Privacy Policy

Last updated: August 2026

1. Introduction

Botomic Limited ("Botomic," "we," "our," or "us") is a company registered in the United Kingdom. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our options trading automation software and related services (the "Service").

For the purposes of applicable data protection laws, including the UK GDPR and EU GDPR, Botomic Limited is the data controller responsible for your personal data.

2. About Our Service

Botomic is trading automation software. We are not a broker-dealer, investment advisor, or financial services provider.

Our software runs locally on your device and connects to your existing brokerage account through their official API. Your brokerage credentials are stored locally on your device and are never transmitted to or stored on our servers. We do not have access to your trades, positions, account balances, or trading strategies.

3. Information We Collect

Information You Provide

We collect information you voluntarily provide, including:

  • Account registration details (email address, username)
  • Communications you send to us (support requests, feedback)
  • Subscription and billing information

Automatically Collected Information

When you access our Service, we may automatically collect certain information, including:

  • Device information (browser type, operating system)
  • Log data (IP address, access times, pages viewed)
  • Usage patterns and feature interactions
  • Referral sources

Payment Information

Payment transactions are processed by our third-party payment processor. We do not directly collect or store your full payment card details. We receive limited information from our payment processor, such as subscription status and transaction dates.

Information We Do Not Collect

We want to be explicit about what we do not have access to:

  • Your brokerage login credentials
  • Your trades, positions, or account balances
  • Trading strategies you configure in the software

This information remains stored locally on your device and is never transmitted to our servers.

4. How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve our Service
  • Process transactions and manage your subscription
  • Communicate with you about service updates and support
  • Monitor and analyse usage to improve user experience
  • Detect and prevent fraud, abuse, or security issues
  • Comply with legal obligations

5. Legal Basis for Processing

Under applicable data protection laws, we process your personal data based on the following legal grounds:

  • Performance of a contract: To provide the Service you have requested
  • Legitimate interests: To improve our Service, ensure security, and prevent fraud
  • Consent: For optional analytics and marketing communications
  • Legal obligation: To comply with applicable laws and regulations

6. Sharing Your Information

We do not sell your personal data. We may share your information with third parties only in the following circumstances:

  • Service providers: Third parties who assist us in operating our Service (e.g., payment processing, email delivery, hosting, analytics)
  • Legal requirements: When required by law, court order, or governmental authority
  • Business transfers: In connection with a merger, acquisition, or sale of assets
  • Protection of rights: To protect our rights, property, or safety, or that of our users

7. International Data Transfers

Some of our service providers may be located outside the UK or European Economic Area. Where we transfer personal data internationally, we ensure appropriate safeguards are in place in accordance with applicable data protection laws.

8. Data Retention

We retain your personal data for as long as your account is active or as needed to provide you with our Service. If you close your account, we will delete or anonymise your personal data within a reasonable period, except where retention is required for legal, accounting, or fraud prevention purposes.

9. Your Rights

Depending on your location, you may have certain rights regarding your personal data, including:

  • Access to your personal data
  • Correction of inaccurate data
  • Deletion of your data
  • Restriction of processing
  • Data portability
  • Objection to processing
  • Withdrawal of consent

To exercise these rights, please contact us using the details below. We will respond to your request in accordance with applicable laws.

You also have the right to lodge a complaint with your local data protection authority.

10. Cookies and Tracking Technologies

We use cookies and similar technologies to operate our Service, remember your preferences, and analyse usage. These include:

  • Essential cookies: Required for the Service to function, including authentication and your saved consent choices
  • Abuse-prevention storage: With your consent, a random first-party browser marker helps us identify account pairs that may need human review
  • Analytics cookies: Help us understand how the Service is used (with your consent)
  • Marketing cookies: Used to deliver relevant advertising (with your consent)

You can manage your cookie preferences through the cookie consent banner or your browser settings. Declining abuse-prevention storage does not block signup, sign-in, billing or product use.

11. Abuse Review and Account Suspension

Each Botomic account may use one self-serve Pulse trial. That decision uses only the trial history of that account; information from another account cannot automatically refuse a trial.

To identify possible account abuse for a person to review, we may record short-lived, one-way hashed evidence:

  • A random first-party browser marker, only after you consent to abuse-prevention storage. The marker may remain in your browser for up to 365 days
  • A Desktop device identifier when you pair the Desktop application
  • Your IP address as supporting context

Browser and device matches can open a review for an administrator. An IP match alone cannot open a review. Detection does not automatically refuse signup, change trial eligibility, cancel a subscription or suspend product access. The evidence is never used for marketing, advertising or profiling. Our legal basis is our legitimate interest in preventing fraud and abuse of the Service.

Human decisions and appeals. An administrator may dismiss the flag or deliberately suspend one account's product access, with a recorded reason. Suspension does not delete the account, change the underlying trial or subscription, or prevent access to account and billing management. It does prevent product use and starting a new Checkout until an administrator restores access. Existing subscription charges do not stop automatically. Contact us using section 17 to appeal or request review.

Retention. Hashed browser-marker and Desktop-device observations are deleted after 90 days. Hashed IP observations are deleted after 30 days. Review actions retain the account identifiers, administrator identifier, action and reason needed for audit, but not the evidence value or an email snapshot. Evidence attached to a deleted account is removed with that account.

12. Pulse Data Allowance Records

Pulse includes a rolling allowance on how much per-instrument detail an account can request. Enforcing and evidencing that allowance uses a separate record, held by our Pulse API and kept apart from the anti-abuse records in section 11.

Each row contains only:

  • a one-way hashed account identifier;
  • the instrument symbol;
  • the time the detail was released; and
  • which published data snapshot it came from.

These rows are used solely to apply and evidence the allowance. They are retained for 90 days and are never joined to the anti-abuse records in section 11, never used for marketing or profiling, and never sold.

Erasure. Where we approve an erasure request, we delete every allowance row for that account. We do not claim a fraud-prevention retention exception for these rows. Deleting them may reset the rolling allowance, which we accept. When an account is deleted by an administrator, these rows are deleted first; if that deletion cannot be completed, the account is left in place and the request is retried.

13. Do Not Track

Some browsers include a "Do Not Track" (DNT) feature. We currently do not respond to DNT signals, as there is no industry standard for handling them.

14. Security

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. However, no method of transmission over the Internet or electronic storage is completely secure, and we cannot guarantee absolute security.

15. Children's Privacy

Our Service is not intended for individuals under 18 years of age. We do not knowingly collect personal data from children. If you believe we have collected information from a child, please contact us immediately.

16. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the updated policy on this page and updating the effective date. Your continued use of the Service after changes are posted constitutes your acceptance of the updated policy.

17. Contact Us

If you have any questions about this Privacy Policy or wish to exercise your data protection rights, please contact us at:

Email: support@botomic.trade

Data Controller: Botomic Limited
Company Number: 16942423
128 City Road, London, EC1V 2NX, United Kingdom

Botomic is trading automation software designed to assist traders in executing their own user-defined rules. We do not provide trade signals, strategies, or investment advice, and we do not make trading decisions on your behalf. Trading options involves substantial risk and may not be suitable for every investor. There is a possibility of losing all or more than the initial investment. Past performance does not guarantee future results.