Draft - not yet in force
EightLot is in development. This document is published for transparency while the operating company and its contact details are being finalised. Highlighted fields are still to be completed, and the text may change before the service is generally available.
Privacy Policy
Last updated 2026-08-08 · Version 1.0-draft
EightLot is a dashboard for Introducing Brokers. This policy explains what personal data we hold about you, why we hold it, who else can see it, and how you get it back or get it deleted. We do not sell personal data, we do not run advertising or analytics trackers, and the only cookies we set are the ones that keep you logged in.
1. Who we are
EightLot is operated by LEGAL ENTITY NAME, registered in COUNTRY OF INCORPORATION under company number COMPANY REGISTRATION NUMBER, with its registered address at REGISTERED ADDRESS("we", "us", "EightLot").
For the personal data described in this policy we act as the controller, except for the data our customers load into the platform about their own clients - there we act as a processor on that customer's instructions. See the Data Processing Addendum.
Privacy questions and data requests: PRIVACY EMAIL.
2. Who this policy covers
Four groups of people appear in our systems:
- Account holders (IBs). Introducing Brokers who sign up and use the dashboard. We are the controller of their data.
- Applicants. People who submit the access application form but do not (yet) have an account. We are the controller of their data.
- Our customers' clients (traders).The traders whose broker records appear inside an IB's dashboard. We are a processor here: the IB decides what happens to that data, and we only act on their instructions. If you are a trader and want your data changed or removed, contact your IB first - if you contact us, we will pass your request to them and support them in answering it.
- People who message an IB's Telegram bot. Also processor data, on the same basis.
3. What we collect
3.1 Account and profile data
- Email address (and the original capitalisation you typed).
- Your name, if you choose to provide it - it is optional.
- A one-way bcrypt hash of your password. We never store or receive your password in a readable form.
- Your timezone preference, your interface settings, and the permission flags that decide what your account can see.
- Account creation, update and last-activity timestamps.
3.2 Security and anti-abuse data
The platform holds financial figures for other people's client books, so account takeover and scraping are real risks. To resist them we record:
- The IP address and browser user-agent recorded when a login session is created, and the session's rotation history.
- Failed login counters and temporary lockouts keyed to the email address and IP involved.
- A device identifier- a random value generated in your browser and kept in that browser's local storage - together with non-unique browser characteristics: vendor, language and language list, platform, timezone, screen dimensions, touch support, browser brand and version, and user-agent string. This exists to detect one banned actor returning under a new account, not to track you across other websites. It is never shared with anyone and never used for advertising.
- An approximate location (country, region, city, network operator) derived from your IP address by a third-party lookup service. We do not use GPS or precise location.
- Ban records and abuse strikes, where an account or address has been blocked.
- Server-side security event logs recording authentication and administrative actions.
3.3 Credentials you give us for your own accounts
To pull your rebate figures and run your Telegram automation, you supply credentials for accounts that belong to you:
- Your broker IB portal email address and password, and the session cookies produced when we log in with them. The password and session data are encrypted at rest with AES-256-GCM and are never displayed back to you or sent to your browser. We use them for one purpose only: signing in to your broker portal, as you, to read your own rebate and client figures.
- Your Telegram bot token, encrypted the same way, plus the non-secret bot username and id.
- The Telegram channel identifiers and invite links you configure for client onboarding and support.
- API keys you mint for machine access - stored only as a SHA-256 digest plus a short non-secret prefix, along with the last IP that used the key.
You can remove any of these at any time from Settings, which deletes the stored secret.
3.4 Broker and client data we pull for you
When you connect your broker portal we retrieve, and store, the records that portal exposes about your own introducing-broker business. This includes personal data about your clients: their name, the email address registered with the broker, account and user identifiers, platform and account type, approval date, account balances, deposit and withdrawal history, traded volume, and the rebate generated. We also store the structure of your sub-IB network.
This data is scoped to your account. Another customer of ours can never see it. We are a processor for it - see section 2.
3.5 CRM and messaging data
- Follow-up status, your private notes, assignments, custom display names and reminder settings for each client you track.
- Telegram chat identifiers, and a log of the messages exchanged between your bot and the people who message it, so you have an audit trail of what your bot said and did.
- Records of failed client self-link attempts, to stop guessing attacks.
3.6 Access applications
If you apply for access we collect your full name, email address, Telegram username, phone number if given, your broker, the size of your network, your monthly traded volume and rebate rate, anything you write in the message field, how you heard about us, and the IP address, user-agent and approximate location of the submission.
3.7 What we do not collect
- No advertising identifiers, no cross-site tracking, no analytics or marketing pixels of any kind.
- No payment card data. We do not process payments through the platform.
- No special-category data (health, biometrics, political or religious views, and so on). Please do not put any into the free-text notes fields.
- No content from your device beyond the browser characteristics listed in section 3.2.
4. Why we use it, and our legal basis
Where the GDPR or a comparable law applies, we rely on the following legal bases:
| What we do | Data used | Legal basis |
|---|---|---|
| Create and run your account, authenticate you, provide the dashboard | Account data, credentials you supply, broker data | Performance of a contract with you (GDPR Art. 6(1)(b)) |
| Protect the platform: rate limiting, lockouts, ban and device-identifier checks, abuse investigation, security logging | Security and anti-abuse data | Our legitimate interests in keeping the service and our customers' data secure (Art. 6(1)(f)) |
| Assess an access application and contact you about it | Application data | Steps taken at your request prior to entering a contract (Art. 6(1)(b)); legitimate interests in vetting applicants (Art. 6(1)(f)) |
| Verify your email address or Telegram handle | Email address, Telegram username, one-time codes | Performance of a contract (Art. 6(1)(b)); legitimate interests in preventing fraudulent signups (Art. 6(1)(f)) |
| Send you service messages about your account, outages or changes to these terms | Account data | Performance of a contract (Art. 6(1)(b)); legitimate interests (Art. 6(1)(f)) |
| Process your clients' broker records, run your CRM and your Telegram bot | Broker, CRM and messaging data | We act as processor on your documented instructions; you are responsible for the legal basis towards your clients |
| Comply with legal obligations and respond to lawful requests | Whatever the obligation requires | Legal obligation (Art. 6(1)(c)) |
Where we rely on legitimate interests, we have weighed them against your rights and interests, and you can object at any time - see section 10.
7. International transfers
Our database and application servers are located in the European Economic Area (Sweden and Germany). Some of the providers listed above operate internationally, so personal data may be transferred outside the EEA or your own country. Where that happens and the destination has no adequacy decision, we rely on the European Commission's Standard Contractual Clauses or an equivalent approved mechanism, together with technical measures such as encryption in transit and at rest. You can ask us for details of the safeguards used.
8. How long we keep it
| Data | Retention |
|---|---|
| Account, broker, CRM and messaging data | Kept while your account is open. When you delete your account it is immediately hidden and disabled, then permanently erased after 30 days, which also erases every record attached to it. |
| Credentials you supplied (broker password, bot token, session data) | Erased as soon as you remove the connection, and in any case with the account. |
| Security event logs | 90 days. |
| Ban and abuse records | Kept while the ban is in force, as they would be pointless if erased on request by the banned actor. |
| Access applications | Kept while under review and for a reasonable period afterwards, so we can explain a decision and detect repeat abusive submissions. |
| One-time verification codes | Minutes - they expire and are cleared automatically. |
The 30-day window after deletion exists so an account deleted by mistake, or by someone who took it over, can still be restored. If you need immediate erasure instead, contact us and say so.
9. How we protect it
- All traffic is encrypted in transit with TLS, with HSTS enforced.
- Passwords are stored only as bcrypt hashes; API keys only as SHA-256 digests; one-time codes only as hashes.
- Third-party credentials you supply are encrypted at rest with AES-256-GCM under a key held outside the database, and are never returned to any browser.
- Every query is scoped to the owning account, so one customer cannot reach another customer's records.
- Rate limiting on every endpoint, login lockouts, CSRF protection, a strict content security policy, and audited administrative access.
- Administrative access to a customer's account is restricted to explicitly-granted permissions and is logged.
No system is perfectly secure. If we suffer a personal data breach that is likely to result in a risk to your rights, we will notify the relevant supervisory authority without undue delay and, where the risk is high, notify you directly.
10. Your rights
Depending on where you live, you have some or all of the following rights over the data we hold about you as controller:
- Access - a copy of your data and an explanation of how it is used.
- Rectification - correction of data that is wrong or incomplete.
- Erasure - deletion of your data. You can do this yourself: Settings, then the Danger zone, then delete your account.
- Restriction - a freeze on processing while a dispute is resolved.
- Portability - your data in a structured, machine-readable format.
- Objection - to processing based on legitimate interests.
- Withdrawal of consent - where we relied on consent, without affecting processing already carried out.
- Complaint - to your local data protection authority. We would rather you came to us first, but you do not have to.
To exercise any of these, email PRIVACY EMAIL. We answer within one month, and will tell you if we need longer because the request is complex. We do not charge, and we do not treat you differently for asking. We may need to verify your identity before acting.
If your request concerns data held by one of our customers about you as their client, see section 2 - we will forward it to them.
11. Region-specific rights
European Economic Area and United Kingdom
The rights in section 10 are your GDPR / UK GDPR rights. You may complain to your national supervisory authority, or in the UK to the Information Commissioner's Office.
California
Under the CCPA as amended by the CPRA you may request to know, delete, and correct your personal information, and to opt out of its sale or sharing. We do not sell or share personal information as those terms are defined, and we have not done so in the preceding twelve months. We do not use or disclose sensitive personal information for purposes requiring an opt-out. You will not be discriminated against for exercising these rights. Categories collected, sources, purposes and recipients are set out in sections 3, 4 and 6.
Other jurisdictions
Our users are international, and other laws - including Brazil's LGPD, Canada's PIPEDA, Australia's Privacy Act, and various US state privacy laws - grant similar rights. We apply the standard in section 10 to everyone regardless of location, and will honour any additional right your local law gives you.
12. Children
EightLotis a business tool and is not directed at children. You must be at least 18 to hold an account. We do not knowingly collect data from children; if you believe a child's data has reached us, tell us and we will delete it.
13. Automated decision-making
We do not make decisions producing legal or similarly significant effects about you by automated means alone. The platform does compute things automatically - a client's activity stage, whether a reminder is due, whether a login looks abusive - but a person can review and override each of them, and an automated security block can be appealed by contacting us.
14. Changes to this policy
We update this policy when the product changes. The version and date at the top always reflect the current text. For changes that materially affect your rights we will give notice in the application or by email before they take effect. Continuing to use EightLot after that means you accept the updated policy.
15. Contact us
LEGAL ENTITY NAME, REGISTERED ADDRESS.
Privacy and data requests: PRIVACY EMAIL
General support: SUPPORT EMAIL
Related documents