Last Updated: July 2025
Calamari Trading LLC (“Calamari”, “we”, “us”, or “our”) acts as the data controller for the personal information you provide to us when using our platform and infrastructure services.
We collect the following categories of data:
Trading-platform credentials are encrypted before storage in Calamari's segregated credential vault. Credentials are never stored in plaintext. Administrative access is restricted, time-limited and logged. Customers can rotate credentials at any time. Credentials are permanently deleted upon service cancellation.
Additional details on credential security:
Each customer receives an isolated Windows VM with allocated CPU, memory and storage. Customers do not share an operating-system environment or trading-terminal installation. Your VM is deployed within a secure virtual network with strict firewall rules.
Staff do not have standing access to your VM. Temporary support access requires your explicit authorization before any session begins. All access events — including the timestamp, purpose, and personnel involved — are logged. Calamari does not inspect, analyze, copy or reuse your trading strategy.
We retain your data only as long as your service is active. Upon cancellation:
We use trusted third-party subprocessors to operate our Services:
We do not sell your data. We do not use your trading data for advertising, signal generation, or any proprietary trading purposes. We do not disclose your trading data to other traders. Limited data may be processed by our infrastructure providers solely to operate Calamari, subject to strict contractual confidentiality and security obligations.
We implement robust security measures, including encryption at rest and in transit, Role-Based Access Control (RBAC), Multi-Factor Authentication (MFA) for administrative access, and continuous monitoring. Your VM state is periodically backed up to allow for rapid recovery in the event of hardware failure. These backups are encrypted and subject to the same strict access controls and retention policies as live data.
Calamari continuously monitors supported VM and terminal health signals while the service is operational, including nights and weekends. Monitoring systems operate outside your VM, using external heartbeat checks so that VM-level failures are detected independently.
In the event of a data breach that compromises your personal information or trading credentials, we will notify you via email within 72 hours of discovering the breach, outlining the nature of the incident and the steps we are taking to mitigate it.
You have the right to:
Your data may be transferred to, and maintained on, computers located outside of your state, province, country, or other governmental jurisdiction where the data protection laws may differ from those of your jurisdiction. We ensure appropriate safeguards are in place for any such transfers.
We may update this Privacy Policy periodically. We will provide 30 days' notice for material changes by posting the updated policy on our website or notifying you via email.
For privacy-related inquiries or to exercise your data rights, please contact us at privacy@calamaritrading.ai.