Skip to content

Legal

Privacy Policy

Effective date: 29 September 2026

Template — to be reviewed by a legal professional before launch.

This policy explains how we process personal data when you visit qtriskmanager.com, create an account, request a beta license, buy a plan or use the QT Risk Manager indicator, in accordance with Regulation (EU) 2016/679 ("GDPR") and Italian Legislative Decree 196/2003 as amended.

1. Data controller

Davide Bettio, VAT IT03081340121, Via Miralago 22, Laveno Mombello (VA), Italy. Email: info@qtriskmanager.com.

2. Data we collect

  • Account data: name, email address, password (stored only as a secure hash), two-factor authentication settings, account creation and last login dates.
  • Beta requests: name, email and the optional message you send (e.g. your broker or prop firm).
  • License data: license key, plan, status, start and expiry dates, device releases.
  • Device data: when the indicator checks your license it sends the license key, a hash of a hardware identifier of your Windows installation (not your name or files), a random one-time value and the indicator version. We record the result of each check with the request's IP address.
  • Payment and billing data: payments are processed by Stripe. We receive a customer and subscription identifier, the plan, amounts, currency, billing country and invoice status. We never receive or store your card details.
  • Support data: the content of tickets and emails you send us.
  • Technical logs: IP address, requested path, status code and timestamp of requests to our servers.

The indicator does not send us your trades, positions, account balance or broker credentials: all of that stays inside Quantower on your computer.

3. Purposes and legal bases

PurposeLegal basis (GDPR)
Creating and managing your account, issuing and validating licenses, delivering downloads and updates, providing supportPerformance of a contract — Art. 6(1)(b)
Reviewing beta requests and sending beta licensesSteps taken at your request before a contract — Art. 6(1)(b)
Payments, invoicing, tax and accounting recordsLegal obligation — Art. 6(1)(c)
Security, preventing fraud and license-key sharing, rate limiting, server logsLegitimate interest — Art. 6(1)(f)
Service emails (verification, password reset, license and billing notices)Performance of a contract — Art. 6(1)(b)
Emails when a new version of the indicator is published, to licence holders (you can stop them with the link in each email or in your account)Legitimate interest in keeping the software you use up to date — Art. 6(1)(f)
Establishing, exercising or defending legal claimsLegitimate interest — Art. 6(1)(f)
Website usage statistics (Google Analytics), only if you accept analytics cookiesConsent — Art. 6(1)(a) and Art. 122 of Legislative Decree 196/2003

We do not use your data for profiling or automated decisions with legal effects, and we do not sell it. We will only send marketing emails with your consent, which you can withdraw at any time.

4. Service providers (processors)

  • Stripe (Stripe Payments Europe, Ltd., Ireland) — payments, subscriptions, billing portal and tax calculation (Stripe Tax). For certain data Stripe acts as an independent controller; see stripe.com/privacy.
  • Resend (Resend, Inc., USA) — delivery of transactional emails.
  • DigitalOcean, LLC (servers in Frankfurt, Germany, EU) — hosting of the Website, database and license server.
  • YouTube (Google Ireland Ltd.) — only if you press play on the product video: the video is then loaded from youtube-nocookie.com, which receives your IP address. Nothing is loaded from YouTube before you click.
  • Google Analytics (Google Ireland Ltd.) — only if you accept analytics cookies: pseudonymous usage statistics (pages visited, referrer, device and browser type, approximate location derived from the IP address). Google Signals and advertising features are disabled. The customer area (/app) is not tracked.
  • Professional advisers (e.g. accountant) where necessary, under confidentiality obligations.

Processors act on our instructions under a data processing agreement (Art. 28 GDPR).

5. Transfers outside the EU

The Website, the database and the license server are hosted in the EU (Frankfurt, Germany). Some providers (e.g. Resend, Stripe group companies, Google, and DigitalOcean as a US company) may process data in, or access it from, the United States. Such transfers rely on the EU–U.S. Data Privacy Framework where the recipient is certified, or on the European Commission's Standard Contractual Clauses (Art. 46 GDPR).

6. Retention

DataRetention
Server logs with IP addresses30 days
License check records (IP address, hashed device identifier, result)30 days
Account and license dataWhile your account exists, then 12 months after closure or last license expiry
Beta requests not converted into a license12 months after the decision
Support tickets24 months after the ticket is closed
Invoices and accounting records10 years (Article 2220 of the Italian Civil Code)
Google Analytics statistics14 months; the _ga cookies expire after at most 13 months
Your cookie choice (stored in your browser)6 months, then you are asked again

7. Your rights

You have the right to access your data, have it rectified or erased, restrict or object to its processing, and receive it in a portable format (Articles 15–22 GDPR). Where processing is based on consent, you can withdraw it at any time. To exercise your rights, write to info@qtriskmanager.com; we will reply within one month. You also have the right to lodge a complaint with the Italian supervisory authority, the Garante per la protezione dei dati personali (garanteprivacy.it), or with the authority of your country of residence.

Some data is necessary to provide the service: without an email address we cannot create an account or send a license.

8. Cookies

Strictly necessary (no consent needed): qtrm_sid, an HTTP-only session cookie set when you log in to the customer area, used to keep you signed in and protect your session. It is deleted when you log out or when the session expires. Your cookie choice is kept in your browser's local storage (qtrm_consent) so we do not ask again on every page.

Analytics (only with your consent): if you click Accept in the cookie banner, Google Analytics sets the _ga and _ga_<id> cookies to count visits and understand how the Website is used. Nothing is loaded from Google before you accept, and refusing has no effect on how the Website works. You can change your choice at any time with Cookie settings in the footer of every page; withdrawing consent deletes these cookies.

We do not use advertising or profiling cookies. If a walkthrough video is embedded, the player is loaded from the video provider only after you press play.

9. Security

We protect your data with encrypted connections (HTTPS), hashed passwords, optional two-factor authentication, access controls, rate limiting and logs that never contain license keys. No system is completely secure; if a breach affects your data we will notify you and the authority as required by law.

10. Minors

Our services are not intended for people under 18 and we do not knowingly collect their data.

11. Changes

We may update this policy. The effective date at the top shows the latest version; we will inform registered users by email of material changes.