Legal
This policy explains what personal data Qabal collects, why, how long we keep it, and what rights you have. We process your data as data controller under Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 on Personal Data Protection (LOPDGDD).
The data controller for your personal data is:
For all data-related enquiries, contact us at privacy@qabal.es. We will respond within 30 days.
We do not have a designated Data Protection Officer (DPO) as we do not meet the thresholds requiring one under GDPR Article 37. However, you may direct all data protection questions to the contact above.
| Data | Source | Purpose | Legal basis (GDPR) | Retention |
|---|---|---|---|---|
| Telegram user ID and username | Telegram API | Account identification; delivering the bot service | Art. 6(1)(b) — performance of contract | Duration of account + 30 days |
| Subscription tier, status, trial dates | Stripe; internal | Access control; billing | Art. 6(1)(b) — performance of contract | Duration of account + 30 days |
| Stripe customer ID | Stripe | Payment processing | Art. 6(1)(b) — performance of contract | 7 years (tax/accounting obligation) |
| OKX API credentials (encrypted) | OKX Fast API OAuth | Accessing market data and executing bots you approve | Art. 6(1)(a) — explicit consent | Until revoked; deleted within 7 days of account deletion |
| Watchlist symbols and settings | User input via Telegram | Personalised monitoring and alerts | Art. 6(1)(b) — performance of contract | Duration of account |
| Analysis history and strategy logs | Service usage | Service delivery; audit trail; rate limiting | Art. 6(1)(b) & (f) — contract; legitimate interest | 12 months rolling |
| Active bot records and PnL data | OKX WebSocket | Portfolio monitoring; TP/SL alerts | Art. 6(1)(b) — performance of contract | 6 months after bot closure |
| Server access logs (IP address, timestamp, endpoint) | Server infrastructure | Security; abuse prevention; debugging | Art. 6(1)(f) — legitimate interest | 30 days |
| Cookie consent preference | Browser localStorage | Remembering your cookie choice | Art. 6(1)(c) — legal obligation (ePrivacy) | 12 months |
We do not collect sensitive personal data (health data, political opinions, biometric data, etc.) and do not process data for profiling or automated decision-making that produces legal effects.
OKX API credentials are stored using AES-256 encryption. Encryption keys are stored separately from the database. Access to production systems is restricted and authenticated.
All data in transit is encrypted via TLS 1.2 or higher. Database access is restricted by IP allowlist.
We share data only with the following processors, each bound by a Data Processing Agreement (DPA):
| Processor | Purpose | Location |
|---|---|---|
| Supabase | Database hosting | EU (Frankfurt, Germany) |
| Hetzner | Server infrastructure | EU (Germany) |
| Stripe | Payment processing | EU/US (SCCs applied) |
| Anthropic | AI analysis (market data only — no personal data sent) | US (SCCs applied) |
| Telegram | Bot delivery platform | Variable (Telegram's privacy policy applies) |
We do not sell your data. We do not share data with advertisers or data brokers. We do not share data with any third party not listed above, except where legally required (e.g. court order or law enforcement request under Spanish law).
Our primary infrastructure is EU-based. Stripe and Anthropic are US-based. Transfers to these processors are covered by Standard Contractual Clauses (SCCs) as approved by the European Commission under GDPR Article 46(2)(c). A copy of applicable SCCs is available on request.
You have the following rights, exercisable free of charge by contacting privacy@qabal.es:
We will respond within 30 days. If we cannot fulfil a request, we will explain why.
You also have the right to lodge a complaint with the Spanish supervisory authority:
Agencia Española de Protección de Datos (AEPD)
C/ Jorge Juan, 6, 28001 Madrid, Spain
www.aepd.es
If you are resident in another EU member state, you may also lodge a complaint with your local supervisory authority.
We use only strictly necessary cookies. See our Cookie Policy for full details.
Qabal is not directed at persons under 18. We do not knowingly collect data from minors. If you believe a minor has provided data, contact privacy@qabal.es and we will delete it promptly.
We will notify users of material changes via Telegram at least 14 days in advance. The “last updated” date at the top reflects the most recent revision. Continued use after changes take effect constitutes acceptance.
Data controller contact: privacy@qabal.es
Response time: within 30 days
Titular: Hasan Irem Yavash · NIE: Y9575466M · Domicilio fiscal: Calle Txacolina 6/105, 03185 Torrevieja, Alicante (España)