Legal

Privacy Policy

Last updated: August 2026

CYGOX AI is a software company. Our algo bots run inside your own broker account; we never hold your money, never see your broker password, and never touch your trading capital. This policy explains what limited personal information we do handle, and how we look after it.

1. Who we are

CYGOX AI ("CYGOX AI," "we," "us," or "our") operates the website cygox.com and licenses algorithmic trading software ("algo bots") on a software-as-a-service basis. CYGOX AI is a technology provider only. We are not a broker-dealer, investment adviser, fund manager, bank, or financial institution of any description, and we have no custody of, or access to, the funds in your brokerage account.

This Privacy Policy describes our practices whenever you browse our website, subscribe to our software, or communicate with our team. It is written to satisfy the EU General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA/CPRA), and comparable privacy laws elsewhere. By continuing to use our website or services, you confirm you have read this policy; if anything here is unacceptable to you, please stop using our services.

2. The information we handle

Details you give us directly

When you create an account, book a call, submit a form, or write to us, we may receive your name, email address, phone number, country, and whatever else you choose to include in your message.

Details gathered automatically

Like most websites, our servers and analytics tools record technical data as you browse: your IP address, approximate region, browser and operating system, device category, the pages you open, how long you stay, where you arrived from, and where you leave to.

Cookies and similar tools

We use cookies, pixels, and campaign (UTM) parameters to understand traffic and measure advertising. The full inventory, retention periods, and your opt-out choices live in our separate Cookie Policy.

What we deliberately do not collect

We never ask for and never store your broker username or password, your account balance, or your payment card's full number. Trading capital stays in your own brokerage at all times, and subscription payments run through specialist payment processors.

3. What we use it for

  • Running the service: activating your bots, administering your subscription, and answering support requests.
  • Talking to you: replying to enquiries, sending service and security notices, and scheduling consultations you request.
  • Making CYGOX AI better: studying aggregate usage so we can fix friction, squash bugs, and prioritise features.
  • Marketing, only with permission: sending offers or updates where you have opted in, or where the law lets us rely on a legitimate interest; every marketing email carries an unsubscribe link.
  • Staying lawful: meeting record-keeping duties, enforcing our terms, and preventing fraud or abuse.

Our lawful bases under the GDPR

  • Contract: most processing simply delivers the service you signed up for.
  • Consent: marketing communications and non-essential cookies rest on your opt-in, which you may withdraw at any time.
  • Legitimate interests: service improvement, security, and fraud prevention, balanced against your rights.
  • Legal obligation: where statute or regulation compels us to keep or disclose records.

4. Who we share it with

We do not sell personal data, ever. Your information is disclosed only in three situations:

  • Vendors working for us: hosting providers, our CRM, scheduling tools, email delivery, analytics, and payment processors, each bound by contract to use your data solely on our instructions.
  • Legal compulsion: where a law, court order, or competent authority requires disclosure, or where disclosure is needed to defend our rights or protect users.
  • Corporate events: if CYGOX AI is merged, acquired, or sells its assets, customer records may transfer with the business; we will tell you before your data becomes subject to a different policy.

Each third-party provider operates under its own privacy terms, which we encourage you to review.

5. How long we keep it

  • Account and correspondence records: for the life of our relationship, then for a limited wind-down period to handle follow-ups and legal obligations.
  • Analytics data: kept in aggregated or de-identified form for no more than 26 months.
  • Consent logs: for as long as your subscription to communications lasts, plus the period needed to evidence compliance.

Once data serves no remaining purpose, we delete it or strip it of anything that identifies you.

6. Your rights

If you are in the EU/EEA (GDPR)

  • Access a copy of the data we hold on you.
  • Correct records that are wrong or incomplete.
  • Ask us to erase your data ("right to be forgotten"), subject to retention we must keep by law.
  • Receive your data in a portable, machine-readable format.
  • Restrict or object to certain processing, including all direct marketing.
  • Withdraw any consent without affecting processing that already happened.
  • Complain to your national data protection authority.

If you are a California resident (CCPA/CPRA)

  • Know what categories of personal information we collect, from where, why, and with whom it is shared.
  • Request deletion, subject to statutory exceptions.
  • Opt out of "sale" or "sharing" of personal information, noting that CYGOX AI does not sell personal information.
  • Exercise these rights without receiving worse service or pricing in return.

To use any of these rights, email [email protected]. We answer verified requests within the statutory windows (generally 30 days under GDPR and 45 days under CCPA).

7. International transfers

CYGOX AI serves customers worldwide, so your data may be processed outside your home country, including in the United States. Where data leaves the European Economic Area, we rely on recognised safeguards: European Commission adequacy decisions where they exist, or Standard Contractual Clauses and equivalent mechanisms where they do not.

8. Children

CYGOX AI is strictly for adults. We do not knowingly process data belonging to anyone under 18. If you believe a minor has given us personal information, write to [email protected] and we will remove it promptly.

9. How we protect your data

  • TLS encryption on every connection between your browser and our servers.
  • Encryption at rest for sensitive records.
  • Least-privilege access: only staff who need your data to do their jobs can reach it.
  • Recurring reviews of our security posture and vendors.

No online system can promise perfect security, and we won't pretend otherwise, but protecting the little data we do hold is treated with the same discipline we apply to our trading software.

10. Updates to this policy

We revise this policy when our practices, tooling, or legal obligations change. The date at the top always reflects the latest version, and material changes will be flagged by email or an on-site notice. Checking back periodically is the best way to stay current.

11. Contact

Questions, concerns, or rights requests: [email protected]. For GDPR matters, add the subject line "Data Protection Inquiry" and we will route it to the person responsible for data protection. We aim to answer every privacy request within 30 days.