Skip to content

CryptoMetric AI Privacy Notice — counsel-review draft

Draft GDPR transparency information for the CryptoMetric AI service; processing facts must be verified before publication.

Draft status and controller

This notice was drafted on 20 September 2026 and is not effective. Syscobyte AB is the intended controller, subject to confirmation of the identity and contacts in the publisher snapshot. [PENDING controller representative or data-protection-officer details if legally required].

Personal data collected

Expected account data includes name, email, authentication state and user identifiers. Service data may include bot settings, signals, paper and live order records, audit events, support messages, security events, IP address and device or request metadata. Connected exchange identifiers and encrypted API credentials may be processed; withdrawal credentials must not be supplied.

[PENDING verified production data inventory, including telemetry, email-delivery records and any special-category or criminal-offence data prohibition].

Purposes and lawful bases

Expected purposes include creating and securing accounts, supplying requested features, recording instructions, preventing abuse, supporting users, maintaining audit evidence and meeting legal obligations.

[PENDING purpose-by-purpose GDPR Article 6 lawful-basis assessment, legitimate-interest balancing tests, consent uses and statutory obligations]. Consent will not be described as freely given where access is conditional on processing that is necessary for the contract.

Exchange credentials and trading records

Exchange credentials are intended to be encrypted at rest and revealed only to the components that require them to perform an authorized action. Logs must not contain plaintext secrets. Trading and audit records may be needed to explain instructions, reconcile activity, investigate incidents and establish legal claims, subject to defined retention limits.

Recipients and processors

Access is limited by role and operational need. Data may be disclosed when the user instructs it, to service providers acting under appropriate terms, or where law requires.

[PENDING complete processor/subprocessor list, processing locations, purposes and links to current notices]. No third-party category should be inferred from this draft.

International transfers

[PENDING confirmed hosting and support locations, whether personal data leaves the EEA, each transfer mechanism, supplementary measures and how to obtain a copy]. A transfer will not be described as protected merely because a supplier uses encryption.

Retention and deletion

Personal data must be retained only as long as needed for the stated purpose, security, disputes and legal duties, then deleted or irreversibly anonymized. Account closure may not immediately erase records that must lawfully be retained.

[PENDING category-specific retention schedule, trigger, deletion method, backup expiry and legal-hold process].

Data-protection rights

Depending on the processing and applicable law, a person may request access, correction, erasure, restriction, portability or objection, and may withdraw consent without affecting earlier lawful processing. Requests will be authenticated proportionately and answered within the applicable period.

A person may complain to the Swedish Authority for Privacy Protection (IMY) or another competent supervisory authority. Contact requests through the pending monitored privacy address; [PENDING verified request workflow and responsible owner].

Automated processing

The product uses rules and machine-learning output to assist user-configured analysis. [PENDING documented assessment of whether any processing produces legal or similarly significant effects under GDPR Article 22, the logic and consequences that must be explained, and available human intervention].

Security and personal-data breaches

Technical and organizational safeguards are selected according to risk, but no system is immune from incidents. Suspected compromise should be reported to the pending security contact. Syscobyte AB will assess personal-data breaches and notify authorities and affected people where GDPR thresholds and time limits require.

Changes and contact

Material notice changes will receive a new version and date. Where processing needs consent, a notice change alone will not create consent. Questions and rights requests go to the literal privacy contact in this version once confirmed.

Primary sources