Privacy Policy
Last Updated: 14 August 2026
1. Introduction
Itoflow ("Company", "we", "us", or "our") operates Itoflow("Platform", "Service"), a quantitative financial analysis platform. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Platform.
We are committed to protecting your privacy and ensuring transparency about our data practices. This policy complies with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, the EU General Data Protection Regulation (EU GDPR), and the California Consumer Privacy Act (CCPA).
Data Controller
Itoflow is the data controller responsible for your personal data under the UK GDPR and EU GDPR. As the data controller, we determine the purposes and means of processing your personal data.
Data Protection Contact: For any questions about this Privacy Policy, our data practices, or to exercise your data protection rights, please contact us at [email protected].
Note: We are in the process of appointing a formal Data Protection Officer (DPO) and will update this policy with their contact details once appointed. In the meantime, all data protection enquiries should be directed to the email address above.
Important Notice About Financial Data
Itoflow processes financial information that you provide or authorise us to retrieve, including portfolio holdings, cash balances, transaction and order history, and investment data. This information may be considered sensitive and is treated with additional care.
When you choose to connect a supported brokerage account:
- We establish the connection only at your direction, and you can disconnect it at any time
- We store sensitive connection credentials through WorkOS Vault
- We access only the account data and permissions made available through the broker connection
- We submit live trades only after your explicit approval
Itoflow is not a broker or custodian and does not hold or withdraw customer funds. We use broker-connected data to provide portfolio visibility, analysis, approved trading workflows, and reconciliation of account activity.
2. Information We Collect
2.1 Information You Provide
| Data Category | Examples | Purpose |
|---|---|---|
| Account Information | Email address, name (via WorkOS authentication) | Account creation and authentication |
| Portfolio Data | Holdings, transactions, financial positions you upload | Providing quantitative analysis services |
| Broker Connection Information | Broker name and account identifiers, connection permissions, and credentials or tokens you provide or authorise us to store | Establishing and maintaining the broker connection you request |
| Chat History | Messages, queries, and conversations with the Platform | Providing AI-powered analysis, improving services |
| Communications | Emails, support requests, feedback | Customer support and service improvement |
2.2 Information We Receive From Connected Services
| Data Category | Examples | Purpose |
|---|---|---|
| Broker-Sourced Financial Data | Holdings, cash balances, account metadata, and order, transaction, and dividend history made available through the broker connection | Providing portfolio visibility, synchronising portfolio state, supporting approved trades, and reconciling account activity |
2.3 Information Collected Automatically
| Data Category | Examples | Purpose |
|---|---|---|
| Usage Data | Features used, pages visited, session duration | Service improvement and analytics |
| Device Information | Browser type, operating system, device identifiers | Security, compatibility, troubleshooting |
| Log Data | IP address, access times, error logs | Security, debugging, fraud prevention |
3. Legal Basis for Processing (GDPR)
Under the UK GDPR and EU GDPR, we process your personal data based on the following legal grounds:
| Processing Activity | Legal Basis (Article 6) |
|---|---|
| Account creation and authentication | Contract performance |
| Portfolio data analysis | Contract performance |
| Broker connection, portfolio synchronisation, and user-approved trade execution | Contract performance |
| Chat history storage and AI processing | Contract performance |
| Optional browser analytics | Consent |
| Security monitoring and fraud prevention | Legitimate interests / Legal obligation |
| Marketing communications (if opted in) | Consent |
| Responding to legal requests | Legal obligation |
| Error monitoring and crash reporting | Legitimate interests |
Legitimate Interests Assessment: Where we rely on legitimate interests, we have conducted a balancing test to ensure that our interests do not override your fundamental rights and freedoms. You may request details of this assessment by contacting us.
4. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve the Platform
- Process and analyse your portfolio data to deliver quantitative insights
- Maintain broker connections you authorise, synchronise account data, and execute and reconcile trades you approve
- Respond to your enquiries and provide customer support
- Send service-related communications (e.g., updates, security alerts)
- Detect, prevent, and address security issues, fraud, and abuse
- Comply with legal obligations and respond to lawful requests
- Develop new features and improve our AI analysis capabilities
- Conduct internal research and analytics to improve service quality
What We Do Not Do: We do not sell your personal information to third parties. We do not use your data for targeted advertising. We do not share your financial data with third parties for their own marketing purposes.
AI Processing and Automated Decision-Making (Article 22 GDPR)
Itoflow uses artificial intelligence and machine learning to analyse your data and provide quantitative insights. This constitutes "profiling" under GDPR, as we process personal data to analyse and make predictions about your financial information.
Nature of AI Processing:
- We use large language models (LLMs) provided by Anthropic to process your queries
- Your chat messages and uploaded data are sent to AI systems for analysis
- AI-generated outputs include portfolio analysis, risk assessments, and visualisations
- No automated decisions are made that produce legal effects or similarly significantly affect you
Your Rights: The AI analysis provided is informational only. All investment decisions remain entirely with you. You have the right to:
- Request information about the logic involved in the AI processing
- Express your views about the AI analysis
- Request human review of any AI-generated insights
- Object to AI processing based on legitimate interests
5. Third-Party Service Providers (Sub-processors)
We share your information with trusted third-party service providers ("sub-processors") who assist us in operating the Platform. We have entered into Data Processing Agreements (DPAs) with each of these providers that include appropriate data protection obligations.
| Provider | Purpose | Data Shared | Location | Transfer Mechanism |
|---|---|---|---|---|
| WorkOS | Authentication, identity, and secure credential storage | Email address, name, authentication tokens, and sensitive broker connection credentials stored through WorkOS Vault | USA | SCCs + DPA |
| Anthropic | AI/LLM processing | Chat messages, queries, uploaded data for analysis | USA | SCCs + DPA |
| Railway | Cloud infrastructure and hosting | All application data, session state, database | USA | SCCs + DPA |
| Cloudflare | Content delivery and security | IP addresses, request metadata | Global (USA HQ) | SCCs + DPA |
| Sentry | Error tracking and user feedback | In staging and production, error logs, stack traces, device/browser information, and screenshots (if submitted via feedback). We do not attach your account identity without analytics consent. After consent, we attach only your Itoflow account identifier, not your email or name. | USA | SCCs + DPA |
| PostHog | Essential browser error tracking and optional product analytics | Without analytics consent, we send only sanitized browser exceptions, stack frames, browser/device information, privacy-safe route templates, release information, and real trace identifiers when available. This essential error channel does not use persistent browser storage, identify your account, or create a person profile. After you opt in, future browser exceptions may use your Itoflow account identifier, and we may also send usage events, browser traces, and optional diagnostic logs. Previously collected anonymous exceptions remain anonymous. We do not send input text, request bodies, URL query strings, portfolio data, or credentials to PostHog. We redact sensitive message substrings without changing stack frames. | EU | SCCs + DPA |
Sub-processor Updates: We may update our list of sub-processors from time to time. Material changes to sub-processors will be notified through updates to this Privacy Policy. You may subscribe to sub-processor update notifications by contacting us at [email protected].
Transfer Safeguards: For transfers to countries outside the UK and EEA that do not have an adequacy decision, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission and the UK Information Commissioner's Office, supplemented by additional technical and organisational measures where necessary.
6. Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected. Our retention periods are based on business needs and legal requirements:
| Data Category | Retention Period | Basis |
|---|---|---|
| Account Data | Duration of account + 2 years | Legal obligations, dispute resolution |
| Chat History | Duration of account or until deletion request | Service provision, user convenience |
| Portfolio Data | Until deletion request or account termination | Service provision |
| Broker Credential Material | Until you disconnect the broker or terminate your account; active credential material is deleted or revoked when the connection ends | Service provision, security |
| Broker Connection and Trading Records | For as long as needed to provide the service and meet security, legal, fraud-prevention, audit, and dispute-resolution obligations | Contract performance, legal obligations, legitimate interests |
| Log Data | 90 days | Security, debugging, fraud prevention |
| Backup Data | 30 days after primary deletion | Disaster recovery |
After the retention period expires, we will securely delete or anonymise your personal data. In some cases, we may retain anonymised data for statistical purposes indefinitely.
7. Your Rights
7.1 Rights Under UK GDPR and EU GDPR
If you are in the UK or European Economic Area, you have the following rights:
- Right of Access: Request a copy of your personal data
- Right to Rectification: Request correction of inaccurate data
- Right to Erasure: Request deletion of your personal data ("right to be forgotten")
- Right to Restriction: Request limitation of processing
- Right to Data Portability: Receive your data in a structured, machine-readable format
- Right to Object: Object to processing based on legitimate interests
- Right to Withdraw Consent: Withdraw consent at any time where processing is based on consent
To exercise these rights, please contact us at [email protected]. We will respond within one month as required by law.
7.2 Rights Under CCPA/CPRA (California Residents)
If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA):
- Right to Know: Request disclosure of personal information collected, used, disclosed, or sold in the preceding 12 months
- Right to Delete: Request deletion of personal information we have collected from you
- Right to Correct: Request correction of inaccurate personal information
- Right to Opt-Out of Sale/Sharing: Opt out of the sale or sharing of personal information (Note: We do not sell or share personal information for cross-context behavioural advertising)
- Right to Limit Use of Sensitive Personal Information: Limit our use of sensitive personal information to purposes necessary to provide the services
- Right to Non-Discrimination: Not receive discriminatory treatment for exercising your privacy rights
We do not sell your personal information. We do not share personal information for cross-context behavioural advertising. We do not use or disclose sensitive personal information for purposes other than those permitted under CCPA/CPRA.
Categories Collected (preceding 12 months): Identifiers (email, name), commercial information (portfolio data), internet activity (usage logs), and inferences drawn from the above.
Verification: When you make a request, we will verify your identity by matching the information you provide with information we have on file. For sensitive requests, additional verification may be required.
Authorised Agents: You may designate an authorised agent to make requests on your behalf. We may require written proof of the agent's authorisation and verify your identity directly.
7.3 How to Exercise Your Rights
To exercise any of your data protection rights, you may:
- Email us at [email protected] with your request
- Specify the right you wish to exercise and provide sufficient information for us to verify your identity
We will respond to verifiable requests within one month (GDPR) or 45 days (CCPA), with possible extensions for complex requests. We may request additional information to verify your identity before processing your request.
8. International Data Transfers
Your information may be transferred to and processed in countries outside the UK and European Economic Area, including the United States. When we transfer data internationally, we ensure appropriate safeguards are in place:
- Standard Contractual Clauses approved by the European Commission and UK ICO
- Data processing agreements with all service providers
- Assessment of the data protection laws in the destination country
9. Data Security
We implement appropriate technical and organisational measures to protect your personal data in accordance with industry best practices and applicable legal requirements:
- Encryption of data in transit (TLS 1.3/HTTPS) and at rest (AES-256)
- Secure authentication through WorkOS (we do not store passwords)
- Regular security assessments and vulnerability scanning
- Access controls limiting employee access to personal data on a need-to-know basis
- Secure infrastructure hosting with Railway in SOC 2 compliant data centres
- Automated security monitoring and alerting
- Regular security training for personnel with data access
Employee Access to Your Data: A limited number of authorised Itoflow administrators may access your account data, including chat conversations and strategy configurations, strictly for the following purposes: investigating support requests you have raised, responding to security incidents, complying with legal obligations, debugging platform issues, and conducting SOC 2 compliance audits. All administrative access is logged in an immutable audit trail and reviewed quarterly. We do not access your data for marketing, analytics, or any purpose beyond platform operation and security.
While we strive to protect your personal data using industry-standard security measures, no method of transmission or storage is 100% secure. We cannot guarantee absolute security, but we commit to promptly investigating and addressing any suspected security incidents.
Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will:
- Notify the supervisory authority: Within 72 hours of becoming aware of the breach, as required by UK GDPR and EU GDPR
- Notify affected individuals: Without undue delay where the breach is likely to result in a high risk to your rights and freedoms
- Document the breach: Maintain records of all breaches, including facts, effects, and remedial actions taken
10. Cookies and Similar Technologies
We use essential cookies necessary for the Platform to function, including authentication tokens and session management. We also send limited browser exception diagnostics to PostHog to detect and fix technical faults. This essential error channel does not use cookies or persistent browser storage and does not identify your account. If you opt in, we also use PostHog analytics cookies and similar browser storage to understand conversion, onboarding drop-off, product usage, and browser performance. If you choose Essential Only or withdraw consent, we do not send product analytics, browser traces, session replay, or optional diagnostic logs to PostHog. We do not use third-party advertising cookies.
| Cookie Type | Purpose | Duration |
|---|---|---|
| Authentication | Keep you logged in securely | Session / 7 days |
| Preferences | Remember your settings (e.g., theme) | 1 year |
| Essential error diagnostics | Detect and diagnose browser exceptions without identifying your account | No cookie or persistent browser storage |
| Analytics (optional) | Measure conversion, product adoption, performance, and funnel drop-off after consent | Until cleared or consent is withdrawn |
11. Children's Privacy
The Platform is not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately at [email protected].
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the "Last Updated" date. We encourage you to review this Privacy Policy periodically.
13. Complaints
If you have concerns about our data practices, please contact us first at [email protected]. We take all privacy concerns seriously and will do our best to resolve your concern promptly.
If you are not satisfied with our response, you have the right to lodge a complaint with a supervisory authority:
- UK: Information Commissioner's Office (ICO) - ico.org.uk | Tel: 0303 123 1113
- EU: Your local data protection authority. A list of EU DPAs is available at edpb.europa.eu
- California (USA): California Attorney General - oag.ca.gov/privacy/ccpa
14. California "Shine the Light" Law
Under California Civil Code Section 1798.83, California residents may request certain information regarding our disclosure of personal information to third parties for their direct marketing purposes.
We do not disclose personal information to third parties for their direct marketing purposes. If this practice changes, we will update this Privacy Policy and provide you with an opportunity to opt out.
15. Contact Us
For any questions or concerns about this Privacy Policy or our data practices:
Itoflow
Data Protection Enquiries
Privacy Email: [email protected]
General Email: [email protected]
Website: https://itoflow.work
For time-sensitive data protection matters, please include "URGENT" in the subject line of your email. We aim to respond to all enquiries within 5 business days.
Record of Processing Activities (GDPR Article 30)
As required under Article 30 of the GDPR, we maintain a record of all processing activities carried out under our responsibility. This record is available to the supervisory authority upon request and includes information about the purposes of processing, categories of data subjects and personal data, recipients of data, international transfers, retention periods, and security measures.
You may request a summary of our processing activities relevant to your personal data by contacting us at [email protected].
This Privacy Policy is effective as of 14 August 2026.
Previous versions of this Privacy Policy may be requested by contacting us at [email protected].
View Terms and Conditions