The short version (plain-language summary)
We are Stratsemble, a backtesting and analysis sandbox for traders. Here is the whole thing in six lines; the full detail is below.
- What we collect: your account email and password (stored hashed), the strategies, backtests, watchlists and alerts you create, basic technical logs, and — only if you tick the box — your consent to receive our newsletter. Later, when paid plans launch, Stripe will handle your card details (we never see or store the card number).
- Why: to run the account and features you asked for, to keep the service secure, and — only with your consent — to send you email and measure how the product is used.
- Who sees it: a small set of service providers who help us run the service (our hosting provider, our email provider Resend, later Stripe for payments, Discord if you opt into Discord alerts, and a privacy-respecting analytics tool). We never sell your personal data.
- The public market prices you see are not your personal data — they come from free public feeds (Yahoo Finance for stocks, Binance for crypto).
- Your controls: you can see, correct, download, or delete your data, withdraw any consent, and unsubscribe from email in one click, at any time.
- Your rights: you can complain to Romania's data-protection authority (ANSPDCP) or to your own country's authority.
The rest of this page explains each of these in full, as EU law (the GDPR) requires.
1. Who we are (the data controller)
Stratsemble is operated by:
- Alexandru Prichindel (the individual or entity that runs stratsemble.com)
- Entity / registration: an individual based in Romania
- Contact for privacy matters: [email protected]
We are the "controller" of your personal data — we decide why and how it is processed, and we are responsible for looking after it under the EU General Data Protection Regulation (GDPR, Regulation (EU) 2016/679) and Romanian data-protection law (Legea nr. 190/2018 and Legea nr. 506/2004).
We are based in Romania, inside the EU, so we do not need an EU representative. We have not appointed a Data Protection Officer, because the law does not require one for a service like ours; for anything about your data, write to the contact above and we will handle it directly.
2. What data we collect, why, and our lawful basis
EU law requires a valid "lawful basis" for every purpose. Here is the full map. Nothing outside this table is used for anything else.
| What we collect | Why (purpose) | Lawful basis (GDPR Art. 6) |
|---|---|---|
| Account data — your email address and a hashed password; your chosen plan | To create and run your account and let you sign in | Contract — Art. 6(1)(b) |
| Your content — strategies you save, backtest and forward-test configurations, watchlists, alert rules | To run the backtests, paper-tests and alerts you configure, and save your work | Contract — Art. 6(1)(b) |
| Alert delivery data — the email address (and, if you opt in, the Discord identifier) we send your alerts to | To deliver the alerts you asked for | Contract — Art. 6(1)(b) |
| Technical / log data — IP address, browser/device information, timestamps, basic event logs | To keep the service running, secure and abuse-free, and to diagnose problems | Legitimate interests — Art. 6(1)(f) (balancing test done, see §3) |
| Aggregate product analytics — a cookieless, daily-rotating anonymous code (no device storage; your IP is not kept) | To understand how the product is used so we can improve it | Legitimate interests — Art. 6(1)(f): genuinely aggregate, non-tracking measurement; no consent cookie is set (see §4) |
| Marketing-list membership + email engagement — the fact you opted in, and whether you open/click the newsletter | To send you our newsletter and see whether it is useful | Consent — Art. 6(1)(a); withdraw any time |
| Support correspondence — messages you send us | To answer you | Legitimate interests — Art. 6(1)(f), or Contract where it concerns your account |
Market price data is not your personal data. The prices, charts and historical series shown in the product come from free, public third-party feeds (Yahoo Finance for equities, Binance for crypto). We pull that data from those sources; we do not send them your personal information.
We do not collect special-category data (health, political opinions, and similar), and we do not collect your Romanian personal numeric code (CNP) or any national ID number.
3. A note on "legitimate interests"
Where we rely on legitimate interests (security and genuinely aggregate analytics), we have weighed our interest against your rights and concluded the processing is limited, expected, and low-impact. You can ask us for a summary of that balancing test, and you can object at any time (see §9).
We do not use "legitimate interests" as a basis for our newsletter or for non-essential cookies — for those we always ask for your consent.
4. Cookies and analytics
The short of it: we use no advertising or tracking cookies, and there is no cookie banner to click.
Strictly-necessary only. The only things we store on your device are what the site needs to work — chiefly a sign-in session cookie (so you stay logged in) and security tokens (e.g. anti-forgery). The law does not require consent for these, because the service cannot run without them.
Cookieless analytics. To understand which features actually help, we measure usage in a privacy-friendly, cookieless way: our server derives a short, daily-rotating anonymous code from your IP address and browser type, and keeps only that code — never your IP address, and nothing on your device. Because we store nothing on your device for analytics and keep no persistent identifier, this needs no consent and sets no tracking cookie, and the code cannot be used to follow you across days or across other sites. We do not use third-party advertising cookies or cross-site tracking, and we do not sell your data.
This cookie section is part of this policy; there is no separate cookie document.
5. Email and the newsletter
We keep two kinds of email completely separate:
- Service (transactional) emails — sign-in help, security notices, and the alerts you configured. These are part of the service you asked for (contract basis); they are not marketing, and you cannot "unsubscribe" from essential account emails while you have an account.
- The newsletter (marketing) — sent only if you gave separate, explicit consent (an unticked box you actively check; never bundled into signup or into accepting the Terms). Every newsletter carries a working one-click unsubscribe and a clear sender identity, and we honour unsubscribes promptly. Unsubscribing from marketing never affects your account or your service emails. If we transfer the business (see §6a), your subscription and consent may pass to the successor, which will continue the newsletter for the same purpose and identify itself to you; you can unsubscribe in one click at any time, before or after.
We never buy, rent or scrape email lists.
6. Who we share your data with (processors and recipients)
We share personal data only with a small number of service providers who process it on our instructions, under a data-processing agreement (GDPR Art. 28), and only for the purposes above. We do not sell or "share" your personal data for anyone else's own purposes, and we do not use it for cross-context behavioural advertising.
| Provider | Role | What they handle |
|---|---|---|
| OVHcloud (OVH US LLC) and Cloudflare, Inc. | Hosting / infrastructure | Runs the servers that store and process your data |
| Resend | Email delivery | Sends our service and (if you consented) marketing emails |
| Discord | Optional alert delivery | Delivers alerts only for users who opt into Discord |
| First-party, cookieless — no third-party analytics processor | Analytics | Aggregate usage measurement (only after consent, if it sets an identifier) |
| Stripe (from paid launch — not active during beta) | Payments | Processes card payments; we never receive or store your card number |
We may also disclose data where the law requires it (for example, a valid legal request), or to protect the security and integrity of the service. If we ever change or add a provider in a way that affects you, we will update this policy.
6a. If we transfer the business (change of controller)
Stratsemble is currently run by an individual. We intend, when paid plans launch, to move the business into a company we form (a Romanian SRL), and it is possible the business (or part of it) could later be transferred to, or merged with, another owner. As part of any such reorganisation, formation, or sale, your account data and — if you subscribed — your newsletter data may be transferred to that successor entity, which will become the new data controller.
If that happens:
- the successor will process your data for the same purposes and on the same basis described in this policy (or one materially the same);
- we will tell you — by email and/or an in-app notice — of the change and the new controller's identity, before or promptly around the transfer;
- all your rights in §9 continue unchanged, including your right to object to marketing and to unsubscribe in one click at any time; and
- because the successor (for example our own SRL) simply steps into our shoes for the same service, we rely on the continuation of the existing lawful bases (contract for your account; your existing consent, as anticipated here, for the newsletter) — we do not need, and will not pretend to need, to re-obtain consent you have already given, but you are always free to withdraw it.
We will not transfer your data to a successor that would use it for materially different purposes without giving you notice and, where the law requires it, obtaining your fresh consent first.
7. Sending data outside the EU (international transfers)
Some of our providers are based in the United States, so your data may be processed there. When that happens we use a lawful transfer mechanism:
- Where a provider is certified under the EU–U.S. Data Privacy Framework (for example our payment provider Stripe and our email provider Resend), we rely on that adequacy decision (European Commission decision of 10 July 2023).
- For any provider that is not so certified, we rely on the European Commission's Standard Contractual Clauses (Implementing Decision (EU) 2021/914).
You can ask us for a copy of the safeguards that apply to a specific transfer, using the contact in §1. (A transfer from us, as an individual in Romania, to our own future Romanian SRL is inside the EU and is not an international transfer.)
Our market-data sources (Yahoo Finance, Binance) are places we read public price data from; we do not transfer your personal data to them.
8. How long we keep your data (retention)
We keep data only as long as we need it, then delete or anonymise it:
- Account and content data — for as long as your account exists. When you ask us to delete your account or your data (email us at [email protected]), we delete or anonymise it without undue delay, and within one month at the latest; for a short period after that, residual copies may survive only until our routine encrypted backups cycle out, and are not used for anything else in the meantime.
- Technical / security logs — up to 12 months.
- Marketing data — until you withdraw consent or unsubscribe, after which we stop and keep only a minimal record that you unsubscribed (so we do not email you again).
- Payment and invoice records (from paid launch) — for the period Romanian accounting law requires: 5 years, calculated from 1 July of the year after the financial year the record relates to (Legea contabilității nr. 82/1991, art. 25, as amended by Legea nr. 36/2023). The lawful basis is our legal obligation (Art. 6(1)(c)). These records are generated and kept only once a paid service produces them; none exist while the service is free.
9. Your rights
Under the GDPR you have the right to: access a copy of your data; rectification of inaccurate data; erasure ("right to be forgotten") where the law allows; restriction of processing while a concern is resolved; portability of the data you gave us (for consent- and contract-based data); to object to processing based on our legitimate interests, and — for direct marketing, an absolute right to object that we always honour immediately; to withdraw consent at any time for anything based on consent (this does not affect processing done before you withdrew); and not to be subject to solely automated decisions with a legal or similarly significant effect.
To exercise any of these, email [email protected]. We respond within one month. Using these rights is free; we may only charge or refuse if a request is clearly unfounded or excessive, and we will explain if so.
10. Automated decision-making
We do not make automated decisions that produce legal effects or similarly significantly affect you. Our backtests, forward-tests and alerts are impersonal tools that you run and act on yourself — identical for every user running the same inputs, not based on your personal circumstances, and not a recommendation about what is right for you. You decide what to do and you execute any trade on your own broker.
11. Your right to complain
If you think we have mishandled your data, please tell us first — we would like the chance to fix it. You also have the right to complain to a supervisory authority:
- In Romania: Autoritatea Naţională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP), B-dul G-ral Gheorghe Magheru 28–30, Sector 1, Bucureşti; email [email protected]; www.dataprotection.ro.
- Anywhere in the EU: you may instead complain to the data-protection authority in your own country.
12. Children
Stratsemble is for adults. You must be at least 18 years old to create an account or use the service. We do not knowingly collect data from anyone under 18, and if we learn an account belongs to someone under 18 we will close it and delete the data.
13. How we protect your data
We use appropriate technical and organisational measures — including hashed passwords, encryption in transit, access controls, and limiting who and what can reach your data — to keep it secure. No system is perfectly secure, but if a personal-data breach occurs that is likely to put you at risk, we will notify ANSPDCP within 72 hours where required, and tell you directly if the risk to you is high.
14. Changes to this policy
We may update this policy as the service or the law changes (including the move from an individual operator to our SRL, and the launch of paid plans). When we do, we change the version number and effective date at the top, and for significant changes we give clear notice (for example by email or an in-app notice). Older versions are kept so it is always clear what applied when.
15. Where your data comes from
We collect your personal data directly from you — when you create an account, use the features, contact us, or opt into the newsletter. We do not buy personal data about you from third parties or build profiles of you from outside sources. (If that ever changes — for example a referral programme that brings us data from someone else, or data received via a business transfer under §6a — we will update this policy with the source, as GDPR Art. 14 requires.)
This policy is written in plain language on purpose. If any part is unclear, ask us at [email protected] and we will explain it.