AEGIS·RHO
// LEGAL · 02

Privacy Policy

This Policy explains, in plain language, what personal data AegisRho collects when you use the Service, why we collect it, how we share it, how long we keep it, and the rights you have over it. It is written to align with the Singapore Personal Data Protection Act 2012 (PDPA) and, where applicable, the EU and UK General Data Protection Regulations (GDPR).

EFFECTIVE
5 July 2026
LAST UPDATED
5 July 2026
CONTROLLER
AegisRho Pte. Ltd.
DPO CONTACT
[email protected]
01

Who we are

AegisRho Pte. Ltd., a private limited company incorporated in Singapore, is the data controller of personal data processed in connection with the Service. References to “we”, “us”, and “our” mean AegisRho. References to “you” mean any natural person whose personal data we process — typically a Subscriber or prospective Subscriber.

02

Scope

This Policy applies to personal data collected through aegisrho.com, console.aegisrho.com, our APIs, and any related communications. It does not apply to third parties such as Connected Exchanges, payment processors, or analytics providers when they act as their own controllers — please consult their respective policies.

03

Data we collect

  • Account data — name, email, password hash, communication preferences. We do not collect identity documents — the Service does not require KYC.
  • Trading metadata — Connected Exchange identifier, API key fingerprint (not the secret), the trades your agent places, position notional, fees accrued. We do not collect the underlying balance or holdings beyond what is necessary to size your agent's trades.
  • Device & technical data — IP address, browser type, operating system, time zone, cookies, session identifiers, approximate geo-location derived from IP.
  • Communications — support tickets, emails, chat transcripts, call recordings (where lawful and disclosed).
  • Marketing data — newsletter subscription status, campaign click-through events.
04

Why we use your data

  • Performance of contract — to provide, operate, and bill for the Service.
  • Legal obligation — to comply with applicable law, including sanctions compliance, tax reporting, and regulatory requests.
  • Legitimate interest — to secure the Service, prevent fraud and abuse, improve performance, manage subscriber communications, and defend legal claims.
  • Consent — for non-essential cookies, marketing communications, and any other processing for which consent is required by law. You may withdraw consent at any time.
05

How we share data

We share personal data only with parties that have a legitimate need and that are bound by appropriate confidentiality and processing terms:

  • Payment & billing processors for credit top-up settlement.
  • Cloud infrastructure providers for hosting and security (encrypted at rest and in transit).
  • Connected Exchanges — via the API keys you provide; we do not pass profile data, only the trade instructions your agent requires.
  • Analytics & error-reporting providers for product-improvement and uptime monitoring.
  • Professional advisers — auditors, lawyers, tax advisers — under professional confidentiality.
  • Regulators, law enforcement, and courts when legally compelled or where disclosure is necessary to protect rights, safety, or property.
  • Acquirers in the event of a merger, acquisition, or asset sale, subject to equivalent privacy protections.

We do not sell personal data. We do not share personal data with third parties for their own marketing purposes.

06

International transfers

AegisRho is headquartered in Singapore. Where we transfer personal data outside your home jurisdiction we rely on appropriate safeguards including Standard Contractual Clauses (for EU/UK data), adequacy decisions where available, and contractual commitments from processors to apply protections at least equivalent to those required under Singapore PDPA.

07

Retention

  • Account data — for the duration of the subscription and up to seven (7) years after termination, in line with financial-services record-keeping obligations.
  • Trading metadata — seven (7) years, for audit and dispute purposes.
  • Marketing data — until you unsubscribe, plus a short suppression-list retention to honour your opt-out.
  • Logs & technical data — typically thirty (30) to ninety (90) days, longer where investigation of a security incident is in progress.
08

Security

We apply technical and organisational measures appropriate to the risk, including encryption at rest and in transit, role-based access controls, second-factor authentication for staff, least-privilege access, secret rotation, and routine security review. Exchange API secrets are stored encrypted and are never exposed in plaintext to staff. No security measure can guarantee absolute protection — you are responsible for safeguarding your own credentials and API keys.

09

Your rights

Subject to applicable law, you have the right to:

  • Access — a copy of the personal data we hold about you.
  • Correct — inaccurate or incomplete data.
  • Delete — your data, where retention is no longer justified.
  • Restrict or object — to certain processing, including for direct marketing.
  • Portability — receive your data in a structured, machine-readable format.
  • Withdraw consent — where processing relies on consent.
  • Lodge a complaint — with the Personal Data Protection Commission of Singapore, or your local supervisory authority.

To exercise any of these rights, write to [email protected]. We will respond within thirty (30) days, or as required by your local law. We may need to verify your identity before acting on a request.

10

Cookies and analytics

We use a small number of cookies and similar technologies to operate the Service. Strictly-necessary cookies (authentication, session, CSRF tokens) cannot be disabled. Analytics and preference cookies are subject to your consent, which you can adjust at any time via the cookie banner or the settings page.

We do not use cross-site advertising trackers. We use privacy-preserving product analytics to understand aggregated usage and reliability of the Service.

11

Automated checks

Some of our compliance checks (sanctions screening and fraud-detection scoring) involve automated processing and may have legal or similarly significant effects on you. You have the right to obtain human review of any decision based solely on automated processing — contact [email protected].

12

Children

The Service is not directed at, and not intended for use by, persons under the age of 18. We do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact us and we will delete it.

13

Changes to this policy

We may update this Policy from time to time. The “Last Updated” date at the top indicates the most recent revision. Material changes will be notified to active Subscribers by email or in-platform notice. Continued use of the Service after the effective date constitutes acceptance.