1. Scope and responsible entity
This Privacy Notice applies to the EAJEE website, secure application and associated internal services operated by Password Technologies Private Limited (“Password Technologies”, “we”, “us” or “our”).
Password Technologies is responsible for determining the purposes and means of personal-data processing carried out through EAJEE, except where a third party independently determines how it processes information under its own terms.
EAJEE is an authorised internal platform. User accounts are created and administered by authorised administrators and are not available through unrestricted public registration.
2. Information we may process
Account and profile information
We may process your name, username, email address, mobile number, assigned role, permissions, account status and other information required to administer authorised access.
Authentication and security information
We may process password hashes, session identifiers, authentication events, login attempts, IP addresses, device or browser information, timestamps, security alerts and records of account or permission changes.
We do not need access to your plain-text account password after it has been set.
Broker and trading-integration information
Depending on the integrations enabled for an authorised user, EAJEE may process:
- broker user or account identifiers;
- API keys, access tokens and related integration credentials;
- broker profile information;
- holdings, positions, margins, orders and trade information;
- instrument, price and market-data records; and
- integration status, refresh events and error records.
Broker passwords, PINs, one-time passwords and similar credentials should not be shared with another user or entered into EAJEE unless the relevant authorised workflow expressly requires them.
Platform and operational information
We may process strategy labels, scores, state changes, research inputs, decision records, proposed actions, approvals, rejections, execution records, outcome classifications, comments, reports, exports and audit history.
Communications
We may retain messages, support requests, incident reports and other communications sent to us in connection with EAJEE.
3. How information is collected
Information may be obtained:
- from authorised administrators;
- directly from you;
- through your use of EAJEE and its security or audit mechanisms;
- from brokers, exchanges, market-data providers and connected services that you or the trading desk has authorised; and
- from systems used to host, secure, monitor or support the platform.
4. Purposes of processing
We process information for lawful purposes including to:
- create, manage and secure authorised user accounts;
- authenticate users and maintain active sessions;
- provide market, strategy, research and decision-support features;
- connect to authorised broker or data-provider services;
- display and reconcile positions, orders and trading information;
- support risk, operational and approval workflows;
- maintain audit trails and investigate incidents;
- improve system reliability and decision-review processes;
- provide support and communicate operational information;
- protect our systems, users and confidential information; and
- comply with applicable legal and regulatory obligations.
Where applicable law requires consent for a particular processing activity, we will seek consent through an appropriate notice or affirmative action.
5. Cookies and similar technologies
EAJEE uses cookies and similar browser mechanisms required for authentication, session continuity, security and cross-site request forgery protection.
Disabling essential cookies may prevent secure login or proper operation of the platform.
6. Sharing and access
Personal and operational information is accessible only to persons and providers who reasonably require it for authorised purposes. This may include:
- authorised directors, employees, developers and administrators;
- authorised members of the trading desk, subject to role-based access;
- hosting, infrastructure, security, communication and technical service providers;
- brokers, exchanges, market-data providers and connected services;
- professional advisers who are subject to confidentiality obligations; and
- government authorities, courts or regulators where disclosure is lawfully required.
We do not sell personal data or disclose it for third-party behavioural advertising.
7. Third-party services
Brokers, exchanges, market-data providers and other linked services may process information under their own privacy notices and terms. You should review the relevant provider’s documentation before authorising an integration.
EAJEE may display links or redirect users to third-party services. Password Technologies does not control the independent privacy practices of those services.
8. Data location and transfers
Information may be processed using infrastructure or service providers located in India or in other jurisdictions permitted under applicable law.
Where personal data is processed across jurisdictions, we will take reasonable steps required by applicable law and applicable contractual arrangements.
9. Security
We use administrative, technical and organisational safeguards designed to protect information against unauthorised access, alteration, disclosure, loss or misuse.
Safeguards may include:
- role-based access controls;
- authenticated sessions and password protection;
- restricted administrator access;
- logging and audit records;
- encrypted network connections where configured;
- backup, recovery and deployment controls; and
- incident investigation and access revocation procedures.
No system can guarantee absolute security. Authorised users must protect their credentials and promptly report suspected compromise.
10. Retention
We retain information for as long as reasonably necessary for authorised access, trading-desk operations, auditability, security, dispute resolution, backup recovery and compliance with applicable obligations.
Retention periods may differ depending on the nature of the data, the relevant account or integration, operational requirements and applicable law.
When information is no longer required, we may delete, anonymise, archive or restrict it, subject to lawful and operational retention requirements.
11. Your requests and rights
Subject to applicable law and any lawful retention requirements, you may contact us to:
- request information about personal data processed about you;
- request correction of inaccurate or incomplete personal data;
- request erasure of personal data that is no longer required;
- withdraw consent where processing depends on consent;
- raise a grievance concerning personal-data processing; or
- report suspected unauthorised access or a personal-data breach.
We may need to verify your identity and authority before acting on a request. Certain information may need to be retained for security, audit, contractual or legal purposes.
12. Data-breach and security reporting
Suspected credential compromise, unauthorised access, disclosure, loss or misuse of personal or trading information should be reported immediately using the contact details below.
We will assess reported incidents and take reasonable steps, including notifications where required by applicable law.
13. Changes to this Notice
We may update this Notice to reflect changes in EAJEE, its integrations, internal operations or applicable requirements. The revised version and effective date will be published on this page.
14. Privacy and grievance contact
Password Technologies Private Limited
126, Villa Greens, Gandipet,
Hyderabad - 500075
Privacy, legal and grievance email: chakravarthi.akiri@passwordtechnologies.in