenticated users can view their own audit trail at any time via the My Activity panel inside the application. The panel exposes only the entries belonging to the signed-in user; the underlying API is hard-filtered server-side to the requesting user's identifier and cannot be used to query another user's activity.

GDPR Right-to-Erasure Handling

Where a user exercises a right of erasure under applicable data-protection law (e.g. GDPR Article 17), Tradyr.ai will anonymize the user-identifying foreign key on retained audit entries while preserving the forensic record of the action verb, timestamp, originating IP address, and outcome. Retaining this minimum forensic record is necessary for our legitimate interests in fraud prevention, abuse investigation, and regulatory reporting, and is consistent with the GDPR Article 17(3)(b) and (e) exceptions for compliance with legal obligations and the establishment, exercise, or defence of legal claims.

External Service Providers

Tradyr.ai relies on third-party providers that may process some categories of information as needed to deliver the service, including infrastructure, security, billing, email, AI-provider, and brokerage integration providers.

Data Security

Tradyr.ai uses application-layer controls including authentication, access control, encryption for sensitive stored credentials, audit logging, automated probe-pattern scanning, and other security measures described in its internal security documentation (see SSP §19 — User-Action Audit Framework).

Contact

Questions regarding privacy or data handling may be directed to [email protected]. Requests to access, correct, or erase personal information may be made to the same address; responses are typically issued within thirty (30) days.