Record of Processing Activities (RoPA)
Controller: Vanquish AI B.V., the Netherlands. Contact: dpo@vqs.ai. This register records the processing activities carried out as controller.
Processing activities
| # | Activity | Purpose | Data subjects | Data categories | Legal basis | Recipients | Transfers | Retention |
|---|---|---|---|---|---|---|---|---|
| 1 | Account & authentication | Provide platform, login, security | Users | Name, email, password hash, MFA, IP | Contract (6(1)(b)) | Hosting, email provider | EEA (hosting); see #note | Account life + 30 days |
| 2 | Broker connection | Operate bots on user's broker | Users | Encrypted API tokens, broker account ID, status | Contract + explicit authorisation | Broker (Alpaca), hosting | Per broker | Until disconnect + 30 days |
| 3 | Strategy & bot config | Build, store, run strategies | Users | Strategies, parameters, risk settings | Contract (6(1)(b)) | Hosting | EEA | Account life |
| 4 | Trading activity & logs | Execution, monitoring, audit | Users | Signals, orders, fills, system logs | Contract; legitimate interest (audit) | Hosting, broker | EEA | 24 months |
| 5 | Billing & subscriptions | Take payment, invoicing | Paying users | Plan, payment reference, invoices | Contract; legal obligation (accounting) | Mollie, accounting | EEA | 7 years (tax) |
| 6 | AI features | Optional AI assistance in product | Users (who use feature) | Prompts/inputs the user submits | Contract; consent where applicable | Anthropic | US — SCCs | Per provider; minimised |
| 7 | Support | Respond to requests | Users | Correspondence | Legitimate interest / contract | Email/helpdesk | EEA | 24 months |
| 8 | Analytics (optional) | Improve site/product | Visitors who consent | Usage, device, pseudonymous ID | Consent (6(1)(a)) | Analytics provider | — | — |
| 9 | Security & abuse prevention | Protect platform & users | Users, visitors | IP, logs, device signals | Legitimate interest (6(1)(f)) | Hosting, security tooling | EEA | 12 months |
Security measures (all activities): encryption in transit and at rest, credential encryption & least-privilege scoping, access controls, isolation, logging, monitoring, backups, and incident response — see the Security Statement. Sub-processors and transfer mechanisms are detailed in the Sub-processor List.