Privacy Policy
Last updated: June 2026
Data Controller
The controller of personal data is QuantMix, an Italian multi-asset quantitative analysis platform (Trading Terminal and Certificate Analyzer). For any request regarding your data, you can write to [email protected].
Data We Collect
We collect only the data necessary to run the service:
- Email and name provided at registration.
- Password, stored exclusively as a bcrypt hash (we never see your password in plain text).
- Data you generate while using the platform, such as watchlists and paper trades (simulated positions).
- Technical logs and IP address, recorded for security and diagnostic purposes.
- Your Telegram chat_id, only if you choose to connect notifications and alerts.
Purposes of Processing
We process your data for the following purposes:
- To provide and deliver the requested service.
- To manage authentication via Single Sign-On (SSO) shared between the two apps (app.quantmix.io and certificati.quantmix.io).
- To send transactional emails (account verification, password reset) and the alerts you have enabled.
- To ensure the security of the platform and prevent abuse.
Legal Basis
Processing is based on:
- Performance of the contract, for everything necessary to provide you with the service and manage your account.
- Legitimate interest, for platform security, diagnostics, and abuse prevention.
Third Parties and Providers
We rely on selected providers to deliver the service:
- Mailjet, for sending transactional emails and alerts.
- Cloudflare, as a CDN and for infrastructure protection.
- Market data sources (for example Binance, Yahoo, CFTC, FRED): from these sources we receive market data only, not personal data of our users.
We do not sell your personal data to third parties.
Cookies
We use an SSO session cookie named qmx_session, which is technically necessary to keep you authenticated across the two apps. We do not use advertising tracking cookies or profiling for marketing purposes.
Data Retention
We retain your account data for as long as your account remains active. Upon account deletion, the associated personal data is removed, except for any legal obligations or security requirements that call for limited retention (for example technical logs, kept for a restricted period).
Your Rights
Under the GDPR, you can exercise the following rights at any time:
- Access to your personal data.
- Rectification of inaccurate or incomplete data.
- Erasure of data.
- Portability of data in a readable format.
To exercise these rights, write to [email protected]. We will respond within the timeframes set by applicable regulations.
Security
We adopt appropriate technical and organizational measures to protect your data: passwords stored as bcrypt hashes, encrypted connections (TLS), restricted database access, and protected authentication. No system is 100% secure, but we are committed to maintaining protection standards consistent with the risk.
Changes
We may update this Privacy Policy over time. In the event of material changes, we will make them clear by updating the date shown at the top of the page and, where necessary, through direct communication. We encourage you to review this page periodically. For details on the use of the service, you can also read our Terms.
The data, analyses, signals, and simulations offered by QuantMix are provided for informational and educational purposes only and do not constitute financial advice.