Privacy Policy
Last Updated: September 2026
1. Scope & Legal Framework
This Privacy Policy explains how the software project operating under the brand name Vylestack ("Vylestack," "Audit," "we," "us," or "our") collects, processes, stores, and protects personal data when you interact with the Audit software application, website, or infrastructure.
This document is structured to comply with applicable data protection legislation globally, including the Protection of Personal Information Act 4 of 2013 (POPIA) of South Africa, the General Data Protection Regulation (EU) 2016/679 (GDPR), and the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA).
By accessing or creating an account on Audit, you acknowledge the processing practices detailed in this policy. If you do not agree with any element of this policy, you must refrain from utilizing the platform.
2. Categories of Information Processed
We process only data necessary to deliver the features of Audit software:
2.1 Account Information
When you register, we collect basic account credentials including your email address, full name, and encrypted authentication hashes. Financial payment transactions are handled entirely by third-party payment gateways; we never receive or store raw credit card numbers or banking passwords.
2.2 User-Entered Trading Journal Data
To render performance charts, metrics, and behavioral analytics, Audit processes trade data that you manually upload. This includes asset names, order timestamps, entry/exit prices, position sizes, profit/loss metrics, and custom strategy tags.
2.3 Automated Device & Operational Telemetry
During user sessions, system logs automatically capture technical information such as IP addresses, session tokens, browser identifiers, operating system versions, and page request timestamps. This telemetry is strictly utilized for session authentication, rate-limiting, and error diagnosis.
3. Legal Bases for Processing
Under POPIA (Section 11) and GDPR (Article 6), we process your personal data under the following legal grounds:
- Contractual Performance: Processing account credentials and journal data is required to provide software functionality and account access as requested by you.
- Legitimate Interests: Analyzing system logs and telemetry allows us to maintain network security, prevent fraudulent activity, and debug application errors.
- Legal Compliance: Retaining basic accounting or billing audit trails where mandated by relevant financial or tax legislation.
- Consent: Where required for specific optional integrations or communications, which you can withdraw at any time.
4. Storage, Security & Encryption Protocols
We implement technical and organizational security controls designed to safeguard personal information against unauthorized access, loss, or alteration:
- Data transmitted between your client device and our servers is encrypted using Transport Layer Security (TLS 1.2+).
- Database records are stored in secure cloud environments protected by row-level access controls and AES-256 encryption at rest.
- Account credentials utilize cryptographic password hashing (bcrypt / Argon2); plain-text passwords are never recorded.
While we utilize rigorous encryption standards, no digital transmission over the internet or database storage system can be guaranteed to be completely immune to compromise. Users are responsible for maintaining strong account passwords and safeguarding their access credentials.
5. Data Retention & Purging Policies
We retain personal data only for as long as your account remains active or as needed to supply software services to you.
If you request account deletion or terminate your account, your personal information and associated trading records will be queued for permanent deletion from our active databases within thirty (30) days. Residual system backups are automatically overwritten according to standard backup retention cycles.
6. Third-Party Sub-Processors & Service Providers
We do not sell, rent, or monetize your personal information or trading data.
We engage third-party infrastructure providers solely to host, secure, and operate the platform (e.g., cloud hosting infrastructure, authentication infrastructure, database hosting, and payment gateways). These service providers act as sub-processors bound by contractual confidentiality and data protection agreements prohibiting them from using your data for independent purposes.
7. Cross-Border Transfers & Safeguards
Audit utilizes cloud infrastructure that may route or store data in secure data centers located outside South Africa or the European Economic Area (EEA).
When cross-border data transfers occur, we ensure compliance with POPIA Section 72 and GDPR Chapter V by utilizing service providers in jurisdictions with adequate legal protection levels or by enforcing standard contractual clauses and binding sub-processor obligations.
8. Statutory Data Subject Rights & Request Handling
Depending on your jurisdiction, you have statutory rights concerning your personal data:
8.1 POPIA & GDPR Rights
- Right of Access: Request confirmation and a copy of the personal data held about you.
- Right to Correction / Rectification: Request correction of inaccurate, misleading, or outdated information.
- Right to Destruction / Erasure: Request the deletion or destruction of your personal data where retention is no longer authorized.
- Right to Object: Object to processing based on legitimate interests on reasonable grounds.
8.2 CCPA / CPRA Rights (California Residents)
- Right to Know: Request disclosure of specific pieces and categories of data collected.
- Right to Delete & Correct: Request erasure or correction of personal information.
- Non-Discrimination: Equal service pricing and quality regardless of exercising statutory privacy rights.
To exercise any statutory privacy rights, please submit a written request to support@vylestack.co.za.
9. Information Regulator & Supervisory Complaints
If you believe our processing of your personal data infringes applicable protection laws, you have the statutory right to lodge a complaint with your local supervisory authority:
Information Regulator (South Africa)
JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
Complaints: POPIAComplaints@inforegulator.org.za
General Enquiries: enquiries@inforegulator.org.za
11. Limitation of Liability for Data Incidents
TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, VYLESTACK, ITS DEVELOPERS, AND OPERATORS SHALL NOT BE LIABLE FOR ANY INDIRECT, INCIDENTAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES ARISING FROM DATA TRANSMISSION DELAYS, UNAUTHORIZED THIRD-PARTY ACCESS RESULTING FROM COMPROMISED USER CREDENTIALS, OR HARDWARE FAILURE BEYOND OUR DIRECT CONTROL.
OUR TOTAL AGGREGATE LIABILITY FOR DIRECT CLAIMS ARISING UNDER THIS PRIVACY POLICY SHALL NOT EXCEED THE TOTAL FEES PAID BY YOU TO ACCESS AUDIT IN THE TWELVE (12) MONTHS PRECEDING THE INCIDENT.
12. Revisions & Contact Information
We reserve the right to amend this Privacy Policy to reflect technical updates, legal requirement changes, or service adjustments. When updates occur, the "Last Updated" date at the top of this document will be updated.
For questions or formal inquiries concerning this Privacy Policy, contact us at: