Privacy Policy
Last reviewed: August 2026 · applies to samurex.com and every Samurex AI service
1. Who we are and what this covers
Samurex AI ("Samurex AI", "we", "us") operates samurex.com and licenses algorithmic trading software on a subscription basis. We are a technology provider. We are not a broker-dealer, investment adviser, fund manager, bank or payment institution, and we have neither custody of nor access to the money in your brokerage account.
This policy applies whenever you browse our website, correspond with our team, book a consultation, or hold a Samurex AI subscription. It is written to satisfy the EU and UK General Data Protection Regulation, the California Consumer Privacy Act as amended by the CPRA, and comparable regimes elsewhere. If you disagree with anything here, please stop using the site and tell us so we can delete what we hold.
2. What we collect
Information you hand us
Your name, email address, telephone number and country, plus anything else you choose to write in a message or say on a call that we record in our notes. If you subscribe, we also hold the identifiers our payment processor returns to us.
Information your browser hands us
Like every website, our servers log technical detail as you read: IP address, approximate region derived from it, browser and operating system, device class, the pages you open, how long you stay, the referrer that sent you and the link you leave by.
Information from cookies and campaign tags
We use cookies, tracking pixels and UTM parameters to measure traffic and advertising. The full inventory, the retention period for each, and every opt-out available to you live in our Cookie Policy.
What we deliberately never collect
We do not ask for and do not store your broker login password, your two-factor codes, your full payment card number, or a copy of your account statements. Trading capital stays in your own brokerage throughout, and subscription payments run through specialist processors who hold the card details, not us.
3. Why we hold it, and on what legal basis
- To run the service — activating engines, administering your subscription, answering support requests. Legal basis: performance of our contract with you.
- To talk to you — replying to enquiries, sending service and security notices, arranging the consultations you ask for. Legal basis: contract, or our legitimate interest in responding to people who write to us.
- To improve the product — studying aggregate usage so we can fix what is confusing and prioritise what is missing. Legal basis: legitimate interest, balanced against your rights.
- To market, where you have said yes — offers and updates. Legal basis: your consent, withdrawable at any time; every marketing email carries an unsubscribe link that works.
- To stay lawful — record-keeping obligations, enforcing our terms, preventing fraud and abuse. Legal basis: legal obligation, and legitimate interest in security.
4. Who else sees it
We do not sell personal information, and we do not share it with data brokers. We do rely on service providers who process data on our behalf under written contract: hosting and infrastructure, email delivery, analytics, customer support tooling and payment processing. Each is bound to use the data only to provide their service to us.
We will also disclose information where the law requires it — a valid court order, a regulatory demand, or the investigation of fraud — and to a buyer or successor if the business is sold, in which case this policy travels with the data.
5. Where the data goes
We operate in Europe, North America and Australia, so personal data may be transferred to and stored in countries other than your own. Where data leaves the UK or EEA we rely on adequacy decisions where they exist and on Standard Contractual Clauses where they do not, together with encryption in transit and at rest.
6. How long we keep it
- Enquiries that do not become subscriptions: up to 24 months, then deleted.
- Subscriber records: for the life of the subscription and for as long afterwards as tax and company law require, typically six to seven years.
- Web analytics: aggregated or deleted within 26 months.
- Marketing consent records: retained as proof of consent until you withdraw it, plus a short period afterwards.
7. Your rights
Depending on where you live you may have the right to: obtain a copy of the personal data we hold about you; correct it; have it deleted; restrict or object to how we use it; receive it in a portable format; withdraw consent; and, in California, know what categories we have collected and disclosed and opt out of any "sale" or "sharing" (we do neither). You will never be treated differently for exercising any of these.
To use any of them, write to [email protected]. We reply within one month and will ask for enough information to be confident you are who you say you are. If our answer does not satisfy you, you may complain to your national data-protection authority.
8. Security
We use encryption in transit, encryption at rest for credentials, access controls on a need-to-know basis, and logging of administrative access. Broker API credentials are stored encrypted and are usable only by the execution layer. No system is perfect, and anybody who tells you theirs is has stopped paying attention; if a breach affects your rights we will notify you and the relevant regulator within the periods the law sets.
9. Children
Our services are for adults. We do not knowingly collect data from anybody under 18, and we delete it promptly if we discover we have.
10. Changes and contact
We may update this policy. The review date at the top always identifies the current version, and material changes are announced by email or an on-site notice. Questions, requests and complaints all go to the same place: [email protected].
