This text is a draft and requires legal review before publication. Sections that are not final contain no invented clause: they are left with a plain statement that they have not been drawn up yet, and we make no claim there. In its current form this text does not replace a signed, binding agreement.
Privacy Policy
What personal data we collect, why we process it, who we share it with, how long we keep it and how you can exercise your rights.
Last updated: 07/25/2026
1. Controller and scope
The data controller is the party operating the panel at bilgintrade.com; this document covers that panel and the services attached to it. The legal entity name, address, data protection registry number and official e-mail address will be published in this section once incorporation and registration are complete. Until then you can submit data subject requests from the support form inside the panel; that channel works today.
The exchanges you connect to through the panel are governed by their own privacy policies; the controller of the data in your exchange account is that exchange.
2. Data we collect
We keep only the data needed to run the service. These are the categories present in our records:
- Account: e-mail address, username, an irreversible hash of your password (Argon2id — the raw password is never stored in any layer), account status, language preference, e-mail verification and last login times.
- Two-factor authentication: your TOTP secret, wrapped (encrypted) with the master key.
- Session: a hash of the session token, IP address, browser identifier (user-agent), session start, last seen and expiry times.
- Exchange connection: your exchange user id (UID), approval status and rejection reason, encrypted API key/secret/passphrase, the masked last characters of the key, and permission verification results.
- Trading: the setups shown to you, trade attempts, orders, positions, executed trades, profit-and-loss ledger records and execution reports coming from the exchange.
- Preferences: leverage, margin, risk settings, the coins and timeframes you follow, notification preferences, theme, language and whether you join the ranking.
- Support: request category and title, the messages you write and the files you upload.
- Referral and revenue: daily trading volume, fees and our share per UID, as reported by the exchange affiliate report.
- Audit log: administrator actions and critical changes on your account, together with IP address, browser identifier and request id.
- Notifications: in-panel notification records and their read status.
3. Data we do not collect
We do not ask for, collect or store the following. If a field is never requested from you, that data simply does not exist in the system.
Screenshots attached to a support request may contain identity or balance information; we recommend redacting the parts that are not needed before uploading.
- Identity documents, national id numbers, date of birth.
- Postal address and phone number.
- Payment card or bank account details — never requested, because the service is free.
- Advertising cookies, third-party tracking identifiers and location data.
4. Purposes and legal bases
We process your data only for the purposes below, and the list of purposes is complete. Which legal basis each purpose relies on under the Turkish data protection law (art. 5) and the GDPR (art. 6) has not been determined yet and will be published in this section after legal review — until then we make no claim as to the specific ground we rely on.
- Performance of the contract: creating your account, showing setups, sending orders upon your instruction and managing the protective orders of the position.
- Legitimate interest: fraud and multi-account detection, system security, debugging and abuse prevention.
- Legitimate interest: verifying referral attribution and reconciling revenue (the basis of our business model).
- Legal obligation: retaining records for the periods required by law.
- Explicit consent: only for marketing and campaign e-mails; the service itself does not depend on this consent and it can be withdrawn at any time.
5. How your exchange API key is protected
Your API key is the most sensitive data in the service, so it gets its own section. Keys are stored with envelope encryption: a separate data key is generated per exchange account, that key is wrapped with a master key (KEK), and every field is encrypted with its own random value.
The point of this design is that the keys stay unreadable even if a database backup is obtained. The master key is not kept in the database but in a separate secret store.
- Decryption happens only inside the order execution process; neither the web interface nor the admin console can decrypt a key.
- The full key is never shown on any screen; only its masked last characters are visible.
- Keys are never written to logs; secret fields are redacted in the logging layer.
- In our records withdrawal permission is kept off by a database constraint and no withdrawal order is ever issued. The key’s permission at the exchange can be read only on OKX and Bitget, so a key that carries it is refused at linking time only on those two.
- Backup copies that leave the server are encrypted on the server; the decryption passphrase is not kept where the backup is stored.
6. Sharing, transfers and sub-processors
We do not sell your personal data and do not share it with advertising networks. We rely on the following providers to run the service:
In addition, upon your instruction your order details are sent to the relevant exchange (OKX, Bitget, WEEX); your UID is matched with that exchange’s affiliate system for referral attribution.
Because our servers are located in Germany, your data is processed abroad; this follows from where the sub-processors listed above are established. The legal basis for that cross-border transfer under the Turkish data protection law (art. 9) — explicit consent or standard contractual clauses — has not been determined yet and will be published in this section after legal review. This text does not assert that a basis is already in place.
- Hetzner (Nuremberg, Germany) — server hosting and database.
- Cloudflare — domain, firewall, TLS and content delivery; backups and support attachments in R2 object storage.
- Brevo (Sendinblue SAS, France) — transactional e-mail delivery: account verification and password reset messages. Only your e-mail address and the contents of the message are transferred; your password, exchange API keys and trading data are NOT sent there.
- Google Drive — encrypted off-site backup copies only; files are encrypted before upload.
- We use no external provider for error tracking or log collection: application logs stay on our own server and are not sent to any third party. If that changes, the new provider is added to this list.
7. Retention periods
We keep data for as long as the purpose requires. The agreed periods are:
When a period expires, the record is deleted or pseudonymised. If a legal dispute is ongoing, the related records are kept until it is resolved.
- Order events and ledger records: 7 years (tax and financial regulation).
- Executed trades and setup records: while your account remains open (history and ranking).
- Audit log: 24 months.
- Support tickets and messages: 36 months after closure.
- Session records: 30 days after the session ends.
- In-panel notifications: 180 days.
- Raw incoming signal records: 14 days.
- Backups: local database dumps on the server 14 days, encrypted off-site copies 90 days. The encryption key bundles that make those copies readable are kept 400 days; they carry no personal data.
8. Your rights and how to exercise them
You have the following rights over your personal data:
You can submit a request by signing in to the panel and using the Support tab; that is the channel that works today and your request is recorded. Requests are answered within 30 days at the latest. The official postal and registered e-mail address for written requests, together with the identity verification method required by the applicable data protection procedure, have not been determined yet; they will be published in this section once the legal entity is registered. To be clear: this means there is no working channel today for a request made from outside the panel, by someone who has no account.
On an erasure request the account is not physically deleted but pseudonymised: e-mail and username are removed irreversibly, while financial records remain for the statutory retention period in a form that cannot be linked to you. If you have an open position, the erasure waits until that position is closed.
- Learn whether your data is processed and request information about it.
- Learn whether it has been used in line with its purpose.
- Request correction if it is incomplete or inaccurate.
- Request deletion or destruction once the conditions are met.
- Receive a copy of your data in a structured format.
- Object to an outcome against you produced solely by automated analysis.
9. Security measures
The main technical measures we take to protect your data are:
No system offers absolute security. If we detect a breach affecting your personal data, we notify the competent authority within the period required by law, and you as well when you are affected. The written internal procedure that fixes the deadline, the recipient and the content of such a notification has not been drawn up yet; it will be published in this section after legal review.
- The session token travels only in an HttpOnly cookie; browser scripts cannot read it.
- Passwords are hashed with Argon2id; the raw password is never stored.
- Two-factor authentication (TOTP) is supported and mandatory for staff sessions.
- Every query is scoped to your user id; access to another user's record is not possible.
- Administrator actions are written to a chained audit log where retroactive modification becomes visible.
- Backups are taken daily, verified, and a restore drill is carried out every quarter.
10. Cookies and browser storage
We use a single cookie that is strictly necessary to keep you signed in; there are no advertising or analytics cookies. Details are on the Cookie Policy page.
11. Children's data
The service is not offered to people under 18 and we do not knowingly collect data from that age group. If we learn of such a record, we close the account and delete the data.
12. Changes and contact
When this policy is updated, the new text is published on this page and the date at the top changes; material changes are announced inside the panel.
You can ask any question about our data practices through the support channel.
Questions about this document and data subject requests can reach us two ways. If you have an account, use the Support tab inside the panel: your request is recorded, answered, and the whole exchange stays in your account. If you cannot get into your account, or do not have one yet, write to [email protected].