Privacy Policy
TFXSignals · Last updated 20 June 2026
I. Introduction
This Privacy Policy (the "Policy") sets out the principles governing the collection, processing, storage, disclosure and protection of personal data in connection with the use of the TFXSignals website, dashboard, Telegram notifications and related services (collectively, the "Service").
The Controller respects the privacy of users and undertakes to process personal data in accordance with applicable laws, including Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (General Data Protection Regulation "GDPR"), as well as any other applicable legislation relating to data protection and privacy.
By accessing or using the Service, users acknowledge that their personal data may be processed in accordance with this Policy.
II. Data Controller
The controller of personal data processed in connection with the provision of the Service is: Kamil Uchwat, conducting business under the TFXSignals brand, Poland (the "Controller", "TFXSignals", "we", "us" or "our").
For all matters relating to personal data and privacy, users may contact the Controller at: support@tfx-signals.com.
III. Categories of Personal Data
Depending on the nature and scope of the user's interaction with the Service, the Controller may process the following categories of personal data:
Account and Identification Data
- email address;
- username or account identifier;
- authentication credentials;
- authentication identifiers obtained through third-party login providers, including Google or Telegram where such login methods are used.
Subscription and Transaction Data
- subscription status;
- purchased plan details;
- billing information;
- payment transaction identifiers;
- invoice and accounting information;
- payment history.
The Controller does not store complete payment card details.
Technical and Device Data
- IP address;
- browser type and version;
- operating system;
- device identifiers;
- language settings;
- access logs;
- session information;
- time and date of access.
Usage Data
- interactions with the Service;
- feature usage statistics;
- dashboard activity;
- subscription management activity;
- service performance and diagnostic information.
Communications Data
- customer support correspondence;
- complaints;
- requests;
- inquiries;
- communications relating to account administration.
IV. Sources of Personal Data
Personal data may be obtained:
- directly from the user;
- through the user's interaction with the Service;
- from authentication providers selected by the user;
- from payment service providers;
- from publicly available sources where permitted by law;
- from third parties where such disclosure is lawful and necessary for the provision of the Service.
The Controller does not knowingly collect personal data from individuals under the age of eighteen (18).
V. Purposes and Legal Bases of Processing
Personal data is processed exclusively to the extent necessary for legitimate business purposes connected with the operation of the Service.
Performance of Contract
Pursuant to Article 6(1)(b) GDPR, personal data may be processed where necessary:
- to create and maintain user accounts;
- to provide access to the Service;
- to manage subscriptions;
- to deliver Signals and related content;
- to administer customer relationships;
- to provide customer support.
Compliance with Legal Obligations
Pursuant to Article 6(1)(c) GDPR, personal data may be processed where necessary to comply with legal obligations, including obligations arising under:
- accounting regulations;
- tax legislation;
- anti-fraud requirements;
- consumer protection laws;
- court orders and lawful requests from public authorities.
Legitimate Interests
Pursuant to Article 6(1)(f) GDPR, personal data may be processed where necessary for the legitimate interests pursued by the Controller, including:
- ensuring the security of the Service;
- preventing fraud, abuse and unauthorized access;
- investigating breaches of contractual obligations;
- improving and developing the Service;
- monitoring system performance;
- maintaining business continuity;
- enforcing legal rights;
- establishing, exercising or defending legal claims.
Consent
Where required by law, personal data may be processed based on the user's consent pursuant to Article 6(1)(a) GDPR. Consent may be withdrawn at any time without affecting the lawfulness of processing carried out before such withdrawal.
VI. Recipients of Personal Data
Personal data may be disclosed only where necessary and proportionate to:
- payment service providers;
- hosting providers;
- cloud infrastructure providers;
- authentication service providers;
- analytics providers;
- customer support providers;
- professional advisers, including lawyers, auditors and accountants;
- governmental, regulatory, judicial or law enforcement authorities where required by law.
The Controller does not sell, rent or otherwise commercially disclose personal data to third parties.
All service providers acting on behalf of the Controller are required to process personal data in accordance with applicable data protection laws and contractual safeguards.
VII. Payment Processing
Payments made through the Service are processed by Stripe and other payment providers designated by the Controller from time to time.
Payment card information is collected and processed directly by the relevant payment provider.
The Controller does not receive, process or store complete payment card details.
Users acknowledge that payment service providers may process personal data under their own privacy policies and regulatory obligations.
VIII. International Transfers of Personal Data
Certain service providers engaged by the Controller may process personal data outside the European Economic Area ("EEA").
Where personal data is transferred outside the EEA, the Controller shall ensure that appropriate safeguards are implemented in accordance with Chapter V GDPR, including where applicable:
- adequacy decisions issued by the European Commission;
- Standard Contractual Clauses;
- other lawful transfer mechanisms recognised under applicable law.
IX. Data Retention
Personal data shall be retained only for as long as necessary to fulfil the purposes for which it was collected. Retention periods may vary depending on the nature of the data and applicable legal requirements.
In particular, personal data may be retained:
- for the duration of the contractual relationship;
- for the period necessary to comply with legal obligations;
- for the limitation period applicable to legal claims;
- for the period necessary to resolve disputes and enforce agreements.
Upon expiry of the applicable retention period, personal data shall be securely deleted, anonymised or otherwise rendered inaccessible, unless further retention is required by law.
X. Data Subject Rights
Subject to applicable law, individuals may exercise the following rights:
- the right of access;
- the right to rectification;
- the right to erasure;
- the right to restriction of processing;
- the right to data portability;
- the right to object to processing;
- the right to withdraw consent;
- the right not to be subject to unlawful automated decision-making;
- the right to lodge a complaint with a competent supervisory authority.
Requests relating to personal data may be submitted to: support@tfx-signals.com.
The Controller may request additional information necessary to verify the identity of the requesting individual.
XI. Cookies and Similar Technologies
The Service may use cookies, local storage technologies and similar mechanisms for purposes including:
- authentication;
- security;
- fraud prevention;
- session management;
- performance monitoring;
- analytics;
- functionality improvement.
Where required by law, non-essential cookies shall only be used following the user's prior consent. Further information regarding cookies may be provided in a separate Cookie Policy.
XII. Security of Personal Data
The Controller implements reasonable and appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, unauthorized access or other unlawful forms of processing.
Such measures may include, among others:
- encryption technologies;
- access controls;
- authentication mechanisms;
- monitoring and logging systems;
- security testing procedures.
Notwithstanding the foregoing, no method of electronic transmission or storage can guarantee absolute security and the Controller cannot warrant that personal data will remain secure under all circumstances.
XIII. Automated Processing
The Service may generate Signals and analytical outputs through automated algorithms and predefined methodologies. Such processing is performed exclusively for the purpose of generating informational content available through the Service. The Controller does not use personal data to make decisions producing legal effects concerning users or similarly significantly affecting users within the meaning of Article 22 GDPR.
XIV. Third-Party Services
The Service may contain integrations with or links to third-party platforms, applications or services. The Controller is not responsible for the privacy practices, policies or content of third-party services. Users are encouraged to review the privacy policies of any third-party services they choose to access.
XV. Changes to This Policy
The Controller reserves the right to amend or update this Policy from time to time.
Any updated version shall become effective upon publication on the Service unless otherwise stated.
Material changes may additionally be communicated through the Service or by email.
Continued use of the Service following publication of an updated Policy constitutes acknowledgement of the revised version.
XVI. Contact
Any questions, requests or concerns relating to this Policy or the processing of personal data should be directed to: support@tfx-signals.com.