Privacy Policy
Product: AuctionMarketTheory (NQ Edition) Data controller: AuctionMarketTheoryIndicator Established in: Argentina Contact for privacy matters: privacy@amtindicator.com Effective date: 31 August 2026 Last updated: 31 August 2026
0. Summary
| What we get | Where from | Why |
|---|---|---|
| Your email, country, order details | Paddle, when you buy | To deliver your licence and support you |
| Your licence key + a hardware/user identifier from your PC | The indicator itself, each time it starts | To check your licence is valid and not shared |
| Your IP address | Our licence provider's servers | Unavoidable part of any internet request; security |
| Whatever you write to us | Support emails | To answer you |
We do not see your card number. We do not see your trading account, your positions, your broker, your P&L, or your chart data. The indicator does not transmit market data or anything about your trading to us. We do not sell your data.
1. Who is responsible for your data
AuctionMarketTheoryIndicator, established in Argentina, is the data controller for the personal data described in this policy. "We" and "us" mean that provider.
Representative in the European Union. We have not appointed a representative under GDPR Article 27. Our processing of EU residents' data is occasional, is limited to what is needed to deliver and validate a software licence, involves no special categories of data, and is unlikely to result in a risk to your rights and freedoms — the conditions of the Article 27(2)(a) exemption. You can contact us directly at the address below, and you keep your right to complain to your own supervisory authority.
Paddle is a separate, independent controller for the payment side. Because Paddle.com is our merchant of record, Paddle collects and processes your payment data for its own purposes as a controller — including fraud prevention and its own tax and regulatory obligations — under Paddle's privacy notice. This policy covers what we do with the data we receive; it does not govern what Paddle does with the data you give it.
2. What personal data we collect
2.1 Purchase and account data (from Paddle)
When you buy, Paddle passes us the information we need to deliver the Product. That is typically:
- your email address;
- your name, if you provided one;
- your country and, where applicable, billing region for tax purposes;
- the plan purchased, the amount, currency, transaction/order ID and date;
- the status of the subscription (active, cancelled, refunded, chargeback).
We never receive your full card number, CVV or bank details. Those go to Paddle and its payment processors, not to us.
2.2 Licence validation data (from the indicator on your computer)
Every time the indicator loads on a chart, it contacts our licence provider (KeyAuth) over HTTPS to verify that your licence is valid. In that request it sends:
- your licence key;
- a hardware/user identifier — specifically, the security identifier (SID) of the Windows user account the platform is running under;
- the application name, owner ID and product version;
- a session identifier generated for that check.
We treat the hardware/user identifier as personal data. It is a value that uniquely and persistently identifies your Windows user account on your machine, and we use it to link a licence to a specific installation. Under the GDPR it is an online identifier within the meaning of Article 4(1), and we declare it as such rather than treating it as anonymous.
In addition, the licence provider's servers necessarily observe the IP address the request comes from, together with the date and time of each check, as is the case for any internet request.
**What the indicator does not send:** it does not transmit your chart data, market data, orders, positions, account balances, broker details, screenshots, keystrokes or files. It reads market data locally from your platform and draws on your chart; nothing about your trading leaves your computer through the Product.
2.3 Support data
If you contact us, we receive your email address, the content of your message, and anything you choose to include (for example log excerpts, screenshots or a licence key so we can find your order).
2.4 Website data
Our website is a static marketing page. It does not run analytics, advertising pixels or tracking cookies of our own, and fonts are self-hosted rather than loaded from a third-party CDN.
However:
- our hosting provider keeps standard server logs (IP address, user agent, requested URL, timestamp) for security and operational reasons;
- the Paddle checkout is loaded from Paddle's own servers when you open it, and Paddle sets its own cookies and collects its own device data at that point, as described in Paddle's privacy notice. That processing is Paddle's, not ours.
2.5 Crypto purchases
We do not accept cryptocurrency payments. All payments are processed by Paddle, and we collect no wallet address, transaction hash or other blockchain data.
3. Why we use it, and our legal basis (GDPR Article 6)
| Purpose | Data used | Legal basis |
|---|---|---|
| Deliver your licence key, the software and the manual | Email, name, order data | Contract — Art. 6(1)(b) |
| Validate your licence each time the Product runs | Licence key, hardware/user identifier, IP | Contract — Art. 6(1)(b) |
| Detect and prevent licence sharing, piracy and fraud | Licence key, hardware/user identifier, IP, validation history | Legitimate interests — Art. 6(1)(f): protecting our software from unlicensed use |
| Provide support | Support emails, order data | Contract — Art. 6(1)(b) |
| Manage renewals, cancellations, refunds and chargebacks | Order and subscription data | Contract — Art. 6(1)(b); legal obligation — Art. 6(1)(c) |
| Keep tax, accounting and transaction records | Order data | Legal obligation — Art. 6(1)(c) |
| Security and abuse prevention on our website | Server logs | Legitimate interests — Art. 6(1)(f) |
| Send product announcements and marketing emails | Email address | Consent — Art. 6(1)(a), or legitimate interests for service emails to existing customers where local law allows |
| Establish, exercise or defend legal claims | Any of the above | Legitimate interests — Art. 6(1)(f) |
Where we rely on legitimate interests, we have considered whether our interest is overridden by your rights, and we have limited what we collect to what the purpose actually requires. You can object to that processing — see §8.
We do not carry out automated decision-making that produces legal or similarly significant effects about you, other than the automatic acceptance or rejection of a licence key, which is a simple validity check and which you can always contest by contacting us.
4. Who we share it with
We share personal data only with the service providers we need to run the business, and only for that purpose. We do not sell personal data, and we do not share it with data brokers or advertisers.
| Recipient | What it receives | Role | Where |
|---|---|---|---|
| Paddle (Paddle.com Market Limited and affiliates) | Payment and order data | Independent controller — merchant of record | UK / EU / US |
| KeyAuth | Licence key, hardware/user identifier, IP, validation timestamps | Licence validation provider | United States (KeyAuth LLC) |
| Resend | Recipient email address and email content | Transactional email delivery | US |
| Vercel | Website server logs | Website hosting | US |
We may also disclose data where we are legally required to, or where necessary to establish, exercise or defend legal claims, or to protect our rights against fraud or unlawful use.
5. International transfers
We are established in Argentina, and our service providers are located in the United Kingdom, the European Union and the United States. This means personal data about EU/EEA users is transferred outside the EEA.
Transfers to Argentina are covered by an EU adequacy decision. The European Commission decided on 30 June 2003 that Argentina ensures an adequate level of protection for personal data (Commission Decision 2003/490/EC). Decisions adopted under the previous Directive "shall remain in force until amended, replaced or repealed by a Commission Decision" (GDPR Article 45(9)), and Argentina remains on the European Commission's current list of adequate jurisdictions. No additional safeguard is therefore required for transfers to us.
For transfers to providers in other third countries, we rely on the data processing terms each provider publishes. Paddle, Resend and Vercel publish data processing agreements incorporating the European Commission's Standard Contractual Clauses. Transfers to KeyAuth LLC are to the United States and are limited to the licence key, the machine/user identifier, the IP address and validation timestamps; we do not send it your name, email address or payment data.
6. How long we keep it
| Data | Retention |
|---|---|
| Order and transaction records | 10 years — the period required by tax and accounting law in Argentina |
| Licence key and associated hardware/user identifier | For the life of the licence, plus 12 months to handle reactivations, disputes and abuse investigation |
| Licence validation logs (IP, timestamps) | 12 months |
| Support correspondence | 24 months after the matter is closed |
| Marketing list | Until you unsubscribe, plus a suppression record so we do not email you again |
| Website server logs | Up to 30 days |
When a retention period ends, we delete the data or irreversibly anonymise it.
7. Security
We use HTTPS for all transmission of licence data, we do not store payment card data at all, and we restrict access to purchase records to the person who runs the business. Licence validation traffic is transmitted to our licence provider over an encrypted connection.
No system is perfectly secure. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours where required (GDPR Article 33) and inform affected users where the law requires it (Article 34).
8. Your rights
If the GDPR applies to you (you are in the EU or EEA), you have the right to:
- access the personal data we hold about you, and get a copy (Art. 15);
- have inaccurate data corrected (Art. 16);
- have your data erased in certain circumstances (Art. 17);
- restrict our processing in certain circumstances (Art. 18);
- receive your data in a portable, machine-readable format (Art. 20);
- object to processing based on our legitimate interests, including profiling (Art. 21);
- object at any time to direct marketing, absolutely and without needing a reason (Art. 21(2));
- withdraw consent at any time, where we rely on consent, without affecting the lawfulness of processing before withdrawal (Art. 7(3));
- lodge a complaint with a supervisory authority in your country of residence, place of work, or place of the alleged infringement (Art. 77).
How to exercise them: email privacy@amtindicator.com. We will respond within one month. We may ask you to confirm the email address used at purchase so we can find your records and be sure we are not disclosing someone else's data.
One practical limitation, stated honestly: if you ask us to erase your licence data while your licence is still active, we will not be able to keep validating it, and the Product will stop working. We will explain this before acting on such a request. We are also required to keep transaction records for tax purposes even after an erasure request, and we will retain only that minimum.
UK users: you have equivalent rights under the UK GDPR and may complain to the Information Commissioner's Office (ICO).
Users in the United States: we do not sell your personal information and we do not share it for cross-context behavioural advertising. If your state grants you consumer privacy rights, you may request access to or deletion of your personal information at the address below, and we will not treat you differently for asking.
Users in Argentina: you have rights of access, rectification, updating and suppression under Ley 25.326 de Protección de los Datos Personales, and may contact the Agencia de Acceso a la Información Pública.
9. Marketing emails
We will email you about your order, your licence and important product or security changes — these are service messages and you cannot opt out of them while you hold a licence.
We will only send you promotional emails if you have opted in, or where permitted by law for our own similar products to existing customers. Every promotional email includes a one-click unsubscribe. Unsubscribing does not affect your licence or your support.
10. Children
The Product is not intended for, and is not offered to, anyone under 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.
11. Cookies
Our own website does not set analytics or advertising cookies. The Paddle checkout, when you open it, sets cookies controlled by Paddle. If we add analytics or advertising technology in future, we will update this policy and — for EU/EEA and UK visitors — implement a consent mechanism before any non-essential cookie or similar technology is set.
12. Changes to this policy
We may update this policy. The current version is always at https://amtindicator.com/legal/privacy-policy, and the "Last updated" date shows when it changed. If we make a change that materially affects how we use your data, we will notify you by email or by a notice on the website.
13. Contact
AuctionMarketTheoryIndicator Argentina Privacy enquiries: privacy@amtindicator.com General support: support@amtindicator.com