Privacy Policy
Last updated: 28 August 2026.
1. Who processes data
This Policy covers eraperemen.info, user accounts, portfolio features, analytical bots, and related Era of Changes services.
Analytical Agency Era of Changes, LLC, 131 Continental Dr, Suite 305, Newark, DE 19713, USA (the “US Company”), is the sole provider of the Portfolio feature and the controller/record holder for portfolio storage, brokerage, exchange and crypto-account connections, portfolio analytics, alerts, and security for that feature.
Analytical Agency Era of Changes LLC (Kyrgyz Republic), TIN 02401202510122, 198 Akhunbaeva St., apt. 52, Leninsky District, Bishkek (the “Kyrgyz Company”), independently processes data for its own local contracts and payments where identified as the seller. The Kyrgyz Company does not provide the Portfolio feature, connect brokerage accounts, store or receive portfolio data or connection secrets, or act as their joint controller, processor, or subprocessor.
Where an organisation provides employee or end-client data for the Portfolio feature, only the US Company acts as processor under the DPA. An agreement with the Kyrgyz Company alone does not include portfolio storage or brokerage-account connection.
2. Data we process
- name, email, phone, language, country, profile, representative, and organisation information;
- account, subscriptions, purchases, support, communications, acknowledgements, and settings;
- IP address, device, browser, cookies, session identifiers, access and security logs;
- payment/refund status, amount, currency, and identifier. We do not store full payment-card details;
- portfolio data: broker/exchange, account name and masked identifier, base currency, connection and sync status;
- financial data: instruments, symbols, asset classes, positions, quantities, value, cost and market value, cash balances, transactions and cash movements, valuations, timestamps, and risk profile, only where enabled by the user or integration;
- connection data: pseudonymous user, account and connection identifiers at the integration provider, an integration token or other secret, status and service metadata. Secrets are kept in a separate protected broker-secret store; the operational database keeps only a secret reference, non-reversible digests and non-secret metadata;
- for organisations, authorised representative and company details and, where covered by the contract/DPA, portfolio data of employees or end clients.
We do not ask for online-banking or trading passwords and do not use a connection to place orders, withdraw funds, or hold assets. A connection must not be activated where the provider cannot technically limit it to the disclosed read-only scope.
3. Sources
Data comes from the user or corporate representative, the account interface and, when file import is available, files uploaded by that person (including CSV, OFX and QFX), the broker, crypto platform, exchange or aggregator selected by the user through its API, payment and app-store services, and service-generated records. Before an external account is connected, the interface identifies the provider, requested data scope, read-only mode, and a separate data-transfer confirmation.
4. Purposes and legal bases
We use data for registration and authentication; contract performance; portfolio display and synchronisation; allocation, risk, and performance calculations; analytics and alerts; support; payments and refunds; fraud prevention; service security; legal compliance; and handling claims.
Legal bases include steps to enter and perform a contract; legal obligations; legitimate interests in security and the defence of rights where not overridden by the individual; and separate consent for an optional broker connection, certain international transfers, or marketing where required. We do not disguise contract performance as compulsory “consent”.
5. Analytics, bots, and automated outputs
Analytical bots may retrieve a strictly limited data set for one user through an authenticated API to calculate indicators, detect deviations, and send alerts to that user or an authorised corporate user. One user's data is not used to answer another user. Outputs are informational, are not personalised investment advice, and cannot execute trades.
We do not make solely automated decisions that produce legal or similarly significant effects. If that changes, the relevant logic, consequences, safeguards, and right to human involvement will be disclosed before activation.
6. Recipients and processors
Where necessary, data may be handled by processors of the US Company: cloud and hosting providers; SnapTrade after the user actually enables the relevant connection; other selected brokerage/crypto API, market-data, email, support, analytics and security providers; professional advisers; and public authorities with lawful authority. The Kyrgyz Company is not a recipient of portfolio data. The current provider status, portfolio-processor and location list appears on the “Portfolio Data Processors” page.
A processor must act under contract and documented instructions, protect confidentiality and security, and use subprocessors only through the authorised process.
7. International transfers
The portfolio infrastructure is hosted in the Amsterdam region (Netherlands); some providers and one company are in the United States or other countries. We use an available lawful mechanism before transfer, such as contractual necessity, separate consent, an adequacy decision, or contractual safeguards. For EEA data, EU Standard Contractual Clauses and supplementary measures are used where required. Kyrgyz data is transferred in accordance with Article 89 of the Digital Code of the Kyrgyz Republic.
8. Retention and deletion
- operational portfolio data is retained while the portfolio feature is active or the data is required for the contract, then erased or anonymised;
- after provider-confirmed disconnection, new synchronisation stops and the active connection secret is deleted or revoked without undue delay; imported portfolio data remains until the user separately deletes it, the service ends, or another applicable deletion ground arises;
- account deletion initiates erasure of operational accounts, positions, transactions, valuations, and risk profile from active systems; records required by law, security, or legal claims are segregated, restricted and kept only as necessary;
- logs and technical records are kept only as long as needed for security, failure investigation, legal compliance and claims, then erased or anonymised;
- deleted data may temporarily remain in isolated backups until scheduled automatic replacement; it is unavailable to ordinary operations and restored only with the system after a disaster, after which the deletion request is applied again;
- tax, accounting, payment, and legal-claim records are retained separately for periods required by applicable law.
9. Security
Portfolios are separated from the shared WordPress database. Service access uses a private network, exact firewall rules, mutual TLS, and short-lived signed tokens. Existing portfolio values remain in their current protected environment, while automatic broker-connection secrets are isolated in a separate broker-secrets-only Vault that cannot access existing portfolio keys. The portfolio read service cannot access broker secrets. Owner access requires a separate short-lived assertion and is logged. Least privilege, backups, monitoring, and isolation tests are applied.
No system can promise absolute security. For a confirmed incident, we contain the impact, preserve evidence, and notify affected individuals and authorities within applicable legal deadlines.
10. Individual rights
Subject to applicable law, an individual may request information and a copy; correction; portability; restriction; erasure; object to processing; withdraw consent; learn the source and recipients; and complain to a data-protection authority or court. Withdrawal does not invalidate earlier lawful processing and may disable optional synchronisation. We verify requests to prevent disclosure to an impostor.
11. Organisations and third-party data
A corporate representative confirms authority and a lawful basis for any employee/end-client data, must provide the required notice, and must not upload excessive data. Before recurring or bulk processing of end-client data, the organisation enters a DPA with the US Company covering roles, instructions, security, subprocessors, rights assistance, return, and deletion. The Kyrgyz Company is not a party to that DPA.
12. Cookies and changes
Necessary cookies support login, security, and settings; analytics or marketing cookies follow applicable settings and legal bases. Material changes are posted with a new date and, where required, notified before effect or presented for renewed confirmation.
13. Contact
Data requests: admin@eraperemen.info. Include the account email and request; never send broker passwords or full card details. The Kyrgyz supervisory authority is the State Agency for Personal Data Protection under the Cabinet of Ministers of the Kyrgyz Republic.
Related documents: Account Connection and Portfolio Data Consent; separate Paid Automatic Connectivity Consent; Public Offer; Corporate Data Processing Addendum; Portfolio Data Processors list.