Privacy Policy

How EdgeFlow collects, uses and protects your data.

Effective date: 2025-06-20 · Mizznes BV, België

This policy explains what personal data we process when you use EdgeFlow, why we process it, and the rights you have under the EU General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA/CPRA) and equivalent international privacy laws. EdgeFlow is operated by Mizznes BV (België), trading as EdgeFlow, and serves users worldwide.

1. Who we are

Data controller: Mizznes BV, Ransuildreef 16, 2900 Schoten, België. Company registration (KBO/BCE): 1026.527.343. VAT: BE 1026.527.343.

For all privacy matters, contact us at privacy@youredgeflow.com. No Data Protection Officer has been appointed; the controller acts through its statutory representative.

2. What we collect and why

2.1 Account data

Email address, hashed password, display name (optional), username (optional), timezone and language. Legal basis: performance of contract (Art. 6(1)(b) GDPR).

2.2 Consent evidence

Timestamps and version identifiers for the age confirmation, Terms acceptance and Privacy acknowledgement given at signup — and, if applicable, marketing opt-in. Stored in an append-only consent_events record. We do not retain your IP address as consent evidence. Legal basis: legal obligation (Art. 5(2), 7(1) GDPR — accountability).

2.3 Trading data

Trades you log, journal entries, screenshots, confluences, rules, trade plans, account balances and statistics. This is your data — we do not buy, sell, share or monetise individual trading data. Legal basis: performance of contract.

2.4 Billing data

Subscription status, plan, invoices and Stripe customer/subscription identifiers. We never see or store your full card number — Stripe processes payments. Legal basis: performance of contract and legal obligation (Belgian accounting law — 7-year invoice retention).

2.5 Technical data

Country code (ISO 2-letter) at signup — derived from your connection metadata via our edge provider — used to enforce sanctions restrictions and adapt tax/billing where applicable. Basic server logs (URL, response code, timestamp) for security and reliability. We do not persist raw IP addresses. Legal basis: legitimate interest in keeping the service secure and operational (Art. 6(1)(f) GDPR).

2.6 Communication

Emails you send us, support tickets, and email open/click events for transactional emails only. Legal basis: legitimate interest.

2.7 Marketing (optional)

If you opt in at signup or later in Settings, we send occasional product updates and offers. You can withdraw consent at any time (Settings → Email preferences, or the unsubscribe link in each marketing email). Legal basis: consent (Art. 6(1)(a) GDPR).

3. AI-generated insights

Where you use AI-powered features (Edge Intelligence, Risk Advisor, Behavioral Coach, Chat), a structured summary of your relevant trade data is transmitted to our AI provider (Emergent LLM proxy → OpenAI gpt-4o-mini) to generate written observations. This may include trade entries/exits, R-multiples, tags, rule violations and — where you explicitly submit them — journal notes. AI output is probabilistic; it does not constitute an automated decision producing legal or similarly significant effects under GDPR Art. 22.

Data sent to the AI provider is subject to their processing terms (no training use per their standard API terms). Legal basis: performance of contract (feature you enabled).

4. Aggregated research use

We may use aggregated, anonymised data — never personally identifiable — for:

  • Improving EdgeFlow's edge-discovery algorithms.
  • Internal research into trading patterns and outcomes.
  • Publishing aggregate insights where individuals cannot be re-identified.

Legal basis: legitimate interest (Art. 6(1)(f) GDPR), assessed via a documented balancing test. We never sell raw data. We never re-identify anonymised records.

Opt out: email privacy@youredgeflow.com with the subject “Research opt-out”. Opting out does not affect normal use of EdgeFlow.

5. Automated decision-making & profiling

EdgeFlow does not use your personal data to make automated decisions that produce legal or similarly significant effects on you (GDPR Art. 22). AI-generated insights are analytical output presented to you — they do not change your subscription, pricing or access rights automatically.

6. Sub-processors

Mizznes BV relies on the following processors, bound by contract and (where applicable) the European Commission's Standard Contractual Clauses for transfers outside the EEA:

  • MongoDB Atlas — primary database. Hosting region: AWS eu-west-3 (Paris, EU).
  • Vercel (USA/EU) — application hosting & edge network.
  • Stripe (Ireland / USA) — payments and subscription management.
  • Resend (USA) — transactional email delivery.
  • Emergent LLM proxy → OpenAI (USA) — AI insights generation.
  • Cloudflare — DDoS protection and edge delivery for parts of the network.

7. Sale and sharing of personal data

Mizznes BV does not sell your personal information and does not share it for cross-context behavioural advertising. There are no advertising cookies, no third-party analytics vendors and no data-broker relationships.

8. How long we keep data

  • Account & trading data: until you delete your account, then permanently erased.
  • Invoices & billing records: 7 years (Belgian accounting law).
  • Consent audit records: retained for the lifetime of the account plus 3 years (accountability requirement).
  • Server access logs: 90 days.
  • Anonymised research data: indefinitely (cannot identify you).

9. Your rights (GDPR + worldwide)

  • Access — request a copy of your data.
  • Rectification — correct inaccurate data.
  • Erasure — “right to be forgotten”.
  • Restriction — limit how we process data.
  • Portability — export your data in machine-readable format.
  • Objection — opt out of research use or marketing emails.
  • Withdraw consent — where processing is based on consent (marketing, cookies).
  • Lodge a complaint — with the Belgian Data Protection Authority (gegevensbeschermingsautoriteit.be) or your local supervisory authority.

To exercise any right, email privacy@youredgeflow.com. We respond within 30 days.

10. California residents (CCPA / CPRA)

If you are a California resident, you have the additional rights to know the categories of personal information collected and shared, to correct inaccurate information, to delete personal information, and to be free from discrimination for exercising these rights. Because Mizznes BV does not sell or share personal information for cross-context behavioural advertising, no “Do Not Sell or Share” mechanism is required. Requests: privacy@youredgeflow.com.

11. Security

Passwords are hashed with bcrypt (10 salt rounds). Connections are HTTPS-only. Databases are encrypted at rest by MongoDB Atlas. Sessions use JSON Web Tokens with a 30-day expiry. We follow industry best practice, but no system is 100% secure. We will notify affected users within 72 hours of confirming any data breach affecting their personal data.

12. Children

EdgeFlow is available only to persons aged 18 or older. We confirm this via a mandatory age checkbox at signup. We do not knowingly collect data from minors. If you believe we have, contact us immediately.

13. International transfers

Your personal data is primarily stored in the European Union (AWS eu-west-3 (Paris, EU)). Some sub-processors (Stripe, Resend, OpenAI, Vercel edge) may process data in the United States or other regions. These transfers rely on the European Commission's Standard Contractual Clauses (2021/914) or equivalent safeguards.

14. Changes to this policy

We will notify you of material changes by email at least 14 days before they take effect. Continued use after the effective date constitutes acceptance.

Questions about this document? Contact privacy@youredgeflow.com.

Mizznes BV · Ransuildreef 16, 2900 Schoten, België · 1026.527.343 · BE 1026.527.343