Privacy Policy
How we collect, use, share and protect your information — including the brokerage account data you choose to connect.
Last updated 24 August 2026 · Effective 24 August 2026
This policy describes actual system behaviour. It is not legal advice, and it should be reviewed by counsel licensed in your jurisdiction before you rely on it commercially.
1. Who we are
Warren Davis Data Systems (“Warren”, “we”, “us”) provides an institutional market-intelligence terminal. This policy applies to the Warren web application, desktop applications, mobile applications and the APIs that serve them (together, the “Service”).
For privacy questions, data-subject requests or security disclosures, contact privacy@warrendavisdata.com.
2. Information we collect
2.1 Information you provide
- Account information — name, work email address, and a password stored only as a salted hash. We never store your password in a recoverable form.
- Mandate profile — optional jurisdiction, mandate objective, risk budget and sector coverage, used solely to order what the terminal shows you first.
- Content you create — watchlists, alerts, saved briefings, trading-agent definitions and assistant conversations.
2.2 Brokerage information (only if you connect an account)
Brokerage connections are optional and are established through a third-party brokerage connectivity provider. When you connect an account:
- You authenticate directly with your brokerage, in the connectivity provider’s interface. Warren never receives, transmits or stores your brokerage username, password, MFA codes or security answers.
- Warren receives only the access tokens and identifiers that provider issues, plus the account data you authorise: account names and numbers in masked form, balances, positions, and order and transaction history.
- You may disconnect a brokerage at any time from within the terminal or from your brokerage. Disconnection revokes our access immediately.
2.3 Information collected automatically
- Operational logs — request paths, timestamps, response codes, latency and error traces, retained for security and reliability.
- Device and session data — IP address, browser or application version, and session identifiers.
- Usage of the assistant — the text of what you ask, and a record of the data retrieved to answer it, so that any answer can be audited back to its sources.
2.4 Voice
Voice is off unless you turn it on. When enabled, audio is carried and transcribed by third-party speech and language processing providers so that the assistant can act on it. We do not retain raw audio recordings. Transcripts are handled the same way as typed messages under this policy.
3. How we use information
- To operate the Service and show you the data and analysis you request.
- To display positions and performance from brokerages you have connected.
- To evaluate the alerts you configure and notify you when they fire.
- To authenticate you, secure accounts and prevent abuse.
- To diagnose faults and improve reliability and performance.
- To meet legal, regulatory and audit obligations.
We do not sell or share personal information as those terms are defined under the CCPA/CPRA, and we do not process it for cross-context behavioural advertising. We do not use your brokerage data, positions or holdings for advertising, and we do not disclose them to data brokers. Because we do not sell or share personal information, there is nothing to opt out of; if that ever changes we will say so here before it takes effect and provide the opt-out the law requires.
3.1 Lawful basis (EEA and UK)
Where the GDPR applies, we rely on: performance of a contract to provide the Service you have subscribed to, including brokerage connectivity and assistant responses; legitimate interests in securing the Service, preventing abuse and diagnosing faults; consent for voice, which is off until you enable it and which you may withdraw at any time; and legal obligation where we are required to retain or produce records. Where processing rests on consent, withdrawing it does not affect processing already carried out.
4. Automated processing and AI
Warren’s assistant sends the text of your question, and the market data retrieved to answer it, to third-party speech and language processing providers engaged by us under contract, for the purpose of producing the response you asked for.
- Do not paste material non-public information, personal data about third parties, or credentials into the assistant.
- We do not permit your content to be used to train third-party models where the provider offers that control, and we configure providers accordingly.
- Assistant output is informational. It is not investment advice and must not be treated as a recommendation.
5. When we share information
We disclose personal information to the following categories of recipient. Service providers are engaged under written contracts that limit them to processing it for the purpose shown; professional advisers are bound by their own duties of confidence.
| Category of recipient | Purpose | What is shared |
|---|---|---|
| Brokerage connectivity providers | Brokerage connection, positions, order routing | User identifier, connection tokens, order instructions you confirm |
| Speech and language processing providers | Assistant responses, voice transport and transcription | Your question text, the market data retrieved for it, and — while a voice session is active — the audio stream and session metadata |
| Cloud infrastructure and hosting providers | Running and delivering the Service | Data at rest and in transit |
| Payment processing | Billing and collection of fees | Billing contact and transaction records. Card details are entered with the processor and are not held by us |
| Email and notification delivery | Account, alert and service notifications | Email address and message content |
| Professional advisers and auditors | Legal, accounting and audit obligations | Only what the specific engagement requires |
Market data is obtained from exchange, regulatory and commercial market data sources; we do not disclose your personal information to them in order to retrieve it. Each figure in the Service shows the source it came from and the time it was retrieved.
A current list of subprocessors, naming each provider and its location, is available to customers and to prospective customers under a confidentiality agreement, on request to privacy@warrendavisdata.com, and forms part of our data processing agreement. We identify recipients by category in this public notice and by name in that list. Customers under a data processing agreement receive advance notice of a change of subprocessor and may object as that agreement provides.
We may also disclose information where required by law or valid legal process, to enforce our agreements, to protect rights and safety, or in connection with a merger or acquisition — in which case we will give notice before your information becomes subject to a different policy.
6. Retention
- Account and content — kept while your account is active, and deleted within 30 days of account closure unless we must retain it by law.
- Brokerage data — deleted within 30 days of disconnecting the brokerage or closing your account.
- Operational logs — retained up to 90 days.
- Records we are legally required to keep — retained for the period the applicable law requires.
7. Security
- Encryption in transit using TLS, and encryption at rest for stored data.
- Passwords stored only as salted hashes.
- Secrets held in a managed secret store, never in source control.
- Access to production data limited to personnel who need it, and logged.
- Orders cannot be submitted without a preview you saw and confirmed; the confirmation is cryptographically bound to the exact order you approved.
No system is perfectly secure. If you believe your account has been compromised, contact security@warrendavisdata.com immediately.
8. Your rights
Depending on where you live, you may have the right to access, correct, delete, port or restrict processing of your personal information, to object to processing, and to withdraw consent. Residents of the EEA and UK have these rights under the GDPR; residents of California have rights under the CCPA/CPRA, including the right not to be discriminated against for exercising them.
California residents also have the right to know the categories of personal information we collect and the categories of recipient to whom we disclose it for a business purpose. Those categories are set out in sections 2 and 5 above. We disclose the categories listed in section 5 for the business purposes stated there, and we do not sell or share personal information. Financial account information is treated as sensitive; we use it only to provide the Service you asked for and not for any purpose that would trigger a right to limit its use.
To exercise any right, contact privacy@warrendavisdata.com. We respond within 30 days, or tell you why we need longer. An authorised agent may act for you where the law allows, and we may need to verify the request against the account. You may also lodge a complaint with your local supervisory authority.
9. International transfers
We and our providers may process information in countries other than your own, including the United States. Where required, transfers rely on Standard Contractual Clauses or another lawful transfer mechanism.
10. Children
The Service is intended for professional and institutional users and is not directed to anyone under 18. We do not knowingly collect information from children.
11. Changes to this policy
We will post any change on this page and update the date above. For material changes we will give notice in the Service or by email before the change takes effect.
12. Contact
Warren Davis Data Systems · privacy@warrendavisdata.com
See also our Terms of Service.