Legal document

Privacy Policy

How Notofin collects and uses personal data

Last updated 20 July 2026

2.1Scope and controller

This Privacy Policy explains how Equity Logica Ltd. / Екуити Лоджика ООД, UIC 208636066, processes personal data when you visit notofin.com, create or use a Notofin account, connect a trading platform, join a workspace, contact us or interact with our communications.

For individual accounts, website visitors, billing contacts and direct customer relationships, Equity Logica Ltd. is generally the data controller. For content processed inside a business customer's Notofin Floor workspace, the business customer may be the controller and Notofin may act as its processor. In that situation, requests about the organisation's use of workspace data should normally be directed to the organisation.

Privacy contact: tech@notofin.com.

2.2Personal data we collect

The categories below depend on how you use the Service.

A. Account and profile data

  • name, email address, password hash, authentication information and account identifiers;
  • country, language, time zone, profile details and communication preferences;
  • workspace, role, permissions, invitations and team membership; and
  • business details for account owners, administrators and billing contacts.

B. Subscription and transaction data

  • plan, billing cycle, trial status, promotional code, seat count and subscription history;
  • billing name, address, tax information and transaction identifiers;
  • limited payment metadata received from our payment processor, such as card brand, last digits, expiry status and payment outcome; and
  • invoices, refunds, chargebacks and customer-service records related to payment.

Full payment-card information is generally collected and processed directly by our payment processor, not stored by Notofin.

C. Trading and performance data

  • trade entries, exits, timestamps, instruments, direction, size, prices, fees, profit and loss, currency and account labels;
  • strategies, setups, tags, notes, goals, rule adherence, execution reviews and custom fields;
  • portfolio and account statistics, historical performance and calculated metrics;
  • manual imports, files and synchronisation data from connected platforms; and
  • team comments, coaching notes, reviews and workspace activity where enabled.

D. Emotion, behaviour and journal data

  • self-reported emotions, mood selections, confidence, stress, hesitation and other check-in responses;
  • behavioural labels, discipline observations, triggers, reflections and decision context; and
  • patterns or scores generated from the information you submit.

Notofin is not a medical or mental-health service. Do not use free-text fields to provide diagnoses, treatment records or other medical information. If you choose to submit information that constitutes special-category data under applicable law, you are responsible for ensuring that you have a lawful basis to do so; business customers must also provide required notices and safeguards.

E. Screenshots, files and user content

  • chart screenshots, platform screenshots, documents, images and attachments;
  • text or metadata extracted from files where a recognition feature is used; and
  • personal or confidential information visible in content you choose to upload.

Review and redact unnecessary personal data, account numbers and third-party information before upload.

F. Connected-platform and integration data

  • platform name, account identifiers, server or connection details and synchronisation status;
  • authorisation tokens, API credentials, investor credentials or similar connection information where required by the selected integration;
  • trade and account data made available by the connected service; and
  • technical logs concerning import, mapping, connection and error handling.

G. AI feature data

  • prompts, selected workspace data, instructions and context sent to an AI-assisted feature;
  • generated summaries, classifications, observations and user feedback on the output; and
  • technical and safety metadata used to operate, secure and evaluate the feature.

H. Device, log and usage data

  • IP address, device type, browser, operating system, language, approximate location derived from IP and identifiers;
  • login times, pages and features used, clicks, session information, referral source and performance data;
  • diagnostic, crash, error, security and audit logs; and
  • cookie and consent choices described in the Cookie Policy.

I. Communications and support

  • support requests, feedback, survey answers and correspondence;
  • newsletter sign-up and marketing preferences; and
  • records of notices, consent, complaints and rights requests.

2.3How we collect data

  • directly from you when you register, subscribe, upload content, complete a check-in or contact us;
  • automatically when you use the website or application;
  • from a workspace owner or administrator who invites or manages you;
  • from connected trading platforms and services when you authorise access;
  • from payment, authentication, analytics, support and infrastructure providers; and
  • from public or business sources where permitted, for example when a company asks for a Notofin Floor proposal.

2.5AI-assisted processing and automated decisions

Notofin may use AI-assisted systems to identify or describe patterns in trade, emotion, behaviour and execution data. These outputs support review and do not independently execute trades or make binding decisions for Notofin.

Notofin does not intend to make decisions about you based solely on automated processing that produce legal or similarly significant effects. Business customers must not use Notofin scores or AI outputs as the sole basis for employment, disciplinary, contracting, credit, insurance or comparable high-impact decisions. Human review and independent verification are required.

Depending on the feature, selected data may be sent to an AI service provider acting under contract. We limit the data to what is reasonably needed for the requested feature and apply contractual, access and security controls. The current subprocessor list should identify any external AI provider used in production.

2.6When we share personal data

We may share personal data with:

  • cloud hosting, database, storage, monitoring, security and content-delivery providers;
  • payment processors, invoicing and tax-service providers;
  • email, customer-support, authentication and communication providers;
  • analytics and cookie providers where you consent or another lawful basis applies;
  • AI and machine-learning service providers where needed for a feature you use;
  • trading platforms, brokers and integration providers at your direction;
  • workspace owners, administrators and authorised members according to permissions;
  • professional advisers, auditors, insurers, investors and transaction counterparties subject to confidentiality;
  • competent authorities, courts or other parties where required by law or necessary to protect rights, safety and security; and
  • a buyer, successor or relevant party in a merger, financing, restructuring or sale, subject to appropriate safeguards.

We do not sell personal data for money. We do not disclose identifiable trading or emotional data to data brokers or advertisers for their independent use.

2.7International transfers

Some providers or support personnel may process data outside the European Economic Area. Where required, we use a recognised transfer mechanism such as an adequacy decision, Standard Contractual Clauses, supplementary safeguards or another lawful basis. You may contact tech@notofin.com for information about the applicable mechanism, subject to confidentiality and security limitations.

2.8Retention

We retain personal data only for as long as reasonably necessary for the purposes described above, including contractual, legal, accounting, security and dispute requirements. Our intended operational periods are:

  • Account and active workspace data: for the life of the account or workspace.
  • Closed individual accounts: active-system deletion normally begins within 30 days, unless the user requests a shorter period that we can lawfully and technically honour.
  • Backups: residual copies may remain for up to 90 days after active deletion and are not ordinarily restored except for disaster recovery.
  • Connected-platform credentials and tokens: removed or disabled when the connection is disconnected or the account is closed, subject to short-lived logs and backups.
  • Support and complaint records: normally up to 3 years after closure of the request, longer where needed for a dispute.
  • Security, access and diagnostic logs: normally up to 12 months, longer where needed to investigate abuse or an incident.
  • Marketing data: until consent is withdrawn or, if there is no engagement, normally no longer than 24 months after the last meaningful interaction.
  • Billing, tax and transaction records: for the period required by applicable accounting, tax and legal rules.
  • Business-customer workspace data: according to the customer agreement and instructions; active deletion normally begins within 30 days after termination unless otherwise agreed or legally required.

We may retain de-identified or aggregated information that no longer reasonably identifies an individual.

2.9Security

We use reasonable technical and organisational measures appropriate to the nature of the Service and the risks involved. Measures may include access controls, authentication, least-privilege permissions, encryption in transit, logging, backups, vulnerability management, provider due diligence and incident procedures.

No online service is completely secure. You must use strong unique passwords, enable available security features, protect connected-account credentials and avoid uploading unnecessary secrets. If you believe your account or data has been compromised, contact tech@notofin.com immediately.

2.10Your rights

Subject to applicable law, you may have the right to:

  • obtain confirmation and access to your personal data;
  • correct inaccurate or incomplete data;
  • request deletion;
  • restrict processing;
  • object to processing based on legitimate interests, including direct marketing;
  • receive data you provided in a structured, commonly used and machine-readable format and request portability where applicable;
  • withdraw consent at any time;
  • not be subject to certain solely automated decisions with legal or similarly significant effects; and
  • complain to a supervisory authority.

To exercise a right, contact tech@notofin.com. We may verify your identity and ask for information needed to locate the relevant account. We generally respond within one month, subject to lawful extensions. Some rights are limited where data must be retained for legal obligations, security, freedom of expression or legal claims.

In Bulgaria, the supervisory authority is the Commission for Personal Data Protection, Sofia 1592, 2 Prof. Tsvetan Lazarov Blvd. Information is available at cpdp.bg. You may also complain to the authority in the EU/EEA country where you live or work or where an alleged infringement occurred.

2.11Marketing choices

You can unsubscribe from marketing emails through the link in the message or by contacting us. Service, security, billing and legal notices are not marketing and may still be sent while your account is active or where required.

2.12Cookies and similar technologies

We use cookies and similar technologies as described in the Cookie Policy. Strictly necessary technologies may operate without consent where permitted. Analytics, advertising or similar non-essential technologies are activated only after the required consent. You can change choices through Cookie Settings.

2.13Children

The Service is intended for adults aged 18 or over. We do not knowingly collect personal data from children. If you believe a child has created an account or provided personal data, contact tech@notofin.com so we can investigate and take appropriate action.

2.14Third-party links and services

The Service may link to or integrate with third-party services. Their processing is governed by their own privacy notices. Review those notices before authorising a connection or providing information.

2.15Changes to this Policy

We may update this Policy to reflect changes in the Service, providers, law or processing. We will post the new version and update the date. For material changes, we will provide additional notice through email, the Service or another suitable channel.

2.16Contact

Equity Logica Ltd. / Екуити Лоджика ООД
UIC 208636066
1680 Sofia, Bulgaria