Legal
Privacy Policy
Last updated: March 23, 2026
Introduction
This Privacy Policy explains how Profalgo Limited ("we", "us", "our", "Provider", "Profalgo") collects, uses, processes, stores, shares, and protects your personal data when you visit our website, purchase our products, or use our services.
Profalgo Limited is a company incorporated and registered in Malta with:
- Company Registration Number: C-93668
- Registered Office: 36, St Dminka Street, Victoria VCT 9030, Gozo, Malta
This Privacy Policy applies to:
- Our website at www.forexeasolutions.com (the "Store")
- Our algorithmic trading software products (the "Product")
- All related services (collectively, the "Services")
By accessing the Store, purchasing the Product, or using the Services, you acknowledge that you have read, understood, and consent to the practices described in this Privacy Policy.
If you do not agree with this Privacy Policy, you must not use the Store, Product, or Services.
1. Data Controller and Scope
1.1 Data Controller
Profalgo Limited is the sole and exclusive data controller (within the meaning of the EU General Data Protection Regulation (GDPR) and other applicable data protection laws) for all personal data collected, processed, or stored in connection with the Store, Product, Services, and user accounts.
As data controller, Profalgo determines:
- What personal data is collected
- How personal data is used and processed
- How long personal data is retained
- Who personal data is shared with
- Security measures for protecting personal data
Contact Information for Data Protection Matters:
Data Controller: Profalgo Limited
Address: 36, St Dminka Street, Victoria VCT 9030, Gozo, Malta
Email: info@forexeasolutions.com
1.2 No Joint Controllers
No third party (including any web hosting provider, cloud infrastructure provider, technical service provider, IT consultant, software developer, payment processor, analytics provider, or other service provider engaged by Profalgo) acts as a joint controller of your personal data.
Any data processing activities performed by third-party service providers are conducted strictly on behalf of Profalgo as data processors under Profalgo's written instructions and in accordance with data processing agreements pursuant to GDPR Article 28.
1.3 User Relationship and Rights
Your data protection rights under applicable law (including GDPR rights) are exercisable solely against Profalgo as the data controller.
You have no direct data protection relationship with, and may not assert data subject rights directly against, any third-party service provider, data processor, or sub-processor engaged by Profalgo.
All data subject access requests, complaints, inquiries, or requests to exercise rights must be directed to Profalgo at the contact information in Section 1.1.
No Claims Against Third Parties: You agree to bring any data protection-related claims, demands, actions, or proceedings solely and exclusively against Profalgo as the data controller, and NOT against any third-party service provider, data processor, sub-processor, hosting provider, infrastructure provider, or other entity engaged by Profalgo.
Profalgo assumes full and exclusive responsibility for all data protection compliance obligations under GDPR and other applicable laws. No third-party service provider, data processor, or sub-processor shall bear any liability, obligation, or responsibility to you in connection with the processing, protection, or security of your personal data.
1.4 Provider Responsibility and No Third-Party Reliance
Profalgo Limited assumes full responsibility for compliance with data protection laws, including the handling of personal data by any data processors or sub-processors engaged on its behalf.
User acknowledges and agrees that:
- User relies solely on Profalgo Limited (as data controller) and not on any data processors, sub-processors, hosting providers, or technical service providers in relation to the processing and protection of their personal data.
- User has not relied on any representations, certifications, privacy policies, or conduct by any data processor or third-party service provider in deciding to provide their personal data to Profalgo Limited.
- To the maximum extent permitted by law, all data processors and third-party service providers engaged by Profalgo Limited shall have no liability whatsoever to User under any legal theory for data protection or privacy-related matters.
- All data protection rights, requests, complaints, or claims must be directed exclusively to Profalgo Limited as the sole data controller.
1.5 Scope of This Policy
This Privacy Policy applies only to personal data collected and processed by Profalgo through:
- The Store and related websites operated by Profalgo
- The Product and related software applications
- User accounts, registrations, and customer interactions
- Communications with Profalgo (email, support tickets, etc.)
This Privacy Policy does NOT apply to:
- Third-Party Websites and Services: Any third-party websites, platforms, brokers, trading platforms, payment processors, or services that you access or use, even if linked from the Store or integrated with the Product.
- Data Collected by Brokers or Trading Platforms: Personal data or trading data collected directly by third-party brokers, trading platforms, or market data providers when you use the Product.
- Public Information: Information that you make publicly available through forums, social media, or other public channels.
2. Personal Data We Collect
2.1 Categories of Personal Data
We collect and process the following categories of personal data:
2.1.1 Account and Registration Information
When you create an account or register for the Services, we collect:
- Full name (first name, last name)
- Email address
- Password (stored in hashed/encrypted form only)
- Country of residence
- Date of birth or age confirmation (to verify you are 18+)
- Account preferences and settings
2.1.2 Purchase and Payment Information
When you make a purchase, we collect:
- Billing name and address
- Email address for receipts and order confirmations
- Order details (product purchased, price, date, order ID)
- Payment method type (credit card brand, PayPal, etc.)
- Last 4 digits of payment card (for order verification only)
- Transaction ID and payment confirmation
Important: We do NOT collect, store, or have access to your full payment card details (complete card number, CVV/CVC code, or expiration date). All payment processing is handled by third-party payment processors (Stripe, PayPal, etc.) who collect and process payment information directly. See Section 4.2.
2.1.3 Product Usage and Technical Data
When you use the Product or Services, we may collect:
- IP address and geolocation data (country, city, region)
- Device information (device type, operating system, browser type and version)
- Product activation and license key information
- Product version, configuration, and settings
- Usage data (features used, session duration, interactions)
- Error logs, crash reports, and diagnostic data
- Performance metrics and analytics
2.1.4 Communications and Support Data
When you contact us for support, inquiries, or feedback, we collect:
- Email address and name
- Support ticket content (your questions, descriptions of issues, attachments)
- Communication history (emails, chat logs, support interactions)
- Any additional information you voluntarily provide
2.1.5 Cookies and Tracking Technologies
We use cookies, web beacons, pixels, and similar tracking technologies to collect:
- Browser and device identifiers
- Website navigation and interaction data (pages visited, links clicked, time spent)
- Referral source (how you found our Store)
- Session data and user preferences
2.1.6 Marketing and Communications Preferences
If you subscribe to our newsletter or marketing communications, we collect:
- Email address
- Subscription preferences (topics of interest, frequency)
- Email engagement data (opens, clicks, unsubscribes)
2.2 Special Categories of Personal Data
We do NOT intentionally collect or process special categories of personal data (also known as "sensitive personal data") as defined under GDPR Article 9, including racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data, health data, sex life or sexual orientation, and criminal convictions or offenses.
If you provide such data to us (e.g., in support communications), you do so at your own risk. We will delete or anonymize such data upon becoming aware of it.
2.3 Children's Data
The Store, Product, and Services are NOT directed at, intended for, or designed to attract individuals under the age of 18 years. We do NOT knowingly collect personal data from individuals under 18. If you are under 18, you may NOT use the Store, purchase the Product, or use the Services.
If we become aware that we have inadvertently collected personal data from an individual under 18, we will delete such data as soon as reasonably practicable.
Parents and guardians: If you believe your child has provided personal data to us, please contact us immediately at info@forexeasolutions.com so we can delete the data.
2.4 Voluntary Provision of Data
Provision of personal data is generally voluntary. However:
Required Data: Certain data is required to provide the Services, such as email address and name (to create an account), billing information (to process purchases), and payment information (processed by payment processors). If you do not provide required data, we may be unable to provide the Services or complete your purchase.
Optional Data: Other data is optional, such as marketing communications preferences, feedback and survey responses, and optional profile information. You may choose not to provide optional data without affecting your ability to use the Services.
3. How We Use Your Personal Data
3.1 Purposes and Legal Bases for Processing
We process your personal data for the following purposes, based on the legal bases specified:
3.1.1 To Provide and Deliver the Services
Purpose: Create and manage your account, process and fulfill purchases, deliver the Product (software download, license key delivery), provide customer support and technical assistance, and communicate with you about your account, orders, and the Product.
Legal Basis: Performance of Contract (GDPR Article 6(1)(b)); Legitimate Interests (GDPR Article 6(1)(f)).
3.1.2 To Process Payments and Prevent Fraud
Purpose: Process payments through third-party payment processors, verify payment information and prevent fraudulent transactions, detect, investigate, and prevent fraud, chargebacks, and abuse, and maintain transaction records for accounting and audit purposes.
Legal Basis: Performance of Contract (GDPR Article 6(1)(b)); Legal Obligation (GDPR Article 6(1)(c)); Legitimate Interests (GDPR Article 6(1)(f)).
3.1.3 To Improve and Optimize the Product and Services
Purpose: Analyze usage patterns and user behavior, identify bugs, errors, and technical issues, optimize Product performance, develop new features and improvements, and conduct research and analytics.
Legal Basis: Legitimate Interests (GDPR Article 6(1)(f)).
3.1.4 To Send Service-Related Communications
Purpose: Send order confirmations, receipts, and invoices, notify you of Product updates, security patches, or changes, send important notices about the Services, Privacy Policy, or Terms and Conditions, and respond to your inquiries and support requests.
Legal Basis: Performance of Contract (GDPR Article 6(1)(b)); Legal Obligation (GDPR Article 6(1)(c)); Legitimate Interests (GDPR Article 6(1)(f)).
3.1.5 To Send Marketing Communications (Optional)
Purpose: Send newsletters, promotional offers, and product announcements, share educational content, tips, tutorials, and best practices, and inform you of new features, updates, or services.
Legal Basis: Consent (GDPR Article 6(1)(a)); Legitimate Interests (GDPR Article 6(1)(f)) for existing customers (soft opt-in).
You may withdraw consent or opt out at any time by clicking the "unsubscribe" link in any marketing email, updating your email preferences in your account settings, or contacting us at info@forexeasolutions.com.
3.1.6 To Comply with Legal Obligations
Purpose: Comply with applicable laws, regulations, and legal processes, respond to lawful requests from courts, regulators, tax authorities, or law enforcement, maintain required records, and enforce our Terms and Conditions.
Legal Basis: Legal Obligation (GDPR Article 6(1)(c)); Legitimate Interests (GDPR Article 6(1)(f)).
3.1.7 To Protect Security and Prevent Abuse
Purpose: Detect, investigate, and prevent fraud, abuse, or unauthorized access, monitor for security threats and malicious activity, enforce our Terms and Conditions, and protect the Store, Product, Services, and users from harm.
Legal Basis: Legitimate Interests (GDPR Article 6(1)(f)).
3.2 Automated Decision-Making and Profiling
We do NOT engage in automated decision-making or profiling that produces legal effects or similarly significantly affects you, as defined under GDPR Article 22.
However, we may use automated systems for fraud detection and risk assessment, and basic analytics and usage statistics. Such automated processing does NOT result in decisions that legally bind you or significantly affect your rights.
4. How We Share Your Personal Data
4.1 General Principle
We do NOT sell, rent, lease, or trade your personal data to third parties for their own marketing or commercial purposes. We share personal data only in the limited circumstances described below, and only to the extent necessary to provide the Services, comply with legal obligations, or protect our rights.
4.2 Third-Party Service Providers (Data Processors)
All third-party service providers listed below act exclusively as data processors on behalf of Profalgo under GDPR Article 28. None of these providers acts as a joint controller of your personal data. All data protection obligations, responsibilities, and liabilities rest solely with Profalgo as the data controller.
4.2.1 Payment Processors
Purpose: To process payments, handle transactions, detect fraud, and manage billing.
Service Providers: Stripe, Inc. (credit/debit cards); PayPal (Europe) S.a r.l. et Cie, S.C.A. (PayPal payments).
Data Shared: Billing name and address, email address, payment method information (handled directly by processor), order amount and transaction details.
Important: Payment processors collect and process payment card information directly. Profalgo does NOT collect, store, or have access to your full payment card number, CVV code, or expiration date. Payment processors are PCI-DSS compliant.
4.2.2 Cloud Hosting and Infrastructure Providers
Purpose: To host the Store, Product files, databases, and technical infrastructure.
Data Shared: Account information, product usage and technical data, server logs and IP addresses.
4.2.3 Email and Communications Providers
Purpose: To send transactional and marketing emails.
Data Shared: Email address, name, email content and engagement data (opens, clicks).
4.2.4 Analytics and Performance Monitoring
Purpose: To analyze Store and Product usage, track performance, identify bugs, and improve user experience.
Data Shared: IP address (often anonymized), device and browser information, usage data and session information, error logs and crash reports.
4.2.5 Customer Support and Help Desk Tools
Purpose: To manage support tickets and provide technical assistance.
Data Shared: Name and email address, support ticket content, account information relevant to the support request.
4.2.6 Content Delivery Networks (CDN)
Purpose: To deliver Store content, Product downloads, and files quickly and securely.
Data Shared: IP address, browser and device information, accessed URLs and file requests.
4.3 Data Processing Agreements
All third-party service providers engaged as data processors are bound by written data processing agreements that require them to: process personal data only on Profalgo's documented instructions; implement appropriate technical and organizational security measures; ensure confidentiality of personal data; assist Profalgo in responding to data subject requests and data breach notifications; delete or return personal data upon termination of services; and engage sub-processors only with Profalgo's authorization.
4.4 No Independent Use by Processors
Third-party service providers are NOT authorized to use personal data for their own purposes, sell, rent, or share personal data with other parties, retain personal data longer than necessary, or make independent decisions about personal data processing.
4.5 Business Transfers
If Profalgo undergoes a merger, acquisition, reorganization, sale of assets, bankruptcy, or other change of control, your personal data may be transferred to the acquiring or successor entity. In such event, we will notify you and the acquiring entity will be bound by the terms of this Privacy Policy. You will have the opportunity to exercise your rights before or after the transfer.
4.6 Legal Disclosures and Compliance
We may disclose personal data if required or permitted by law, including to comply with court orders, subpoenas, warrants, or legal processes; respond to lawful requests from regulatory or law enforcement authorities; enforce our Terms and Conditions and protect our rights; and respond to emergencies involving danger of death or serious physical injury.
4.7 Aggregated and Anonymized Data
We may share aggregated, anonymized, or de-identified data that cannot reasonably be used to identify you. Such data is NOT considered personal data under GDPR and may be used or shared without restriction.
4.8 No Sharing for Marketing Purposes
We do NOT share your personal data with third parties for their own marketing purposes. You will NOT receive marketing communications from third parties as a result of providing your personal data to us.
5. International Data Transfers
5.1 Location of Data Processing
Profalgo is based in Malta (a member of the European Union). However, your personal data may be transferred to, stored in, and processed in jurisdictions outside the European Economic Area (EEA), including the United States (for cloud hosting, payment processing, analytics, and other services) and other countries where our service providers operate.
5.2 Safeguards for International Transfers
When we transfer personal data outside the EEA, we implement appropriate safeguards including:
- Adequacy Decisions: For transfers to countries deemed adequate by the European Commission.
- Standard Contractual Clauses (SCCs): For transfers to countries without an adequacy decision. You may request a copy by contacting info@forexeasolutions.com.
- Service Provider Certifications: Including EU-U.S. Data Privacy Framework, Binding Corporate Rules, and ISO 27001 certification.
5.3 User Acknowledgment
By using the Services, you acknowledge and consent to the transfer of your personal data to countries outside the EEA as described in this section. If you do not consent to such transfers, you should not use the Store, Product, or Services.
6. Data Retention
6.1 Retention Principles
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, comply with legal obligations, resolve disputes, and enforce our agreements.
6.2 Retention Periods by Category
| Data Category | Retention Period | Reason |
|---|---|---|
| Account Information | Duration of account + 3 years after closure | Account history, disputes, legal/regulatory requirements |
| Purchase and Transaction Data | 7 years from transaction date | Tax, accounting, and financial record-keeping (Maltese law, EU regulations) |
| Communications and Support Data | 3 years from last communication | Customer service history, dispute resolution |
| Product Usage and Technical Data | 2 years from collection | Usage analysis, bug fixes, performance improvement |
| Marketing Communications Data | Until unsubscribe + 6 months | Honor opt-out requests, maintain suppression lists |
| Cookies and Tracking Data | Session to 2 years (varies by type) | See Cookie section for specific retention periods |
6.3 Legal Holds and Disputes
If personal data is subject to a legal hold, litigation, investigation, or dispute, we may retain such data beyond the standard retention periods until the matter is resolved.
6.4 Deletion and Anonymization
After the applicable retention period expires, we will securely and permanently delete personal data, or anonymize it so that it can no longer identify you. Anonymized data may be retained indefinitely for statistical, research, and analytical purposes.
6.5 User-Requested Deletion
You may request deletion of your personal data at any time by exercising your Right to Erasure under GDPR Article 17 (see Section 9.3). However, we may be unable to delete all data if retention is required by legal or regulatory obligations, legitimate interests (e.g., fraud prevention, dispute resolution), or necessity to establish, exercise, or defend legal claims.
7. Data Security
7.1 Security Measures
We implement reasonable technical and organizational measures to protect personal data from unauthorized access, use, alteration, disclosure, or destruction. Security measures include:
Technical Safeguards:
- Encryption of data in transit (using SSL/TLS protocols)
- Encryption of sensitive data at rest (e.g., passwords hashed using industry-standard algorithms)
- Secure authentication and access controls
- Regular security updates, patches, and vulnerability assessments
- Firewalls, intrusion detection systems, and network security monitoring
Organizational Safeguards:
- Limiting access to personal data on a need-to-know basis
- Requiring confidentiality agreements from employees and contractors
- Regular security training and awareness programs
- Incident response and data breach procedures
Third-Party Security:
- Selecting service providers with strong security practices (e.g., ISO 27001, SOC 2, PCI-DSS)
- Requiring appropriate security measures via data processing agreements
7.2 Security Disclaimer
Important: Despite our security measures, no system is completely secure. We cannot and do not guarantee absolute security of personal data or the Store, Product, or Services.
7.3 Limitation of Liability for Security Breaches
To the maximum extent permitted by applicable law, Profalgo is not liable for unauthorized access, use, alteration, disclosure, or destruction of personal data resulting from security breaches or causes beyond our reasonable control; losses or damages arising from data breaches; security failures caused by third-party service providers; or your failure to protect your own account credentials.
Exception: This limitation does NOT exclude liability for death or personal injury caused by our negligence, fraud or fraudulent misrepresentation, or any other liability that cannot be excluded under applicable law. For EU data subjects, your statutory rights under GDPR are NOT affected.
7.4 User Responsibility for Security
You are responsible for keeping your account credentials confidential and secure, using a strong unique password, enabling multi-factor authentication (MFA) if available, not sharing your credentials with any third party, monitoring your account for suspicious activity, and immediately notifying us at info@forexeasolutions.com if you suspect unauthorized access.
7.5 Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority (Malta Information and Data Protection Commissioner) within 72 hours as required by GDPR Article 33, and notify affected individuals without undue delay if the breach is likely to result in a high risk, as required by GDPR Article 34.
8. Cookies and Tracking Technologies
8.1 What Are Cookies?
Cookies are small text files stored on your device by your web browser when you visit a website. Cookies allow the website to recognize your device, remember your preferences, and track your activity.
8.2 Types of Cookies We Use
Essential Cookies (Strictly Necessary)
Required for the Store to function properly, including user authentication, session management, shopping cart and checkout functionality, and security and fraud prevention. You cannot disable these cookies.
| Cookie | Purpose | Duration |
|---|---|---|
| cookie_consent | Stores the user's cookie consent state for the current domain | 1 year |
| offer_deadline | Stores the countdown timer deadline for the promotional offer | Persistent |
Performance and Analytics Cookies
Collect information about how visitors use the Store, including pages visited, time spent, and navigation paths. These cookies help us improve the Store's performance and user experience.
| Cookie | Purpose | Duration |
|---|---|---|
| _ga | Google Analytics: distinguishes unique users by assigning a randomly generated number | 2 years |
| _ga_* | Google Analytics: used to persist session state | 2 years |
Functional Cookies
Remember your preferences and settings, such as language and currency preferences, login credentials, and user interface customizations. These cookies enhance your experience but are not essential.
Marketing and Advertising Cookies
We do NOT currently use marketing/advertising cookies. This section is reserved for future use.
8.3 Third-Party Cookies
Some cookies are set by third-party service providers we use, including analytics providers (e.g., Google Analytics) and payment processors (e.g., Stripe, PayPal). Third-party cookies are governed by the service provider's own privacy policy. We do NOT control third-party cookies.
8.4 Cookie Consent and Management
EU/EEA Users: When you first visit the Store, we will display a cookie banner requesting your consent to use non-essential cookies. You can accept all cookies, reject non-essential cookies, or customize cookie preferences. You can change your preferences at any time.
Browser Settings: You can also control cookies through your web browser settings, including disabling cookies entirely, deleting existing cookies, blocking third-party cookies, or receiving notifications when cookies are set.
Opt-Out Tools: For analytics cookies (e.g., Google Analytics), you can opt out using the Google Analytics Opt-Out Browser Add-On.
8.5 Do Not Track (DNT) Signals
We do NOT currently respond to DNT signals or similar browser-based privacy signals (e.g., Global Privacy Control), as there is no industry-standard interpretation of DNT signals.
9. Your Rights Under GDPR
If you are located in the European Union (EU) or European Economic Area (EEA), you have the following rights under the General Data Protection Regulation (GDPR):
- Right of Access (Article 15): You have the right to obtain confirmation as to whether we process your personal data and to access such data, including information about purposes, categories, recipients, and retention periods.
- Right to Rectification (Article 16): You have the right to request correction of inaccurate or incomplete personal data.
- Right to Erasure / "Right to be Forgotten" (Article 17): You have the right to request deletion of your personal data in certain circumstances, such as when the data is no longer necessary, you withdraw consent, you object to processing, or the data has been unlawfully processed. Exceptions apply where retention is necessary for legal obligations, legal claims, or archiving purposes.
- Right to Restriction of Processing (Article 18): You have the right to request restriction of processing when you contest accuracy, processing is unlawful, we no longer need the data but you need it for legal claims, or you have objected to processing.
- Right to Data Portability (Article 20): You have the right to receive your personal data in a structured, commonly used, and machine-readable format (e.g., CSV, JSON) and to transmit it to another controller, where processing is based on consent or contract and carried out by automated means.
- Right to Object (Article 21): You may object to processing based on legitimate interests. For direct marketing, you have an absolute right to object and we will immediately cease processing.
- Right Not to Be Subject to Automated Decision-Making (Article 22): You have the right NOT to be subject to decisions based solely on automated processing that produce legal effects. We do NOT currently engage in such automated decision-making.
- Right to Withdraw Consent (Article 7): Where processing is based on consent, you have the right to withdraw consent at any time. Withdrawal does NOT affect the lawfulness of processing before withdrawal.
9.9 How to Exercise Your Rights
To exercise any of the above rights, send an email to info@forexeasolutions.com with a subject line indicating the right you wish to exercise, your full name and email address associated with your account, sufficient information to verify your identity, and a clear description of your request.
We will respond within 1 month (extendable by 2 additional months for complex or numerous requests). We do NOT charge a fee for exercising your rights, except for manifestly unfounded or excessive requests.
9.11 Right to Lodge a Complaint
If you believe we have violated your data protection rights, you have the right to lodge a complaint with a supervisory authority.
Malta Supervisory Authority:
Office of the Information and Data Protection Commissioner (IDPC)
Level 2, Airways House, High Street, Sliema SLM 1549, Malta
Website: idpc.org.mt
Email: idpc.info@idpc.org.mt
Phone: +356 2328 7100
EU/EEA residents may also lodge a complaint with the supervisory authority in their country of residence. You also have the right to seek a judicial remedy if you believe your rights have been violated.
10. Children's Privacy
The Store, Product, and Services are NOT directed at, intended for, or designed to attract individuals under the age of 18 years. We do NOT knowingly collect, use, or disclose personal data from children under 18.
If you are under 18, you may NOT create an account, purchase the Product, use the Services, or provide any personal data to us.
If you are a parent or guardian and believe your child has provided personal data to us, please contact us immediately at info@forexeasolutions.com. We will verify the child's age, delete the child's personal data, terminate any account created by the child, and take steps to prevent future collection.
11. Third-Party Websites and Services
11.1 Links to Third-Party Websites
The Store and Product may contain links to third-party websites, platforms, brokers, trading platforms, or services. We do NOT control, operate, or endorse such third-party websites or services, and we are NOT responsible for their privacy practices, data collection, security, content, or availability.
11.2 Brokers and Trading Platforms
The Product is designed to integrate with third-party brokers and trading platforms. Profalgo does NOT own, operate, or control any broker or trading platform; collect or have access to personal data or trading data you provide to brokers; or guarantee the privacy practices or regulatory compliance of brokers or platforms. Data collected by brokers and platforms is governed by their own privacy policies.
11.3 Payment Processors
Payments are processed by third-party payment service providers (Stripe, PayPal, etc.). Payment processors collect and process payment card information (full card numbers, CVV codes, expiration dates), billing information, and transaction data. Profalgo does NOT have access to your full payment card information.
11.4 Technical Infrastructure and Service Providers
The Store, Product, and Services rely on various technical infrastructure providers including cloud hosting providers, content delivery networks, domain and DNS services, email and communication services, security and monitoring services, and technical service providers.
Any personal data processed by technical infrastructure providers is processed on behalf of Profalgo as data processors under strict contractual obligations pursuant to GDPR Article 28. You have no direct contractual or data protection relationship with any technical infrastructure provider.
11.5 No Liability for Third Parties
To the maximum extent permitted by law, Profalgo is not liable for privacy practices, data breaches, or security incidents by third-party websites, brokers, platforms, or service providers; unauthorized access, use, or disclosure of your personal data by third parties; or losses arising from your use of third-party websites or services. This does NOT exclude liability for fraud or fraudulent misrepresentation.
12. Changes to This Privacy Policy
We reserve the right to update, modify, amend, or replace this Privacy Policy at any time. We will notify you of material changes by posting the updated Privacy Policy on the Store with a new "Last Updated" date, sending an email notification (if applicable), and displaying a prominent notice on the Store or within the Product.
Changes become effective on the date specified in the updated Privacy Policy or immediately upon posting. Continued use of the Store, Product, or Services after changes become effective constitutes your acceptance of the updated Privacy Policy.
If you do NOT agree to the updated Privacy Policy, you must cease using the Store, Product, and Services immediately. You may request deletion of your personal data by exercising your Right to Erasure (see Section 9).
13. Contact Information
For questions, concerns, or requests regarding this Privacy Policy or our data practices:
Profalgo Limited
Company Registration Number: C-93668
Registered Office: 36, St Dminka Street, Victoria VCT 9030, Gozo, Malta
Email: info@forexeasolutions.com
Business Hours: Monday - Friday, 09:00 - 17:00 CET
To exercise your GDPR rights (access, rectification, erasure, restriction, portability, objection), email info@forexeasolutions.com with a subject line specifying the right (e.g., "Data Access Request"), your full name, email address associated with your account, description of your request, and information to verify your identity.
Malta Supervisory Authority:
Office of the Information and Data Protection Commissioner (IDPC)
Level 2, Airways House, High Street, Sliema SLM 1549, Malta
Website: idpc.org.mt
Email: idpc.info@idpc.org.mt
Phone: +356 2328 7100
14. Governing Law and Jurisdiction
This Privacy Policy and all matters relating to data protection and privacy shall be governed by the laws of Malta and the General Data Protection Regulation (GDPR) (EU) 2016/679.
Any disputes arising from or related to this Privacy Policy shall be subject to the exclusive jurisdiction of the courts of Malta. For EU/EEA residents, you may also bring proceedings in the courts of your country of residence under applicable consumer protection laws.
The Malta Information and Data Protection Commissioner (IDPC) is the lead supervisory authority for Profalgo under GDPR.
15. Miscellaneous
- Entire Agreement: This Privacy Policy, together with our Terms and Conditions and Cookie Policy, constitutes the entire agreement regarding our data practices. In case of conflict with the Terms and Conditions, this Privacy Policy shall prevail with respect to data protection and privacy matters.
- Severability: If any provision is found invalid or unenforceable, it shall be modified to the minimum extent necessary or severed, with all other provisions remaining in full force.
- No Waiver: Our failure to enforce any provision shall NOT constitute a waiver of that provision or any other provision.
- Language: This Privacy Policy is drafted in English. Any translation is for convenience only. In case of conflict, the English version prevails.
Acknowledgment
By using the Store, Product, or Services, you acknowledge that:
- You have read, understood, and consent to the collection, use, processing, and sharing of your personal data as described in this Privacy Policy.
- You understand that personal data may be transferred outside the EEA to countries with different data protection standards.
- You understand your rights under GDPR (if applicable) and how to exercise them.
- You acknowledge the limitations of liability for security breaches and third-party actions as described in Sections 7 and 11.
- You agree to the retention periods described in Section 6.
- If you are under 18, you may NOT use the Store, Product, or Services.
- You agree to bring any data protection-related claims solely against Profalgo and not against any third-party service provider, data processor, or sub-processor.
If you do not consent to this Privacy Policy, do not use the Store, Product, or Services.
Document Version: 1.0 | Last Updated: March 23, 2026 | Effective Date: March 23, 2026
Profalgo Limited | Company Registration Number: C-93668 | Registered Office: 36, St Dminka Street, Victoria VCT 9030, Gozo, Malta | Email: info@forexeasolutions.com