Seasonality360 – Privacy Policy

    Last updated: 5 March 2026

    1. Introduction

    This Privacy Policy (the "Policy") explains how Lis Tech Company S.R.L.S. ("Lis Tech Company", "we", "us", "our") collects, uses, stores, shares and protects personal data in connection with the online platform Seasonality360 and related websites, applications, products and services (together, the "Services").

    We are committed to protecting the privacy of users of the Services ("you", "your") and to processing personal data in a lawful, fair and transparent manner.

    This Policy is drafted in accordance with Regulation (EU) 2016/679 (General Data Protection Regulation, "GDPR") and the applicable provisions of Italian data protection law.

    Please read this Policy carefully. By accessing or using the Services, you acknowledge that you have been informed about our processing of your personal data as described in this Policy.

    2. Who is the data controller?

    The data controller responsible for the processing of your personal data in connection with the Services is:

    Lis Tech Company S.R.L.S. Tax ID / VAT: 06240540879 Email: [email protected]

    If we appoint a Data Protection Officer (DPO), we will indicate the DPO's contact details here or in a supplemental notice.

    3. What personal data we collect

    The categories of personal data we may collect and process include in particular:

    • Identification data – such as first name, last name, username, password, company name (if applicable), country of residence and language. • Contact data – such as email address, billing address, postal address and telephone number. • Account and subscription data – such as your login credentials, plan type, subscription status, usage limits, preferences and settings. • Payment and billing data – such as details required to process payments, limited payment card or bank details (processed via our payment service providers), tax information and invoices. • Technical data – such as IP address, device identifiers, browser type and version, operating system, time zone setting, and other technical information about the devices and connections you use to access the Services. • Usage data – such as information about how you interact with the Services, including pages visited, features used, search queries, clicks, session duration and error logs. • Communication data – such as your requests and messages sent via contact forms, email, in‑platform chat or other channels, as well as related metadata and, where applicable, call recordings. • Marketing preference data – such as your preferences regarding newsletters, product updates and promotional communications. • Professional data (B2B contacts) – such as job title, organisation, role and professional contact details, where you interact with us on behalf of a legal entity (e.g. a broker or other business partner).

    We do not intentionally collect or process special categories of personal data (e.g. health data, data revealing racial or ethnic origin, political opinions, religious beliefs, or trade‑union membership) via the Services. Please do not provide such information through the platform.

    4. For what purposes we use personal data and legal bases

    We process your personal data for the purposes and on the legal bases described below:

    4.1. Account creation and management

    We use identification and contact data, and account data to create, administer and secure your user account, authenticate you when you log in, and manage your relationship with us. Legal basis: performance of a contract (Article 6(1)(b) GDPR) and our legitimate interests in operating the Services securely (Article 6(1)(f) GDPR).

    4.2. Provision of the Services

    We process your personal data to provide access to the Seasonality360 platform and its features, including allowing you to view analytics, save settings and use any paid or free functionalities. Legal basis: performance of a contract (Article 6(1)(b) GDPR).

    4.3. Payments and billing

    We use payment and billing data to process subscription fees and other amounts payable, issue invoices, handle renewals, manage refunds where applicable and keep accounting records. Legal basis: performance of a contract (Article 6(1)(b) GDPR) and compliance with legal obligations relating to accounting and tax (Article 6(1)(c) GDPR).

    4.4. Customer support and communications

    We process identification, contact and communication data to respond to your enquiries, provide technical support, manage complaints and send service notices (e.g. changes to the Services, security alerts, updates to this Policy). Legal basis: performance of a contract (Article 6(1)(b) GDPR) and our legitimate interests in ensuring quality customer support (Article 6(1)(f) GDPR).

    4.5. Service improvement, analytics and security

    We use technical and usage data to monitor the performance of the Services, improve functionalities, detect and prevent errors, abuse and fraud, and ensure the security of our systems. Legal basis: our legitimate interests in improving and protecting the Services (Article 6(1)(f) GDPR).

    4.6. Marketing and newsletters

    We may use your contact data, account data and usage data to send you newsletters, product updates and other marketing communications about Seasonality360 and related services, and to measure the effectiveness of such communications. Legal basis: your consent (Article 6(1)(a) GDPR) where required by law; or our legitimate interests in promoting our Services (Article 6(1)(f) GDPR) where consent is not mandatory. You can withdraw your consent or opt out of marketing at any time by using the unsubscribe link in our emails or by contacting us.

    4.7. Compliance with legal obligations

    We may process personal data to comply with obligations arising from applicable laws and regulations, such as record‑keeping, responding to requests from public authorities, enforcing our Terms & Conditions and protecting our legal rights. Legal basis: compliance with a legal obligation (Article 6(1)(c) GDPR) and our legitimate interests in protecting our rights (Article 6(1)(f) GDPR).

    5. Cookies and similar technologies

    We use cookies and similar technologies (such as pixels and local storage) on our websites and within the Services to enable core functionalities, remember your preferences, perform analytics and improve user experience.

    For further details about the types of cookies we use, their purposes and how you can manage your cookie preferences, please refer to our separate Cookie Policy, which forms part of this Privacy Policy. Where required by law, we will obtain your consent before placing non‑essential cookies.

    6. Sources of personal data

    We obtain personal data primarily from you when you: • create and manage an account; • use the Services; • communicate with us through support channels; • subscribe to newsletters or marketing communications; • participate in surveys, webinars or events.

    We may also receive personal data from: • our payment service providers and financial institutions, in relation to payments; • analytics and marketing service providers, regarding your interaction with our Services and campaigns; • business partners (for example, where your access is provided via a broker or other intermediary); • publicly available sources, such as professional social networks, public registers or websites, where permitted by applicable law.

    7. Automated decision-making

    We do not use personal data to take decisions based solely on automated processing, including profiling, which produce legal effects concerning you or similarly significantly affect you, within the meaning of Article 22 GDPR.

    If in the future we introduce such forms of automated decision‑making, we will provide you with specific information about the logic involved, as well as the significance and the envisaged consequences for you, and we will ensure that such processing takes place in compliance with applicable law.

    8. How we share personal data

    We do not sell your personal data. We may share your personal data only with the following categories of recipients, to the extent necessary for the purposes described in this Policy:

    • Service providers (processors) – third‑party companies that provide services on our behalf, such as hosting and cloud infrastructure, payment processing, analytics, email delivery, customer support tools, marketing automation and security monitoring. These providers process personal data only on our instructions and are bound by contractual obligations to protect personal data. • Business partners – in B2B contexts, we may share limited contact and usage information with a broker or other partner that has facilitated your access to the Services, to manage the relationship and for reporting purposes, where permitted by law and the applicable agreements. • Professional advisers – such as lawyers, auditors or consultants, where necessary to protect our rights, comply with legal obligations or manage our business. • Public authorities – where required by law, regulation, court order or a request from competent authorities, or to protect our rights, users or third parties.

    In all cases, we limit the personal data shared to what is strictly necessary and ensure, where required, that appropriate data protection safeguards are in place.

    9. International data transfers

    Some of our service providers or business partners may be located outside the European Economic Area ("EEA") or may process personal data from locations outside the EEA.

    Where such transfers occur, we will ensure that an adequate level of protection is provided for your personal data, in particular by: • relying on an adequacy decision by the European Commission for the relevant country; or • entering into standard contractual clauses (SCCs) adopted by the European Commission with the recipient; or • implementing other appropriate safeguards in accordance with Articles 46 et seq. GDPR.

    You may contact us for more information about international transfers and the safeguards applied, and, where applicable, to obtain a copy of the relevant contractual safeguards (with redactions where necessary to protect confidential information).

    10. Data retention

    We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, including to comply with legal, accounting or reporting obligations, or to establish, exercise or defend legal claims.

    In general: • Account data is retained for the duration of your relationship with us and for a subsequent period where required by law or to protect our rights. • Payment and billing data is retained for the period required by applicable tax and accounting laws. • Technical and usage data is retained for the time necessary to perform analytics and ensure security, typically for shorter periods, unless a longer retention is needed in connection with investigations or legal proceedings. • Marketing data is retained until you withdraw your consent or object to processing for marketing purposes, or for a shorter period if required by law.

    When personal data is no longer needed for the purposes for which it was collected and there are no legal obligations requiring its retention, we will delete it or anonymise it so that you can no longer be identified.

    11. How we protect personal data

    We implement appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure of or access to personal data.

    These measures include, as appropriate: access controls, encryption or pseudonymisation of certain data, secure development practices, logging and monitoring, regular backups, employee confidentiality obligations and procedures for responding to suspected data breaches.

    While we strive to protect personal data, no system can be completely secure. If we become aware of a personal data breach that is likely to result in a high risk to your rights and freedoms, we will notify you and the competent supervisory authority, where required by law.

    12. Your rights

    Under the GDPR and applicable data protection law, you have the following rights in relation to your personal data, subject to the conditions and limitations set out in the law:

    • Right of access – to obtain confirmation as to whether we process personal data concerning you and to receive a copy of such data. • Right to rectification – to have inaccurate personal data corrected and incomplete data completed. • Right to erasure ("right to be forgotten") – to request the deletion of your personal data in certain circumstances, for example where it is no longer necessary for the purposes for which it was collected, or where you withdraw consent and there is no other legal basis for processing. • Right to restriction of processing – to request that we restrict the processing of your personal data in certain situations (e.g. while we verify its accuracy or assess an objection). • Right to data portability – to receive personal data that you have provided to us in a structured, commonly used and machine‑readable format and to transmit it to another controller, where the processing is based on consent or contract and carried out by automated means. • Right to object – to object, on grounds relating to your particular situation, to processing based on our legitimate interests. You also have the right to object at any time to processing of your personal data for direct marketing purposes. • Right to withdraw consent – where processing is based on your consent, you may withdraw that consent at any time, without affecting the lawfulness of processing carried out before withdrawal. • Right to lodge a complaint – to lodge a complaint with a supervisory authority, in particular in the EU Member State of your habitual residence, place of work or place of the alleged infringement. In Italy, the competent authority is the Garante per la protezione dei dati personali.

    To exercise your rights, please contact us using the contact details provided in section 14 below. We may need to verify your identity before responding to your request. We will respond within the time limits set out in the GDPR.

    13. Children's privacy

    The Services are intended for users who are at least 18 years old and are not directed to children. We do not knowingly collect personal data from children under 18. If you believe that a child has provided personal data to us through the Services, please contact us so that we can take appropriate steps to delete such data.

    14. Changes to this Privacy Policy

    We may update this Privacy Policy from time to time, for example to reflect changes in the Services or in applicable laws. When we make material changes, we will take appropriate measures to inform you, such as by posting a prominent notice on our website, updating the "Last updated" date at the top of this Policy and, where appropriate, notifying you by email or via the Services.

    We encourage you to review this Privacy Policy periodically to stay informed about our practices.

    15. Contact

    If you have any questions about this Privacy Policy or our data protection practices, or if you wish to exercise your rights, you can contact us at:

    Lis Tech Company S.R.L.S. Email: [email protected]

    If you are located in the European Union, you also have the right to lodge a complaint with a supervisory authority. In Italy, the supervisory authority is the Garante per la protezione dei dati personali (www.garanteprivacy.it).

    16. Seasonality360-specific data categories and processing records

    In addition to the general categories described above, the current Seasonality360 implementation may process and store the following service-specific data fields and records. These details supplement, and do not replace, the general provisions of this Privacy Policy.

    16.1. Account and identity data

    In connection with account registration, authentication and profile management, we may process: username, email, password_hash, google_id (where Google OAuth login is used), timezone, and telegram_chat_id (where Telegram notifications are enabled). These data are processed in order to create and manage the account, authenticate access, personalise service timing and deliver requested notifications. Legal basis: performance of a contract (Article 6(1)(b) GDPR) and, for account security and abuse prevention, our legitimate interests (Article 6(1)(f) GDPR).

    16.2. Billing and subscription data

    For subscription management and recurring billing, we may process: stripe_customer_id, stripe_subscription_id, stripe_subscription_status (for example active, trialing, past_due, canceled), stripe_plan, stripe_trial_end, stripe_current_period_end, and stripe_cancel_at_period_end. These data are processed to activate plans, manage free trials and renewals, verify subscription status, support invoicing and accounting, and handle cancellations or payment issues. Legal basis: performance of a contract (Article 6(1)(b) GDPR), compliance with legal obligations relating to accounting and tax (Article 6(1)(c) GDPR), and our legitimate interests in fraud prevention, payment recovery and dispute management (Article 6(1)(f) GDPR).

    16.3. Legal acceptance and audit trail data

    To evidence contractual acceptance and document integrity, we may process: doc_type, doc_version, doc_language, doc_url_at_acceptance, doc_content_sha256, accepted_at_utc, source_flow, ip_address, user_agent, request_id, and session_id. These data are processed for auditability, proof of acceptance, integrity verification of the accepted text, dispute handling and internal compliance controls. Legal basis: performance of a contract (Article 6(1)(b) GDPR) and our legitimate interests in legal protection, traceability and service security (Article 6(1)(f) GDPR).

    16.4. Notification and messaging data

    Where notification features are used, we may process memo, notes, instrument, pattern_data, push endpoints, related authentication data, and outbox or delivery logs including sending status, errors and retry information. These data are processed to deliver user-requested notifications, operate reminder features, maintain delivery reliability and investigate sending failures. Legal basis: performance of a contract (Article 6(1)(b) GDPR); where optional marketing or non-essential promotional notifications are enabled, consent may apply where required by law (Article 6(1)(a) GDPR); and our legitimate interests support service reliability and security logging (Article 6(1)(f) GDPR).

    16.5. Trading and research workspace data

    The Services may process backtest parameters and results, trade lists, equity curves, portfolios, saved research configurations and related analytical outputs generated or stored in the user workspace. These data are processed solely to provide the requested analytics and research functionality, preserve the user workspace and support the study and comparison features of the platform. Legal basis: performance of a contract (Article 6(1)(b) GDPR).

    16.6. Technical, infrastructure and traffic analytics data

    The Services may also process technical event logs, security logs, request identifiers, IP-related security data, Cloudflare proxy and protection data, and privacy-friendly traffic analytics generated through Ahrefs Web Analytics in accordance with the configured implementation. These data are processed for cybersecurity, fraud and abuse mitigation, diagnostics, service continuity, infrastructure optimisation and aggregate traffic analysis. Legal basis: our legitimate interests in operating and protecting the Services (Article 6(1)(f) GDPR), and consent where non-essential technologies are used and consent is required by law (Article 6(1)(a) GDPR).

    17. Service-specific retention schedule

    The following schedule supplements section 10 above and describes the retention logic currently intended for the main service-specific records processed within Seasonality360. Where legal obligations, ongoing disputes, security incidents or the defence of legal claims require longer retention, the data may be retained for a longer period to the extent permitted by law.

    Category

    Examples of records

    Standard retention logic

    Account and identity data

    username, email, password_hash, google_id, timezone, telegram_chat_id

    For the life of the account and ordinarily up to 30 days after account closure, unless longer retention is required by law, security needs or legal claims.

    Billing and subscription data

    stripe_customer_id, stripe_subscription_id, status, plan, trial and period-end data

    For the life of the subscription and thereafter for the period required by accounting, tax, fraud-prevention and dispute-management obligations; accounting-relevant data may be retained for up to 10 years where required by applicable law.

    Legal acceptance records

    doc_type, doc_version, doc_language, doc_url_at_acceptance, doc_content_sha256, accepted_at_utc, source_flow, ip_address, user_agent, request_id, session_id

    For the contractual relationship and ordinarily up to 10 years thereafter where needed to evidence acceptance, defend legal claims and comply with record-keeping obligations.

    Notification content and delivery logs

    memo, notes, instrument, pattern_data, push endpoint data, outbox status, errors, retries

    User workspace notification content is generally retained while the feature is active and for a short post-closure deletion window (normally around 30 days); delivery and error logs are typically retained for up to 12 months unless a security or dispute-related need justifies longer retention.

    Trading and research workspace data

    backtest parameters and results, trade lists, equity curves, portfolios

    For the life of the account or workspace until deletion by the user or account closure, plus a short technical deletion window, normally around 30 days, unless longer retention is legally required or technically necessary for defence or recovery purposes.

    Technical and security logs

    request identifiers, error logs, security event logs, abuse-prevention logs

    Typically up to 12 months depending on the security purpose and operational necessity, subject to longer retention for incidents, investigations or legal claims.

    Traffic analytics data

    privacy-friendly Ahrefs analytics and related aggregate data

    Retained according to the configured analytics implementation and provider logic, typically up to 13 months and with a focus on aggregate or minimised retention rather than individually identifying storage.

    18. Specific third-party providers and privacy roles

    The following information supplements section 8 above. Depending on the relevant processing activity and contractual setup, certain integrated third-party providers act on our instructions as processors, while others may independently determine purposes for parts of their processing and therefore operate as separate or independent controllers for those parts.

    18.1. Stripe

    Stripe is used for payments, subscriptions, recurring billing workflows and related fraud-prevention functions. In many processing operations connected to payment execution on our behalf, Stripe acts as a processor or service provider; however, for certain compliance, fraud-prevention, network security or regulatory obligations, Stripe may act as a separate controller under its own documentation.

    18.2. Google OAuth

    Where Google sign-in is enabled, Google acts as a separate controller for the identity and authentication services it provides to end users. We process only the user data actually received in our systems and needed to create or manage the Seasonality360 account and related access.

    18.3. Telegram

    Where Telegram notifications are enabled by the user, Telegram acts as a separate controller for the messaging service and related delivery infrastructure. We use the relevant chat identifier solely for the purpose of delivering the notifications requested by the user.

    18.4. SMTP providers and transactional email services

    Providers used to send transactional emails, account notices or notification emails generally act as processors or service providers on our behalf, subject to the applicable contractual arrangements and data protection terms.

    18.5. Browser push services and endpoints

    Push notification delivery may involve browser vendors, operating system providers or related push endpoint services, which may act as separate controllers for the operation of their own delivery networks. We act as controller for the storage and use of the endpoint information within our own systems.

    18.6. Cloudflare

    Cloudflare is used for content delivery, reverse proxying, infrastructure protection, traffic filtering, performance support and related security services. Depending on the specific service component and contractual framework, Cloudflare generally acts as our processor or service provider for those infrastructure operations.

    18.7. Ahrefs Web Analytics

    Ahrefs Web Analytics is used for privacy-friendly traffic analytics and website performance analysis in accordance with the configured implementation. Where used in a cookie-less and non-identifying configuration, the tool is intended to support aggregate analytics rather than individual profiling.

    Provider

    Primary function in Seasonality360

    Typical privacy role

    Stripe

    Payments, subscriptions, recurring billing, fraud-prevention support

    Processor / service provider for many payment operations; may act as separate controller for certain compliance, fraud or regulatory processing.

    Google OAuth

    User sign-in and identity authentication

    Separate controller for its identity services; we are controller for the data received into our own systems.

    Telegram

    Optional notification delivery channel

    Separate controller for its messaging infrastructure; we control the use of the chat identifier within our systems.

    SMTP provider

    Transactional emails and service notices

    Typically processor / service provider on our behalf.

    Browser push services

    Push delivery network and endpoint routing

    Separate controllers for their own delivery infrastructure; we control the stored endpoint data in our systems.

    Cloudflare

    Reverse proxy, delivery, filtering, protection and performance support

    Typically processor / service provider for infrastructure and security operations, subject to the applicable contractual framework.

    Ahrefs Web Analytics

    Privacy-friendly website traffic analytics

    Analytics provider used for aggregate traffic analysis in the configured implementation.

    19. International transfers and supplementary safeguards

    Because some of the integrated providers listed in this Policy may use global infrastructure, personal data may be processed outside the European Economic Area. In such cases, we rely on the safeguards described in section 9 above, including adequacy decisions where applicable, standard contractual clauses, and supplementary technical and organisational measures such as data minimisation, transport encryption, access controls and role-based access restrictions.

    Where a provider independently determines part of the processing and acts as a separate controller, the provider's own privacy documentation will govern the corresponding transfer mechanisms for that processing. We encourage users to review those third-party notices where relevant.

    20. Legal document versioning and proof of acceptance

    For contractual and compliance purposes, the Services may maintain a document versioning and acceptance framework under which only one current version of each legal document type and language is intended to be active at a time. When a user accepts or re-accepts a legal document, we may record the document type, language, version, exact document URL, content hash, acceptance timestamp and related technical metadata described in section 16.3 above.

    Where changes are material - for example, changes that materially affect user rights or obligations, billing logic, processing purposes, legal bases, or the risk profile of the Services - we may require renewed acceptance before further access to relevant parts of the Services is allowed. Non-material or editorial changes may instead be implemented through publication of an updated version and related notice, as described in section 14 above.