1. About this policy
This Privacy Policy explains how CLFNCE OÜ (“Cleo,” “we,” “us,” “our”) collects, uses, shares, and protects personal data when you use the Cleo platform - available via cleo.finance, our iOS and Android apps, and any other interface we provide (together, the “Platform”).
Cleo is a company registered in Estonia under company number 17165857, with its registered office at Harju maakond, Tallinn, Kesklinna linnaosa, Järvevana tee 9, 11314, Estonia.
This policy applies in addition to our Terms of Use. Our processing of personal data is governed primarily by the General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”) and applicable Estonian data protection law. If you are a resident of certain US states, additional rights apply under your state’s privacy law - see Section 15.
Questions or requests about your personal data? Contact our Privacy Contact at hello@cleo.finance.
2. Our role: when we are a controller, when we are a processor
How Cleo handles your personal data depends on how you reached us - the same two paths described in our Terms of Use.
2.1 Prop firm partner users
If your Cleo account was created by a proprietary trading firm we partner with (a “Prop Firm Partner”) so you can use the Platform for their evaluation, challenge, or funded program:
- Your Prop Firm Partner is the controller of your trading data - your trading account configuration, simulated trades, performance metrics, and challenge progress.
- Cleo is a processor that handles that trading data on the Prop Firm Partner’s behalf, under a Data Processing Agreement entered into between Cleo and the Prop Firm Partner under Article 28 GDPR.
- For requests about how your trading data is collected and used (including access, deletion, correction, or portability requests), please contact your Prop Firm Partner first. If we receive such a request directly, we will direct you to your Prop Firm Partner.
2.2 Direct subscribers
If you signed up with Cleo directly - for backtesting, premium features, automated risk-management tools, or our partner discount portal - Cleo is the controller of your personal data and is responsible for it under the GDPR. You exercise your rights directly with us (Section 9).
2.3 What Cleo controls regardless of path
Regardless of how you reached us, Cleo is an independent controller for:
(i) Account-level data necessary to operate the Platform interface - login credentials managed via Auth0, session data, security and audit logs, and information about your use of the Platform;
(ii) Fraud-prevention and abuse-detection data - signals we collect and analyze to protect the Platform and our other users;
(iii) Direct communications with you - support tickets you file with Cleo, security or service notices we send you, and any communications between you and our team that fall outside the Prop Firm Partner relationship.
You may exercise rights regarding this data directly with Cleo at any time.
3. Personal data we collect
3.1 Account and identity data
- Name (where provided)
- Email address
- For OAuth sign-ins via Google or Facebook: we receive your name, email address, and a unique provider identifier from the OAuth provider, via Auth0. We do not receive your password from the provider.
For your responsibility for keeping any third-party authentication account (e.g. Google or Facebook) secure, see Terms of Use Section 5(a).
3.2 Authentication data
- We do not store your password. Authentication is handled entirely by Auth0 (Okta, Inc.) - see Section 6.
- Authentication logs (login attempts, IP address, device fingerprint, session times) are stored by Auth0 on our behalf.
3.3 Usage data
- IP address, browser type, device type, operating system version, app version
- Pages visited, features used, time on platform, referrer URL
- Application error logs that may include user or session context for diagnostic purposes
3.4 Mobile-device data
- Unique device identifiers (where provided by iOS / Android)
- App version, OS version
3.5 Biometric authentication (mobile only)
If you enable biometric login on the mobile app, biometric data (fingerprint, facial geometry) is stored only on your device, in the operating system’s secure enclave (iOS Secure Enclave or Android Keystore). Cleo never receives, stores, or has access to biometric identifiers. We only receive a yes/no signal from your device confirming that you authenticated successfully.
We do not perform biometric categorization or biometric identification within the meaning of the EU AI Act. The biometric authentication is a binary success/failure signal generated entirely on your device.
3.6 Trading-related data
- For Prop Firm Partner users: the trading account configuration (initial balance, challenge type, rules), simulated trades you make, performance metrics, and challenge progress. As described in Section 2.1, this data is processed on behalf of your Prop Firm Partner.
- For Direct subscribers: backtesting configurations, saved analyses, custom settings, simulated demo account activity. As described in Section 2.2, Cleo is the controller of this data.
3.7 Communications data
- Customer-support tickets, contact-form submissions, feedback you send us
- Email correspondence
3.8 Payment data
- For Direct subscribers: limited payment metadata (subscription tier, billing date, payment status). Cleo does not store full card numbers or bank details - these are held by Stripe (see Section 6).
3.9 Marketing data
- Email address and any preferences you give us, if you opt in to marketing emails (or where soft opt-in applies - see Section 14).
We do not knowingly collect any special-category personal data under Article 9 GDPR (such as data revealing racial or ethnic origin, political opinions, religious beliefs, health data, etc.). Please do not submit such data to us.
4. Why we process your data (legal bases under Article 6 GDPR)
| Purpose | Legal basis | Examples |
|---|---|---|
| Provide the Platform to you | Article 6(1)(b) - performance of a contract | Account creation, login, running the simulator, saving your work |
| Process payments and manage subscriptions | Article 6(1)(b) - performance of a contract | Stripe billing, refund handling |
| Comply with legal and regulatory obligations | Article 6(1)(c) - legal obligation | Tax records, sanctions screening, responding to lawful authority requests |
| Secure the Platform and prevent fraud or abuse | Article 6(1)(f) - legitimate interests | Authentication logs, abuse detection, blocking suspicious sign-ups |
| Improve the Platform and analyze usage | Article 6(1)(f) - legitimate interests | Aggregate analytics, error diagnostics, feature usage trends |
| Send marketing communications (new opt-in) | Article 6(1)(a) - consent | Newsletters, product announcements where you have opted in |
| Send marketing about similar products to existing customers (soft opt-in) | Article 6(1)(f) - legitimate interests, with PECR Reg 22(3) opt-out at every touch | See Section 14 |
| Process Prop Firm Partner user data on their behalf | Article 28 - processor role; the legal basis is held by your Prop Firm Partner | Trading data, performance metrics |
Legitimate-interest balancing. Where we rely on legitimate interests (security, analytics, soft-opt-in marketing), we have considered the impact on your privacy and concluded the processing is proportionate. We use technical measures (pseudonymization, IP truncation in analytics, data minimization) to reduce the impact. You can object to legitimate-interest processing at any time (Section 9.5).
Withdrawing consent. Where we rely on consent (new opt-in marketing), you can withdraw it at any time without affecting the lawfulness of past processing. Use the unsubscribe link in any marketing email or contact us.
5. Who we share your data with
5.1 Prop Firm Partners
For Prop Firm Partner users, your trading data is accessible to your Prop Firm Partner, who is the controller of that data (Section 2.1).
5.2 Service providers (processors)
We share data with third-party processors who help us operate the Platform. They process data only on our instructions and under written Data Processing Agreements (DPAs) under Article 28 GDPR. See Section 6 for the full list.
5.3 Legal and regulatory disclosures
We may disclose data if required by law, court order, or competent authority - for example, in response to law enforcement requests, tax authorities, or in connection with regulatory investigations.
5.4 Business transfers
If Cleo is involved in a merger, acquisition, sale of assets, or insolvency proceeding, your data may be transferred. We will notify you of any change in controller as required by GDPR. See also Terms of Use Section 15 (Assignment).
5.5 With your consent
For any other sharing, we will ask for your consent first.
We do not sell or rent your personal data to third parties for their own marketing purposes.
6. Our processors
| Processor | Purpose | Location of processing | Transfer mechanism |
|---|---|---|---|
| Auth0 (Okta, Inc.) | Authentication, password management, login security, MFA | EU + US | EU SCCs (Decision 2021/914) |
| Stripe Payments Europe Ltd. | Payment processing for Direct subscribers | EU primary processing + US subprocessors and parent group access | EU SCCs |
| Cookiebot (Cybot A/S) | Cookie consent management | EU (Denmark) | EU - no transfer |
| Google Analytics (Google Ireland Ltd.) | Aggregate website analytics | EU + US | EU SCCs + EU-US Data Privacy Framework |
| Microsoft Clarity (Microsoft Ireland Operations Ltd.) | Heatmaps, session replay (with PII redaction) | EU + US | EU SCCs + EU-US Data Privacy Framework |
| Brevo (Sendinblue SAS) | Transactional and marketing email | EU (France) | EU - no transfer |
| Contabo GmbH | Application hosting and core compute | EU (Germany) | EU - no transfer |
| Amazon Web Services EMEA SARL | Cloud hosting and storage | EU (Ireland - eu-west-1) | EU - no transfer |
| Cloudflare, Inc. | Content-delivery network, DDoS protection, IP-level traffic processing (Cloudflare receives only network-layer data - IP addresses and request metadata - and does not receive user identifiers such as email or account ID) | Global edge network (EU edges for EU traffic; US data plane) | EU SCCs + EU-US Data Privacy Framework |
We have signed Data Processing Agreements under Article 28 GDPR with each processor listed above, and we maintain Transfer Impact Assessments where transfers leave the EEA. Contact our Privacy Contact for details.
7. International data transfers
Some of our processors process or replicate data outside the European Economic Area (“EEA”) - primarily the United States. The categories of transfer are:
- Authentication and security: Auth0 (US-based parent; some logs replicated to US).
- Payments: Stripe (parent and certain subprocessors in the US).
- Analytics and product diagnostics: Google Analytics, Microsoft Clarity (US-based parents; data may be processed in the US).
- Content delivery and security:Cloudflare’s global edge network (EU edges for EU-originating traffic; US-based control plane).
We protect these transfers by:
(a) Standard Contractual Clauses (SCCs)- the European Commission’s 2021 SCCs (Decision 2021/914), which contractually impose EU-equivalent protections on the recipient;
(b) EU-US Data Privacy Framework certifications for transfers to certified US recipients (currently Google, Microsoft, Cloudflare);
(c) Transfer Impact Assessmentsin line with the European Data Protection Board’s recommendations, where we evaluate whether the destination country’s laws would undermine the SCCs;
(d) Data minimization- we transfer only what’s needed for the specific service.
If you would like a copy of the SCCs we use, contact our Privacy Contact.
8. How long we keep your data
We keep personal data only as long as we need it. After the periods below, we delete it or irreversibly anonymize it, except where law requires longer retention.
| Data category | Retention period |
|---|---|
| Account profile data (name, email) | While your account is active + 30 days (pending-deletion grace period) |
| Authentication logs (Auth0) | Up to 30 days |
| Usage logs (IP, device, app version) | 90 days |
| Application error logs (with user or session context) | 6 months |
| Analytics aggregates (Google Analytics) | 14 months |
| Customer-support communications | 2 years from last contact about the matter |
| Other communications sent to us (contact forms, feedback) | 2 years from receipt |
| Subscription and payment records | 7 years (Estonian Bookkeeping Act § 12, applicable accounting and tax law) |
| Marketing consent records | While consent is in force, plus 3 years after withdrawal (to evidence lawful past processing) |
| Trading data (Prop Firm Partner users) | Per the Prop Firm Partner’s instructions; default of deletion or anonymization within 30 days of the relevant agreement ending |
| Trading data (Direct subscribers) | While your account is active + 30 days; backtesting configurations you save are retained until you delete them |
| Biometric data | Never stored by Cleo |
| Cookies and similar | Per the relevant cookie’s lifetime - see our Cookie Policy |
Account deletion.When you delete your account, it enters a 30-day pending state during which it can be restored. After 30 days, your account and associated personal data are permanently deleted - except for records we are legally required to retain (e.g., payment records). The 30-day window does not extend our overall retention obligations under the GDPR’s right to erasure (Article 17); it is a recovery feature you can short-circuit by contacting our Privacy Contact if you want immediate erasure.
9. Your rights under the GDPR
You have the following rights regarding your personal data. To exercise any of them, email hello@cleo.finance. We will respond within one month of receipt (extendable by up to two further months for complex requests, with notice to you).
9.1 Right of access (Article 15)
Get a copy of the personal data we hold about you and information about how we process it.
9.2 Right to rectification (Article 16)
Correct any inaccurate or incomplete data we hold about you.
9.3 Right to erasure (“right to be forgotten” - Article 17)
Have your personal data deleted, subject to legal retention obligations. You can also delete your account directly from your account settings.
9.4 Right to restrict processing (Article 18)
Have us pause processing of your data while we resolve a dispute about its accuracy or our use of it.
9.5 Right to object (Article 21)
Object to processing based on legitimate interests (Article 21(1)). For processing for direct marketing(Article 21(2)), you have an absolute right to object - we’ll stop on request, no balancing test, and you can also use the unsubscribe link in any marketing email.
9.6 Right to data portability (Article 20)
Receive the personal data you provided to us in a structured, commonly used, machine-readable format and transmit it to another controller.
9.7 Right to withdraw consent (Article 7(3))
Withdraw consent for any processing based on consent. Doesn’t affect the lawfulness of past processing.
9.8 Right not to be subject to automated decisions (Article 22)
See Section 11.
9.9 Right to lodge a complaint
You can complain to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon):
- Website: https://www.aki.ee/
- Address: Tatari 39, 10134 Tallinn, Estonia
- Email: info@aki.ee
If you are a resident of another EU country, you can also complain to the supervisory authority in your country of residence.
If you are a UK resident, you can also complain to the UK Information Commissioner’s Office (ICO):
- Website: https://ico.org.uk/
9.10 Identity verification
To protect your data, we may ask you to provide information confirming your identity before we respond to a rights request - for example, by verifying that the request comes from the email address registered to your account. We use any such information only to verify your identity and do not retain it longer than needed for that purpose.
10. Cookies and similar tracking
We use cookies and similar technologies to operate the Platform, remember your preferences, secure your session, and analyze usage. Some cookies are essential and don’t require consent; others (analytics, marketing) require your consent under the ePrivacy Directive.
Manage your cookie preferences via the cookie banner or our Cookie Policy, which lists each cookie, its purpose, its provider, and its retention period. You can change your preferences at any time.
11. Automated decision-making and profiling
Cleo does not currently make decisions about you that produce legal or similarly significant effects based solely on automated processing. We do not use automated profiling to determine creditworthiness, eligibility, or pricing.
Some Platform features use algorithmic processing - for example, calculating performance statistics, detecting fraud or abuse signals, or generating analytical insights from your simulated trades. These are not “decisions” in the Article 22 GDPR sense because they do not produce legal effects on you and they do not affect your rights, status, or ability to use the Platform without human review.
In particular, if a fraud or abuse signal could result in the suspension or closure of your account, a human reviewer makes the final decision before that action takes effect, except where immediate action is required by law or to prevent imminent harm to other users or the Platform.
If we introduce features in the future that involve Article 22 automated decisions, we will update this policy and obtain the lawful basis required.
12. Children
The Platform is not intended for use by anyone under the age of 18. We do not knowingly collect personal data from anyone under 18.
At signup, we require you to confirm that you are at least 18 years old. We rely on this self-declaration as a measure proportionate to the nature of the Platform. If we become aware that a person under 18 has provided us personal data, we will delete it without undue delay; if you believe this has happened, please contact our Privacy Contact.
13. Security and breach notification
13.1 Security measures
We protect your personal data using technical and organizational measures appropriate to the risk, including:
- Encryption in transit (TLS 1.2 or higher)
- Encryption at rest for personal data in our primary databases
- Access controls, role-based access, and audit logging
- Regular security reviews and dependency monitoring
- Use of vetted processors with their own security certifications
We assess privacy risks on an ongoing basis and conduct Data Protection Impact Assessments where required under Article 35 GDPR.
No system is perfectly secure. We cannot guarantee absolute security, but we work continuously to reduce risk.
13.2 Breach notification - to the supervisory authority (Article 33)
If a personal data breach is likely to result in a risk to your rights and freedoms, we will notify the Estonian Data Protection Inspectorate within 72 hours of becoming aware of the breach.
13.3 Breach notification - to you (Article 34)
If a breach is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay. We will not be required to notify you individually if:
(a) we had appropriate technical protections in place (such as encryption) that made the data unintelligible to unauthorized parties;
(b) we have taken subsequent measures that ensure the high risk is no longer likely; or
(c) individual notification would involve disproportionate effort, in which case we will use a public communication or equivalent measure.
14. Marketing emails vs. transactional emails
We distinguish between three categories of email:
- Marketing emails to new contacts (consent basis). Newsletters, product announcements, and promotional content sent to people who have opted in (Article 6(1)(a) GDPR). You can withdraw consent at any time using the unsubscribe link in any marketing email or by contacting us.
- Marketing emails to existing customers about similar products (soft opt-in). Where you are a Direct subscriber and we send you marketing emails about products or features similar to those you already use, we may rely on the “soft opt-in” exemption under Regulation 22(3) of the UK Privacy and Electronic Communications Regulations and equivalent provisions in EU member-state ePrivacy law. We give you a clear opportunity to opt out (a) when we first collected your contact details and (b) in every marketing email we send. The legal basis is our legitimate interests, and you can object at any time (Section 9.5).
- Transactional and service emails (contract / legal obligation). Account notices, security alerts, billing receipts, important updates to these policies, and responses to your support requests, sent based on the contract between us (Article 6(1)(b)) or our legal obligations (Article 6(1)(c)). These are not marketing and we will continue to send them while you have an active account, regardless of your marketing preferences.
If you no longer wish to receive transactional emails, you can close your account (Section 8).
15. Additional information for US residents
This Section 15 applies if you are a resident of any US state with a comprehensive consumer privacy law (including, as of the date of this policy, California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Iowa, Delaware, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky, and Rhode Island, and any other state whose privacy law later enters into force) (collectively, “US State Privacy Laws”). It supplements - not replaces - the rest of this policy.
15.1 Categories of personal information we collect
In the 12 months preceding the effective date of this policy, we collected the following categories of personal information defined by the California Consumer Privacy Act / California Privacy Rights Act (“CCPA/CPRA”):
| CCPA category | Examples in our case |
|---|---|
| Identifiers | Name, email address, IP address, account/device identifiers |
| Customer records (Cal. Civ. Code § 1798.80) | Name, email, billing information |
| Internet or network activity | Pages visited, features used, referrer, session data |
| Geolocation | Approximate location derived from IP address (no precise GPS data) |
| Commercial information | Subscription tier, payment history (metadata only - full card data held by Stripe) |
| Inferences | Aggregate usage patterns and feature preferences derived from internet activity |
The purposes for which we collect this information are described in Section 4. The sources are: you (when you provide it), your device (when you use the Platform), and our processors listed in Section 6.
We do not collect “sensitive personal information” as defined under CCPA/CPRA (e.g., government IDs, financial account credentials, precise geolocation, racial or ethnic origin, religious beliefs, biometric identifiers used for identification, health data, sex life or sexual orientation). Biometric authentication, where used, occurs entirely on your device - see Section 3.5.
15.2 Sale and sharing of personal information
We do not sell your personal information for monetary or other valuable consideration, and we do not share your personal information for cross-context behavioral advertising, as those terms are defined under CCPA/CPRA.
We do not knowingly sell or share the personal information of consumers under 16.
15.3 Your rights as a US resident
Subject to verification of your identity (Section 9.10) and any exceptions under your state’s law, you have the following rights:
- Right to know - request the categories and specific pieces of personal information we have collected about you, the sources, the purposes, and the categories of third parties with whom we share it.
- Right to delete - request deletion of personal information we hold about you, subject to legal retention obligations.
- Right to correct - request correction of inaccurate personal information.
- Right to opt out of sale or sharing - although we do not sell or share personal information as defined above, you may still exercise this right; it will be confirmed and recorded.
- Right to limit use of sensitive personal information - although we do not collect sensitive personal information beyond what is described above, you may still exercise this right.
- Right to data portability - receive a copy of the personal information you provided in a portable, commonly used format.
- Right to opt out of profiling for decisions producing legal or similarly significant effects - although we do not currently engage in such profiling (see Section 11), you may still exercise this right.
- Right to non-discrimination - we will not discriminate against you (e.g., by denying service, charging different prices, or providing a different level of service) for exercising any of these rights.
To exercise any of these rights, email hello@cleo.finance. We will respond within the time period required by your state’s law (typically 45 days from receipt, with one possible extension).
15.4 Authorized agents
If you use an authorized agent to submit a request on your behalf, we may require: (a) signed written permission from you authorizing the agent, and (b) verification of your identity directly with us. We may deny requests from agents who do not provide proof that they have been authorized by you.
15.5 Notice of financial incentive
We do not offer any financial incentives in exchange for the collection, sale, or retention of personal information.
15.6 State-specific notes
- California:“Shine the Light” (Cal. Civ. Code § 1798.83) - California residents may request information about disclosures of personal information to third parties for those third parties’ direct marketing purposes. We do not make such disclosures.
- All US State Privacy Laws other than California: You generally have the right to appeal a refusal to take action on a privacy rights request. To appeal, reply to our refusal within 60 days, or email us at hello@cleo.finance with “Privacy Appeal” in the subject line. If your appeal is denied, you may contact your state attorney general.
16. Changes, version, and notices
Changes. We may update this policy from time to time. We will post the updated version with a new effective date. For material changes, we will provide at least 30 days’ advance notice before the new version takes effect:
- For Direct subscribers, we will notify you by email and via the Platform.
- For Prop Firm Partner users, we will notify you via the Platform; your Prop Firm Partner may also notify you separately.
If you do not accept the change, you can stop using the Platform and (for Direct subscribers) cancel your subscription.
Version. This Privacy Policy applies in the version posted on cleo.finance at the time of the relevant processing, except where amended in accordance with this Section 16.
Notices. For how Cleo gives notice to you and how you give notice to Cleo (including for purposes of exercising your rights under this Privacy Policy), see Section 15 of our Terms of Use.
17. Contact
For privacy questions, requests, or complaints:
- Email (Privacy Contact): hello@cleo.finance
- Postal address: CLFNCE OÜ, Harju maakond, Tallinn, Kesklinna linnaosa, Järvevana tee 9, 11314, Estonia
For complaints to a supervisory authority, see Section 9.9. For US state-specific complaints, see Section 15.6.