Privacy Policy

Last updated: March 29, 2026

1. Data controller

Nomox ("we", "the platform") is responsible for the processing of personal data you provide through this website and the associated application.

2. Data we collect

  • Registration data: name, email address, and password (encrypted).
  • Configuration data: bot preferences (risk level, time horizon, paper/live mode).
  • Third-party API keys: API Key and API Secret from your trading account, stored encrypted (AES-256). We never store your keys in plain text.
  • Usage data: bot activity logs, executed trades, performance metrics, and session history.
  • Technical data: IP address, browser type, operating system, and strictly necessary cookie data.

3. Purpose of processing

  • Manage your account and provide you access to the platform.
  • Execute trading orders on your behalf via connected broker APIs.
  • Generate performance statistics and metrics for your dashboard.
  • Send you transactional notifications (account approval, bot alerts) from info@nomox.xyz.
  • Improve the platform and ensure its security.

4. Legal basis

Processing is based on the execution of the contract (Terms and Conditions you accept upon registration), your explicit consent where necessary, and our legitimate interest in the security and improvement of the platform.

5. Data sharing

We do not sell or transfer your personal data to third parties for commercial purposes. We share data only with:

  • Infrastructure providers: Vercel (hosting), Supabase (database and authentication), Resend (email sending).
  • Brokers: API keys are used exclusively to execute orders in your trading account. We do not share these keys with any other service.

6. Security

We implement technical and organizational measures to protect your data, including encryption of API keys at rest (AES-256), two-factor authentication (TOTP), TLS/HTTPS connections, and restricted access to infrastructure.

7. Data retention

We retain your data as long as your account remains active. Upon requesting account deletion, we will delete your personal data within a reasonable period, except for data we must retain for legal obligations.

8. Your rights

You may exercise your rights of access, rectification, erasure, restriction, portability, and objection to the processing of your personal data by writing to info@nomox.xyz.

9. Cookies

We use only strictly necessary technical cookies for authentication and session functionality. We do not use advertising or third-party tracking cookies.

10. Modifications

We reserve the right to update this policy. We will notify you of significant changes by email or through a notice on the platform.

Contact

For any privacy-related inquiries: info@nomox.xyz