Draft status and scope
This is an implementation draft for legal review. It describes verified current application behavior and clearly separates planned future processing. It does not claim jurisdiction-specific certification or approval.
Information currently handled
Registration details such as name and email address.
Password hashes, email-verification state, password-reset data, TOTP configuration, encrypted recovery-code material, sessions, and device information.
Security and audit events used to protect accounts and investigate misuse.
Contact-form name, email, subject, message, consent acknowledgement, technical request information, and correlation identifier.
Necessary cookies and session identifiers required for authentication, security, CSRF protection, and application continuity.
Why information is used
Create and protect accounts.
Authenticate users and support password recovery, verification, MFA, and session controls.
Detect abuse, enforce rate limits, preserve audit evidence, and maintain platform security.
Receive and route Contact-page enquiries and privacy requests.
Operate, diagnose, and improve the current technical service.
Contact-message handling
The Contact page queues a dedicated mail message to a destination selected from server configuration. It does not create a permanent contact-message business record. Queue infrastructure and the configured mail transport may temporarily retain the submitted fields for dispatch. Local development may use a non-delivering log or test mailer. External provider delivery is not confirmed by the public success message.
Available choices and controls
Users can update available profile information, review security and device controls, revoke sessions where provided, use MFA controls, and submit privacy questions or requests through Contact. Requests remain subject to identity verification, technical capability, approved policy, and applicable law.
Planned future processing
Future subscriptions, payments, course progress, signals, live sessions, community, notifications, mobile features, and MT5 licensing may require additional information and providers. Those activities are not described as active and require updated notices and approvals before release.
Retention and security
GFK applies application security controls appropriate to the current implementation, but no online service can promise absolute security. Specific legal retention periods, subprocessors, international-transfer mechanisms, and production provider terms require approval and are not invented in this draft.
Policy updates and contact
This draft may change as functionality and legal review progress. Use the Contact page for privacy questions; no unapproved physical privacy address or data-protection officer is represented.