Privacy Policy
Last updated: October 6, 2026
1. Identity and Contact Details of the Data Controller
Pursuant to Article 13 of Regulation (EU) 2016/679 (hereinafter "GDPR"), Legislative Decree 196/2003 (Italian Data Protection Code), and Directive 2002/58/EC (ePrivacy), we inform you that your personal data will be processed by the following Data Controller:
- Controller: DOJO TRADING GROUP SOCIEDAD DE RESPONSABILIDAD LIMITADA
- Registered office: POZOS, Forum Uno, Edificio G, Primer Piso, Oficinas NCC Law, Costa Rica
- Email: official.comunication@tradingdojo.org
- Platform: Trading Dojo (tradingdojo.org)
EU Representative (Art. 27 GDPR):
- Name: Alex Solignani
- Address: Marano sul Panaro (MO), Italy
- Email: official.comunication@tradingdojo.org
2. Types of Personal Data Collected
In the course of providing its services, Trading Dojo collects and processes the following categories of personal data:
Identification and contact data
- First and last name, email address, phone number, country of residence, address
Authentication data
- Password (stored exclusively as a cryptographic hash), multi-factor authentication (MFA) backup codes
Application data
- Name, date of birth, email, phone number, residence, profession, trading experience level, difficulties encountered, services selected in the configurator
Chatbot data (access form)
- First name, last name, country of residence, email address, acceptance of the terms, optional newsletter consent, questions and answers exchanged during the conversation
Newsletter and commercial communication data
- Name, email address, consent given and subscription date, status of the emails sent (delivered, not delivered), opens and clicks detected through tracking pixels and tracked links contained in the emails
Payment data
- Amount, currency, payment method, bank transfer reference or blockchain transaction ID
Electronic contract signing data
- Contractual personal details (first and last name, residential address, email, phone number), contract content and economic terms, the signature applied (image of the drawn signature or typed name), IP address, browser user agent, acceptance event log (opening, scrolling through the document, acceptance of the clauses, identity verification), cryptographic fingerprints (hashes) of the contract content and of the PDF document
Course data
- Course access records, lesson completion status, visibility settings
Trading journal data
- Emotional state (mood), currency pair, trade direction, result, amount, personal notes
Tracking service data
- Trade date, profit or loss, symbol or instrument, direction (long/short), entry and exit price, quantity, R multiple, tags, free-form notes, preferred display currency
Messaging data
- Text messages, attachments exchanged through the internal chat system
Device data
- Device fingerprint, user agent, device type, browser, operating system
Analytics data
- Anonymized visitor ID, pages visited, scroll depth, session duration, referrer, UTM parameters
Bug report data
- Title, problem description, screenshots
3. Purposes and Legal Bases for Processing
Your personal data is processed for the following purposes, each supported by an appropriate legal basis under Article 6 GDPR:
Performance of a contract (Art. 6(1)(b) GDPR)
- Account registration: creation and management of your account on the platform. During registration, first and last name, phone number and residential address are collected on a mandatory basis, for pre-contractual and contractual purposes: they are necessary for the preparation and signing of the contractual documents relating to the requested educational services
- Electronic contract signing: preparation, conclusion and performance of the educational services contract signed online through the platform (see Section 13)
- Payments: processing of payments via bank transfer or cryptocurrency
- Courses and progress: delivery of the educational service and progress tracking
- Chat and messaging: communication between student and instructor
- Trading journal: provision of the personalized educational tool
- Tracking service: provision of the personal trading journal available by subscription and management of its access lifecycle (activation, expiration, renewal)
- Transactional emails: sending of service-related communications (confirmations, notifications, updates)
Data entered in the Tracking service may be viewed in read-only mode by authorized Trading Dojo staff (administrators and instructors), exclusively through the administration pages and for the purpose of assisting the User and providing personalized coaching support.
Pre-contractual measures (Art. 6(1)(b) GDPR)
- Application: evaluation of your application for admission to educational programs
- Chatbot: handling of assistance requests submitted through the homepage chatbot and follow-up by email regarding the request received
Legal obligation (Art. 6(1)(c) GDPR)
- Payment data: compliance with tax and accounting obligations under applicable law
Legitimate interest of the Controller (Art. 6(1)(f) GDPR)
- Device fingerprinting: access control and device limit management to protect the integrity of the service
- Cloudflare Turnstile: protection of the platform from bots and abusive behavior, including the chatbot access form
- Cloudflare (CDN, DNS and reverse proxy): anti-DDoS protection, TLS termination and content delivery optimization
- Video watermark: overlay of email address on video content to protect intellectual property
- Bug reports: improvement of service quality and reliability
- Chatbot conversations: logging of the questions and answers exchanged with the chatbot for the purpose of assisting the visitor and improving the service
- Evidentiary retention of signed contracts: retention of the contract signed online and of the related signing evidence (see Section 13) to safeguard the ability to establish, exercise or defend legal claims
Consent of the data subject (Art. 6(1)(a) GDPR)
- Analytics (custom internal system): anonymized analysis for service and user experience improvement
- Newsletter and commercial communications: sending of promotional and informational communications, subject to optional consent given during registration, when submitting an application, through the service configurator, through the chatbot form, or through an external contact collection form. Consent is never required as a condition for accepting the mandatory terms and may be withdrawn at any time via the unsubscribe link in each communication or by contacting the Controller. Newsletters and commercial communications are sent through Zoho Campaigns, a service of Zoho Corporation B.V. delivered from the provider’s European datacenter (see section 4): in this context the data processed are name, email address, consent, subscription date, status of the emails sent, and the opens and clicks detected through tracking pixels and tracked links inserted in the emails, in order to measure interest in the communications sent. Those who have only requested information, without giving consent, receive solely the reply to their request
In its default mode, the chatbot answers by selecting a response from a predefined list of questions and answers, processed lexically on the hosting infrastructure already indicated (Vercel Inc., see Section 4): no third-party artificial intelligence service or new sub-processor is involved. Future experimental modes may involve generating responses through an artificial intelligence system running on infrastructure operated by the Data Processor (ConcAI) on behalf of the Controller, likewise without the involvement of any third-party artificial intelligence service.
4. Sub-Processors and Data Recipients
To provide its services, the Controller engages the following sub-processors (Art. 28 GDPR), with whom appropriate data processing agreements have been executed:
- Supabase Inc. (USA) — Database, authentication, realtime functionality, and storage. Safeguards for extra-EU transfers: EU-US Data Privacy Framework (DPF) and Standard Contractual Clauses (SCCs). Privacy: supabase.com/privacy.
- VdoCipher (VdoTok Tech Pvt. Ltd.) (India) — DRM-protected video hosting with watermark. Safeguards: Standard Contractual Clauses pursuant to Commission Implementing Decision (EU) 2021/914. Privacy: vdocipher.com/privacy.
- Vercel Inc. (USA) — Web application hosting, including matching of chatbot responses in default mode (lexical processing, no third-party artificial intelligence). Safeguards: DPF + SCCs. Privacy: vercel.com/legal/privacy-policy.
- Amazon Web Services EMEA SARL (registered office Luxembourg; primary data centers in Ireland — eu-west-1 region) — Cloud infrastructure (S3 storage, CloudFront CDN distribution) used by the sub-processors Supabase, Vercel, and VdoCipher to host data and deliver video and static content. The data subject’s browser may communicate directly with AWS servers when loading resources (e.g., files from Supabase Storage or VdoCipher videos). Safeguards: EU-US Data Privacy Framework (DPF) and Standard Contractual Clauses pursuant to Commission Implementing Decision (EU) 2021/914. Privacy: aws.amazon.com/privacy.
- Cloudflare, Inc. (USA) — CDN, DNS, reverse proxy with TLS termination, anti-DDoS protection and Turnstile service for anti-bot verification on authentication forms (login, registration, password recovery) and on the public information request form. Cloudflare processes IP address, HTTP headers, User-Agent and behavioral signals necessary for the service to operate. Safeguards: DPF + SCCs. Privacy: cloudflare.com/privacypolicy.
- Upstash, Inc. (USA; data hosted in the EU region — Frankfurt, Germany) — Distributed rate-limiting counters protecting against abuse and unlawful access attempts (brute force) on sensitive operations: MFA backup code verification, password change, video OTP generation. The service receives only pseudonymized technical identifiers (HMAC-SHA256), never plain IP addresses, email addresses or user identifiers. Safeguards: Standard Contractual Clauses pursuant to Commission Implementing Decision (EU) 2021/914. Privacy: upstash.com/trust/privacy.pdf.
- Zoho Corporation B.V. (Netherlands; service delivered from the provider’s European datacenter, data hosted in the European Union) — Email service for the tradingdojo.org domain: sending and receiving transactional and service emails (registration and account verification, password recovery, course and subscription notifications, support communications). The service processes sender and recipient email addresses, message content and delivery metadata; no open or click tracking is active on transactional and service emails. Through Zoho Campaigns, a service of the same company delivered from the same European datacenter, the Controller also sends newsletters and commercial communications to those who have given their consent: in this context the service processes name, email address, consent and subscription date, status of the emails sent, and the opens and clicks detected through tracking pixels and tracked links inserted in each email. Legal basis: the data subject’s consent, which may be withdrawn at any time via the unsubscribe link in every email; data are retained until consent is withdrawn. Safeguards: processing takes place on datacenters located in the European Union, with no transfer to third countries. Privacy: zoho.com/privacy.html.
- Lecto.ai (machine translation API provider; company name and registered office not published by the provider: the transfer is prudentially treated as extra-EU) — Machine translation of the platform’s textual content into the supported languages: chat messages, bug reports, course content and emails, transmitted to the service for the sole purpose of translation. The provider states that content is deleted once processing is complete; translations are stored within the platform’s systems. Website: lecto.ai.
- Functional Software, Inc. (Sentry) (USA; organization with data hosted in the EU region — Frankfurt, Germany) — Error and technical log monitoring for the platform: when a page or an operation fails, the service receives the error message, the technical stack trace, the URL and browser type, a request identifier and, where present, a pseudonym of the user (a code derived from the internal identifier, not attributable to the person without the platform’s key); email addresses, names, cookies, IP addresses and request contents are removed before sending. Retention: 30 days. Safeguards: DPF + Standard Contractual Clauses pursuant to Commission Implementing Decision (EU) 2021/914. Privacy: sentry.io/privacy.
- Telegram FZ-LLC (Dubai, United Arab Emirates) — Internal staff notification of new applications via the Bot API: the service receives the data entered in the application form (name, email, phone, date of birth, place of residence, profession, experience level) for the sole purpose of enabling their timely handling. Privacy: telegram.org/privacy.
Personal data is not disclosed to third parties for marketing purposes. Data may be communicated to competent authorities in cases required by law.
The list of data processors may be updated periodically. The latest version is always available on this page.
5. International Data Transfers
Some of the sub-processors listed in the previous section are established outside the European Economic Area (EEA). Transfers of personal data to such third countries are carried out in compliance with Chapter V of the GDPR (Articles 44–49), based on the following appropriate safeguards:
United States of America (Supabase, Vercel, Cloudflare, and Amazon Web Services for U.S. endpoints)
- European Commission adequacy decision regarding the EU-US Data Privacy Framework (Commission Implementing Decision (EU) 2023/1795 of 10 July 2023)
- Standard Contractual Clauses (SCCs) adopted pursuant to Commission Implementing Decision (EU) 2021/914, as an additional safeguard
Luxembourg / Ireland (Amazon Web Services EMEA SARL)
- Processing within the European Economic Area (EEA), with the safeguards of the GDPR directly applicable
- Standard Contractual Clauses (SCCs) for any technical transfers to other AWS regions, pursuant to Commission Implementing Decision (EU) 2021/914
Netherlands (Zoho Corporation B.V.)
- Email service and newsletter sending service (Zoho Campaigns) delivered from the provider’s European datacenter: processing takes place entirely within the European Union and involves no transfers to third countries
India (VdoCipher)
- Standard Contractual Clauses (SCCs) pursuant to Commission Implementing Decision (EU) 2021/914 of 4 June 2021
United Arab Emirates (Telegram FZ-LLC)
- Transfer limited to the data of the application form, for the sole purpose of internal staff notification; in the absence of an adequacy decision, the transfer relies on the provider’s contractual safeguards and on the minimization of the data transmitted
Lecto.ai (machine translation; provider’s registered office not published)
- The transfer is prudentially treated as a transfer to a third country; content is transmitted for the sole purpose of translation and the provider states that content is deleted once processing is complete
You have the right to obtain a copy of the appropriate safeguards in place by contacting the Controller at official.comunication@tradingdojo.org.
6. Data Retention Periods
Personal data is retained for the time strictly necessary to fulfill the purposes for which it was collected, in accordance with the principle of storage limitation (Art. 5(1)(e) GDPR):
- Profile data (name, email, preferences, account): for the duration of the contractual relationship, plus 30 days after termination (subject to earlier deletion upon request by the data subject)
- Administrative, tax and payment data (invoice headers, transaction records, receipts): 10 years from the date of the transaction (Art. 2220 of the Italian Civil Code and Italian Presidential Decree 633/72)
- Electronically signed contracts and signing evidence (contract, signer’s personal details, signature, IP address, user agent, event log, hashes): 10 years from the date on which the contract ceases to be effective (ordinary limitation period under Art. 2946 of the Italian Civil Code; retention of records under Art. 2220 of the Italian Civil Code). This data is retained even if the account is deleted, pursuant to Art. 17(3)(b) and (e) GDPR (see Section 13)
- Application data: 2 years from the date of the decision regarding the application
- Chatbot lead data and related conversations: 2 years from the last contact, by analogy with application data; newsletter consent, where given, remains valid until withdrawn regardless of this period
- Newsletter and commercial communication data (subscription, status of the emails sent, opens and clicks): until consent is withdrawn; after unsubscribing, the email address is kept only in the unsubscribe list so that it is no longer contacted
- Course progress: for the duration of course access, plus 1 year after termination
- Chat messages: for the duration of the contractual relationship, plus 6 months after termination
- Trading journal data: for the duration of the contractual relationship, plus 30 days after termination
- Tracking service data: for the duration of the contractual relationship, including any periods in which the subscription is expired or suspended, during which the data remains stored but inaccessible, so that renewing the subscription fully restores the history of recorded operations; data is deleted upon account deletion or at the data subject’s request
- Device fingerprints: 6 months from the last access with the device
- Analytics data: 26 months from collection
- Anti-bot and anti-spam logs: for security purposes we record automated requests (bots, crawlers, referral spam) with user agent and truncated IP address (last octet removed); retained for 90 days, legal basis: legitimate interest in service security
- Bug reports: 1 year from the resolution of the reported issue
- Email logs: 2 years from dispatch
- Cookie consent log: 13 months from the date of consent (Italian Garante guidelines 10/06/2021)
Personal data may be retained beyond the above periods only insofar as strictly necessary for the establishment, exercise, or defense of a legal claim, pursuant to Art. 17(3)(e) GDPR (ordinary ten-year limitation period under Art. 2946 of the Italian Civil Code).
Upon expiration of the above periods, data will be securely deleted or irreversibly anonymized.
7. Rights of the Data Subject
As a data subject, you have the right to exercise the following rights under Articles 15–22 of the GDPR:
- Right of access (Art. 15 GDPR): obtain confirmation as to whether your personal data is being processed and access its content
- Right to rectification (Art. 16 GDPR): obtain the correction of inaccurate personal data or the completion of incomplete data
- Right to erasure (Art. 17 GDPR): obtain the deletion of your personal data, unless processing is necessary for compliance with legal obligations (e.g., tax requirements) or for the establishment, exercise, or defense of legal claims
- Right to restriction of processing (Art. 18 GDPR): obtain restriction of processing in the circumstances provided by law
- Right to data portability (Art. 20 GDPR): receive your personal data in a structured, commonly used, and machine-readable format, and transmit it to another controller
- Right to object (Art. 21 GDPR): object at any time to the processing of your personal data based on legitimate interest, including profiling
- Right not to be subject to automated decision-making (Art. 22 GDPR): not to be subject to a decision based solely on automated processing that produces legal effects concerning you or similarly significantly affects you
To exercise your rights, you may contact the Controller at official.comunication@tradingdojo.org.
Right to lodge a complaint: You also have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la Protezione dei Dati Personali), Piazza Venezia 11, 00187 Rome, Italy, email: garante@gpdp.it, website: www.garanteprivacy.it.
8. Automated Decision-Making and Profiling
Pursuant to Article 22 GDPR, we inform you that Trading Dojo does not employ any automated decision-making process, including profiling, that produces legal effects concerning you or similarly significantly affects you.
In particular:
- Applications for admission to educational programs are evaluated manually by the Trading Dojo team
- No automated profiling is carried out for decision-making purposes
- Device fingerprinting is used exclusively for security purposes (device limits) and not for user profiling
9. Cookies and Tracking Technologies
Trading Dojo uses cookies and similar technologies in compliance with Directive 2002/58/EC (ePrivacy) and the GDPR.
For detailed information about the cookies used, their purposes, duration, and consent management, please refer to our Cookie Policy.
Trading Dojo’s analytics system is a custom internal system, not based on third-party services such as Google Analytics. Analytics data collection occurs exclusively with your prior consent (Art. 6(1)(a) GDPR).
10. Data Security
The Controller implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk, pursuant to Article 32 GDPR, including:
- Encryption of data in transit (TLS/HTTPS) and at rest
- Passwords stored exclusively as cryptographic hashes (bcrypt)
- Role-based access control (RBAC)
- Authorized device control and limitation through device fingerprinting
- Anti-bot protection via Cloudflare Turnstile
- DRM protection and watermarking on video content
- Periodic security monitoring and audits
- Retention of a cookie consent audit log for accountability purposes (Art. 5(2) GDPR), stored for 13 months from collection
11. Changes to This Privacy Policy
The Controller reserves the right to amend this privacy policy at any time, notifying users via the platform and, where possible, by email.
Changes shall take effect from the date of publication on the platform. You are therefore encouraged to consult this page periodically to review the latest updated version.
Where changes concern processing activities whose legal basis is consent, the Controller will obtain new consent from the data subject where necessary.
Regulatory references: Regulation (EU) 2016/679 (GDPR), Legislative Decree 196/2003 (Italian Data Protection Code), Directive 2002/58/EC (ePrivacy).
12. Consequences of Failure to Provide Data
The provision of personal data marked as mandatory is necessary for the following reasons:
- Registration data (first and last name, email, password, phone number, residential address): failure to provide this data makes it impossible to create an account and access the platform’s services; phone number and residential address are also necessary for the preparation of the contractual documents
- Application data: failure to provide this data makes it impossible to evaluate the application and grant access to educational programs
- Electronic signing data (contractual personal details, residential address, signature): failure to provide this data makes it impossible to sign the proposed contract online
- Payment data: failure to provide this data makes it impossible to process the payment and activate paid services
- Chatbot form data: failure to provide the mandatory data (first name, last name, country of residence, email, acceptance of the terms) makes it impossible to use the chatbot and receive a response to the request
The provision of data for consent-based purposes (analytics and newsletter) is optional, regardless of the collection channel (registration, application, configurator, or chatbot): refusal to give consent does not in any way affect access to or use of the platform’s services.
13. Electronic Contract Signing
The platform allows you to sign contracts for educational services online. When the staff sends you a contract proposal, you can read it in full, accept its clauses and sign it directly on the platform, either by drawing your signature or by typing your name.
Data processed. For the conclusion of the contract and as proof of signing, the following data is processed: your contractual personal details (first and last name, residential address, email, phone number), the contract content with its economic terms, the signature applied (image of the drawn signature or typed name), the IP address and browser user agent at the time of signing, the acceptance event log (page opening, scrolling through the entire document, acceptance of the individual clauses, identity verification, submission of the signature) and the cryptographic fingerprints (SHA-256 hashes) of the contract content and of the PDF document. This information is included in the signature certificate that forms the last page of the document.
The signature is not biometric data. Only the final image of the drawn signature is captured: no pressure, speed, rhythm or other behavioral characteristics of the stroke are recorded.
Identity verification. At the time of signing, an identity check is required (re-entering your account password or a code from two-factor authentication, if enabled on your account); the method used is recorded in the signature certificate.
Purposes and legal bases. The data is processed for the preparation, conclusion and performance of the contract (Art. 6(1)(b) GDPR) and for the evidentiary retention of the signed contract, to safeguard the ability to establish, exercise or defend legal claims (Art. 6(1)(f) GDPR).
Copy of the contract. Once the signing is complete, you receive a copy of the contract in PDF format by email; the copy also remains available for download at any time from your profile (durable medium).
Retention. The signed contract and the related evidence are retained for 10 years from the date on which the contract ceases to be effective (ordinary limitation period under Art. 2946 of the Italian Civil Code; retention of records under Art. 2220 of the Italian Civil Code). Deleting your account does not delete signed contracts and the related evidence, which remain stored within the limits of the law pursuant to Art. 17(3)(b) and (e) GDPR.
14. Language and prevailing version
This privacy policy is drafted in Italian and translated into English and German for the User’s convenience. In the event of any discrepancy or doubt of interpretation between the versions, the Italian version shall prevail.
