chartping

Data Processing Agreement

Effective 27 July 2026 · Version 2026-06

This agreement applies if you use the Licensing module — that is, if you issue licences for your own product to your own end users through Chartping. It is the UK GDPR Article 28 contract between you and us for the personal data of those end users. If you only monitor your own trading accounts, this page does not apply to you; your relationship with us is covered by the Terms of Service and the Privacy Notice.

1. Who is who

For your traders' personal data, you are the controller and we are your processor. You decide why and how that data is processed; we act on your instructions. You own the notices and consents your traders receive — we have no relationship with them and cannot give them privacy information on your behalf.

For your own account with us — your sign-in details, your billing, and the monitoring of accounts you connect for yourself — we are the controller, and the Privacy Notice governs.

2. What we process, and on whose instruction

  • Subject attributes you send us — the key/value pairs you choose when you issue a licence, typically a trading-account number. We store them as you send them: we apply no hashing of our own.
  • A derived one-way fingerprint of those attributes, used for seat enforcement.
  • Licence and activation metadata — issue, activation, revocation, seat counts, timestamps.
  • Transport payloads you send from your product to your traders. We carry them; we do not interpret them.

Your instruction, and the one thing we ask of you: send pseudonymous or hashed references rather than raw identifiers wherever your product allows it. We cannot enforce this — the platform stores what you send — which is exactly why it is a contractual term and not a feature description.

We process this data only to provide the Licensing module and only on your documented instructions, which are these terms and your use of the module. If we ever believe an instruction breaks UK data protection law, we will tell you.

3. Security

The measures we actually operate are described in the Privacy Notice and summarised here: encryption in transit; encryption of stored broker credentials with key rotation; proof-of-possession binding of the desktop agent's connection; secrets held in a managed vault; per-user data scoping; rate limiting; append-only audit trails for privileged actions; staff access restricted by allow-list and mandatory two-factor authentication. Credentials are never returned by any API. We keep everyone who can access personal data under a duty of confidentiality.

4. Sub-processors

You give general authorisation for us to engage sub-processors. The current list is published in Privacy Notice §4.1 and is the authoritative register. We give 30 days' notice before adding or replacing one that touches your traders' data, and you may object on reasonable data-protection grounds; if we cannot resolve your objection, you may terminate the affected service. Where a change is urgent — security, legal compliance or service continuity — we may act first and notify as soon as we reasonably can, and the same objection and termination rights apply afterwards. Every sub-processor is bound by terms no less protective than these, and we remain liable to you for what they do.

5. Where data is processed

Our platform runs in the United Kingdom. Where data reaches a provider outside the UK, we rely on appropriate safeguards under Article 46 — the UK International Data Transfer Agreement or Addendum, or the EU Standard Contractual Clauses, as incorporated in that provider's data-processing terms. We do not rely on consent for those transfers. A copy of the relevant safeguard is available on request.

6. If there is a breach

We notify you without undue delay and in any event within 48 hours of becoming aware of a personal data breach affecting your traders' data, with what we know at the time: what happened, which categories and roughly how many records, the likely consequences, and what we are doing. We will not delay a first notification in order to make it complete. Notifying your supervisory authority and your traders is your decision as controller; we give you what you need to make it.

7. Requests from your traders

If a trader contacts us about data we hold for you, we will not answer for you — we tell them to contact you and let you know. On your instruction we help you retrieve, export, correct or delete the relevant data. This assistance is included in your subscription at no additional charge.

8. Deletion

On your instruction, or on termination, we delete the traders' personal data we hold for you — deletion means deletion, not anonymisation. We keep only what the law requires us to keep, and we tell you what that is if it applies. Backups age out on their normal cycle, and anything restored from a backup is re-deleted before the restore completes.

9. Audit

On reasonable notice, and no more than once a year unless a regulator or a breach requires otherwise, we will answer your written questions about how we process your traders' data and provide the documentation we hold — our records of processing, our security policies and our sub-processor register. On-site audits are available where a supervisory authority requires one, at your cost, under confidentiality.

10. Türkiye

Where your traders are in Türkiye, KVKK applies to you as the data controller. Our platform is in the United Kingdom, so your transfer of that data to us is a cross-border transfer under KVKK Article 9, and choosing and completing the mechanism for it is yours to do. We will provide what you need from our side.

11. How this fits with everything else

This page is the operative summary of our full Data Processing Addendum. Where the two differ, the full addendum governs; request a copy at [email protected]. This agreement prevails over the Terms of Service on anything concerning the processing of your traders' personal data, and it lasts as long as we process that data for you. It is governed by the law of England and Wales.

You accept this agreement inside Chartping, before you can use the Licensing module. We record which version you accepted and when, and you can re-read it at any time from Settings → Legal.

Contact

TrendSoft Ltd, Aa House 54, 27 Old Gloucester Street, London, WC1N 3AX, United Kingdom. Company No. 16144241. Data protection: [email protected]. General: [email protected].