Legal document
Acceptable Use Policy
Rules protecting users, data and the Service
Last updated 20 July 2026
6.1General rule
You may use Notofin only lawfully, safely and in accordance with the Terms. You are responsible for users, administrators, integrations and content under your account or workspace.
6.2Prohibited conduct
You must not use or attempt to use the Service to:
- violate applicable law, sanctions, court orders or third-party rights;
- access, collect, disclose or process another person's data without authority or a lawful basis;
- upload malware, ransomware, malicious code or content designed to disrupt or gain unauthorised access;
- probe, scan, test or bypass security, authentication, rate limits, seat limits or access controls without written permission;
- reverse engineer, decompile, copy or extract source code, models, prompts, databases or protected product elements except where non-waivable law permits;
- scrape, crawl or make automated requests that create unreasonable load or are not authorised by documented APIs;
- share accounts, resell access or provide a service bureau unless your plan or written agreement permits it;
- misrepresent identity, authority, trading results, account ownership, credentials, performance or affiliation;
- fabricate, manipulate or present journal data as independently verified performance;
- facilitate fraud, market manipulation, money laundering, unauthorised investment services or evasion of broker, prop-firm or regulatory rules;
- upload content that is unlawful, infringing, defamatory, threatening, abusive or designed to expose another person's confidential information;
- submit passwords, authentication secrets, full payment-card data, government identifiers or unnecessary medical information to free-text or AI fields;
- use Notofin or AI outputs to make solely automated employment, disciplinary, credit, insurance or similarly significant decisions about a person;
- use emotional or behavioural information for unlawful discrimination, coercion, surveillance or retaliation;
- claim that Notofin provides regulated advice, signals, execution or guaranteed performance; or
- help another person do any of the above.
6.3Business-customer duties
Workspace owners and administrators must:
- invite only authorised users and promptly remove access when no longer needed;
- configure roles and permissions according to least privilege;
- provide privacy, monitoring and employment notices required by law;
- use a lawful basis for trader, employee, contractor and applicant data;
- provide a meaningful human review before acting on analytics or AI output;
- honour data-subject rights and cooperate with Notofin where we act as processor; and
- avoid uploading special-category or highly sensitive data unless necessary, lawful and agreed.
6.4Enforcement
We may investigate suspected violations and may remove content, restrict functionality, rotate credentials, suspend integrations or accounts, or terminate access. We will consider severity, recurrence, risk and available remedies. Serious security, fraud or legal threats may require immediate action and reporting to competent authorities.
Report abuse or security concerns to tech@notofin.com.
Data Processing Addendum
For Notofin Floor and other business customers
Version 1.0 - 20 July 2026
7.1Parties and priority
This Data Processing Addendum ("DPA") is between the customer identified in the applicable subscription, order form or agreement ("Customer") and Equity Logica Ltd. / Екуити Лоджика ООД, UIC 208636066 ("Notofin"). It applies to Customer Personal Data processed by Notofin as a processor to provide the Service.
If this DPA conflicts with the main agreement on personal-data processing, this DPA controls. Other terms of the main agreement remain unchanged.
7.2Definitions
"Applicable Data Protection Law" means the GDPR, the Bulgarian Personal Data Protection Act and other binding data-protection laws applicable to the processing. "Customer Personal Data" means personal data processed by Notofin on Customer's behalf. "Subprocessor" means a processor engaged by Notofin to process Customer Personal Data.
7.3Roles
Customer is the controller and Notofin is the processor for Customer Personal Data, unless the parties are processors and subprocessors under another controller. Customer is responsible for its instructions, notices, lawful bases, consents where required, data accuracy, access decisions and compliance with laws applying to its use of the Service.
Notofin remains an independent controller for data processed for its own account administration, billing, security, fraud prevention, legal compliance, product communications and establishment or defence of legal claims.
7.4Processing instructions
Notofin will process Customer Personal Data only on documented instructions from Customer, including instructions contained in the agreement and the Customer's use and configuration of the Service, unless law requires otherwise. If legally permitted, Notofin will inform Customer before legally required processing.
Notofin will promptly inform Customer if, in its opinion, an instruction infringes Applicable Data Protection Law. Notofin may suspend the affected processing until the parties resolve the issue.
7.5Details of processing
| Subject matter | Provision of Notofin Floor, integrations, storage, analytics, support and related services |
|---|---|
| Duration | For the subscription or agreement term plus deletion, backup and legal-retention periods |
| Nature and purpose | Hosting, organising, importing, analysing, displaying, securing, supporting and deleting trading-journal and workspace data according to Customer instructions |
| Data subjects | Customer users, traders, employees, contractors, coaches, administrators, prospects or other individuals whose data Customer submits |
| Personal-data categories | Account and contact data; workspace roles; trading and performance data; emotion and behavioural journal data; screenshots and files; platform identifiers and connection metadata; comments; support data; technical logs |
| Special-category data | Not intended. It may be included only if Customer lawfully chooses to submit it and implements required safeguards |
| Frequency | Continuous or as initiated by users, integrations and scheduled synchronisation |
7.6Confidentiality and personnel
Notofin will ensure that persons authorised to process Customer Personal Data are bound by confidentiality and receive appropriate privacy and security guidance. Access will be limited to persons who need it for the Service, support, security or legal obligations.
7.7Security measures
Notofin will maintain technical and organisational measures appropriate to the risk, taking into account the state of the art, costs, nature, scope, context and purposes of processing. Measures may include:
- logical access controls, role-based permissions and least privilege;
- authentication, credential management and administrative-access controls;
- encryption in transit and appropriate protection of stored data and backups;
- logging, monitoring, vulnerability management and incident response;
- backup, recovery and availability procedures;
- secure development, change management and provider due diligence;
- confidentiality commitments and staff awareness; and
- periodic review of security controls and risks.
Customer is responsible for secure configuration, user access, devices, credentials, endpoint security, lawful content and its own systems connected to Notofin.
7.8Subprocessors
Customer gives Notofin general written authorisation to engage Subprocessors needed to provide the Service. Notofin will maintain a current list at a designated public or customer-accessible location and will require each Subprocessor to protect Customer Personal Data through obligations materially consistent with this DPA.
Notofin will provide reasonable notice of a new Subprocessor where required. Customer may object on reasonable data-protection grounds within the stated notice period. The parties will work in good faith on a practical solution. If none is available, Customer may terminate the affected Service without penalty for the unused prepaid portion, unless the main agreement provides a lawful alternative.
Notofin remains responsible for its Subprocessors to the extent required by Applicable Data Protection Law.
7.9International transfers
Notofin will not transfer Customer Personal Data to a country outside the EEA unless a lawful transfer mechanism applies, such as an adequacy decision, Standard Contractual Clauses or another valid safeguard. Where the EU Standard Contractual Clauses are needed, the parties agree to incorporate the applicable controller-to-processor or processor-to-processor module, with the details in this DPA and Subprocessor list completing the relevant annexes.
7.10Data-subject requests
Taking into account the nature of processing, Notofin will provide reasonable assistance through product functionality or support so Customer can respond to requests for access, correction, deletion, restriction, objection and portability. If Notofin receives a request relating to Customer Personal Data, it will redirect the requester to Customer where appropriate and will not respond substantively unless instructed or legally required.
7.11Security incidents
Notofin will notify Customer without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data. The notice will include available information reasonably needed for Customer's obligations, such as the nature of the incident, affected data and subjects, likely consequences, measures taken or proposed, and a contact point. Information may be provided in phases as it becomes available.
Notification does not constitute an admission of fault or liability. Customer is responsible for notifications to authorities and data subjects unless the parties agree otherwise or law requires Notofin to notify directly.
7.12DPIAs and regulatory consultations
Notofin will provide reasonable information and assistance for Customer's data-protection impact assessment or prior consultation where the requested assistance relates to the Service and is not otherwise available. Extensive or customer-specific work may be charged at agreed rates.
7.13Deletion and return
During the term, Customer may use available export and deletion functions. After termination, Notofin will delete or return Customer Personal Data according to the agreement and Customer's instruction, normally beginning active-system deletion within 30 days. Residual backup copies may remain for up to 90 days and will remain protected and isolated from ordinary use. Notofin may retain data required by law or for legal claims, subject to continued protection and restricted use.
7.14Information and audits
Notofin will make available information reasonably necessary to demonstrate compliance with processor obligations, which may include policies, security summaries, completed questionnaires or independent reports when available.
If that information is insufficient and Applicable Data Protection Law requires an audit, Customer may request one no more than once per year, except after a significant incident or regulator request. Audits must be coordinated in advance, occur during business hours, avoid disruption, protect other customers and confidential information, and be conducted by an independent qualified auditor. Customer bears reasonable audit costs unless the audit identifies a material breach by Notofin.
7.15Liability and termination
Liability under this DPA is subject to the liability provisions of the main agreement, to the extent permitted by law. A material uncured breach of this DPA may be treated as a material breach of the main agreement.