Draft - not yet in force
EightLot is in development. This document is published for transparency while the operating company and its contact details are being finalised. Highlighted fields are still to be completed, and the text may change before the service is generally available.
Data Processing Addendum
Last updated 2026-08-08 · Version 1.0-draft
This addendum governs the personal data about YOUR clients that EightLot processes on your behalf. You are the controller of that data; we are your processor and only act on your instructions. It forms part of the Terms of Service and applies automatically - there is nothing separate to sign.
1. Scope and roles
This Data Processing Addendum ("DPA") is entered into between LEGAL ENTITY NAME ("Processor", "we") and the customer accepting the Terms of Service ("Controller", "you"). It forms part of those Terms and applies whenever we process personal data on your behalf.
The split of roles is:
- You are the controller of the personal data about your clients and prospective clients that reaches the platform - the traders in your introducing-broker book, and anyone who messages your Telegram bot. You decided to collect it, you decide what it is used for, and you have the relationship with those people.
- We are the processor of that data, and only process it to deliver the service to you.
- We are the controller of the data about you as our customer - your account, your login security records, your billing details if any. That is governed by our Privacy Policy, not by this DPA.
We do not use Client Personal Data for our own purposes. We do not sell it, do not use it for advertising, do not use it to train machine-learning models, and do not combine one customer's data with another's.
2. Definitions
- Data Protection Lawmeans every law on the protection of personal data applicable to the processing, including the EU General Data Protection Regulation (2016/679) ("GDPR"), the UK GDPR and Data Protection Act 2018, the California Consumer Privacy Act as amended, and any equivalent law in a country where a data subject is located.
- Client Personal Data means personal data relating to your clients, prospective clients and sub-IBs that we process on your behalf through the platform.
- Controller, Processor, Subprocessor, Data Subject, Personal Data Breach and Processing have the meanings given in the GDPR, or the nearest equivalent under other applicable law.
- Standard Contractual Clauses or SCCs means the clauses approved by the European Commission in Implementing Decision (EU) 2021/914, and the UK Addendum issued under section 119A of the Data Protection Act 2018 where UK data is involved.
3. Processing instructions
We process Client Personal Data only on your documented instructions, including for transfers to a third country, unless required to do otherwise by law - in which case we will tell you first, unless that law prohibits it on important grounds of public interest.
Your documented instructions consist of the Terms of Service, this DPA, and the configuration you set in the application: which broker account to connect, which clients to track, which Telegram bot and channels to use, what reminders to send and to whom, what notes to keep, and which API keys to issue. Using a feature is an instruction to perform the processing that feature performs.
We will tell you if, in our opinion, an instruction infringes Data Protection Law. We may refuse to carry out an instruction that would put us in breach.
4. Your obligations as controller
You warrant and undertake that:
- you have a valid legal basis under Data Protection Law for every act of processing you instruct, in every country where your clients are located;
- you have given your clients the information they are entitled to, including the fact that a third-party service provider processes their data on your behalf, and how to exercise their rights;
- where consent is the basis - in particular for Telegram messaging and any electronic marketing - you have obtained it and can evidence it, and you honour withdrawals promptly;
- you are entitled to disclose the Client Personal Data to us and to authorise us to process it as described;
- you will not instruct us to process special-category data (Article 9 GDPR) or criminal-offence data, and will not enter any into free-text fields such as CRM notes - the platform is not designed for it; and
- you are responsible for the accuracy and lawfulness of the data you bring in, including data pulled from your broker portal at your instruction.
5. Confidentiality
We ensure that every person authorised to process Client Personal Data is bound by an appropriate duty of confidentiality, is trained in their obligations, and has access strictly on a need-to-know basis. Administrative access to a customer's account requires an explicitly granted permission and is logged.
6. Security measures
We implement and maintain appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking account of the state of the art, the cost of implementation, and the nature, scope, context and purposes of processing. Those measures are described in Annex II. We may update them provided the level of security is not reduced.
7. Subprocessors
You give us general authorisation to engage subprocessors. Those engaged as at the date of this DPA are listed in Annex III.
- We will give at least 30 days' notice - in the application or by email - before adding or replacing a subprocessor.
- If you reasonably object on data protection grounds within that period, tell us and we will work with you in good faith to find an alternative. If we cannot, you may terminate the affected part of the service without penalty. Because the service is provided free of charge, no refund arises.
- We impose data protection obligations on each subprocessor that are no less protective than those in this DPA, and we remain fully liable to you for their performance.
8. Data subject requests
Taking account of the nature of the processing, we assist you by appropriate technical and organisational measures - insofar as possible - in fulfilling your obligation to respond to requests to exercise data subject rights. In practice the platform lets you access, correct, export and delete client records yourself.
If a data subject contacts us directly about data we process on your behalf, we will not respond substantively. We will tell them to contact you and forward the request to you without undue delay.
9. Personal data breaches
We will notify you without undue delay, and in any event within 48 hours, after becoming aware of a Personal Data Breach affecting Client Personal Data. The notification will describe, so far as we know it: the nature of the breach and the categories and approximate number of data subjects and records concerned; the likely consequences; the measures we have taken or propose to take; and a contact point for more information. Where we cannot provide all of it at once, we will provide it in phases without further undue delay.
Notifying you is not an acknowledgement of fault. Deciding whether to notify a supervisory authority or the affected data subjects is your responsibility as controller; we will provide reasonable assistance.
10. Assessments and consultation
Taking into account the nature of processing and the information available to us, we will provide reasonable assistance with your data protection impact assessments and any prior consultation with a supervisory authority, in relation to the processing carried out through the platform.
11. Return and deletion
You may export or delete Client Personal Data at any time through the application. On termination of the service, and at your choice, we will delete or return all Client Personal Data and delete existing copies, unless law requires us to keep it.
Deleting your account disables it immediately and triggers permanent erasure of all associated records after 30 days. Backups are overwritten on their ordinary cycle; data in a backup remains subject to this DPA until it is overwritten. If you need erasure sooner than the standard window, contact us.
12. Audits
We will make available to you the information necessary to demonstrate compliance with Article 28 GDPR, and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate.
In practice: send your questions to PRIVACY EMAILand we will answer in writing. An on-site or hands-on audit may be requested no more than once a year (unless required by a supervisory authority or following a breach), on at least 30 days' notice, during business hours, without unreasonably disrupting our operations, subject to confidentiality, and must not involve access to another customer's data or to anything that would compromise platform security. You bear the cost of any such audit.
13. International transfers
Client Personal Data is stored in the European Economic Area. Where a transfer to a country outside the EEA or the UK takes place and that country is not covered by an adequacy decision, the transfer is made under the Standard Contractual Clauses, which are hereby incorporated into this DPA as follows:
- Module Two (controller to processor) applies to transfers from you to us;
- Module Three (processor to processor) applies to onward transfers to our subprocessors;
- you are the data exporter and we are the data importer, and the optional docking clause applies;
- in Clause 9, Option 2 (general written authorisation) applies with the 30-day notice period in section 7;
- in Clause 17, the governing law is that of GOVERNING LAW COUNTRY where it is an EU member state, and otherwise the law of Ireland; in Clause 18 the forum is the courts of that same jurisdiction;
- Annexes I, II and III of this DPA serve as Annexes I, II and III of the SCCs; and
- for UK data, the UK International Data Transfer Addendum applies to the SCCs, with the tables completed using the information in this DPA.
14. Liability and term
This DPA takes effect when you accept the Terms of Service and continues for as long as we process Client Personal Data on your behalf. The limitations and exclusions of liability in the Terms of Service apply to this DPA, except where Data Protection Law does not permit them. Where this DPA conflicts with the Terms of Service on the processing of Client Personal Data, this DPA prevails; where it conflicts with the SCCs, the SCCs prevail.
Annex I - Details of processing
A. Parties
Data exporter / controller: the customer accepting the Terms of Service, whose identity and contact details are those held on their EightLot account. Activities: operating an introducing-broker business.
Data importer / processor: LEGAL ENTITY NAME, REGISTERED ADDRESS. Contact: PRIVACY EMAIL. Activities: providing the EightLot rebate dashboard, CRM and Telegram automation.
B. Categories of data subjects
- The customer's clients and prospective clients (traders).
- The customer's sub-IBs and their clients.
- People who message the customer's Telegram bot.
- The customer's own staff who use the account.
C. Categories of personal data
| Category | Fields |
|---|---|
| Identity | Name as registered with the broker; any custom display name set by the customer. |
| Contact | Email address registered with the broker; Telegram username and chat identifier. |
| Account identifiers | Broker user id, trading account numbers, platform, account type, introducing agent account, approval date. |
| Financial and behavioural | Account balance, deposits and withdrawals, traded volume, rebate generated, activity dates, derived pipeline stage. |
| Customer-generated | Follow-up status, free-text notes, assignment, reminder history and settings. |
| Communications | Content of messages exchanged between the customer's Telegram bot and the data subject, and records of failed account-link attempts. |
Special categories: none. The customer is contractually prohibited from submitting them (section 4).
D. Frequency and nature of the processing
Continuous. Broker data is retrieved on a recurring automated schedule and on demand. Processing operations comprise collection from the broker portal at the customer's instruction, storage, structuring and aggregation, display to the customer, transmission via Telegram at the customer's instruction, and erasure.
E. Purpose
Providing the EightLot platform: rebate and performance reporting, sub-IB network reporting, client relationship management, and automated client onboarding and re-engagement over Telegram.
F. Duration
For the duration of the Terms of Service, plus the erasure period in section 11.
G. Competent supervisory authority
Determined by the data exporter's place of establishment, or where it is not established in the EEA, by the member state where its representative is established or its data subjects are located.
Annex II - Technical and organisational measures
| Area | Measures |
|---|---|
| Encryption in transit | TLS on all connections, HTTP Strict Transport Security enforced, secure cookie flags. |
| Encryption at rest | Database encryption at rest at the hosting provider. Third-party credentials supplied by the customer (broker portal password, portal session state, Telegram bot token) are additionally encrypted with AES-256-GCM under a key held outside the database and are never returned to any browser. |
| Hashing | Account passwords stored as bcrypt hashes; API keys as SHA-256 digests with only a non-secret prefix retained; one-time verification codes stored hashed. |
| Access control and tenancy | Every query is scoped to the owning account, enforced server-side. Administrative access to another account requires a specific granted permission, is limited in scope, and is logged. Role and permission changes are restricted to super-admin accounts. |
| Authentication | Short-lived access tokens with rotating refresh sessions, server-side session revocation, progressive login lockouts, CSRF protection, and device and IP checks for ban evasion. |
| Application hardening | Rate limiting on every endpoint, strict content security policy, input validation, parameterised SQL throughout, and generic client-facing error messages that do not disclose internal structure. |
| Logging and monitoring | Security event logging retained for 90 days, automated alerting on integration failures and suspicious activity. |
| Resilience and recovery | Managed database with provider-operated backups; application state reconstructable from the broker source of record. |
| Data minimisation and deletion | Only fields needed for the reporting and CRM features are stored. Customer-initiated deletion cascades to all owned records and completes within 30 days. |
| Personnel | Access limited to those who need it, under confidentiality obligations. |
| Subprocessor governance | Written terms with each subprocessor no less protective than this DPA; list maintained in Annex III. |
Annex III - Subprocessors
The following subprocessors are authorised as at 2026-08-08:
| Subprocessor | Purpose | Processing location |
|---|---|---|
| Supabase | Managed PostgreSQL database hosting - stores all Client Personal Data | European Union (Sweden) |
| Hetzner Online GmbH | Application server hosting | Germany |
| Cloudflare, Inc. | DNS for the eightlot.io domain | Global network |
| Telegram Messenger | Delivery of messages sent by the customer's own bot | International |
| Resend | Transactional email delivery (configured; not currently enabled) | International |
IP geolocation providers (ipapi.co, ipinfo.io, ip-api.com) receive IP addresses for security checks on the customer's own logins. They receive no Client Personal Data and are therefore not subprocessors under this DPA; they are disclosed in the Privacy Policy.
The customer's broker is not our subprocessor. It is an independent controller with which the customer has its own relationship; we access its portal as the customer's agent, on the customer's instruction.
Related documents