Legal

Privacy Policy

Last updated: 16 July 2026

Hesgram Ltd (“Hesgram”, “we”, “us”, “our”) operates the website at hesgram.com and the associated mobile and desktop applications. This policy explains what personal data we collect, why we collect it, how we use it, and your rights under UK GDPR and the Data Protection Act 2018.

Our registered office is in England & Wales. We are the data controller for all personal data processed under this policy. If you have any questions, email us at privacy@hesgram.com.

1. What data we collect

Account data. When you register, we collect your email address, chosen username, and hashed password. We never store your password in plain text.

Broker credentials. To connect to your MT5 broker account, we store a MetaApi account token. This token is encrypted at rest using AES-256 and never logged or exposed in API responses.

Trading data. We store the trades executed by the bot on your behalf (symbol, direction, open/close price, lot size, timestamps, PnL). This data is used to power your trade journal and to retrain the machine learning model.

Billing data. Payments are processed by Stripe. We store only your Stripe customer ID and subscription status. We do not store card numbers, sort codes, or bank details — these remain with Stripe under their own PCI-DSS compliance.

Usage data. We collect server logs (IP address, browser user-agent, pages visited, timestamps) to maintain security and diagnose errors. Logs are retained for 30 days.

Communications. If you contact support, we retain the conversation to help resolve your issue.

3. How we use your data

  • Provide and maintain the Hesgram service and your trading dashboard.
  • Execute and log automated trades on your connected MT5 account.
  • Send transactional emails (trade alerts, subscription receipts, account security notices).
  • Retrain the ML model using anonymised, aggregated trade outcomes — never individual identifiable data.
  • Respond to customer support requests.
  • Detect and prevent fraud, abuse, and unauthorised access.
  • Comply with legal and regulatory obligations.

4. Third parties we share data with

We share data only where necessary to deliver the service:

  • MetaApi (Cloud Forex API Ltd) — receives your broker account token to place and manage MT5 trades on your behalf. Governed by their own privacy policy.
  • Stripe Inc. — payment processing. We share your email to create a billing customer. Stripe is PCI-DSS Level 1 certified.
  • DigitalOcean LLC — cloud hosting provider. Your data is stored on servers in the EU (Amsterdam) region.
  • Vercel Inc. — hosts the web frontend. Edge logs may contain your IP and request metadata.

We do not sell, rent, or share your personal data with advertisers or data brokers.

5. Data retention

We keep your data for as long as your account is active. If you close your account:

  • Account data is deleted within 30 days of your request.
  • Trade history is anonymised and retained in aggregate form for ML training (no link back to you).
  • Billing records are retained for 7 years to comply with UK tax law.
  • Server logs are retained for 30 days.

6. Your rights

Under UK GDPR you have the right to:

  • Access — request a copy of all personal data we hold about you.
  • Rectification — ask us to correct inaccurate data.
  • Erasure — ask us to delete your personal data (subject to legal retention obligations).
  • Portability — receive your data in a machine-readable format.
  • Restriction — ask us to pause processing while a dispute is resolved.
  • Objection — object to processing based on legitimate interests.
  • Withdraw consent — for any processing based on consent, at any time.

To exercise any right, email privacy@hesgram.com. We will respond within 30 days. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO).

7. Security

We implement technical and organisational measures to protect your data including:

  • All data in transit encrypted with TLS 1.2+.
  • Broker tokens encrypted at rest with AES-256.
  • Passwords hashed with bcrypt (cost factor 12).
  • Database access restricted to internal services only — no public exposure.
  • Automated security scanning via GitHub Actions on every deployment.

No system is 100% secure. If you believe your account has been compromised, contact us immediately at security@hesgram.com.

8. Cookies

We use a small number of essential cookies to keep you logged in and protect against CSRF. We do not use advertising or tracking cookies. See our full Cookie Policy for details.

9. Children

Hesgram is not intended for anyone under the age of 18. We do not knowingly collect data from minors. If you believe a minor has registered, contact us and we will delete the account.

10. Changes to this policy

We may update this policy from time to time. We will notify registered users by email at least 14 days before any material change takes effect. The latest version is always available at hesgram.com/privacy.

11. Contact

Hesgram Ltd
England & Wales
Email: privacy@hesgram.com