ELEGG
Finance
Privacy

Privacy policy

Information on the processing of personal data via the eleggfinance.com website and the ELEGG FX client area, in accordance with articles 13 and 14 of Regulation (EU) 2016/679 (GDPR).

Last updated: 5 September 2026

1. Data controller

The controller of personal data collected via the eleggfinance.com website and the ELEGG FX client area is Elliot Alexis LEGGE, sole proprietor trading under the commercial name ELEGG CONSEIL and the brand ELEGG FINANCE, registered with the Brive Trade Register under number 842 848 442. No data protection officer (DPO) has been appointed, the organisation not being subject to this obligation under article 37 GDPR. For any question regarding your data:

Data-protection contact
contact@eleggfinance.com

2. Data collected

The data collected differs depending on whether you visit the public site or hold access to the client area:

  • Contact, demo or quote request form: name, business email, company, company registration number, phone (optional), currencies used, estimated annual volume, free-text message.
  • Client-area account: name, email, company, address, reporting currency. The password is managed by Supabase Auth and stored as a hash — it is never stored in clear text and we have no access to it.
  • Sign-in security: six-digit codes sent by email for two-factor authentication, and password-reset tokens. Both are stored only as a salted fingerprint.
  • Hedging activity data: currency requirements, positions, hedges and their settlements, projects and commercial margins, cash balances, bank counterparties. This is largely corporate data, but it may contain the names of individuals (a bank contact, the signatory of a transaction).
  • Documents uploaded to the client area: term sheets, broker confirmations, contracts and attachments, together with their filename and category.
  • FX alerts: email address, currency pair, level, direction and language, plus the date of the last notification so that you are never emailed more than once a day.
  • Subscription: billing details and payment method are collected and stored by Stripe. No card number passes through or is stored on our servers.
  • Technical data: IP address (anonymised by our hosting provider Vercel for abuse-protection purposes), browser user-agent, page visited. Traffic is measured with Vercel Web Analytics, which counts page views without setting any cookie and without keeping an identifier that would recognise you between visits: it is counting, not tracking. No advertising pixel and no tool such as Google Analytics or Meta Pixel is deployed.
  • Anonymised term-sheet corpus: when you upload a document on the Pricer page, we retain by default an anonymised version of the text (no company name, email, phone, bank account, registration number or address) to improve the pricing engine. You may opt out by ticking a box before upload. The identifiable original is never retained for this purpose: it is processed in memory and destroyed after extraction.

3. Purposes and legal bases

Data is processed for the following purposes and on the following legal bases:

  • To provide the client area, the valuations and the hedge monitoring — legal basis: performance of the contract (GDPR art. 6.1.b).
  • To answer a contact, demo or quote request — legal basis: pre-contractual measures (GDPR art. 6.1.b) or legitimate interest of the controller (GDPR art. 6.1.f).
  • To secure account access: two-factor authentication, rate limiting, sign-in logging — legal basis: legitimate interest (GDPR art. 6.1.f) and the security obligation (GDPR art. 32).
  • To send the FX alerts you requested — legal basis: consent (GDPR art. 6.1.a). Consent is collected by double opt-in: the alert stays inactive until the emailed link is clicked. It can be withdrawn at any time via the unsubscribe link in every message.
  • To read an imported document automatically in order to extract the terms of an FX transaction — legal basis: performance of the contract (GDPR art. 6.1.b). This reading uses a third-party artificial-intelligence service (see section 4).
  • To manage the subscription, collect payment and issue invoices — legal basis: performance of the contract (GDPR art. 6.1.b) and legal obligation (GDPR art. 6.1.c).
  • To improve the precision of the FX pricer — legal basis: legitimate interest (GDPR art. 6.1.f). The data actually retained is anonymised within the meaning of GDPR recital 26 and therefore no longer constitutes personal data. You nonetheless have an express right to object, exercisable before upload via a checkbox and at any time thereafter on simple request.
  • To meet our accounting and tax obligations — legal basis: legal obligation (GDPR art. 6.1.c).

4. Recipients and sub-processors

Your data is accessible to the controller and, where applicable, to persons he authorises. It is processed on his behalf by the following technical sub-processors, each bound by a data-processing agreement under article 28 GDPR:

Application hosting and traffic measurement
Vercel Inc. (US company; functions executed in Frankfurt)
Database and authentication
Supabase Inc. (US company; data hosted in Germany, European Union)
Transactional email
Resend (USA) — sign-in codes, FX alerts, acknowledgements
Subscription payment
Stripe Payments Europe Ltd (Ireland) and Stripe Inc. (USA)
Assisted reading of imported documents
Anthropic PBC (USA) — the document is sent for extraction and is not used to train any model
Anonymised corpus storage
GitHub Inc. (USA)

5. No sale of data

No personal data is sold, rented, exchanged or transferred to third parties for commercial or advertising purposes. The only third parties with access are the sub-processors listed above, acting on instruction and solely for the purposes described.

6. Transfers outside the European Union

Several of the sub-processors above are established in the United States. Each transfer is governed either by the sub-processor's adherence to the EU-US Data Privacy Framework (European Commission adequacy decision of 10 July 2023, OJ L 231 of 20.9.2023, p. 118) or by the standard contractual clauses adopted by the European Commission and included in its data-processing agreement. Details of the safeguard applicable to each sub-processor are available on request to contact@eleggfinance.com.

7. Retention periods

Client-area account
Duration of the contractual relationship, then 3 years
Hedging data and uploaded documents
Duration of the contractual relationship, then 5 years (limitation period)
Sign-in codes
10 minutes, then purged
Password-reset tokens
1 hour
FX alerts
Until unsubscribed, effective immediately via the link in every email
Contact-form data
3 years from last contact (CNIL recommendation)
Anonymised corpus
Retained until deletion is requested by the contributor
Technical access logs
1 year maximum
Traffic statistics
Aggregated data, with no individual identifier
Accounting and billing data
10 years (French Commercial Code)

8. Your rights

Under articles 15 to 22 GDPR, you have the following rights over your personal data at any time:

  • Right of access: obtain a copy of the data we process about you.
  • Right to rectification: have inaccurate data corrected.
  • Right to erasure (the 'right to be forgotten'): request deletion of your data, subject to overriding legal obligations.
  • Right to restriction of processing: have certain processing suspended.
  • Right to data portability: receive your data in a structured, machine-readable format.
  • Right to object: object, on grounds relating to your particular situation, to processing based on legitimate interest.
  • Right to withdraw consent at any time, without prejudice to the lawfulness of processing carried out before withdrawal.
  • Right to give directions on the fate of your data after your death (article 85 of the French Data Protection Act).

9. Exercising your rights

To exercise any of these rights, write to contact@eleggfinance.com explaining your request. We will respond within one month at most, extendable by two months if complex. Proof of identity may be requested if there is reasonable doubt about your identity.

10. Complaint to the CNIL

If you believe, after having contacted us, that your data-protection rights are not respected, you may lodge a complaint with the French Data Protection Authority (CNIL):

Postal address
3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France
Phone
+33 1 53 73 22 22
Website
www.cnil.fr/en/plaints

11. Data security

The site uses HTTPS on all pages. Access to the client area relies on two-factor authentication: the password is verified server-side, then a six-digit code is emailed; no session is opened until that second factor is validated. Passwords are managed by Supabase Auth and stored as a hash. Sign-in codes and reset tokens are stored only as a SHA-256 fingerprint salted with a deployment-specific secret. Database tables are protected by row-level security policies: each client can reach only their own data. Sign-in attempts and requests are rate-limited per address. Uploaded documents are stored in a private space accessible only to the owning client.

12. Policy updates

This policy may be updated to reflect service or regulatory changes. The last-updated date is shown at the top of this page. For substantial changes, account holders and those who have shared their contact details will be notified by email.