Back to home

Privacy Policy

Last updated: 26 March 2026 | Version 2.0

This Privacy Policy explains how Quantum Academy collects, uses, stores, and protects your personal data. We are committed to protecting your privacy and handling your data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

1. Data Controller

1.1. The data controller responsible for your personal data is Quantum Trader, a sole proprietorship registered in England, operating the Quantum Academy platform at quantumtrader.life/academy.

1.2. For any data protection queries, contact us at: support@quantumtrader.life

2. Personal Data We Collect

2.1. Data you provide directly:

  • Account registration: email address, display name, password (stored as a one-way hash)
  • Profile information: username, avatar, bio, timezone preferences
  • Payment information: processed by Stripe - we do not store your card details on our servers. We receive your Stripe customer ID, subscription status, and billing history metadata
  • Consent records: your acceptance of our Terms, Privacy Policy, Risk Disclaimer, and marketing preferences, including your typed digital signature
  • Community content: forum posts, chat messages, comments, chart annotations, poll votes
  • AI Mentor conversations: questions you ask and the educational responses generated
  • Trade debriefs: CSV trade data you upload for educational analysis
  • Support requests: messages sent through our contact form
  • Event notes: personal notes you write during market event replays

2.2. Data collected automatically:

  • Device and browser information: browser type, operating system, screen resolution
  • IP address: recorded for security, fraud prevention, and legal compliance
  • Usage data: pages visited, features used, learning progress, quiz scores, XP earned
  • Authentication data: login timestamps, session tokens (httpOnly cookies)
  • Referral information: if you were referred by another user, we record the referral code used

2.3. Data we do NOT collect:

  • We do not use advertising cookies or tracking pixels
  • We do not use Google Analytics, Facebook Pixel, or similar third-party analytics
  • We do not collect biometric data
  • We do not collect data from social media profiles unless you voluntarily provide it
  • We do not access your trading accounts, brokerage data, or financial account information

3. How We Use Your Data

3.1. We process your personal data for the following purposes:

  1. Account management: Creating and maintaining your account, authenticating your identity, managing your subscription
  2. Service delivery: Providing access to courses, events, AI Mentor, community features, and other platform functionality
  3. Payment processing: Processing subscription payments, refunds, and managing billing via Stripe
  4. Learning personalisation: Tracking your progress, XP, quiz scores, and achievements to provide a personalised learning experience
  5. AI educational content: Using your questions and context to generate personalised educational responses via our AI Mentor system
  6. Community features: Enabling you to post, comment, share charts, vote in polls, and interact with other members
  7. Communication: Sending transactional emails (password resets, billing confirmations, security alerts) and, with your consent, marketing communications
  8. Security and fraud prevention: Protecting your account and our platform from unauthorised access, fraud, and abuse
  9. Legal compliance: Recording consent, maintaining audit trails, and fulfilling our legal obligations
  10. Platform improvement: Analysing aggregated, anonymised usage patterns to improve our services
  11. Support: Responding to your enquiries and resolving issues
  12. Referral programme: Tracking referrals and calculating commissions for our affiliate programme

4. Legal Basis for Processing

4.1. Under Article 6 of the UK GDPR, we process your data on the following legal bases:

  • Contract performance (Article 6(1)(b)): Processing necessary to provide the services you have subscribed to, including account management, content delivery, and payment processing
  • Consent (Article 6(1)(a)): Where you have given explicit consent, including marketing communications and optional data processing. You can withdraw consent at any time
  • Legitimate interest (Article 6(1)(f)): Processing necessary for our legitimate interests, including platform security, fraud prevention, service improvement, and basic analytics. We balance our interests against your rights and freedoms
  • Legal obligation (Article 6(1)(c)): Processing required to comply with applicable laws, including tax, financial regulations, and data protection requirements

5. Data Sharing

5.1. We share your personal data only with the following categories of recipients, and only to the extent necessary:

  • Stripe (payment processor): Your email, name, and payment details are shared with Stripe to process payments. Stripe acts as an independent data controller for payment data. See Stripe's Privacy Policy
  • Hostinger (infrastructure provider): Our servers are hosted by Hostinger on infrastructure located in Manchester, UK and Boston, US. Hostinger provides the physical servers but does not access your data
  • AI model providers (OpenAI, Anthropic): When you use the AI Mentor or when we generate educational content, your questions and relevant context are sent to OpenAI or Anthropic APIs for processing. These providers act as data processors under our instructions. See their respective privacy policies for details
  • Email delivery: Transactional and marketing emails may be sent via SMTP services. Email addresses and message content are shared with the email delivery provider for the purpose of sending emails only

5.2. We do NOT sell, rent, or trade your personal data to any third party.

5.3. We may disclose your data if required by law, court order, or regulatory authority, or if we believe disclosure is necessary to protect our rights, property, or safety, or the rights, property, or safety of others.

6. International Transfers

6.1. Your data is primarily stored on servers in the United Kingdom (Manchester). Some data may be processed in the United States:

  • AI model API calls (OpenAI, Anthropic) - processed in the US
  • Stripe payment processing - processed in the US and other jurisdictions
  • Test/backup infrastructure - US-based servers

6.2. Where data is transferred outside the UK, we ensure appropriate safeguards are in place, including reliance on adequacy decisions, standard contractual clauses (SCCs), or the data processor's certification under recognised frameworks.

7. Data Retention

7.1. We retain your personal data for as long as necessary to fulfil the purposes for which it was collected, or as required by law. Specific retention periods:

  • Account data: Retained while your account is active and for 30 days after account deletion request (reversible window), then permanently deleted or anonymised
  • Learning progress: Retained while your account is active. Deleted with your account
  • AI Mentor conversations: Retained for up to 12 months for service improvement, then anonymised or deleted
  • Community content: Retained while your account is active. May be anonymised (author name replaced) rather than deleted to preserve thread context for other users
  • Payment and billing data: Retained for 7 years to comply with UK tax and accounting obligations (HMRC requirements)
  • Consent and legal acknowledgment records: Retained for 7 years as evidence of consent
  • Security logs (IP addresses, login records): Retained for up to 12 months
  • Support correspondence: Retained for up to 3 years

8. Your Rights

8.1. Under the UK GDPR, you have the following rights regarding your personal data:

  • Right of access (Article 15): You can request a copy of the personal data we hold about you. You can initiate a data export from your account Settings page, or by contacting us
  • Right to rectification (Article 16): You can update your account information at any time through your Settings page, or request corrections by contacting us
  • Right to erasure (Article 17): You can request deletion of your account and personal data. We will process erasure requests without undue delay and within one month. Some data may be retained where we have a legal obligation (see Section 7)
  • Right to data portability (Article 20): You can request your data in a structured, commonly used, machine-readable format (JSON/CSV)
  • Right to object (Article 21): You can object to processing based on legitimate interest. You can opt out of marketing communications at any time via your Settings page or the unsubscribe link in any marketing email
  • Right to restrict processing (Article 18): You can request that we restrict the processing of your data in certain circumstances
  • Right to withdraw consent: Where processing is based on consent, you can withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal

8.2. To exercise any of these rights, contact us at support@quantumtrader.life. We will respond to your request within one month. In complex cases, we may extend this by up to two additional months, and we will inform you of any extension.

8.3. We will not charge a fee for processing your request unless it is manifestly unfounded or excessive.

9. Right to Complain

9.1. If you are unhappy with how we handle your data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK's supervisory authority for data protection:

  • Website: ico.org.uk
  • Telephone: 0303 123 1113
  • Address: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

9.2. We would appreciate the chance to address your concerns before you contact the ICO. Please reach out to us first at support@quantumtrader.life.

10. Cookies

10.1. We use essential cookies to keep you signed in to your account. We do not use advertising, analytics, or tracking cookies.

10.2. For full details about the cookies and similar technologies we use, please see our Cookie Policy.

11. Children's Privacy

11.1. Quantum Academy is not intended for use by anyone under the age of 18. We do not knowingly collect personal data from children under 18. If we become aware that we have collected data from a child under 18, we will delete that data promptly.

11.2. If you believe a child under 18 has provided us with personal data, please contact us at support@quantumtrader.life.

12. Security

12.1. We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. These include:

  • Encrypted data transmission (HTTPS/TLS) for all communications
  • Password hashing using bcrypt (passwords are never stored in plain text)
  • HttpOnly, Secure cookies for authentication tokens
  • Database access restricted to authorised services only
  • Regular security updates and patching
  • Access logging and audit trails
  • Firewall protection (UFW) and intrusion prevention (Fail2Ban)

12.2. No system is 100% secure. While we take reasonable precautions, we cannot guarantee absolute security of your data.

13. Data Breach Notification

13.1. In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will:

  • Notify the ICO within 72 hours of becoming aware of the breach, as required by Article 33 of the UK GDPR
  • Notify you without undue delay if the breach is likely to result in a high risk to your rights and freedoms, as required by Article 34
  • Provide you with information about the nature of the breach, the likely consequences, and the measures we have taken or propose to take to address it

14. Marketing Communications

14.1. We will only send you marketing communications (educational updates, event notifications, platform news) if you have given explicit consent during signup or through your account Settings.

14.2. You can withdraw marketing consent at any time by:

  • Toggling the marketing preference in your account Settings
  • Clicking the unsubscribe link in any marketing email
  • Contacting us at support@quantumtrader.life

14.3. Opting out of marketing does not affect transactional communications (billing confirmations, password resets, security alerts, service notifications), which are always sent regardless of marketing preferences.

14.4. When you opt out of marketing, we suppress your record (keep you on a "do not contact" list) rather than deleting it, to ensure we do not accidentally re-add you to marketing lists in the future.

15. Changes to This Policy

15.1. We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.

15.2. Material changes will be communicated to you via email or a prominent notice on our platform at least 30 days before taking effect. The "Last updated" date at the top of this page will be updated.

15.3. We encourage you to review this Privacy Policy periodically.

16. Contact Us

If you have any questions about this Privacy Policy or how we handle your data, please contact us:

  • Email: support@quantumtrader.life
  • Website: quantumtrader.life/academy/contact