Privacy Policy
Last updated: August 20, 2026. This policy explains what personal data LOCK IN collects, why, on what legal basis, who we share it with, how long we keep it, and the rights you have over it.
1. Who is responsible for your data
LOCKIN (CY) LIMITED, a company incorporated in the Republic of Cyprus is the controller of the personal data described in this policy. In this policy, "LOCK IN", "we", "us" and "our" mean that company.
This policy applies to the LOCK IN mobile applications, the lockin.trade website, and all related services. It does not apply to any third party you deal with separately, including the exchange or broker where you hold your trading account.
If you have any question about this policy or about how we handle your data, contact us at: support@lockin.trade
2. The data we collect
We collect the following categories of personal data.
- Account data
- the email address, name or handle, password credentials, country and account settings you provide when registering, together with any access code you use.
- Connection credentials
- the read-only API keys or equivalent credentials you supply to link a trading venue, and the identifiers of the venues and accounts connected.
- Trading data
- records retrieved from the venues you connect, including balances, open positions, orders, executions, fees, funding, transfers and their timestamps. This is the core data the Service analyses.
- Derived analysis
- the results we generate from your trading data, including behavioural patterns, archetype classifications, scores, statistics and the alerts, plans and summaries built on them.
- Conversation data
- the prompts, questions and messages you send to AXEL and the responses returned to you.
- Payment data
- subscription plan, billing status, transaction identifiers and partial card details. Full card numbers are collected and processed by our payment processor and are never received or stored by us.
- Usage and device data
- IP address, approximate location derived from it, device and operating system, application version, pages and screens viewed, features used, session timing, referral source and crash diagnostics.
- Communications
- the content of emails, support requests and messages you send us, and records of our replies.
- Programme data
- where you take part in a referral or ambassador programme, the referrals attributed to you, the content you submit, and the payment details needed to pay you.
We do not intentionally collect special categories of personal data, and you should not send them to us.
3. Where the data comes from
- directly from you, when you register, connect a venue, subscribe, use AXEL or contact us;
- automatically, when you use the Service, through our own logging and the analytics providers named in section 9;
- from Connected Venues, through the read-only credentials you supply, for as long as that connection remains active; and
- from our payment processor and app store partners, in relation to your subscription.
4. Why we use it, and our legal basis
Under the General Data Protection Regulation we must have a legal basis for each purpose. Ours are as follows.
- To provide the Service — performance of a contract
- creating and running your account, connecting the venues you choose, retrieving and analysing your trading data, generating analysis and alerts, running AXEL, and giving you support.
- To take payment — performance of a contract
- processing subscriptions, renewals, refunds and programme payouts.
- To keep the Service secure and working — legitimate interests
- authentication, fraud and abuse prevention, rate limiting, diagnosing faults, and protecting our systems and our users. Our interest is in operating a secure and reliable service, and we consider it is not overridden by your rights because the data used is limited to what security requires.
- To improve the Service — legitimate interests
- understanding which features are used and where people get stuck, measuring performance, and developing new features. Wherever it is sufficient for the purpose we use aggregated or de-identified data instead of personal data.
- To send service messages — performance of a contract
- notifying you about your account, security, billing, and material changes to the Service or these documents.
- To send marketing — consent, or legitimate interests where the law allows
- product news and offers. You can withdraw consent or object at any time, and every marketing message carries an unsubscribe link. We do not need your consent to send service messages, and you cannot opt out of those while you hold an account.
- To meet legal obligations — legal obligation
- accounting and tax records, responding to lawful requests from authorities, and complying with sanctions and other applicable law.
- To establish, exercise or defend legal claims — legitimate interests
- keeping the records needed to resolve a dispute or defend a claim.
5. Automated processing and AI
The Service is built on automated analysis of your trading data. It classifies your behaviour, scores setups, and generates written analysis using large language models.
This processing produces information for you to consider. It does not make decisions about you that produce legal effects or similarly significantly affect you within the meaning of Article 22 of the GDPR: it does not decide whether you can trade, what you may trade, what credit or price you are offered, or whether you have access to any service.
Where we use third-party model providers to generate output, we send only the data needed for the request. We do not permit those providers to use your data to train their models, and we contract with them as processors on that basis.
Automated output can be wrong. You may ask us to explain, in general terms, how a particular piece of analysis was produced, and you may tell us if you believe it is inaccurate.
6. Who we share it with
We do not sell your personal data, and we do not share it for anyone else’s independent marketing.
We share it with the following categories of recipient, in each case only so far as needed:
- hosting, storage, database and content-delivery providers who run our infrastructure;
- analytics and product-monitoring providers, as described in section 9;
- AI model providers, for the purpose described in section 5;
- payment processors and app stores, to take payment and manage subscriptions;
- email, messaging and customer-support providers, to communicate with you;
- professional advisers — lawyers, accountants, auditors and insurers — where necessary;
- authorities, regulators or courts, where we are required by law or where it is necessary to establish, exercise or defend legal claims; and
- an acquirer or successor, if we are involved in a merger, reorganisation, financing or sale of assets, subject to this policy continuing to apply.
Each provider acting on our behalf does so as a processor, under a written contract that limits them to our instructions and requires appropriate security. We do not send your data to a Connected Venue beyond what is needed to authenticate the read-only connection you asked us to make.
7. International transfers
We are established in Cyprus and your data is processed within the European Economic Area wherever we can arrange it. Some of our providers are located outside the EEA, including in the United States.
Where personal data is transferred outside the EEA, we rely on an adequacy decision of the European Commission where one covers the recipient, and otherwise on the European Commission’s Standard Contractual Clauses together with any additional technical and organisational measures the transfer requires. You may request a copy of the safeguards in place by contacting us.
8. How long we keep it
We keep personal data only for as long as we need it for the purpose it was collected for, or for as long as the law requires.
- Account data
- for as long as your account is open, and for 12 months after you close it, so that an account reopened in that period is not lost and so that we can deal with any dispute.
- Connection credentials
- until you revoke the connection or close your account, at which point they are deleted. Revoking at the venue also renders them useless immediately.
- Trading data and derived analysis
- for as long as your account is open, and deleted within 90 days of closure, except where retained in aggregated or de-identified form that cannot be linked back to you.
- Conversation data
- for 24 months from the date of the conversation, or until you delete it, whichever is earlier.
- Payment and accounting records
- for as long as tax and company law require, currently 7 years from the end of the relevant financial year.
- Usage and analytics data
- for up to 26 months, in a form that is progressively aggregated over that period.
- Communications with us
- for 36 months from the last message, so that we have context if you contact us again.
- Records needed for a legal claim
- until the claim and any appeal period is finally resolved.
Backups are held for a limited period on a rolling cycle and are overwritten in the ordinary course. Data deleted from live systems persists in backups only until those backups expire.
9. Cookies and analytics
We use cookies and similar technologies on our website. Strictly necessary ones make the site work and cannot be turned off. Others help us understand how the site and the app are used.
We use PostHog for product analytics, configured to store data in the European Union, and Microsoft Clarity to understand how pages are used. These providers set cookies or similar identifiers and receive usage and device data as described in section 2.
You can control cookies through your browser settings, including refusing them or being warned before one is set. Blocking non-essential cookies does not affect your ability to use the Service. Where the law requires consent for non-essential cookies, we ask for it before setting them and you may withdraw it at any time.
We honour Global Privacy Control and similar automated opt-out signals where they are legally recognised.
10. Security
We take appropriate technical and organisational measures to protect your data, including encryption of data in transit and at rest, encryption of connection credentials with restricted access, access control on a least-privilege basis, network isolation, logging and monitoring, and regular review of our providers.
The Service is designed so that we never need the ability to move your funds: we ask only for read-only credentials, and the Service has no facility to place an order or make a withdrawal.
No system is completely secure and we cannot guarantee absolute security. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours of becoming aware of it where required, and we will notify you without undue delay where the risk is high.
11. Your rights
Subject to the conditions and exemptions in data protection law, you have the right to:
- be informed about how we use your data — which is what this policy is for;
- access the personal data we hold about you, and receive a copy;
- have inaccurate data corrected, and incomplete data completed;
- have your data erased, where we no longer need it, where you withdraw consent we relied on, or where you successfully object;
- restrict our processing while a dispute about accuracy or our legal basis is resolved;
- receive the data you gave us in a structured, commonly used, machine-readable format, and have it transmitted to another controller where technically feasible;
- object to processing based on our legitimate interests, on grounds relating to your particular situation, and to object to direct marketing at any time and without giving a reason; and
- withdraw consent at any time, where our processing is based on consent, without affecting processing carried out before withdrawal.
To exercise any of these rights, contact us at: support@lockin.trade
We will respond within one month. That period may be extended by two further months for complex or numerous requests, and we will tell you within the first month if it is. We may need to verify your identity before acting. Exercising your rights is free, unless a request is manifestly unfounded or excessive.
If you are unhappy with how we have handled your data you may complain to your local data protection supervisory authority. In Cyprus this is the Office of the Commissioner for Personal Data Protection. We would appreciate the chance to address your concern first.
12. Data you are required to provide
Some data is necessary for the contract between us. Without an email address we cannot create an account; without a read-only connection to a venue we cannot analyse your trading, which is the whole of what the Service does; without payment details we cannot take payment for a paid plan. If you do not provide them, we cannot provide the Service or the relevant part of it.
13. Children
The Service is for adults. It is not directed to anyone under 18 and we do not knowingly collect personal data from a person under that age. If we learn that we have, we will delete it promptly. If you believe a minor has provided us with personal data, contact us at the address in section 1.
14. Third-party sites and platforms
The Service links to third-party sites and platforms, including trading venues, app stores and community channels. We are not responsible for their privacy practices, and their handling of your data is governed by their own policies, which you should read.
15. Changes to this policy
We may update this policy. If a change is material — for example a new purpose, a new category of recipient, or a change to the legal basis for something — we will give you notice by email or in the Service before it takes effect, and where the change requires your consent we will ask for it. Other changes take effect when posted, and the date at the top of this page always shows when it was last revised.
Previous versions are available on request.
16. Contact
The controller of your personal data is LOCKIN (CY) LIMITED, a company incorporated in the Republic of Cyprus.
For any privacy question, or to exercise any right under this policy, contact us at: support@lockin.trade