Privacy Policy

Documentation of our data collection, use and protective measures pursuant to the GDPR and the Austrian Data Protection Act

1. Scope and Legal Bases

This privacy policy applies to all visitors to our website (www.blackquantempire.trade) as well as to all persons who use our services, subscribe to our quantitative trading algorithm or otherwise interact with Black Quant Empire. Black Quant Empire GmbH is an Austrian company based in Vienna and is subject to the General Data Protection Regulation (GDPR) – Regulation (EU) 2016/679 – the Austrian Data Protection Act (DSG 2018) as well as the ePrivacy Directive concerning cookies and tracking technologies. We have appointed a Data Protection Officer (DPO) to ensure GDPR compliance and to handle all data protection matters. You will find our contact information in section 13.

2. What Personal Data We Collect

2.1 Contact form data

When you submit our contact form on the website, we collect the following information:

  • Your full name (required)
  • Your email address (required)
  • Phone number (optional, for business enquiries)
  • Type of enquiry (subscription, careers, technical support, general enquiry)
  • The content of your message or enquiry
  • Timestamp of the form submission
  • Your Internet Protocol address (IP address) for anti-spam verification and security
  • Where applicable, information about your browser and operating system

This data is used to process your enquiry, to respond to you and, where applicable, to manage your application. The collection is necessary in order to be able to process your enquiry.

2.2 Website visit data (not directly identifiable)

When you visit our website we automatically collect various technical information:

  • Which pages you access and in what order
  • How long you stay on each page
  • Which website you came to us from (referrer URL)
  • Your browser type and version
  • Your operating system
  • Your Internet Protocol address (IP address), which we anonymise
  • Device type (desktop, tablet, mobile phone)
  • Screen resolution and time zone
  • Date and time of the visit

This data is used for website optimisation, security monitoring, fraud prevention and to improve our services. The collection takes place automatically and does not require explicit consent for basic functionality.

2.3 Subscription data

When you subscribe to our quantitative trading algorithm, we collect comprehensive account information:

  • Account information: full name, email address, username and password
  • Billing address and shipping address (if different)
  • Payment information: credit card or bank details (processed and encrypted by our certified payment provider)
  • Subscription details: plan type, billing cycle, renewal date, billing history
  • Account activity: login times, last login, API usage, access patterns
  • Customer support interactions: tickets, enquiries, communication history
  • Payment history and invoices

This data is necessary in order to fulfil the contract with you, to manage your account, to process payments, to provide technical support and to ensure the security of your account. All payment information is encrypted by our payment provider and processed according to PCI-DSS standards.

2.4 Algorithm-specific data

If you upload algorithms, trading strategies or code files via our platform, we collect and store:

  • Your algorithm source code and all versions of it (protected and private)
  • Backtesting results and test results
  • Historical performance data and key figures
  • Equity curves and history charts
  • Insights, analyses and reports on the algorithm
  • Metadata: upload date, last modification, file size
  • Dependencies and libraries used

Your algorithm source code remains exclusively your intellectual property and is at no time visible to other users. Only meta information (historical performance, general strategy details, insights) may be shared in the marketplace with potential funds with your express written consent. Your code is stored encrypted and only you and authorised Black Quant Empire personnel can view it.

2.5 Marketplace and strategy sharing (if enabled)

If you offer an algorithm in the marketplace, we additionally collect:

  • Meta information: strategy description, category, ratings
  • Performance statistics: Sharpe ratio, Sortino ratio, maximum drawdown, total return
  • Visitor numbers and information on interested parties
  • Revenue and licences granted (if applicable)
  • Fund enquiries and cooperation communications

This data is used to present your algorithm in the marketplace and to enable connections with quantitative funds. You are in control of the visibility at all times and can adjust it at any time or remove the algorithm from the marketplace.

2.6 Data we do NOT collect

We deliberately and as a matter of principle do NOT collect the following categories of sensitive personal data:

  • Social security numbers or tax numbers (except where legally required for tax purposes)
  • Biometric data (fingerprints, facial recognition, iris scans)
  • Racial or ethnic origin
  • Political opinions or voting behaviour
  • Religious affiliation or philosophical beliefs
  • Trade union membership
  • Genetic data
  • Data on your health or medical conditions
  • Criminal records or penalties (except where this is required for compliance)

This data is protected under the GDPR as "special categories" and we have no legitimate reason to collect it.

3. How We Use Your Data

3.1 Contact form processing

Your contact form data is used for the following purposes:

  • Answering enquiries: to understand your question or enquiry and to give you a helpful answer (legal basis: legitimate interest or pre-contractual measures)
  • Application processing: if you apply, we use your data for screening, interviews and the hiring decision (legal basis: contract and legitimate interest for recruiting)
  • Transactional emails: to send you confirmations, updates and important service notifications (legal basis: contract)
  • Anti-spam verification: to ensure that the form is submitted by a real person and not by a bot (legal basis: legitimate interest for security)
  • Security monitoring: to detect suspicious activity or patterns of abuse (legal basis: legitimate interest for security)

Your data is stored for up to 30 days after your enquiry has been answered. If you have an active application or an active subscription, the data is retained for longer in accordance with the respective retention policies in section 7.

3.2 Subscription processing and customer relationship

Subscription data is used for these purposes:

  • Performance of the contract: to process monthly billing, subscription renewals and automatic payments (legal basis: contract)
  • Service provision: to provide you with access to the trading algorithm, API access and all subscribed services (legal basis: contract)
  • Account security: to protect your account, to detect suspicious login attempts, to carry out two-factor authentication (legal basis: legitimate interest for security)
  • Fraud detection: to prevent fraudulent payments, account takeovers or abuse (legal basis: legitimate interest for security)
  • Invoices and receipts: to send official invoices, to provide proof of payment, to document subscription details (legal basis: contract and legal obligation for accounting)
  • Service updates and support: to provide important updates, maintenance notifications and customer support (legal basis: contract)
  • Account administration: to update your profile, manage password resets, correct account information (legal basis: contract)

3.3 Website analytics and cookies

We use various technical instruments for data collection:

  • Session cookies (technically required): small files that your browser stores in order to maintain form functionality, security sessions and website stability. (no explicit consent required)
  • Preference cookies (optional): to store your design, language and navigation preferences. These cookies can persist for up to 12 months.
  • Analytics cookies (with opt-in): if we implement analytics, we use only privacy-oriented tools and NO invasive trackers such as Google Analytics (explicit consent required).
  • Marketing/advertising cookies (NOT used): we do NOT use any cookies for advertising purposes, cross-site tracking or profiling.

3.4 Legal compliance and regulatory requirements

Data is used for the following compliance purposes:

  • Tax purposes: invoices and transaction data are retained in accordance with Austrian tax law (retention for 7 years).
  • Regulatory requirements: your data will be disclosed if legally required or in order to comply with official orders.
  • Combating fraud: to detect and prevent fraud, money laundering or the financing of terrorism.

4. Data Sharing and Third Parties

4.1 Who we share data with

Payment provider (for subscription processing)

Service: credit card processing, payment handling
Data shared: name, email address, billing address, payment information
Legal basis: contract (necessary for payment handling)
Data storage: payment information is not stored on our servers; the payment provider stores it encrypted according to PCI-DSS standards.

Email service provider (for notifications)

Service: sending of transactional emails
Data shared: email address, name
Opt-out: you can unsubscribe from optional marketing emails at any time; transactional emails (invoices etc.) cannot be unsubscribed from.

Hosting provider (GitHub Pages)

Service: website hosting and content delivery
Data shared: page views, IP addresses (automatically through HTTP requests)
Important: GitHub Pages does NOT store any personal data of subscribers. Only anonymised access logs are collected.

4.2 Who we do NOT share data with

We expressly do NOT share your data with:

  • Marketing agencies or advertising networks
  • Data brokers or data aggregation companies
  • Social media platforms for tracking or profiling
  • Competitors or third-party traders

4.3 International data transfers

All personal data is primarily processed and stored in the European Union (Austria). Data servers are located in EU data centres with GDPR compliance. If we ever have to transfer data to a third country, we use mechanisms approved by the GDPR (standard contractual clauses).

5. Data Security and Protective Measures

5.1 Technical security measures

We implement comprehensive security measures in line with industry standards:

  • HTTPS/SSL encryption: data transfers take place over TLS 1.2+
  • Data encryption at rest: sensitive data is encrypted with AES-256
  • Access controls: only authorised personnel have access; access is logged
  • Two-factor authentication (2FA): available and recommended for all subscriptions
  • Rate limiting: protection against brute-force attacks by limiting login attempts

5.2 Your personal responsibility

Use a strong password, enable 2FA and never share your access credentials with third parties. Report suspicious activity immediately to security@blackquantempire.at.

5.3 Security limits and liability

We cannot guarantee absolute 100% security. Should a data breach occur, we will notify you and the Austrian Data Protection Authority (DSB) within 72 hours in accordance with the GDPR.

6. Your Rights Under the GDPR

6.1 Right of access (Article 15 GDPR)

You have the right to request a copy of all personal data free of charge. Response time: within 30 days.

6.2 Right to rectification (Article 16 GDPR)

You can have inaccurate or out-of-date data corrected. Contact our Data Protection Officer at dpo@blackquantempire.at.

6.3 Right to erasure (Article 17 GDPR)

You can request the erasure of your data (“right to be forgotten”), except where we imperatively need it for the performance of the contract or on account of legal requirements (e.g. the 7-year retention obligation for tax data).

6.4 Right to restriction of processing (Article 18 GDPR)

You can ask us to restrict the processing of your data if you contest its accuracy or have lodged an objection.

6.5 Right to data portability (Article 20 GDPR)

You can request the data you have provided in a structured, portable format (e.g. CSV, JSON) in order to transfer it to another service provider.

6.6 Right to object (Article 21 GDPR)

You can object to the processing of your data, in particular where this takes place on the basis of legitimate interests (e.g. direct marketing).

6.7 Right against automated decision-making (Article 22 GDPR)

We hereby state that we do NOT make any automated decisions about you. All material decisions (account rejection, termination, pricing) are made by humans.

6.8 How to exercise your rights

To exercise any of these rights, contact our Data Protection Officer:
By email: dpo@blackquantempire.at
Subject line: "GDPR request: [access/rectification/erasure]"

7. Data Storage and Erasure

7.1 Retention periods by data type

  • Contact form submissions: 30 days after being answered
  • Application data: 6 months after the application
  • Subscription data: for the duration of the membership, then for a further 30 days
  • Invoices and transaction data: 7 years (Austrian tax requirement)
  • Website server logs: 30 days (security)

7.2 Automatic erasure

After these periods have expired, the data is deleted from the database, removed from backups (after 90 days) or fully anonymised.

8. Cookies and Tracking Technologies

8.1 What are cookies?

Cookies are small text files that are stored on your device in order to save your preferences, maintain sessions and personalise the experience.

8.2 Types of cookies and their purpose

  • Technically required cookies: for form submission, security, login sessions. No explicit consent required.
  • Preference cookies: store settings such as design (light/dark). (Require consent via our cookie banner.)
  • Marketing cookies: ARE NOT USED. We do not run any retargeting advertising.

8.3 Managing cookies

You can adjust your cookie preferences via the cookie banner on our website or block cookies directly in your browser settings. Please note that blocking necessary cookies impairs website functionality (e.g. login).

9. Children's Privacy

Our website and services are not intended for children under 18 years of age. We do not knowingly collect personal data from persons under 18 years of age. Should we determine that we have collected data from a minor, we will delete it immediately.

10. Algorithms and Intellectual Property

When you upload code files via our platform, the source code remains your exclusive intellectual property. Your code is stored encrypted and is not visible to third parties. Black Quant Empire claims NO ownership rights to your algorithm. Metadata (performance) is only shared with your express consent (e.g. in the marketplace).

11. Compliance with Trade and Export Control Regulations

Because we offer financial technology, we are subject to sanctions regulations. We cannot provide our services to users in sanctioned countries (e.g. North Korea, Syria, Iran, the Crimea region) or to persons on sanctions lists (OFAC). By using our services you confirm that you are not in breach of any of these requirements.

12. Updates to this Privacy Policy

We may adapt this privacy policy to new case law or technological changes. In the event of significant changes we will notify our subscribers by email.

13. Contact and Complaints

13.1 Data Protection Officer

Email: dpo@blackquantempire.at
Post: Black Quant Empire GmbH, Kärntner Straße 1, 1010 Vienna, Austria

13.2 Complaint to the supervisory authority

You have the right to lodge a complaint with your local data protection authority:

Austrian Data Protection Authority (DSB)
Barichgasse 40-42, 1030 Vienna, Austria
Website: www.dsb.gv.at
Email: dsb@dsb.gv.at

13.3 Further contact options

Last updated: 8 May 2026
Effective from: 8 May 2026
Next scheduled review: May 2027