Privacy Policy
Last Updated: November 2025 | Status: Draft - Requires Legal Review
Welcome to the AI Investment Platform. We respect your privacy and are committed to protecting your personal data. This Privacy Policy explains how we collect, use, and protect your information when you use our Service.
By using our Service, you agree to the collection and use of information in accordance with this policy.
1. Information We Collect
1.1 Information You Provide
Account Information:
- Email address (required)
- Password (hashed, never stored in plaintext)
- Username/display name (optional)
Investment Data:
- Stock watchlist
- Portfolio positions
- Investment preferences
- Alert configurations
1.2 Information We Collect Automatically
Usage Data:
- Pages visited and features used
- Time spent on the platform
- Search queries and interactions
- API usage (for quota enforcement)
Technical Data:
- IP address
- Browser type and version
- Device information
- Operating system
2. How We Use Your Information
2.1 Service Delivery
- Provide and maintain the Service
- Authenticate your account
- Process payments and manage subscriptions
- Deliver personalized recommendations
- Enable features (watchlist, portfolio, alerts)
2.2 Service Improvement
- Understand how users interact with the Service
- Improve features and functionality
- Fix bugs and optimize performance
- Develop new features
2.3 Security & Compliance
- Prevent fraud and abuse
- Enforce usage quotas
- Comply with legal obligations
- Protect user data and security
3. Data Sharing
3.1 Service Providers
We share data with trusted third-party service providers:
Payment Processing (Stripe): Email, subscription status - Purpose: Process payments
AI Services (Azure OpenAI): Stock queries, chat messages - Purpose: Generate AI insights
Vector Database (Pinecone): User preferences (anonymized) - Purpose: Personalized recommendations
Data Providers: Ticker symbols, market data requests - Purpose: Fetch stock data
3.3 We Do NOT Sell Your Data
We never sell your personal data to third parties.
4. Data Security
4.1 Security Measures
We implement industry-standard security measures:
- Encryption: TLS for data in transit, encryption at rest
- Authentication: Secure password hashing (bcrypt)
- Access Control: Role-based access control
- Monitoring: Continuous security monitoring
- Updates: Regular security updates
4.2 Your Responsibility
- Use strong passwords
- Don't share your account credentials
- Log out when using shared devices
- Notify us immediately of unauthorized access
5. Data Retention
Active Accounts: Account data retained while account is active. Usage data retained for 2 years.
Inactive Accounts: Account data deleted after 2 years of inactivity.
Legal Requirements: Financial records retained for 7 years (if applicable). Audit logs retained for 1 year minimum.
6. Your Rights (GDPR)
If you are located in the EU/UK, you have the following rights:
Right to Access
Request a copy of your personal data. Email privacy@vibhatech.com with subject "Data Access Request"
Right to Rectification
Request correction of inaccurate data. Update in account settings or email us.
Right to Erasure
Request deletion of your personal data. Delete account in settings or email us.
Right to Data Portability
Request your data in a machine-readable format. Email privacy@vibhatech.com with subject "Data Portability Request"
Right to Object
Object to processing based on legitimate interests. Email privacy@vibhatech.com
Right to Withdraw Consent
Withdraw consent for optional features. Update preferences in account settings.
Response Time: We will respond within 30 days of your request.
8. Children's Privacy
Age Requirement: Users must be 18+ to use the Service.
We do not knowingly collect data from users under 18. If we discover a user under 18, we will delete their account immediately.
10. Data Breach Notification
If a data breach occurs that may affect your personal data:
- We will notify you within 72 hours (if required by law)
- We will report to ICO within 72 hours (if required)
- We will take immediate action to contain and remediate the breach
12. Contact Us
Privacy Inquiries:
Email: info@vibhatech.com
Company: VIBHA TECHNOLOGY LIMITED
Registered Address: Regus Building, Central Boulevard, Blythe Valley Park, Solihull B90 8AG
Company Registration Number: 07589393
13. Your Consent
By using our Service, you consent to:
- ✅ Collection and use of information as described in this policy
- ✅ Processing of your data in the UK/EU
- ✅ Sharing of data with service providers as described
Note: This Privacy Policy is a draft and requires review by qualified legal counsel specializing in GDPR/data protection before publication. Customize with your specific company information and contact details.