利用規約
verdiktum.com / legal / prywatnosc

Verdiktum — Privacy Policy

§

拘束力を持つのはポーランド語版です。本翻訳は情報提供のみを目的としています。

Version: 2026-07 · Effective: 22 July 2026

The Polish version of this document is the binding one. This translation is provided for information.

1. Controller

Data contact: contact@verdiktum.com

This policy fulfils the information duty under Articles 13–14 of Regulation (EU) 2016/679 (GDPR).


2. Minimisation by design

Verdiktum is built to process as little personal data as possible. There are no passwords, no names, no addresses, no financial data and no questions about investment experience. We never ask about your capital — asking would amount to personalising the service, which we deliberately do not do.

The public commitment ledger contains no personal data whatsoever — only numbers, cryptographic digests, timestamps, signal contents and outcomes.

Statistics of monitored sources are published only in anonymised form — under a stable, irreversible identifier, without the channel's name or @handle (see section 3.6).


3. Data we process

Account: e-mail address; interface language, theme and notification preferences; date and version of the accepted Terms and of the age confirmation.

Telegram link: the numeric Telegram account id and, optionally, the public @handle.

Payments: the customer identifier at the payment provider, payment method brand and last 4 digits of the card, billing period dates, invoice numbers. We never store full card data.

Technical data: IP address and browser user-agent recorded when a session is created and in the security log; the signal delivery log (signal number, channel, status) as proof of performance; API and webhook call logs for the Operator plan.

What we do not process: no marketing profiling, no tracking tools, no behavioural profiles, and no transfers to data brokers or advertising networks.

Monitored sources (signal channels). As part of the analytical layer we process data of publicly available signal channels: the channel identifier and name (@handle, title), message content and publication time, and the fact of their edit or deletion — solely as statistical material to assess source quality.

  • We publish only anonymised data, under a stable, irreversible identifier (src_…). A channel's name, @handle or title is never shown to users of the Service; the link between a statistic and a specific channel is available only to the administrator and never leaves our infrastructure.
  • Where a channel is run by a natural person, this data may be their personal data. We process it on the basis of legitimate interest (Art. 6(1)(f) GDPR) — conducting independent market analysis and verifying the quality of public sources — applying anonymisation before publication and data minimisation.
  • The data is obtained not from the data subject (Art. 14 GDPR). Given the public nature of the channels and the scale of monitoring, informing each operator directly would involve disproportionate effort (Art. 14(5)(b) GDPR); we meet the information duty by making this notice available in the Service.
  • A monitored channel's operator has the right to object to this processing (Art. 21 GDPR) and the other rights in section 8. Requests to contact@verdiktum.com are handled without undue delay; upholding an objection means removing the source from monitoring.

4. Purposes and legal bases

PurposeLegal basis (GDPR)
Running the account and providing the serviceArt. 6(1)(b) — contract
Monitoring and analysing the quality of public sources (anonymised before publication)Art. 6(1)(f) — legitimate interest
Delivering signals over TelegramArt. 6(1)(b) — contract
Payments and subscriptionsArt. 6(1)(b) — contract
Issuing and retaining invoicesArt. 6(1)(c) — legal obligation
Age verificationArt. 6(1)(c) and (f)
Security, rate limits, logsArt. 6(1)(f) — legitimate interest
Complaints and requestsArt. 6(1)(c) and (f)
Establishing or defending claimsArt. 6(1)(f)

5. Recipients

Data may be entrusted only to providers acting on our instructions: the payment provider, the transactional e-mail provider, Telegram Messenger (account identifier only) and the hosting provider. Current list: Sub-processors.

Market data providers are not processors — they receive only requests for public quotes, with no link to any user.


6. Transfers outside the EEA

Where a provider processes data outside the EEA, the transfer relies on an adequacy decision (e.g. the EU–US Data Privacy Framework) or on Standard Contractual Clauses with supplementary measures. A copy of the safeguards is available on request.


7. Retention

  • Account data — until the account is deleted; deletion is immediate, backups roll off within 30 days.
  • Invoices and billing data — 5 years from the end of the tax year (statutory).
  • Consent records (Terms, age, request for immediate performance) — for the limitation period.
  • Technical and security logs — up to 12 months.
  • Sessions — 30 days from last use; expired rows deleted automatically.

8. Your rights

You have the right of access (Art. 15) — an immediate JSON export is available in the panel; rectification (Art. 16); erasure (Art. 17) — one click in the panel; restriction (Art. 18); portability (Art. 20); objection (Art. 21); withdrawal of consent at any time; and to lodge a complaint with the Polish supervisory authority (PUODO, ul. Stawki 2, 00-193 Warsaw, uodo.gov.pl).

Requests are handled without undue delay and within one month at the latest.


9. Profiling and automated decisions

We make no automated decisions producing legal or similarly significant effects (Art. 22 GDPR).

Automated processing concerns market data and source messages, never user behaviour. Every subscriber on a plan receives identical content — the absence of personalisation is both a legal requirement here and a product characteristic.


10. Voluntariness

An e-mail address is required to create an account and receive signals. The public track record verifier works without an account and without providing any data at all.


11. Security

Encrypted connections; password-free sign-in via short-lived single-use links; only digests of session tokens and API keys are stored; access control; rate limiting; an audit log; and backups in several locations.

In the event of a personal data breach posing a risk to individuals, we will notify the supervisory authority within 72 hours and, where required, the individuals concerned.


12. Changes

Material changes are announced in the Service and by e-mail. The date at the top reflects the last update.


Verdiktum · contact@verdiktum.com