1. Introduction
EasyQuant Intelligence (“we,” “our,” or “us”) operates the EasyQuant platform, an AI-powered financial research and analysis service. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform. This policy applies to all users worldwide, including users in India, the European Economic Area (EEA), the United Kingdom, California (USA), and all other jurisdictions. By accessing or using EasyQuant, you agree to the terms of this Privacy Policy.
2. Information We Collect
2.1 Information You Provide
- Account Information: Name, email address, and encrypted password when you create an account.
- Analysis Preferences: Search queries, ticker symbols, and analysis preferences you enter (e.g., market, risk level, time horizon, sector, capital range).
- Payment Information: When you subscribe to a paid plan, your payment is processed by a PCI DSS-compliant third-party payment processor. We receive your transaction ID, plan type, and payment status. We do not store your credit/debit card numbers, UPI IDs, or bank account details — these are handled exclusively by the payment processor.
- Communications: Any feedback, correspondence, or support requests you submit to us.
2.2 Automatically Collected Information
- Usage Data: Pages visited, analysis types requested, features used, timestamps, and interaction patterns.
- Device & Browser Data: IP address, browser type and version, operating system, device type, screen resolution, and language preference.
- Geolocation Data: Approximate location derived from your IP address, used to personalize market data and trending instruments for your region.
- Cookies & Similar Technologies: We use cookies and local storage to maintain session state, remember preferences, and improve your experience. See Section 11 for details.
- Log Data: Server logs that record API requests, error events, response times, and other diagnostic information for security and performance monitoring.
2.3 Third-Party Data
We retrieve real-time and historical market data from third-party financial data providers to enrich AI-generated analysis. This data pertains to publicly traded securities and does not include your personal information.
3. Legal Basis for Processing
We process your personal data on the following legal bases:
- Contract Performance: Processing necessary to provide the Service you requested (e.g., running analyses, managing your account, processing payments).
- Legitimate Interests: Processing for our legitimate business interests such as improving the platform, preventing fraud, and ensuring security, where these interests are not overridden by your rights.
- Consent: Where you have given explicit consent, such as for optional analytics cookies or marketing communications (if any). You may withdraw consent at any time.
- Legal Obligation: Processing necessary to comply with applicable laws and regulations.
For Indian users: Under the Digital Personal Data Protection Act, 2023 (DPDPA), we process your data based on your consent (provided at account creation) and for legitimate uses as permitted under the Act.
For EEA/UK users: Under the General Data Protection Regulation (GDPR), the legal bases include contract performance (Art. 6(1)(b)), legitimate interests (Art. 6(1)(f)), consent (Art. 6(1)(a)), and legal obligation (Art. 6(1)(c)).
4. How We Use Your Information
- To provide, operate, and maintain the EasyQuant platform and its analysis features.
- To personalize your experience, including region-specific market data and trending instruments.
- To process your analysis requests through our AI agent pipeline and deliver results.
- To process payments, manage subscriptions, and handle billing-related communications.
- To improve our platform, algorithms, and AI models based on aggregate, anonymized usage patterns.
- To communicate with you regarding updates, support, or service-related notices.
- To detect, prevent, and address technical issues, fraud, or security threats.
- To comply with applicable legal obligations.
5. AI-Generated Content & Data Processing
EasyQuant uses large language models (LLMs) from third-party AI service providers to generate financial research and analysis. Your queries and selected preferences are sent to these providers solely to generate responses for you.
- We do not use your individual queries to train, fine-tune, or improve any AI models.
- Queries sent to LLM providers do not include your name, email, or account identifiers.
- AI-generated outputs are not a substitute for professional financial advice.
6. Data Sharing & Disclosure
We do not sell, rent, or trade your personal information. We may share information in the following limited circumstances:
- AI Service Providers: Third-party large language model providers for processing analysis requests. Only query content and market data are shared — no personal identifiers.
- Payment Processor: A PCI DSS-compliant third-party payment processor handles your payments. They receive your email and name for transaction purposes, subject to their own privacy policy.
- Hosting & Infrastructure: Our servers and database hosting providers who store encrypted data subject to confidentiality obligations.
- Legal Requirements: When required by law, regulation, legal process, or governmental request from any jurisdiction.
- Business Transfers: In connection with a merger, acquisition, or sale of assets, your information may be transferred as part of the transaction. We will notify you via email and/or prominent notice on the platform before your data is transferred.
- With Your Consent: When you explicitly authorize us to share information.
7. International Data Transfers
Your data may be processed in countries outside your country of residence, including India and the United States (where our AI service providers operate). When we transfer data internationally, we ensure appropriate safeguards are in place:
- For EEA/UK users: Transfers are made pursuant to Standard Contractual Clauses (SCCs) approved by the European Commission, or to countries with an adequacy decision.
- For Indian users: Transfers comply with the provisions of the Digital Personal Data Protection Act, 2023 and any rules issued thereunder.
- All third-party processors are bound by data processing agreements that require them to protect your data consistent with this policy.
8. Data Retention
- Account Data: Retained as long as your account is active. Upon account deletion request, we delete your data within 30 days, except as required by law.
- Analysis History: Stored analysis results are retained to allow you to revisit past analyses. You may request deletion at any time.
- Payment Records: Retained for 7 years as required by Indian tax and accounting laws (Income Tax Act, GST regulations).
- Server Logs: Retained for up to 90 days for security and debugging purposes, then automatically deleted.
- Cached Data: Temporary caches (market data, analysis context) expire within 10–60 minutes.
9. Data Security
We implement industry-standard technical and organizational measures to protect your information:
- Encryption in transit (TLS/HTTPS) for all communications.
- Passwords are hashed using bcrypt with salting — we never store plaintext passwords.
- Authentication via secure, httpOnly JWT cookies to prevent XSS-based token theft.
- Rate limiting and abuse detection on all API endpoints.
- Role-based access controls for administrative functions.
- Input validation and sanitization to prevent injection attacks.
No method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security, but we commit to promptly addressing any identified vulnerabilities.
10. Data Breach Notification
In the event of a data breach that poses a risk to your rights and freedoms, we will:
- Notify affected users by email within 72 hours of becoming aware of the breach.
- Notify the relevant supervisory authority as required by applicable law (e.g., the Data Protection Board of India under DPDPA, or the relevant EEA supervisory authority under GDPR).
- Describe the nature of the breach, the data affected, and the remedial measures taken.
11. Cookies & Tracking Technologies
11.1 Types of Cookies We Use
- Strictly Necessary Cookies: Authentication tokens (httpOnly JWT cookie), session state, and CSRF protection. These cannot be disabled as they are essential for the platform to function.
- Functional Cookies: Remember your preferences such as dismissed banners, theme settings, and last-used analysis parameters. Stored in localStorage/sessionStorage.
11.2 Third-Party Cookies
We do not use third-party advertising cookies or trackers. We do not use any third-party analytics or advertising services. The only third-party cookie may be set by our payment processor during the checkout process.
11.3 Managing Cookies
You can manage or delete cookies through your browser settings. Disabling strictly necessary cookies may prevent you from logging in or using the platform.
12. Your Rights
12.1 Rights for All Users
- Access: Request a copy of the personal data we hold about you.
- Correction: Request correction of inaccurate or incomplete data.
- Deletion: Request deletion of your personal data (subject to legal retention requirements).
- Portability: Request a machine-readable copy of your data.
- Withdraw Consent: Withdraw consent for processing where consent is the legal basis.
12.2 Additional Rights for EEA/UK Users (GDPR)
- Right to restrict processing of your data.
- Right to object to processing based on legitimate interests.
- Right not to be subject to solely automated decision-making with legal effects.
- Right to lodge a complaint with your local Data Protection Authority.
12.3 Additional Rights for California Residents (CCPA/CPRA)
- Right to know what personal information we collect, use, and disclose.
- Right to delete your personal information.
- Right to opt-out of the sale or sharing of personal information. Note: We do not sell or share your personal information.
- Right to non-discrimination for exercising your privacy rights.
- In the preceding 12 months, we have not sold or shared any personal information as defined by the CCPA/CPRA.
12.4 Rights for Indian Users (DPDPA 2023)
- Right to access information about your personal data being processed.
- Right to correction and erasure of your personal data.
- Right to grievance redressal — contact us and we will respond within 30 days.
- Right to nominate another person to exercise your rights in case of death or incapacity.
To exercise any of these rights, please contact us at [email protected]. We will respond within 30 days (or sooner if required by applicable law). We may need to verify your identity before processing your request.
13. Do Not Track
Some browsers transmit “Do Not Track” (DNT) signals. Since we do not use any third-party tracking or advertising technologies, we effectively honor DNT signals by default.
14. Third-Party Links
The platform may contain links to third-party websites or services (e.g., news sources, financial data providers). We are not responsible for the privacy practices of those third parties. We encourage you to review their privacy policies before providing any personal information.
15. Children's Privacy
EasyQuant is not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If we learn that we have collected information from a child under 18, we will take steps to delete it within 72 hours. If you believe a child has provided us with personal data, please contact us immediately.
16. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by:
- Posting the updated policy on this page with a revised “Last updated” date.
- Sending an email notification for significant changes that affect your rights.
Your continued use of the platform after changes constitutes acceptance of the updated policy. If you disagree with any changes, you should stop using the platform and request deletion of your data.
17. Grievance Officer / Data Protection Contact
For any questions, concerns, or complaints about this Privacy Policy or our data practices, including exercising your data protection rights, please contact:
Grievance Officer / Data Protection Contact
EasyQuant Intelligence
Email: [email protected]
We will acknowledge your request within 48 hours and provide a substantive response within 30 days.