Privacy Policy

Last Updated: July 2025

1. Data Controller

Calamari Trading LLC (“Calamari”, “we”, “us”, or “our”) acts as the data controller for the personal information you provide to us when using our platform and infrastructure services.

2. What Data We Collect

We collect the following categories of data:

  • Account Information: Name, email address, and payment information (processed securely via Stripe).
  • Trading-Platform Credentials: Broker or prop firm account numbers, passwords, and server details. These are stored securely as described in Section 3.
  • Trade Execution Data: Orders, positions, and trading history generated on your provisioned Virtual Machine (VM).
  • Terminal Health Metrics: CPU usage, memory consumption, connection status, and application crash logs.
  • Dashboard Usage Data: How you interact with the Calamari dashboard.
  • LiveView Session Data: LiveView streams your terminal interface directly to your browser. We do not retain or store these screenshots; they are streamed only.
  • Support Interaction Records: Communications with our support team.

3. How Credentials Are Stored

Trading-platform credentials are encrypted before storage in Calamari's segregated credential vault. Credentials are never stored in plaintext. Administrative access is restricted, time-limited and logged. Customers can rotate credentials at any time. Credentials are permanently deleted upon service cancellation.

Additional details on credential security:

  • Encryption keys are stored separately from encrypted credential data. A compromise of the application database would not expose your credentials.
  • Only automated provisioning systems decrypt credentials during terminal configuration. Human staff cannot retrieve plaintext passwords.
  • Every credential access — automated or manual — is logged with timestamp and purpose.
  • Customers can update credentials through the dashboard at any time.
  • Credentials are permanently deleted within 30 days of cancellation, or immediately upon explicit request.

4. VM Isolation

Each customer receives an isolated Windows VM with allocated CPU, memory and storage. Customers do not share an operating-system environment or trading-terminal installation. Your VM is deployed within a secure virtual network with strict firewall rules.

5. Support Access Model

Staff do not have standing access to your VM. Temporary support access requires your explicit authorization before any session begins. All access events — including the timestamp, purpose, and personnel involved — are logged. Calamari does not inspect, analyze, copy or reuse your trading strategy.

6. Data Retention and Deletion

We retain your data only as long as your service is active. Upon cancellation:

  • Your infrastructure is queued for decommissioning.
  • We retain your encrypted data and VM snapshots for 30 days post-cancellation to allow for account recovery.
  • After 30 days, all VMs are destroyed, and all associated data (including credentials and trading history) are permanently wiped.
You may request immediate deletion of all data upon cancellation by contacting support.

7. Subprocessors

We use trusted third-party subprocessors to operate our Services:

  • Cloud Infrastructure Providers: For hosting your VMs.
  • Stripe: For payment processing.
  • Monitoring Tools: For tracking system health metrics (CPU, memory, uptime).
We do not share your trading data with subprocessors. They only process the infrastructure metrics required to keep the systems running. All subprocessors are subject to contractual confidentiality and security obligations.

8. Data Sharing and Confidentiality

We do not sell your data. We do not use your trading data for advertising, signal generation, or any proprietary trading purposes. We do not disclose your trading data to other traders. Limited data may be processed by our infrastructure providers solely to operate Calamari, subject to strict contractual confidentiality and security obligations.

9. Security Measures and Backups

We implement robust security measures, including encryption at rest and in transit, Role-Based Access Control (RBAC), Multi-Factor Authentication (MFA) for administrative access, and continuous monitoring. Your VM state is periodically backed up to allow for rapid recovery in the event of hardware failure. These backups are encrypted and subject to the same strict access controls and retention policies as live data.

10. Monitoring

Calamari continuously monitors supported VM and terminal health signals while the service is operational, including nights and weekends. Monitoring systems operate outside your VM, using external heartbeat checks so that VM-level failures are detected independently.

11. Breach Notification

In the event of a data breach that compromises your personal information or trading credentials, we will notify you via email within 72 hours of discovering the breach, outlining the nature of the incident and the steps we are taking to mitigate it.

12. Customer Rights

You have the right to:

  • Access the personal data we hold about you.
  • Correct inaccurate data.
  • Request deletion of your data.
  • Request a portable copy of your data.
  • Rotate or update your trading credentials at any time through the dashboard.

13. International Transfers

Your data may be transferred to, and maintained on, computers located outside of your state, province, country, or other governmental jurisdiction where the data protection laws may differ from those of your jurisdiction. We ensure appropriate safeguards are in place for any such transfers.

14. Policy Updates

We may update this Privacy Policy periodically. We will provide 30 days' notice for material changes by posting the updated policy on our website or notifying you via email.

15. Contact Information

For privacy-related inquiries or to exercise your data rights, please contact us at privacy@calamaritrading.ai.