Privacy Policy

This notice is provided pursuant to Article 13 of Regulation (EU) 2016/679 (the "GDPR") and applicable Italian implementing rules. It describes, in a transparent manner, how Valuera processes personal data of visitors, prospective clients, clients, partners and other counterparties who interact with the websites and services operated under the domain valuera.cloud and the related authenticated applications.

August 2026

Identity of the controller and contact details

The data controller is Davide Pio Simeone, owner of valuera.cloud. Tax ID: SMNDDP02E26F027T. Registered office: Via Umberto Giordano 14, 74027 San Giorgio Ionico (TA), Italy.

Invoicing documents use the same tax ID. Companies Register / REA particulars, if any, may be added in later updates of this notice.

For any request concerning personal data protection, the exercise of data-subject rights, or clarifications on this notice, you may contact the controller at davide.simeone@valuera.cloud. At present no dedicated certified email address (PEC) is indicated: formal communications may nevertheless be sent to the email address above, using methods that allow their origin and content to be identified.

Data Protection Officer (DPO)

As of the update date of this notice, no Data Protection Officer has been appointed because — based on the controller's assessment — the mandatory appointment triggers under Article 37 GDPR do not apply (large-scale processing of special categories of data, large-scale regular and systematic monitoring, or public authority/body status within the meaning of the law).

This assessment is reviewed periodically. If the evolution of the services, volumes or processing types makes the appointment of a DPO mandatory or appropriate, this notice will be updated and the relevant contact details will be published clearly.

Categories of personal data processed

Depending on the nature of the relationship (simple website visit, contact request, registration, subscription to signal providers, configuration of trading accounts, or operational use of the platform), the following categories of data may be processed, by way of example and without limitation.

Purposes of processing and legal bases

Personal data are processed for specified, explicit and legitimate purposes and only to the extent necessary. In particular, processing is aimed at: handling pre-contractual and contact requests; concluding and performing the Valuera software/SaaS supply contract; delivering signal ingestion, evaluation, routing and technical execution services toward MetaTrader environments; ensuring security, fraud prevention and operational continuity; complying with legal obligations (tax, accounting, retention); improving product reliability on the basis of technical and traffic metrics; and, where required, sending service-related communications.

The legal bases typically relied upon are: Article 6(1)(b) GDPR (performance of a contract to which the data subject is party, or of pre-contractual measures); Article 6(1)(c) (compliance with legal obligations); Article 6(1)(f) (legitimate interests of the controller in platform security, abuse prevention and service continuity, balanced against the rights and freedoms of data subjects); and Article 6(1)(a) (consent), only where the law so requires — for example for certain non-essential tracking tools or promotional communications, if and when activated.

Where consent is collected, it is free, specific, informed and withdrawable at any time, without affecting the lawfulness of processing based on consent before its withdrawal.

Nature of provision and consequences of refusal

Providing the data marked as necessary in registration, onboarding or service-configuration forms is indispensable in order to assess the request, activate the account and correctly perform contractual obligations.

Failure to provide such data, or a later withdrawal of the possibility to process them where no other legal basis applies, may make it impossible to conclude the contract, deliver the service or provide full support. Providing optional data does not, in itself, prevent access to essential features, subject to any technical limitations arising from their absence.

Processing methods and security measures

Processing is carried out mainly by electronic means and organisational procedures proportionate to the risk, taking into account the state of the art, implementation costs and the nature of the data (including, where present, authentication secrets toward brokers and trading environments).

Measures include, by way of example: access control according to least privilege; segregation of environments and roles; encryption of transport channels (TLS); encryption at rest for certain categories of secrets; traceability of privileged actions; backup and incident-management procedures. No security measure can reduce residual risk to zero.

Specific processing connected with the execution platform

Valuera provides software infrastructure for ingesting and routing signals toward automated trading environments. In that context, data may be processed which — although primarily technical and contractual in nature — are particularly sensitive from an operational-confidentiality standpoint (terminal credentials, risk parameters, signal contents).

Where language models or third-party text-processing services are used for classification, parsing assistance or the optional support chat, strictly necessary contents (the question, the reply, and a tenant snapshot without credentials) may be transmitted to such providers — currently OpenAI, LLC in the United States — acting as processors, with the safeguards required by Chapter V GDPR. Support-chat transcripts are retained for 90 days and then deleted. Optional short memory facts stored on the account can be cleared by the user in the chat. Data subjects may request up-to-date information on the providers actually used by contacting davide.simeone@valuera.cloud.

Automated processing relating to routing, policy gates and execution queues is technical and instrumental to service delivery; it is not aimed at solely automated decisions producing legal or similarly significant effects on the individual under Article 22 GDPR in the sense of commercial profiling.

Cookies, local storage and similar technologies

The website and applications may use technical cookies, session mechanisms and local storage tools strictly connected with service operation and — within the limits described in the Cookie Policy — first-party traffic measurement on public pages.

For details of the technologies used, related purposes and preference-management options, please refer to the Cookie Policy, which forms an integral part of the information framework provided to data subjects.

Recipients and processing roles

Personal data may be accessed by authorised persons acting under the controller's authority, instructed as to confidentiality and limited to what is necessary for their tasks.

Data may also be disclosed to third-party providers that process data on behalf of the controller as processors under Article 28 GDPR, on the basis of agreements imposing security, confidentiality and binding instructions. Such categories include, in particular: hosting and cloud/VPS infrastructure providers, including Hetzner, Hostinger; providers of communication, support and ticketing services where used; accounting, tax and legal advisers within the scope of their professional remit; and providers of processing components (including, where used, language-model services) strictly necessary to deliver or improve the service.

Where you choose to sign in with Google, Google LLC acts as login provider. We receive your Google account identifier (sub), email address and name; Google sees that you are signing in to this service, including your IP address on the redirect.

Data are not subject to indiscriminate dissemination. Disclosures to public authorities will occur only where required by law or by binding orders.

Transfers of data to third countries

Primary hosting infrastructure is selected with attention to location in the European Economic Area or to EU-oriented offerings of Hetzner, Hostinger. The controller undertakes, where reasonably practicable, to favour solutions that reduce the need for transfers outside the EEA.

If a transfer to a third country becomes necessary (for example because a technological sub-process is not available on equivalent terms in the EEA), it will take place only with an appropriate safeguard under Chapter V GDPR — such as an adequacy decision of the European Commission, Standard Contractual Clauses, or another lawful instrument — together with supplementary measures where required.

Retention periods

Personal data are retained for no longer than is necessary for the purposes for which they are collected and processed, without prejudice to mandatory retention periods under law (in particular civil, tax and accounting rules).

In general: account and contractual data are processed for the duration of the relationship and for the subsequent period needed to handle disputes, residual obligations and legal duties; security and audit logs are retained according to proportionality and, for certain platform audit traces, also over multi-year horizons consistent with accountability needs (for example up to 730 days where so configured in the systems); credentials and operational links to trading environments are deactivated and removed according to offboarding procedures, without prejudice to what is necessary for security and to evidence contract performance; contact data collected via forms are retained for the time useful to handle the request and reasonable follow-ups.

After the applicable periods expire, data are deleted or irreversibly anonymised, except where further retention is required by law.

Automated decision-making and profiling

The controller does not carry out decision-making based solely on automated processing that produces legal effects concerning the data subject or similarly significantly affects them under Article 22 GDPR.

Automation present in the platform concerns the technical logic of parsing, application of risk/routing rules and dispatch toward execution environments configured by the user. Such automation does not constitute commercial profiling of the individual, nor credit scoring or equivalent.

Data-subject rights

Within the limits and under the conditions set by the GDPR, the data subject may exercise the following rights.

How to exercise rights and lodge a complaint

Requests to exercise rights may be sent to davide.simeone@valuera.cloud, accompanied by information sufficient to verify the requester's identity and to identify the scope of the request. The controller will respond within the statutory time limits and will inform the data subject of any motivated extension where needed.

Without prejudice to any other administrative or judicial remedy, a data subject who considers that processing concerning them infringes applicable law has the right to lodge a complaint with the Italian Supervisory Authority (Garante per la protezione dei dati personali — www.garanteprivacy.it) or with the supervisory authority of the Member State of habitual residence, place of work, or place of the alleged infringement.

Updates to this notice

The controller may update this Privacy Policy to reflect legal changes, technical evolution of the services, organisational or supplier changes, or guidance from competent authorities.

Material changes will be published on this page with an updated date and, where required by law or by fairness in the relationship, communicated to data subjects through appropriate channels (for example an in-product notice or a message to the contact account).

Loading