Политика конфиденциальности
IMPORTANT: This Policy explains how HedgeCore collects and uses personal data. It does not authorize HedgeCore to withdraw or transfer your Trading Assets, and it does not replace the separate privacy notices of Bybit, Telegram, or a Strategy Provider.
Key Points
- HedgeCore Inc. is the controller of personal data processed for the HedgeCore Platform, except where another party acts as an independent controller for its own services.
- HedgeCore does not routinely collect identity documents from every User. Users must maintain a Bybit account that satisfies Bybit identity-verification requirements, and HedgeCore may verify available KYC status and region indicators.
- HedgeCore processes a limited trading-only API Credential to validate permissions and connect the User-selected Strategy. Credentials with withdrawal, wallet, transfer, or other prohibited permissions are rejected.
- Subscription payments are direct payments for HedgeCore services. HedgeCore does not maintain a User deposit account, custodial wallet, internal balance, prepaid balance, or service-credit balance.
- HedgeCore does not currently sell personal data or use personal data for cross-context or cross-site targeted advertising.
- Depending on applicable law, you may have rights to access, correct, delete, restrict, object, receive a portable copy, obtain information about disclosures, or appeal a decision on a privacy request.
1. Scope and Relationship to Other Terms
This Privacy Policy (the "Policy") explains how HedgeCore Inc. ("HedgeCore", "Company", "we", "us", or "our") collects, uses, stores, discloses, and otherwise processes personal data when you access or use the HedgeCore website at HedgeCore.ai, the HedgeCore Telegram Mini App, and related software, interfaces, and services (collectively, the "Platform").
This Policy applies to Users, prospective Users, referral participants, Strategy Providers and their representatives, website visitors, and persons who communicate with HedgeCore. It should be read with the Terms of Use, Cookie and Similar Technologies Policy, Referral Programme Rules, and any notice shown when you activate a specific feature.
Bybit, Telegram, blockchain networks, wallet providers, and Strategy Providers may process personal data for their own purposes under their own privacy notices. HedgeCore is not responsible for an independent third party's privacy practices.
2. Controller and Contact Details
Controller: HedgeCore Inc., a Delaware corporation.
Registered address: 8 The Green, Ste D, Dover, Delaware 19901, USA
Privacy enquiries and requests: admin@hedgecore.ai
Where applicable law requires HedgeCore to appoint a local representative or data-protection contact, current details will be made available through the Platform or on request.
3. Sources of Personal Data
We obtain personal data:
- directly from you when you register, pay for a Subscription, submit an API Credential, activate a Strategy, join the Referral Programme, contact support, or provide compliance information;
- from Telegram when you launch or authenticate through the Telegram Mini App;
- from Bybit through the API Credential and the Bybit integration;
- from blockchain networks, payment infrastructure, wallet-screening and compliance providers, and public records or lists;
- from Strategy Providers, service providers, referral attribution systems, and security tools; and
- automatically from your browser, device, network connection, and use of the Platform.
4. Categories of Personal Data We Process
4.1 Account and Contact Data
Telegram user ID, username, display name and authentication data; email address; Account identifier; language, notification and interface preferences; acceptance records; and information you provide in communications or support requests.
4.2 Bybit and Eligibility Data
Bybit UID, account type, account relationship, KYC status or level, KYC region, account eligibility indicators, API-key type, IP restrictions, credential expiry information, and other data returned by Bybit that is reasonably necessary to validate eligibility and the connection.
HedgeCore does not routinely receive copies of the identity documents you submit to Bybit. Bybit identity verification is conducted by Bybit for its own purposes and does not constitute identity verification by HedgeCore.
4.3 API Credential and Security Data
The API key, associated secret or signing material, credential status, permission scope, validation results, IP allowlist information, connection identifier, security-control metadata, access and audit events where generated, and revocation or deletion status. The Platform accepts only a credential limited to the selected Connected Account and the trading functions strictly necessary for the selected Strategy.
4.4 Strategy, Trading, and Connection Data
Strategy selections, activations, pauses, deactivations, connection status, error events, technical routing records, and data available through the permitted Bybit API scope, which may include orders, positions, trades, instrument and product information, account or margin information, performance metrics, profit-and-loss information, fees, timestamps, and risk or configuration data necessary to operate or display the selected Strategy.
4.5 Subscription and Payment Data
Subscription plan, billing period, fee, payment status, recurring-billing choice where offered, supported cryptocurrency and network, source or payment wallet address, payment address, transaction hash, amount, exchange-rate or quote information, confirmation status, invoice or receipt data, refund or correction information, and related tax and accounting records.
A Subscription payment is a direct payment for HedgeCore services. HedgeCore does not create or maintain a User deposit account, custodial wallet, internal balance, prepaid balance, or service-credit balance.
4.6 Referral Data
Referral code or link, attribution information, referrer and Referred User identifiers, qualifying Subscription payments, commission calculations, pending or approved commission status, fraud and validation results, payout threshold and timing, payout wallet, payout transaction hash, tax forms, and related communications. HedgeCore does not maintain a withdrawable referral balance.
4.7 Compliance and Verification Data
Sanctions-screening results, KYC-region and geographic indicators, IP and VPN or proxy indicators, wallet-risk and blockchain analytics, investigation notes, restriction or suspension records, and information collected in response to a documented risk trigger. Where necessary, this may include legal name, date of birth, nationality, residence, address, government-issued identification, proof of address, wallet-ownership evidence, source-of-funds or source-of-wealth information, beneficial ownership information, and tax data.
Where any information qualifies as sensitive data under applicable law, HedgeCore processes it only as permitted by that law and obtains consent or another required authorization where applicable.
4.8 Technical, Device, and Usage Data
IP address, approximate location derived from IP, browser and device type, operating system, application version, language, time zone, session and authentication identifiers, request timestamps, pages and features used, click and interaction data, diagnostic logs, crash reports, security events, and cookie or similar-technology information described in the Cookie and Similar Technologies Policy.
4.9 Communications and Marketing Data
Support requests, correspondence, complaint and dispute information, notification delivery status, communication preferences, marketing consent or opt-out records, and responses to surveys or feedback requests.
5. How and Why We Use Personal Data
The following table summarizes our principal purposes and, where EU or UK data-protection law applies, the typical legal bases. A different basis may apply where permitted or required by local law.
| Purpose | Examples | Typical legal basis where required |
|---|---|---|
| Provide and administer the Platform | Create Accounts, authenticate Users, provide subscriptions, display the Strategy catalogue, maintain settings, and provide support. | Performance of a contract; steps requested before entering a contract. |
| Validate Bybit eligibility and API scope | Verify UID, KYC indicators, region, account relationship, credential status, IP restrictions, expiry, and permissions; reject prohibited permissions. | Performance of a contract; legitimate interests in security and lawful operation. |
| Connect and operate a selected Strategy | Bind the validated credential to the selected Execution Environment, route permitted instructions, monitor connection status, and display trading information. | Performance of a contract; your direction to connect the selected Strategy. |
| Process payments and Referral Commissions | Match blockchain payments, activate subscriptions, maintain accounting records, validate referrals, and make approved treasury payouts. | Performance of a contract; legal obligation; legitimate interests in payment integrity. |
| Security, fraud, sanctions, and compliance | Screen accounts, locations and wallets; investigate alerts; prevent abuse; enforce terms; respond to lawful requests. | Legal obligation where applicable; legitimate interests in security, fraud prevention, and legal compliance. |
| Communicate with you | Send service, payment, strategy, security, legal, and policy notices and respond to enquiries. | Performance of a contract; legal obligation; legitimate interests. |
| Improve and analyze the Platform | Diagnose errors, understand feature use, test performance, and improve products using aggregated or appropriately protected data. | Legitimate interests; consent where required for non-essential device technologies. |
| Marketing | Send promotional communications or use optional marketing technologies only where enabled and permitted. | Consent or another basis permitted by applicable law. |
6. How We Disclose Personal Data
We disclose personal data only as reasonably necessary for the purposes described in this Policy, as directed by you, or as permitted or required by law. Categories of recipients include:
6.1 Selected Strategy Providers and Execution Environments
The validated API Credential, relevant connection information, and data necessary to operate the selected Strategy may be made available to the selected Strategy Provider or its designated Execution Environment. We do not make the credential available to unrelated Strategy Providers.
6.2 Bybit
We send authentication requests, validation queries, connection instructions, and trading instructions generated by the selected Strategy to Bybit through its API. Bybit processes account and trading information under its own terms and privacy notice.
6.3 Telegram
When you use the Telegram Mini App or Telegram authentication, Telegram provides identifiers and authentication data and may process device, account, and interaction information under its own terms and privacy notice.
6.4 Payment, Blockchain, and Payout Providers
Payment processors, wallet infrastructure, blockchain nodes or data providers, and payout service providers may process wallet addresses, transaction details, Account references, network information, and related data necessary to receive a Subscription payment or make a Referral Commission payout.
6.5 Compliance, Security, and Fraud Providers
Sanctions-screening, blockchain analytics, identity or document-verification, fraud-prevention, cybersecurity, logging, monitoring, and incident-response providers may process information necessary to perform the relevant service.
6.6 Other Service Providers
Cloud hosting, database, infrastructure, communications, customer-support, email, analytics, software-development, and professional service providers may process personal data on our behalf under contractual restrictions and confidentiality obligations appropriate to their role.
6.7 Authorities, Legal Process, and Protection of Rights
We may disclose personal data to courts, regulators, law-enforcement agencies, sanctions authorities, tax authorities, or other competent bodies where required by law or valid process, or where permitted and reasonably necessary to protect rights, investigate fraud or unlawful activity, enforce agreements, or protect the Platform, Users, or others.
6.8 Corporate Transactions
Personal data may be disclosed or transferred in connection with a proposed or completed financing, merger, acquisition, reorganization, sale of assets, bankruptcy, or similar transaction, subject to confidentiality and applicable law.
6.9 No Sale or Targeted Advertising
HedgeCore does not currently sell personal data for monetary or other valuable consideration and does not process personal data for cross-context or cross-site targeted advertising. We do not permit advertising partners to track Users across unrelated websites or applications through the Platform. If this changes, we will update this Policy and provide any notice, consent, or opt-out required by law before the new processing begins.
7. International Data Transfers
HedgeCore is based in the United States and the Platform may use service providers, Strategy Providers, and infrastructure in the United States and other countries. Those countries may have data-protection laws different from the laws where you live.
Where applicable law restricts international transfers, we use an available lawful mechanism, which may include an adequacy decision, the European Commission's Standard Contractual Clauses, the UK International Data Transfer Agreement or UK Addendum, contractual and technical safeguards, consent where legally valid, or another permitted derogation or mechanism. You may contact us for information about the transfer safeguards relevant to your data.
8. Data Retention
We retain personal data only for as long as reasonably necessary for the purposes described in this Policy, including service delivery, security, fraud prevention, tax and accounting, sanctions and legal compliance, dispute resolution, and enforcement. The following are typical periods or criteria; a longer or shorter period may apply based on law, risk, or the specific record.
| Data category | Typical retention period or criterion |
|---|---|
| Account and contact data | For the life of the Account and generally up to 3 years after closure, unless a longer period is needed for a dispute, legal claim, fraud matter, or legal requirement. |
| API Credential | For the active Strategy connection. Removed from active connection systems after deactivation or Account closure; protected backup copies remain only until overwritten in the ordinary backup cycle, unless preservation is required. |
| Strategy, trading, and connection records | For the Account life and generally up to 3 years afterward, or longer where needed for security, dispute, tax, or legal purposes. |
| Subscription payment, referral, tax, and accounting records | Generally up to 7 years from the relevant transaction or reporting period, or longer where required by tax, accounting, sanctions, or legal rules. |
| Compliance and sanctions records | For the period reasonably necessary for the review and any resulting restriction, report, investigation, or legal obligation. Where U.S. sanctions recordkeeping rules apply, certain records may be kept for up to 10 years. |
| Security and technical logs | Usually up to 12 months, unless a longer period is needed to investigate an incident, maintain system integrity, or establish or defend a claim. |
| Support and communications | Usually up to 3 years after the matter closes, unless connected to a longer-lived contract, complaint, dispute, or legal requirement. |
| Marketing preferences | Until you withdraw consent or opt out; a minimal suppression record may be retained to respect the choice. |
| Cookies and similar technologies | As stated in the Cookie and Similar Technologies Policy and the current preference interface. |
We may de-identify or aggregate data so that it no longer identifies you. We may retain and use properly de-identified or aggregated information for lawful purposes without applying the periods above, subject to applicable law and safeguards against re-identification.
9. Security
We maintain administrative, technical, and physical measures designed to protect personal data according to its nature and risk. Measures may include encryption, credential vaulting or protected secret storage, least-privilege access, role-based controls, environment separation, IP restrictions, multi-factor authentication for administrative access, logging, monitoring, secure development practices, backups, vendor review, incident response, and personnel confidentiality obligations.
No method of transmission, storage, or security is completely secure. You are responsible for protecting your Telegram and email accounts, devices, Bybit credentials, and API Credential and for revoking the API Credential directly through Bybit when it is no longer needed or if compromise is suspected.
10. Your Privacy Rights and Choices
10.1 General Rights
Depending on your jurisdiction and subject to applicable exceptions, you may have the right to:
- confirm whether we process your personal data and access it;
- correct inaccurate personal data;
- request deletion;
- restrict or object to certain processing;
- receive a portable copy of personal data you provided or that is processed by automated means;
- obtain information about categories of third parties to which data was disclosed;
- withdraw consent without affecting processing completed before withdrawal;
- opt out of sale, targeted advertising, or qualifying profiling where those rights apply;
- appeal a refusal to act on a privacy request where applicable; and
- complain to a competent data-protection or consumer-protection authority.
10.2 Delaware and Other U.S. State Rights
Where the Delaware Personal Data Privacy Act or another applicable U.S. state privacy law applies, eligible consumers may exercise the rights provided by that law. For an authenticated Delaware request, we will respond without undue delay and generally within 45 days. We may extend the period once by up to 45 additional days where reasonably necessary and will explain the extension. If we deny a request, eligible Delaware consumers may appeal by replying to the decision or emailing us with the subject "Privacy Appeal". We will respond to the appeal within the period required by law, which is generally 60 days under Delaware law.
You may use an authorized agent for an opt-out request where permitted. We may request information reasonably necessary to verify your identity, Account, or the agent's authority. We will not discriminate against you for exercising a privacy right.
10.3 EEA, UK, and Similar Rights
Where the EU GDPR, UK GDPR, or a similar law applies, you may also have rights to restriction, objection based on legitimate interests, data portability, and to lodge a complaint with the supervisory authority where you live, work, or believe an infringement occurred. You may object at any time to direct marketing. Where processing is based on consent, you may withdraw consent at any time.
10.4 How to Submit a Request
Submit a request through available Account controls or email admin@hedgecore.ai. Describe the right you wish to exercise and the Account or contact information needed to locate the relevant data. We may ask for additional information to authenticate the request and protect your data. You do not need to create a new Account solely to submit a privacy request.
11. Automated Rules and Profiling
The Platform uses automated rules to perform security and eligibility functions, including rejecting an API Credential with prohibited permissions, detecting an invalid or expired credential, flagging an ineligible KYC region or IP location, identifying payment or wallet risk, and detecting referral abuse. These rules may temporarily prevent activation, payment processing, payout, or access.
Where applicable law gives you a right concerning a decision based solely on automated processing that produces legal or similarly significant effects, you may request human review, provide relevant information, and contest the decision. HedgeCore does not use personal data to assess your investment suitability or to generate the trading decisions of a Strategy.
12. Cookies, Tracking, Do Not Track, and Preference Signals
The Web Platform uses cookies and similar technologies as described in the Cookie and Similar Technologies Policy. Strictly necessary technologies support authentication, security, routing, and consent records. Non-essential technologies are not activated before consent where consent is required.
Because HedgeCore does not currently sell personal data or use cross-site targeted advertising, browser Do Not Track signals and opt-out preference signals do not currently change advertising or sale processing on the Platform. Where a legally recognized signal applies to processing we conduct, we will honor it as required by law. Independent services such as Telegram and Bybit may process data under their own policies when you interact with them.
13. Children
The Platform is not directed to persons under 18, and the Terms of Use require Users to be at least 18 and at least the age of legal majority in their jurisdiction. We do not knowingly collect personal data from a child through the Platform. Contact us if you believe a child has provided personal data, and we will review and take appropriate action.
14. Changes to This Policy
We may update this Policy to reflect changes in the Platform, data practices, service providers, law, or security and compliance needs. We will post the revised Policy and update the Effective Date. Material changes will be communicated through the Platform, email, or another reasonable method before they take effect, unless earlier action is required for legal, security, fraud-prevention, or technical reasons.
Contact
HedgeCore Inc.
Registered address: 8 The Green, Ste D, Dover, Delaware 19901, USA
Legal, privacy, and compliance enquiries: admin@hedgecore.ai
Support: https://t.me/hedgecoreaisupport