Privacy Policy

Effective date: March 20, 2026

Last updated: March 20, 2026

This Privacy Policy explains how Buildix ("we", "us"), operated via buildix.trade, collects, uses, and protects your personal data in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR") and Italian data protection laws (D.Lgs. 196/2003, as amended by D.Lgs. 101/2018).

1. Data Controller

The data controller is The Buildix Team, contactable at hello@buildix.trade.

2. Data We Collect

Account data: email address, hashed password, display name (optional). Collected at registration.

Subscription data: subscription tier, payment amount, cryptocurrency used, transaction hash. Collected at payment.

Usage data: pages visited, features used, deep view count, watchlist symbols, alert configurations. Collected automatically.

Technical data: IP address, browser type, device type, operating system. Collected automatically via server logs.

Exchange API keys: if provided, encrypted at rest with AES-256-GCM. Used solely to read market data or execute trades on your behalf on your exchange account. Never shared with third parties.

AI API keys (BYOK): if provided, encrypted at rest. Used solely to make API calls to your chosen AI provider on your behalf. Never shared.

Wallet address: if provided for portfolio tracking, used read-only to fetch position data from Hyperliquid. Publicly visible on-chain by nature.

3. Legal Basis for Processing

Contract performance (Art. 6(1)(b) GDPR): processing account and subscription data to provide the Service.

Legitimate interest (Art. 6(1)(f) GDPR): processing usage and technical data to improve the Service and ensure security.

Consent (Art. 6(1)(a) GDPR): processing analytics cookies (if accepted via cookie banner).

4. How We Use Your Data

To provide and maintain the Service. To process payments and manage subscriptions. To send transactional emails (payment confirmation, account security). To improve the Service based on usage patterns. To detect and prevent abuse. We do NOT use your data for advertising, profiling for marketing, or selling to third parties.

5. Data Sharing

We share data only with the following categories of processors, all with appropriate data processing agreements:

Supabase (database and authentication): stores account data, usage data, encrypted API keys. Servers in EU/US.

Vercel (hosting): processes HTTP requests, server logs. Servers globally.

Your chosen AI provider (BYOK): when you use the AI advisor, your question and market data context are sent to the provider you selected using your own API key. This is initiated by you and governed by the provider's privacy policy.

We do NOT share your data with advertisers, data brokers, or any other third parties.

6. Data Retention

Account data: retained while your account is active, deleted within 30 days of account deletion request.

Subscription data: retained for 10 years (Italian tax law obligation).

Usage data: retained for 12 months, then anonymized.

Technical logs: retained for 90 days.

Exchange/AI API keys: deleted immediately upon your request or account deletion.

7. Your Rights (GDPR)

You have the right to:

Access: request a copy of your personal data.

Rectification: correct inaccurate data.

Erasure: request deletion of your data ("right to be forgotten").

Restriction: restrict processing in certain circumstances.

Portability: receive your data in a structured, machine-readable format.

Objection: object to processing based on legitimate interest.

Withdraw consent: for analytics cookies, at any time via cookie settings.

To exercise any right, email hello@buildix.trade. We will respond within 30 days.

8. Data Security

We implement appropriate technical and organizational measures: encryption at rest (AES-256-GCM for sensitive data), encryption in transit (TLS 1.3), database Row Level Security (RLS), input validation, rate limiting, and regular security reviews.

9. International Transfers

Your data may be processed outside the EEA (Supabase, Vercel). These transfers are protected by Standard Contractual Clauses (SCCs) approved by the European Commission.

10. Cookies

See our Cookie Policy for details on cookies used.

11. Children

The Service is not intended for users under 18. We do not knowingly collect data from minors.

12. Changes

We may update this policy. Material changes will be communicated via email or notice on the Service.

13. Supervisory Authority

You have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali) at www.garanteprivacy.it.

14. Contact

For privacy inquiries: hello@buildix.trade

The Buildix Team — hello@buildix.trade

Last updated: March 2026