RS Trader Academy

Schools

Privacy notice

⚠ Not yet reviewed by a lawyer. This notice describes what we actually do today, and the legal review of it has been requested and has not come back. We have not carried out a data protection impact assessment: the law asks for one where processing is likely to be high risk to people, and an email address, a password hash and some practice trades against historical data is not that. If what we hold ever grows into it, we will do one and say so here.

Version 2026-08-10.

Who is responsible

Sigmalitics B.V., KvK 98029940, Moreelsehoek 180, 3511 EZ Utrecht, Netherlands, is the controller of the personal data described here. Write to support@sigmalitics.com about anything on this page. We have not appointed a data protection officer; we are not required to, and the address above reaches someone who can act.

What we hold, why, and on what basis

What Why we have it Lawful basis
Your email address on the alpha invitation list, before you register The alpha is invitation-only, so the list is what lets you in Legitimate interest in running a closed test
Email address, display name To identify your account and contact you about it Performance of the contract
Password, stored as a scrypt hash So you can sign in and nobody else can Performance of the contract
Session records (a token hash, when it was made, when it expires) To keep you signed in and to let you sign out everywhere Performance of the contract
Consent records (what you were shown, what you answered, when) To prove we asked properly Legal obligation
Lesson progress and badges The features themselves Performance of the contract
Practice decisions: tickets, journal entries, grades, challenge answers The practice environment is the product Performance of the contract
Practice orders relayed to a brokerage simulation, under a random reference that is not your name The simulated Live Desk, if you open one Performance of the contract
The same practice decisions, used as research data To study how traders read charts, and to improve the courses Your separate consent — see below
Feedback you send us: your note, the page you were on, your browser version, and any screenshot you paste To fix what is broken and decide what to build next, while this is an alpha Legitimate interest in improving the service
Payment records, if you buy tooling To take the payment and keep the books Contract, and tax law for the retention
Server logs, including IP address To keep the service up and to stop abuse Legitimate interest in security

We do not profile you for advertising, we run no advertising, and we sell your data to nobody. There is no analytics or tracking script on the site.

The research consent is separate, and refusing it costs you nothing

Your practice decisions are useful to research, and we ask for them separately rather than burying the question in these terms. Saying no changes nothing about what your account can do. You can change your mind at any time, in both directions, from your account settings. The details are in Using your practice decisions in research.

How long we keep it

Two honest limits on that. It is retention, not anonymisation — a screenshot shows whatever was on your screen when you pressed paste, and that can include your own name or address inside our own pages, which nothing we overwrite in a database can reach. And while your account is open, your reports and screenshots are yours: they are in the copy you can download, and you can ask us to delete them, at closure or afterwards, and we will. Please do not paste anything into a report you would rather we did not hold — the feedback box says so too. - Server logs: 90 days. - Sessions: deleted once expired or signed out. - Password-reset links: they stop working after 45 minutes or one use, whichever comes first, and the record is swept away after that. We never store the link itself, only a one-way fingerprint of it, so nobody reading our database could open one.

Who else sees it

Almost nobody, because there is no hosting company in this picture. We run the service on our own equipment in the Netherlands, so your account, your practice decisions and your consent records sit on hardware we control, and no third party is holding them on our behalf.

The one exception is if you buy something. Stripe takes the payment — you enter your card on Stripe's own page, never on ours, so we never hold your card number at all. Our contract is with Stripe Payments Europe, Limited in Ireland, and Stripe moves some payment data to the United States inside its own group; the transfer runs on the EU–US Data Privacy Framework, with the European Commission's standard contractual clauses behind it if that framework falls. If you never buy anything, Stripe never hears of you.

There is one more, and it is small. If you ask to reset a password, the mail carrying the link goes out through Namecheap, who host our own mailbox — the same route any email from us takes. They see the address and the message on its way, as any mail provider does. We use no marketing or newsletter service of any kind, so this is the only email we ever send you, and it only exists because you asked for it thirty seconds earlier.

And one that only applies if you open a Live Desk. That feature runs against Alpaca's brokerage simulation — a US company — and it is worth being precise about what they receive, because it is deliberately very little. We mint a random reference for your simulated account and open it under that, with placeholder contact details that belong to nobody. Your name, your email address and everything else about you stay on our machine. What Alpaca holds is that reference and the practice orders placed against it: they cannot tell who you are from it, and neither could anyone reading their records. The account is a simulation, holds no money and cannot hold any. Some of that data sits in the United States; because it contains no identifying detail of yours, there is nothing here to name a transfer mechanism for — and if that ever changes, this page changes before it does.

That is the whole list. If it ever grows, this page changes first.

Where it lives

In the Netherlands, on our own machines. Everything in the table above — your account, your lessons, your practice decisions, your consent records — stays inside the European Economic Area and is never copied out of it.

Payment data is the single exception, and it is described above: it goes to Stripe, and Stripe moves some of it to the United States under the transfer mechanism named there. That exception exists only for people who buy something. If we ever move anything else out of the EEA, this page will say so, and name the mechanism, before it happens.

The Live Desk is the near-miss worth explaining rather than glossing. Practice orders do reach a US company's simulation — but under a random reference and with no detail that identifies you, so what crosses is not personal data about you in the first place. We would rather set out that reasoning here than let you discover the arrangement and have to guess at it.

Cookies

We set none. Not one, not even a necessary one.

The lessons are plain pages that ask your browser to remember nothing. If you sign in, your session token is kept in your browser's own local storage rather than a cookie, which means it is never attached to a request you did not make. Signing out erases it, and it expires by itself after thirty days.

There is no consent banner because there is nothing to consent to: no analytics, no advertising, no third-party scripts, and nothing that follows you to another site.

Your rights

Two of them need no email at all. A copy of your data is a button on your account page: it downloads one file holding your profile, every consent answer, your lessons, your desks with their full journals, your drills, your backtests, your forward register and your simulated brokerage account with the orders placed on it. Two things are left out — the token for a live session and the token for a password reset — and the file says so itself, with the reason, because a copy that quietly omits something is worse than one that names what it omits. Deleting your account is a button on the same page.

For the rest — correcting something, objecting to a use, or anything the two buttons do not cover — email support@sigmalitics.com and we will answer within a month. Your account page also shows your consent history, and lets you withdraw the research consent, without asking anyone.

If we get it wrong, you can complain to the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl). We would rather you told us first.

Age

You must be at least 16 to hold an account. We do not knowingly hold data about anyone younger, and we delete it if we find it.

A note on what this data is

Information about someone's trading is treated by the Dutch regulator as sensitive in practice, even where it is not a special category under the AVG. We treat it that way: it stays inside the account and it is never published against your name. The practice environment holds no real money. Its Live Desk runs against a broker's simulation, which cannot hold or move real funds and is not an account you could ever deposit into — so there is nothing anywhere in this product that could move anyone's actual money.