Privacy Policy

How we handle and protect your data

Our Commitment to Your Privacy

At Awalyt, we believe in complete transparency about how we collect, use, and protect your data. This policy explains everything in clear, approachable language.

Privacy Policy

Last updated: October 2025

This Privacy Policy explains how Awalyt ("we," "us," or "our") collects, uses, stores, and protects your personal data when you use our website, platform, and related services (collectively, the "Platform").

We are committed to handling your data responsibly, transparently, and in compliance with all applicable data protection laws, including the EU General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and the Personal Information Protection and Electronic Documents Act (PIPEDA).

By creating an account or using Awalyt, you agree to this Privacy Policy.


1. Who We Are

The Platform is operated by Melillo Srl (company name to be confirmed), based in Naples, Italy.

For privacy-related matters, you can contact us at: Email: privacy@awalyt.com

We act as the Data Controller for the personal data we collect directly from you.

Governing law: Italy


2. Information We Collect

We collect personal and technical data to provide, improve, and secure the Awalyt Platform. We only collect the minimum amount of data necessary to operate effectively.

A. Information you provide directly

When you use Awalyt, you may provide:

  • Account Information: name (if provided), email address, and password.
  • Portfolio and Backtest Data: the data you upload or create (e.g., assets, allocations, simulations).
  • Survey and Feedback Data: optional responses to user surveys or feedback forms.
  • Support Requests: information shared when contacting our team for help.

B. Information collected automatically

When you access the Platform, we automatically collect:

  • Usage data: actions performed in the app, pages visited, features used, session duration.
  • Device data: IP address, browser type, operating system, and general location (country or region).
  • Cookies and analytics: information gathered via cookies or similar technologies for analytics and performance tracking.

C. Payment and billing

All payment information is processed exclusively by Stripe, Inc. Awalyt does not store or have access to your credit card details. Stripe processes payments according to its own Privacy Policy.


3. Purpose and Legal Basis for Processing

We process your personal data only when there is a lawful reason to do so.

PurposeLegal BasisDescription
Account creation and managementPerformance of a contractTo provide you access to the Awalyt Platform and manage your account.
Service improvementLegitimate interestTo understand how the Platform is used and improve user experience.
Customer supportPerformance of a contractTo answer questions and resolve technical issues.
Analytics and performance monitoringConsentWe use cookies and Google Analytics to analyze usage trends and performance.
Communication and surveysConsentTo send optional surveys and collect feedback.
Legal compliance and protectionLegal obligationTo comply with applicable laws or respond to lawful requests.

You may withdraw your consent at any time (for example, by disabling cookies or unsubscribing from communications).


4. Cookies and Analytics

Awalyt uses cookies and similar technologies to:

  • Keep you signed in and maintain secure sessions.
  • Remember preferences and language settings.
  • Analyze traffic and understand how users interact with the Platform, so we can improve its design and performance.

We currently use Google Analytics for these purposes. Analytics cookies collect aggregated and anonymized information such as page visits, time on site, and general geographic distribution (for example, number of users per country).

IP addresses are anonymized before storage or processing, and ad-personalization features are disabled. Analytics data may be transferred to the United States and processed under Standard Contractual Clauses (SCCs) approved by the European Commission.

When you first visit the site, you'll see a short notice informing you that cookies are used for analytics and functionality. You can disable cookies in your browser settings at any time, but some parts of the Platform may not function correctly without them.


5. Data Storage and Security

We store data on Supabase cloud servers. Supabase hosts data in the European Union whenever possible; otherwise, data may be processed in other regions that provide adequate protection under GDPR through standard contractual clauses.

Security Measures

We protect your data using:

  • HTTPS encryption for all connections.
  • Hashed and salted passwords.
  • Access controls that limit employee and third-party access.
  • Regular security monitoring and backups.

While we take all reasonable precautions, no method of transmission or storage is 100% secure. You acknowledge that you use the Platform at your own risk, and Awalyt cannot be held liable for security breaches beyond our reasonable control.


6. Data Retention

We retain your personal data as long as your account is active or as needed to provide the service.

You can delete your account at any time, and all associated personal data and portfolio data will be permanently removed from our systems within a reasonable period.

Backups containing deleted data may exist temporarily but are automatically purged. We may retain minimal records if required by law (e.g., tax or accounting obligations for paid users).


7. Data Sharing and Third-Party Processors

We never sell your personal data.

However, we rely on a limited number of trusted third-party providers to operate Awalyt:

Third PartyPurposeData ProcessedLocation
SupabaseDatabase hosting and authenticationAccount data, portfolio dataEU or other GDPR-compliant regions
StripePayment processingBilling data, email, name (Pro users only)USA / EU
Google AnalyticsUsage analyticsCookies, IP, usage dataUSA (with SCCs)

All third parties are bound by data processing agreements (DPAs) ensuring compliance with GDPR and equivalent standards.


8. International Data Transfers

Because some of our providers are based outside the European Economic Area, personal data may be transferred internationally.

Whenever we transfer data outside the EU, we rely on:

  • Adequacy decisions issued by the European Commission, or
  • Standard Contractual Clauses (SCCs) ensuring equivalent data protection.

We always aim to store and process user data within the EU whenever technically possible.


9. Your Rights

If you are located in the EU or other jurisdictions with privacy laws, you have the following rights:

  • Access: Request a copy of your personal data.
  • Correction: Ask us to fix inaccurate or incomplete data.
  • Deletion: Request that we delete your data and account.
  • Portability: Obtain your data in a structured, machine-readable format.
  • Restriction: Ask us to limit how we use your data.
  • Objection: Object to processing based on legitimate interests.
  • Withdraw consent: For cookies, analytics, or communications.

To exercise these rights, contact us at privacy@awalyt.com. We may need to verify your identity before acting on your request.

If you believe we have mishandled your data, you can also lodge a complaint with your national data protection authority. In Italy, this is the Garante per la Protezione dei Dati Personali (www.garanteprivacy.it).


10. AI and Automated Processing

Awalyt may in the future integrate AI-powered tools to support portfolio analysis or offer insights. These systems will not make automated decisions that produce legal or significant effects on users. Any AI features will operate transparently, with users retaining full control over their decisions and portfolios.


11. Aggregated and Anonymized Data

We may analyze aggregated and anonymized data (e.g., general usage statistics) to understand platform performance and improve our services. This data does not identify individuals and is excluded from personal data regulations.


12. Children's Privacy

Awalyt is not intended for use by anyone under the age of 18. We do not knowingly collect data from minors. If you believe a minor has provided us with personal information, please contact us immediately and we will delete it.


13. No Financial Advice

Awalyt provides analytical and educational tools to help users explore investment strategies. We do not provide personalized financial advice, and nothing on the Platform should be interpreted as such. You are solely responsible for your investment decisions. Awalyt shall not be held liable for any financial loss resulting from use of the Platform or its outputs.


14. Liability Limitation

While we implement strict data protection and security standards, Awalyt cannot guarantee absolute security of information transmitted over the internet. We are not responsible for damages or losses resulting from unauthorized access, cyberattacks, or user error beyond our reasonable control.


15. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect new features, legal requirements, or changes to our data practices.

If we make significant changes, we will:

  • Notify you by email (if you have an account), or
  • Display an in-app or on-site notification before the changes take effect.

The latest version will always be available at www.awalyt.com/privacy.


16. Contact Us

If you have questions or requests about this Privacy Policy, please contact us at: Email: privacy@awalyt.com


Summary

  • We collect only what's necessary.
  • We use it to run and improve Awalyt.
  • We never sell your data.
  • You remain in full control of your information.
  • You can delete your data or account at any time.

Awalyt exists to help you make informed investment decisions with clarity and confidence — and that includes transparency about how your data is handled.

Questions about your data?

We're here to help. Contact us anytime about privacy concerns or data requests.

Contact Privacy Team