Privacy Policy
How Exatoshi AG processes personal data in connection with HyperAgent.
Key principle. HyperAgent is non-custodial software. We do not hold your private keys, seed phrases, or withdrawal-capable credentials. Trading funds remain in wallets and exchange accounts you control. This Policy should be read with our Terms of Service, Risk Disclosure, and Data Processing documentation.
Table of contents
1. Controller
The data controller for HyperAgent is Exatoshi AG, Riva Paradiso 30, 6900 Paradiso, Switzerland ("Exatoshi", "we", "us"). Contact for privacy matters: privacy@hyperagent.ch (copy legal@hyperagent.ch for formal notices).
2. Scope
This Policy applies to personal data processed when you visit hyperagent.ch and related domains, create an Account, use the Service, contact support, subscribe to newsletters, or interact with our marketing. It does not govern processing by third-party Exchanges (including Hyperliquid) or payment networks under their own policies.
3. Data We Process
Depending on how you use the Service, we may process:
- Identity and account data: email address, name if provided, authentication identifiers (including OAuth subject IDs), password hashes (never plaintext passwords).
- Commercial data: subscription tier, trial status, invoices, payment status, limited payment-method metadata from Stripe (we do not store full card numbers).
- Service configuration: agent settings, risk parameters, linked exchange public metadata, encrypted trade-only API credentials where you supply them.
- Operational logs: application logs, security logs, approximate IP address, user-agent, device/browser signals needed for security and diagnostics.
- Support communications: tickets, emails, and chat content you send us.
- Usage and product analytics: feature usage, funnel events, and performance metrics (where enabled and subject to cookie choices).
- Marketing data: newsletter subscription status and campaign engagement if you opt in.
We do not intentionally collect private keys, seed phrases, withdrawal-capable API keys, or government ID documents as a condition of standard self-serve use. If you paste secrets into support channels, delete them and rotate credentials immediately.
4. Purposes and Legal Bases
We process personal data for:
- Contract performance: creating and securing Accounts, delivering the Service, billing, and support (Swiss FADP legitimate processing / GDPR Art. 6(1)(b) where applicable).
- Legitimate interests: security, fraud prevention, service improvement, aggregated analytics, and defending legal claims — balanced against your rights.
- Legal obligations: accounting, tax, and regulatory requests where binding.
- Consent: non-essential cookies/marketing where required; you may withdraw consent without affecting prior lawful processing.
5. Non-Custodial Principle
Exatoshi does not custody digital assets. Balances and positions exist on third-party Exchanges or wallets you control. Trade execution uses permissions you grant via API Keys. Loss of Exchange access, key compromise, or market outcomes are outside the scope of personal-data custody described here; see the Terms and Risk Disclosure.
6. Sharing and Subprocessors
We share personal data only as needed with: (a) infrastructure and communications providers; (b) Stripe for payments; (c) analytics providers if enabled; (d) professional advisers under confidentiality; (e) authorities when legally required; (f) a successor in a corporate transaction. We do not sell personal data. Current subprocessors are listed at /legal/subprocessors.
7. International Transfers
Exatoshi is established in Switzerland. Data may be processed in the EEA, UK, US, or other countries by subprocessors. Where required, we use appropriate safeguards such as standard contractual clauses, adequacy decisions, or comparable Swiss-approved mechanisms.
8. Retention
- Account and profile data: for the life of the Account and a limited wind-down period after closure (unless longer retention is required).
- Billing and invoice records: typically up to 10 years under Swiss commercial/tax rules.
- Security and application logs: retained for operational and security periods (often 30–180 days, longer if investigating an incident).
- Support tickets: retained as needed to resolve issues and maintain service history.
- Marketing lists: until you unsubscribe or we purge inactive contacts.
9. Security
We apply administrative, technical, and organizational measures appropriate to risk, including TLS in transit, encryption of secrets at rest, access controls, audit logging, and least-privilege operations. No method of transmission or storage is perfectly secure; please use strong unique passwords and protect your Exchange keys.
10. Your Rights
Subject to Swiss FADP and, where applicable, GDPR/UK GDPR, you may request: access, rectification, erasure, restriction, portability, and objection to certain processing. You may lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC) or your local supervisory authority. To exercise rights, email privacy@hyperagent.ch from your Account email; we may need to verify identity.
11. Cookies
We use necessary cookies for authentication and security, and may use analytics or marketing cookies subject to your choices. Details: Cookie Policy.
12. Children
The Service is not directed to individuals under 18. We do not knowingly collect personal data from children. If you believe a minor has provided data, contact us for deletion.
13. Changes
We may update this Policy from time to time. Material changes will be indicated by updating the effective date and, where appropriate, by email or in-product notice. Continued use after the effective date constitutes acknowledgment of the updated Policy to the extent permitted by law.
14. Contact
Exatoshi AG — Privacy
Riva Paradiso 30
6900 Paradiso, Switzerland
privacy@hyperagent.ch
legal@hyperagent.ch
Trust Center: /legal
Document control: Privacy Policy v2.0 · Effective 26 July 2026 · © Exatoshi AG. All rights reserved.