LEGAL DOCUMENT — GDPR

Privacy Notice

CONTROLLERVeritanix
PLATFORMEDON Platform
EFFECTIVE DATE27 April 2026
JURISDICTIONEuropean Union / EEA
CONTACTprivacy@veritanix.com

01 Introduction

Veritanix operates the EDON Platform ("EDON Platform", "we", "us", "our"). This Privacy Notice explains how we collect, use, store, and share your personal data when you use EDON Platform, and describes your rights under Regulation (EU) 2016/679 (the General Data Protection Regulation, "GDPR").

Please read this notice carefully. By using EDON Platform, you acknowledge that you have read and understood how we process your personal data.

02 Data Controller

The data controller responsible for your personal data is:

Veritanix
Email: privacy@veritanix.com
Jurisdiction: European Union / EEA

03 Personal Data We Collect

3.1 Account and Identity Data

  • Email address (via Google OAuth authentication)
  • Name and profile information provided by Google at sign-in
  • Authentication tokens and session identifiers

3.2 Usage and Technical Data

  • IP address and approximate geographic location
  • Browser type, operating system, and device information
  • Pages accessed, features used, and actions taken within EDON Platform
  • Access timestamps and session duration
  • Cloudflare Access logs (authentication events and OTP verification)

3.3 Data You Provide

  • Content you create, upload, or submit within EDON Platform
  • Communications you send to us (e.g. support requests)

04 Legal Bases for Processing

We process your personal data only where we have a lawful basis under Article 6 GDPR:

  • Performance of a contract — to provide EDON Platform services you have signed up for (Art. 6(1)(b))
  • Legitimate interests — to secure the platform, prevent fraud, and improve our services, where not overridden by your rights (Art. 6(1)(f))
  • Legal obligation — where processing is required by EU or member state law (Art. 6(1)(c))
  • Consent — where you have given explicit consent, e.g. for optional communications (Art. 6(1)(a))

05 Purposes of Processing

  • Authenticating your identity and managing your account access
  • Providing, maintaining, and improving EDON Platform
  • Enforcing security controls including Cloudflare Zero Trust access policies and OTP verification
  • Detecting and preventing unauthorised access, abuse, or fraud
  • Complying with legal and regulatory obligations
  • Communicating with you about your account or our services
  • Analysing usage patterns to improve user experience

06 Data Sharing and Third-Party Processors

We do not sell your personal data. We share data only in the following circumstances:

6.1 Infrastructure and Security Processors

  • Cloudflare, Inc. — provides tunnel infrastructure, Zero Trust access control, OTP authentication, and DDoS protection. Cloudflare processes authentication logs and traffic metadata on our behalf.
  • Google LLC — provides OAuth 2.0 identity verification. When you sign in with Google, Google processes your credentials in accordance with Google's Privacy Policy.

6.2 Hosting Infrastructure

  • Self-hosted Kubernetes infrastructure operated by Veritanix within the EU/EEA.

6.3 Legal Requirements

We may disclose your data to competent authorities where required by law, court order, or to protect the rights and safety of Veritanix or others.

07 International Data Transfers

Cloudflare and Google are US-based entities. When your data is processed by these providers, it may be transferred outside the EEA. Such transfers are conducted under appropriate safeguards, including Standard Contractual Clauses (SCCs) approved by the European Commission and adequacy decisions where applicable.

You may request a copy of the relevant transfer mechanisms by contacting privacy@veritanix.com.

08 Data Retention

We retain your personal data only for as long as necessary for the purposes described in this notice, or as required by law.

Account data30 days post-closure
Authentication and access logs90 days
Usage analytics (anonymised)12 months
Support communications2 years

09 Your Rights Under GDPR

As a data subject in the EU/EEA, you have the following rights:

Art. 15
Right of access
Obtain a copy of the personal data we hold about you.
Art. 16
Right to rectification
Have inaccurate or incomplete data corrected.
Art. 17
Right to erasure
Request deletion where there is no legitimate ground for continued processing.
Art. 18
Right to restriction
Restrict processing of your data in certain circumstances.
Art. 20
Right to data portability
Receive your data in a structured, machine-readable format.
Art. 21
Right to object
Object to processing based on legitimate interests or for direct marketing.
Art. 7(3)
Right to withdraw consent
Withdraw consent at any time without affecting prior processing.

To exercise any of these rights, contact privacy@veritanix.com. We will respond within 30 days and may request identity verification before processing your request.

10 Right to Lodge a Complaint

If you believe we have processed your personal data in breach of GDPR, you have the right to lodge a complaint with a supervisory authority in your EU member state of residence.

Full list of EU supervisory authorities: edpb.europa.eu

11 Security Measures

We implement appropriate technical and organisational measures to protect your personal data, including:

  • Cloudflare Zero Trust access control with Google OAuth and OTP multi-factor authentication
  • Encrypted transport (TLS) for all data in transit via Cloudflare tunnels
  • Role-based access controls and network segmentation on the EDON Platform infrastructure
  • Regular review of access logs and security policies

12 Cookies and Similar Technologies

EDON Platform uses the following cookies and session tokens:

  • CF_Authorization Set by Cloudflare Access to maintain your authenticated session. Strictly necessary for the platform to function.
  • Session ID Used to maintain your logged-in state within EDON Platform.

We do not use tracking cookies or third-party advertising cookies.

13 Changes to This Notice

We may update this Privacy Notice from time to time to reflect changes in our practices or applicable law. We will notify you of material changes via the platform or by email. The effective date at the top of this document indicates when it was last revised.

Risk & Regulatory Disclosure

This Privacy Notice governs how we handle your personal data. For information about the regulatory status of EDON Platform, market risk disclosures, the scope of paper trading simulation, and jurisdiction-specific legal notices, please refer to our separate:

Risk & Regulatory Disclosure →
Includes: regulatory status (MiFID II, FCA, SEC), paper trading limitations, market risk warnings, no-investment-advice disclaimer, no-execution notice, jurisdiction-specific notices, and liability limitation.

Veritanix is not a regulated financial services provider. EDON Platform is an analytical tool only and does not constitute a regulated financial service in any jurisdiction.

14 Contact Us

For any questions, requests, or concerns regarding this Privacy Notice or our data processing practices:

Veritanix — Data Privacy
Email: privacy@veritanix.com