chartping
This is an archived version. It is the text of the Data Processing Agreement (summary) exactly as published under version 2026-08 (effective 7 August 2026), kept unchanged so that anyone who accepted it can read what they accepted. It is not the current version — read the current Data Processing Agreement (summary), and see every archived version.

Data Processing Agreement

Effective 7 August 2026 · Version 2026-08

This agreement applies if you use the Licensing module — that is, if you issue licences for your own product to your own end users through Chartping. It is the UK GDPR Article 28 contract between you and us for the personal data of those end users. If you only monitor your own trading accounts, this page does not apply to you; your relationship with us is covered by the Terms of Service and the Privacy Notice.

1. Who is who

For your traders' personal data, you are the controller and we are your processor. You decide why and how that data is processed; we act on your instructions. You own the notices and consents your traders receive — we have no relationship with them and cannot give them privacy information on your behalf.

For your own account with us — your sign-in details, your billing, and the monitoring of accounts you connect for yourself — we are the controller, and the Privacy Notice governs.

2. What we process, and on whose instruction

  • Subject attributes you send us — the key/value pairs you choose when you issue a licence, typically a trading-account number. We store them as you send them: we apply no hashing of our own.
  • A derived one-way fingerprint of those attributes, used for seat enforcement.
  • Licence and activation metadata — issue, activation, revocation, seat counts, timestamps.
  • Transport payloads you send from your product to your traders. We carry them; we do not interpret them.

Your instruction, and the one thing we ask of you: send pseudonymous or hashed references rather than raw identifiers wherever your product allows it. We cannot enforce this — the platform stores what you send — which is exactly why it is a contractual term and not a feature description.

We process this data only to provide the Licensing module and only on your documented instructions, which are these terms and your use of the module. If we ever believe an instruction breaks UK data protection law, we will tell you.

3. Security

The measures we actually operate are described in the Privacy Notice and summarised here: encryption in transit; encryption of stored broker credentials with key rotation; proof-of-possession binding of the desktop agent's connection; secrets held in a managed vault; per-user data scoping; rate limiting; append-only audit trails for privileged actions; staff access restricted by allow-list and mandatory two-factor authentication. Credentials are never returned by any API. We keep everyone who can access personal data under a duty of confidentiality.

4. Sub-processors

You give general authorisation for us to engage sub-processors. The current list is published at /legal/subprocessors, mirroring the Privacy Notice's “Who receives your data” list, and is the authoritative register. Previous versions of it stay published at the archive, which is the change history. We give 30 days' notice before adding or replacing one that touches your traders' data, and you may object on reasonable data-protection grounds; if we cannot resolve your objection, you may terminate the affected service. Where a change is urgent — security, legal compliance or service continuity — we may act first and notify as soon as we reasonably can, and the same objection and termination rights apply afterwards. Every sub-processor is bound by terms no less protective than these, and we remain liable to you for what they do.

5. Where data is processed

Our platform runs on dedicated servers in Germany, with a standby site in Finland, both operated by Hetzner Online GmbH. Our secrets are held separately in the United Kingdom. We are a UK company, so this is a transfer out of the UK, and it relies on the UK's recognition of the EEA as adequate — no Article 46 instrument is needed for it. Where data reaches a provider outside the UK and the EEA, we rely on safeguards under Article 46 — the UK International Data Transfer Agreement or Addendum, or the EU Standard Contractual Clauses, as incorporated in that provider's data-processing terms. We do not rely on consent for those transfers. A copy of the relevant safeguard is available on request, and the full list is at /legal/subprocessors.

6. If there is a breach

We notify you without undue delay and in any event within 48 hours of becoming aware of a personal data breach affecting your traders' data, with what we know at the time: what happened, which categories and roughly how many records, the likely consequences, and what we are doing. We will not delay a first notification in order to make it complete. Notifying your supervisory authority and your traders is your decision as controller; we give you what you need to make it.

7. Requests from your traders

If a trader contacts us about data we hold for you, we will not answer for you — we tell them to contact you and let you know. On your instruction we help you retrieve, export, correct or delete the relevant data. This assistance is included in your subscription at no additional charge.

8. Deletion

On your instruction, or on termination, we delete the traders' personal data we hold for you — deletion means deletion, not anonymisation. We keep only what the law requires us to keep, and we tell you what that is if it applies. Copies taken for disaster recovery may still contain the data for a short period after deletion: today those are manual snapshots taken before a deployment or database change and kept only until the next one; when our automated backup regime is in place, deleted data will age out of backups within the backup retention period. Anything restored is re-deleted before the restore completes.

9. Audit

On reasonable notice, and no more than once a year unless a regulator or a breach requires otherwise, we will answer your written questions about how we process your traders' data and provide the documentation we hold — our records of processing, our security policies and our sub-processor register. On-site audits are available where a supervisory authority requires one, at your cost, under confidentiality.

10. Türkiye

Where your traders are in Türkiye, KVKK applies to you as the data controller. We are a UK company and our servers are in Germany and Finland, so your transfer of that data to us is a cross-border transfer under KVKK Article 9, and choosing and completing the mechanism for it is yours to do. We will provide what you need from our side.

11. How this fits with everything else

This page is a summary. The operative text is our full Data Processing Addendum, published in full at chartping.com/legal/dpa-full — read it there rather than asking us for a copy. Where this page and the full addendum differ, the full addendum governs. It contains terms this summary does not restate, including the indemnity in §13.2, which is expressly outside the liability cap in the Terms of Service. This agreement prevails over the Terms of Service on anything concerning the processing of your traders' personal data, and it lasts as long as we process that data for you. It is governed by the law of England and Wales.

You accept this agreement inside Chartping, before you can use the Licensing module. We record which version you accepted and when, and you can re-read it at any time from Settings → Legal.

Contact

TrendSoft Ltd, Aa House 54, 27 Old Gloucester Street, London, WC1N 3AX, United Kingdom. Company No. 16144241. Data protection: [email protected]. General: [email protected].

Every version of this document stays available, unchanged, at its own address — see the archive. If your record of what you accepted names a version, you can read exactly that text there.