Controller Information: Capo Horn Lab B.V. (hereinafter "Capo Horn Lab", "we", "us", or "our") is the data controller for the processing of personal data as described in this policy. Our registered office is located in the European Union. For all data protection inquiries, contact
privacy@capohornlab.com.
1. Scope of This Policy
This Privacy Policy explains how Capo Horn Lab collects, uses, discloses, and safeguards your personal data when you visit our website, use our backtesting services, subscribe to our research publications, or otherwise interact with us. It applies to all users of our platform, including visitors, registered users, and subscribers.
We process personal data in accordance with the General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"), the ePrivacy Directive (2002/58/EC), and applicable EU Member State implementing legislation.
2. What Data We Collect
We collect only the personal data necessary to provide our quantitative backtesting and research services. The categories of data we may collect include:
2.1 Information You Provide Directly
- Account Data: Name, email address, company name, and billing information when you register for an account or subscribe to our services.
- Strategy Data: Trading strategy descriptions, entry and exit rules, parameters, and optional uploaded files that you submit for backtesting analysis. This data is pseudonymised and processed solely for the purpose of the analysis you request.
- Communication Data: Any information you provide when contacting our support team, scheduling a consultation, or participating in surveys.
- Payment Data: Payment card details and billing address. All payment processing is handled by our PCI-DSS compliant payment processors; we do not store full credit card numbers on our servers.
2.2 Information Collected Automatically
- Usage Data: Pages visited, features used, time spent on pages, referring URLs, and interaction patterns within our platform.
- Device Data: IP address, browser type and version, operating system, device type, and screen resolution.
- Cookie Data: Information collected via cookies and similar tracking technologies. Please refer to our Cookie Policy for detailed information.
3. How We Use Your Data
We process your personal data exclusively for the following purposes:
- Service Delivery: To perform the quantitative backtesting and strategy analysis services you request, including processing submitted strategy parameters and delivering results.
- Account Management: To create and maintain your account, manage subscriptions, process payments, and provide customer support.
- Research Communication: To send you research publications, market insights, and service updates that you have subscribed to receive.
- Platform Improvement: To analyse usage patterns and improve our platform, user experience, and service offerings using aggregated, anonymised data.
- Legal Compliance: To comply with applicable legal obligations, including anti-money laundering (AML) checks and tax reporting requirements.
We do not use your personal data for automated decision-making or profiling that produces legal effects concerning you. We do not sell your personal data to third parties.
4. Legal Basis for Processing (GDPR)
Under the GDPR, we rely on the following legal bases for processing your personal data:
- Performance of a Contract (Article 6(1)(b)): Processing your strategy data and account information is necessary to provide the backtesting and research services you have contracted.
- Consent (Article 6(1)(a)): We rely on your freely given consent for optional communications, newsletter subscriptions, and non-essential cookies. You may withdraw consent at any time.
- Legitimate Interests (Article 6(1)(f)): We process usage data and analytics for platform improvement and security, based on our legitimate interest in maintaining and enhancing our services, balanced against your privacy rights.
- Legal Obligation (Article 6(1)(c)): Where we are required to retain or disclose data by applicable EU or Member State law.
5. Data Sharing and Disclosure
We share your personal data only with the following categories of recipients, and only to the extent necessary:
- Service Providers: Cloud infrastructure providers (hosting, data storage), payment processors, email delivery services, and analytics platforms. All processors are bound by data processing agreements compliant with GDPR Article 28.
- Professional Advisors: Lawyers, auditors, and accountants where necessary for compliance or dispute resolution.
- Legal Authorities: Where required by law, court order, or regulatory obligation, we may disclose data to competent law enforcement, tax, or regulatory authorities.
We do not share your strategy data or research analysis with any third party without your explicit consent, except as described above.
6. Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes described in this policy, or as required by law:
- Account Data: Retained for the duration of your account plus 6 months after closure, unless legal retention periods require longer storage.
- Strategy Data: Retained for the duration of your backtesting engagement plus 12 months, after which it is irreversibly anonymised or deleted.
- Payment Data: Retained for the period required by tax and accounting regulations (typically 7 years under EU law).
- Communication Data: Retained for 3 years from the last interaction.
- Usage and Cookie Data: Retained in accordance with our Cookie Policy.
7. Your Rights Under GDPR
As a data subject in the European Union, you have the following rights regarding your personal data:
- Right of Access (Article 15): Request confirmation of whether we process your data and obtain a copy of the data we hold about you.
- Right to Rectification (Article 16): Request correction of inaccurate or incomplete data.
- Right to Erasure (Article 17, "Right to be Forgotten"): Request deletion of your personal data where it is no longer necessary for the purposes for which it was collected.
- Right to Restriction of Processing (Article 18): Request restriction of processing in certain circumstances, such as contesting accuracy or objecting to processing.
- Right to Data Portability (Article 20): Receive your data in a structured, commonly used, machine-readable format and transmit it to another controller.
- Right to Object (Article 21): Object to processing based on legitimate interests, including direct marketing.
- Rights in Relation to Automated Decision-Making (Article 22): Not be subject to decisions based solely on automated processing that produce legal effects.
To exercise any of these rights, please contact us at privacy@capohornlab.com. We will respond within 30 days as required by the GDPR. You also have the right to lodge a complaint with your local data protection supervisory authority.
8. International Transfers
Your data is processed and stored within the European Economic Area (EEA). Where we use service providers located outside the EEA, we ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses (SCCs) adopted by the European Commission (Decision 2021/914); and
- Transfer Impact Assessments conducted where required.
You may request a copy of the relevant safeguards by contacting privacy@capohornlab.com.
9. Data Security
We implement appropriate technical and organisational measures to protect your personal data, including:
- Encryption in transit (TLS 1.3) and at rest (AES-256).
- Access controls based on the principle of least privilege.
- Regular security audits and penetration testing.
- Employee training on data protection and confidentiality obligations.
- Incident response procedures for data breach notification under GDPR Articles 33–34.
Notwithstanding these measures, no method of transmission or storage is 100% secure. We encourage you to use strong, unique passwords and enable two-factor authentication where available.
10. Children's Privacy
Our services are not directed to individuals under the age of 18. We do not knowingly collect personal data from minors. If we become aware that a minor has provided us with personal data, we will delete it promptly. If you believe a minor has submitted data to us, please contact privacy@capohornlab.com.
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or operational needs. Material changes will be communicated via email to registered users and through a notice on our website. The "Last updated" date at the top of this page indicates when the policy was last revised.
If you have any questions, concerns, or requests regarding this Privacy Policy or our data processing practices, please contact:
Data Protection Officer
Capo Horn Lab B.V.
Email: dpo@capohornlab.com
Privacy Inquiries: privacy@capohornlab.com
You also have the right to lodge a complaint with the relevant data protection supervisory authority in your EU Member State of residence.