Data Processing
Agreement

This Data Processing Agreement (“DPA”) forms part of the Terms of Service between Libertas Project Management – FZCO (“Processor”, “we”, “us”) and the user (“Controller”, “you”, “your”) and governs the processing of personal data in connection with the BTC Breakout service.

This DPA applies where we process personal data on your behalf and you are subject to data protection laws, including the EU General Data Protection Regulation (GDPR), UK GDPR, or equivalent laws.

1. Definitions

  • “Personal Data” means any information relating to an identified or identifiable natural person
  • “Processing” means any operation performed on Personal Data
  • “Data Subject” means the individual whose Personal Data is processed
  • “Sub-processor” means any third party engaged by us to process Personal Data
  • “Data Protection Laws” means GDPR, UK GDPR, and other applicable data protection legislation

2. Scope of Processing

2.1 Subject Matter

We process Personal Data solely to provide the BTC Breakout service as described in our Terms of Service and Privacy Policy.

2.2 Categories of Data Subjects
  • BTC Breakout users and account holders
2.3 Types of Personal Data
  • Contact information (name, email address)
  • Account credentials (encrypted)
  • Broker connection details (encrypted)
  • Trading activity and performance data
  • Usage data and interaction logs
  • IP addresses and device information
2.4 Duration of Processing

Processing continues for the duration of your subscription plus retention periods as specified in our Privacy Policy and as required by law.

3. Processor Obligations

We agree to:

  • Process Personal Data only on your documented instructions
  • Ensure personnel processing data are bound by confidentiality obligations
  • Implement appropriate technical and organizational security measures
  • Not engage Sub-processors without prior authorization (general or specific)
  • Assist you in responding to Data Subject requests
  • Assist you in meeting obligations under Data Protection Laws
  • Delete or return Personal Data upon termination (subject to legal requirements)
  • Make available information necessary to demonstrate compliance
  • Allow and contribute to audits conducted by you or your auditor

4. Security Measures

We implement security measures including:

  • Encryption of Personal Data in transit and at rest
  • Access controls and authentication requirements
  • Regular security assessments and penetration testing
  • Incident response procedures
  • Employee training on data protection
  • Secure backup and disaster recovery systems

5. Sub-processors

5.1 Authorized Sub-processors

You authorize our use of the following categories of Sub-processors:

CategoryPurposeLocation
Cloud HostingInfrastructure and data storageEU/US
Payment ProcessorsTransaction processingEU/US
Ttech Solutions Limited (trading as “Tradesync”)Broker connectivity and cloud-hosted trade execution infrastructureHong Kong
Analytics ServicesUsage analysis (anonymized)EU/US
Support ToolsCustomer serviceEU

Ttech Solutions Limited (trading as “Tradesync”), incorporated under the laws of Hong Kong with company number 2928825, with registered office at Unit 2A, 17/F Glenearly Tower, No 1 Glenealy, Central, Hong Kong, processes broker-connection data for the purpose of establishing and maintaining broker connectivity and cloud-hosted trade execution infrastructure.

Personal Data processed may include MT4 account number, trading password, broker server, connection status, and trade/execution data.

The trading password is a sensitive access credential to your broker account. It is encrypted in transit and at rest and is the primary focus of the supplementary technical and organisational measures referenced in Section 6.

5.2 New Sub-processors

We will notify you of any intended changes to Sub-processors at least 14 days in advance.

You may object to new Sub-processors by notifying us within 14 days of our notice.

If you object, we will work with you to find a resolution or, if no resolution is possible, you may terminate the affected services.

6. International Transfers

Personal Data may be transferred to and processed in countries outside the EEA and UK, including the United States, the United Arab Emirates, and Hong Kong, where the Company and certain Sub-processors operate.

Where Personal Data is transferred outside the EEA/UK, we ensure appropriate safeguards are in place, including:

  • EU Standard Contractual Clauses (SCCs), including Module 2 (Controller to Processor) where applicable
  • UK International Data Transfer Agreement (IDTA) or UK Addendum, as applicable
  • Transfer risk assessments where required
  • Adequacy decisions where applicable
  • Supplementary technical and organisational measures where appropriate

Ttech Solutions Limited (trading as “Tradesync”) is located in Hong Kong. Hong Kong does not currently have an EU or UK adequacy decision. For EEA Personal Data transferred to Hong Kong, the parties rely on EU Standard Contractual Clauses, Module 2 (Controller to Processor), as applicable. For UK Personal Data transferred to Hong Kong, the parties rely on the UK IDTA or UK Addendum as applicable.

Copies of relevant transfer mechanisms are available upon request, subject to appropriate redactions for confidentiality and security.

7. Data Subject Rights

We will assist you in responding to Data Subject requests to exercise their rights under Data Protection Laws, including rights of access, rectification, erasure, restriction, portability, and objection.

We will notify you promptly if we receive a request directly from a Data Subject.

8. Data Breach Notification

We will notify you without undue delay (and in any event within 72 hours) upon becoming aware of a Personal Data breach.

Notification will include:

  • Description of the nature of the breach
  • Categories and approximate number of Data Subjects affected
  • Likely consequences of the breach
  • Measures taken or proposed to address the breach

9. Audit Rights

Upon reasonable notice and no more than once per year (unless required by a supervisory authority or following a breach), you may audit our compliance with this DPA.

We may satisfy audit requests by providing relevant third-party audit reports or certifications.

Audits shall be conducted during normal business hours and shall not unreasonably interfere with our operations.

10. Data Deletion

Upon termination of the service agreement or upon your request, we will delete or return all Personal Data within 30 days, except where retention is required by law.

We will provide certification of deletion upon request.

11. Liability

Each party’s liability under this DPA is subject to the limitations of liability in the Terms of Service, except that such limitations shall not apply to the extent prohibited by Data Protection Laws.

12. Conflict

In the event of any conflict between this DPA and the Terms of Service, this DPA shall prevail with respect to data protection matters.

13. Governing Law

This DPA shall be governed by the laws specified in the Terms of Service, subject to mandatory data protection laws applicable to the processing of Personal Data.

14. Contact

For data protection inquiries:

Company: Libertas Project Management – FZCO
Product: BTC Breakout
Data Protection Contact: Available through dashboard
Website: btcbreakout.com