1 Introduction and scope
This Privacy Policy explains how HedgeGuard SAS ("HedgeGuard", "we", "us", "our") handles personal data. It covers two distinct situations, which are governed by different rules and set out separately below:
- Data we control. Personal data for which we decide the purposes and means — for example data about visitors to this website, prospects, and the individuals who administer a client account. For this data we act as a data controller (Section 4).
- Data we process for clients. Personal data contained within the data a client loads into or generates through the platform — for example personal data relating to a client's investors, beneficial owners, or personnel. For this data we act as a data processor on the client's instructions (Section 5).
The controlling framework for this Policy is the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR") and French data-protection law.
2 Who we are
HedgeGuard SAS is a French société par actions simplifiée, registered with the Paris Trade and Companies Register (RCS) under number 910 033 141, with its registered office at 58 rue de Monceau, 75008 Paris, France.
For any privacy question, contact us at contact@hedgeguard.com or by post at the address above.
3 Where your data is hosted
The HedgeGuard platform and the data processed through it are hosted on infrastructure located within the European Union. Our hosting provider is Scaleway, using data-centre regions in Paris (France) and Amsterdam (Netherlands). We do not transfer platform data outside the European Union / European Economic Area in the ordinary course of providing the service.
4 Data we control
This Section applies to the personal data for which we determine the purposes and means.
| Who | What we collect | Why | Legal basis (GDPR Art. 6) |
|---|---|---|---|
| Website visitors | Technical and usage data such as IP address, device and browser data, and pages viewed; cookie identifiers | Operating and securing the website; measuring and improving it | Our legitimate interests in running and securing the site; consent for non-essential cookies |
| Prospects and enquirers | Name, business contact details, company, role, and correspondence | Responding to enquiries; arranging demos; business-to-business marketing | Our legitimate interests; consent where required |
| Client account users | Name, business email, job title, credentials, and activity logs | Provisioning access, authentication, security, support, and account administration | Performance of a contract; our legitimate interests in security and service operation |
We keep this data only as long as necessary for the purpose it was collected for, or as required by law. You can ask us to stop sending marketing communications at any time.
5 Data we process for clients
When a client uses the platform, it loads and generates data including portfolio, trade, position, transaction, cash, and NAV records. Most of that data describes financial instruments rather than individuals. To the extent it contains personal data, the client — not HedgeGuard — decides why and how it is processed. In that situation the client is the controller and HedgeGuard is a processor acting only on the client's documented instructions.
This processing is governed by a data-processing agreement that forms part of the client contract and meets the requirements of Article 28 GDPR. As processor, we commit to:
- process client personal data only on the client's documented instructions;
- use client data solely to provide and support the service, and not for any commercial purpose of our own and not to build derivative datasets;
- keep persons authorised to process the data under an obligation of confidentiality;
- apply appropriate technical and organisational security measures (Section 7);
- engage sub-processors only under the conditions in Section 8;
- assist the client in meeting its own obligations to data subjects and regulators; and
- notify the client without undue delay after becoming aware of a personal-data breach affecting client data.
The client retains all rights, title, and interest in its data. We disclose it only as directed by the client or as required by law.
6 Access, return, and deletion of client data
Clients can access and extract their data at any time during the term of their service. After a service agreement ends, we retain client data in a limited-function account for 7 days so the client can extract it. At the end of that period we disable the account and delete the client data, subject to any legal retention requirement.
7 Security
We maintain technical and organisational measures appropriate to the risk, which currently include:
- EU-only hosting on Scaleway infrastructure (Paris and Amsterdam);
- access controls on a least-privilege basis;
- monitoring and alerting across our production environment;
- automated disaster-recovery failover and daily backups; and
- audit-ready logging of relevant system and user activity.
No security measure is absolute. We do not represent that the service is immune from all risk, and clients remain responsible for the security of their own systems, credentials, and access management.
8 Sub-processors
We use a limited number of sub-processors to provide the service. Our infrastructure sub-processor is Scaleway (cloud hosting, France and Netherlands — EU). We impose data-protection obligations on each sub-processor that are no less protective than those we owe to clients, and we will inform clients of any intended change to a sub-processor that handles client data, giving a reasonable opportunity to object before the change takes effect. A current list is available to clients on request.
10 Your rights
Where we act as controller, you have the rights to access, rectification, erasure, restriction, data portability, and objection, and the right to withdraw consent where processing is based on consent (without affecting processing carried out before withdrawal). To exercise any of these, contact us at contact@hedgeguard.com.
You also have the right to lodge a complaint with the French supervisory authority, the Commission Nationale de l'Informatique et des Libertés (CNIL) — www.cnil.fr.