Privacy & Data Protection
Global Compliance Protocol // Forneus Technologies
This document governs the collection, processing, storage, and protection of personal data across the entire Forneus Technologies ecosystem — including KAIROS, GARM, PHANES, ELIGOS, and AUTHENTICATOR platforms.
Document Version: 3.1.0 // Effective: March 1, 2025 // Last Reviewed: March 5, 2025
Data Controller & Legal Entity
Legal Entity: Forneus Technologies (hereinafter “Forneus Technologies”, “We”, “Us”, “the Company”).
Data Protection Officer (DPO): oleksandr.l@forneus.io
Scope of Application: This Privacy Policy applies to all personal data processed by Forneus Technologies through:
- The corporate website (forneus.io) and all subdomains
- KAIROS — Autonomous Neural Trading Ecosystem
- GARM — Zero-Knowledge Encrypted Communication Platform
- PHANES — Decentralized Identity & Authentication Framework
- ELIGOS — Autonomous Defense & Tactical Intelligence System
- AUTHENTICATOR — Hardware-Bound Multi-Factor Authentication Module
- All APIs, SDKs, cloud services, and infrastructure operated by Forneus Technologies
Lawful Grounds Under GDPR Art. 6 & Art. 9
We process personal data exclusively under the following legal bases as defined by Regulation (EU) 2016/679 (GDPR):
| Legal Basis | GDPR Article | Data Categories | Purpose |
|---|---|---|---|
| Contractual Necessity | Art. 6(1)(b) | Account credentials, trading parameters, license keys | Service delivery for KAIROS, GARM, PHANES, ELIGOS |
| Legitimate Interest | Art. 6(1)(f) | Usage analytics, performance telemetry, error logs | System improvement, fraud detection, security hardening |
| Legal Obligation | Art. 6(1)(c) | Transaction records, compliance audit trails | AML/CFT compliance, tax reporting obligations |
| Explicit Consent | Art. 6(1)(a) | Marketing communications, optional telemetry | Newsletters, product announcements (opt-in only) |
| Special Categories | Art. 9(2)(a) | Biometric identifiers (AUTHENTICATOR) | Hardware-bound authentication; processed exclusively in device Secure Enclave |
Balancing Test (Art. 6(1)(f)): Where we rely on legitimate interest, we conduct and document a Legitimate Interest Assessment (LIA). You may request a copy of any LIA by contacting our DPO.
Comprehensive Data Inventory
The following details every category of personal data processed across the Forneus Technologies ecosystem:
3.1 — Cross-Platform Data (All Products)
| Data Type | Storage | Encryption | Retention |
|---|---|---|---|
| Email address | Firebase Auth (Cloud) | TLS 1.3 in transit, AES-256 at rest | Until account deletion + 30 days |
| Hashed password | Firebase Auth (Cloud) | Argon2id hashing | Until account deletion |
| IP address | Server logs (ephemeral) | Anonymized after 24h | 24 hours raw; 90 days anonymized |
| Device fingerprint | Local + Cloud | SHA-256 hash only | Duration of active session |
3.2 — KAIROS (Neural Trading Ecosystem)
| Data Type | Storage | Encryption | Retention |
|---|---|---|---|
| MT5 broker credentials | Local device only | AES-256-GCM, Hardware Keystore | User-controlled; wiped on uninstall |
| Trading history | Cloud sync (Firebase) | TLS 1.3 + AES-256 at rest | Active subscription + 6 months |
| AI conversation context | Local Vector DB | AES-256, device-bound key | User-controlled; never uploaded |
| Voice commands (Vosk/Whisper) | RAM only (ephemeral) | N/A — never stored | <2 seconds |
| Screen analysis (YOLO) | VRAM only | N/A — never stored | Duration of frame processing |
| Psychographic profile | Local encrypted DB | AES-256 / ISO 27001 | Never leaves device |
3.3 — GARM (Encrypted Communications)
| Data Type | Storage | Encryption | Retention |
|---|---|---|---|
| Message content | End-to-End Encrypted | Double Ratchet + X3DH + AES-256-GCM | User-controlled; Burn-on-Read available |
| Message metadata | Zero metadata policy | N/A — not collected | Not retained |
| Key exchange material | Local Secure Element | X25519 + Kyber-1024 hybrid | Ephemeral; rotated per session |
3.4 — PHANES & AUTHENTICATOR
| Data Type | Storage | Encryption | Retention |
|---|---|---|---|
| Biometric templates | Device Secure Enclave (TEE) | Hardware-isolated; Forneus Technologies receives pass/fail only | Managed by OS; Forneus Technologies has zero access |
| TOTP/HOTP secrets | Hardware Security Module | TPM-bound, non-extractable | Until user revocation |
| Recovery seed phrases | User responsibility only | Never transmitted to Forneus Technologies | Forneus Technologies has zero knowledge |
3.5 — ELIGOS (Tactical Intelligence)
| Data Type | Storage | Encryption | Retention |
|---|---|---|---|
| Tactical operation parameters | Air-gapped local system | AES-256-GCM + ChaCha20-Poly1305 | Mission duration only; auto-wiped |
| Sensor/telemetry feeds | Edge device VRAM | Processed in-memory; never persisted | Real-time only |
| Operator credentials | Hardware Security Module | TPM-sealed, non-exportable | Operator assignment period |
Military-Grade Protection Framework
Forneus Technologies implements a 7-layer defense architecture to protect all personal data:
- Layer 7 — Post-Quantum Encryption: Kyber-1024 + X25519 hybrid key exchange; AES-256-GCM symmetric encryption.
- Layer 6 — Zero-Knowledge Authentication: TPM-bound biometric fusion with neural risk scoring.
- Layer 5 — Hardware-level isolation Isolation: Hardware-level vault below OS kernel. Self-destructs in <200ms.
- Layer 4 — VRAM-Only Rendering: Sensitive data via DirectX 12 / Vulkan to GPU VRAM. Never touches CPU RAM.
- Layer 3 — AI Sentinel (Edge ML): Local NVIDIA TensorRT models. Sub-50ms threat response.
- Layer 2 — Decentralized Mesh Network: P2P routing with onion-style encryption. Zero metadata leakage.
- Layer 1 — Hardware Silicon Binding: Cryptographic binding to TPM/HSM unique silicon ID.
Certification Roadmap: SOC 2 Type II, ISO/IEC 27001:2022, FIPS 140-3, Common Criteria EAL4+.
Zero-Knowledge Financial Protocol
- Broker Credentials (MT5/MT4): Encrypted via AES-256-GCM and stored exclusively in the device’s Hardware-Backed Keystore (NIST SP 800-53). Forneus Technologies has Zero Knowledge.
- On-Device Cryptographic Keys: Private keys generated and stored locally using standard cryptographic frameworks. Forneus Technologies never has access.
- Trading Execution: All orders pass directly from client to broker. Forneus Technologies is not an intermediary.
- Algorithmic Risk Management: Circuit Breakers modeled on SEC Rule 15c3-5 and MiFID II RTS 6.
No Profit Guarantee: Forneus Technologies does not guarantee profits. Primary directive: Capital Preservation.
Automated Decision-Making (GDPR Art. 22)
The KAIROS ecosystem utilizes a decentralized AI consortium (Risk Engine) for autonomous trade execution and lot recalculation. By utilizing the platform, you acknowledge and explicitly consent to automated processing that carries financial consequences, voluntarily waiving the right to mandatory "human intervention" prior to individual trade execution.
Our algorithms assess market volatility and execute decisions based strictly on mathematical parameters without subjective bias or hidden profiling.
Data License for Machine Learning
Forneus Technologies enforces strict separation between Local Processing and Global Telemetry to protect your intellectual property:
- Local Processing: Uploaded strategies (RAG Pipeline) and visual data (Computer Vision screenshots) are processed and vectorized strictly within your isolated local instance. They are never transmitted, stored, or reviewed by Forneus Technologies servers.
- Global Telemetry: Only anonymized, obfuscated mathematical weightings are synced to the cloud. We do not ingest your proprietary trading setups to train global models for other clients.
Zero-Knowledge Credential Management
KAIROS acts purely as an infrastructure layer integrating with external brokerages (e.g., MetaTrader 5) and proprietary trading firms. We employ Zero-Knowledge Credential Management, meaning Forneus Technologies cannot access, intercept, or modify your API keys or funds.
Forneus Technologies acts exclusively as a Software Provider. We bear zero liability for broker downtime, infrastructure hacks at the broker level, or account bans initiated by third-party proprietary firms resulting from algorithmic configurations (e.g., HFT detection limits).
Software Infrastructure Classification
Forneus Technologies processes technical data and telemetry to provide algorithmic infrastructure. We are not a broker, financial advisor, or asset manager.
The routing of trading signals via the KAIROS or PHANES protocols constitutes raw data transmission, not financial instruction or advisory services. All financial risks remain the sole responsibility of the operator.
Defensive Network Optimization
To ensure protocol integrity and bypass latency arbitrage restrictions (Execution Jittering), our systems collect micro-telemetry including ping variations, execution timestamps, and packet routing metrics. This data is end-to-end encrypted and used strictly for defensive node optimization (Project GARM) to protect execution quality.
Authorized Data Processors
| Processor | Purpose | Data Shared | Jurisdiction | Safeguard |
|---|---|---|---|---|
| Google Firebase | Authentication, Cloud Firestore | Email, UID, encrypted sync data | EU/US | SCCs + DPA |
| Cloudflare | DDoS protection, CDN | IP addresses (transit only) | Global | SCCs + DPA |
| Hetzner / OVH | Dedicated server infrastructure | Encrypted database backups | EU | GDPR Art. 28 DPA |
No Data Sales: Forneus Technologies does not sell, rent, lease, or trade personal data to any third party for any purpose.
Your Rights Under GDPR, CCPA/CPRA & Global Privacy Laws
| Right | GDPR | CCPA | Description |
|---|---|---|---|
| Access | Art. 15 | §1798.100 | Obtain a copy of all personal data we process |
| Rectification | Art. 16 | §1798.106 | Correct inaccurate data |
| Erasure | Art. 17 | §1798.105 | Request deletion of personal data |
| Restriction | Art. 18 | — | Restrict processing during disputes |
| Portability | Art. 20 | — | Receive data in JSON/CSV format |
| Objection | Art. 21 | — | Object to legitimate interest processing |
| Automated Decision Review | Art. 22 | — | Request human review of AI decisions |
| Withdraw Consent | Art. 7(3) | — | Withdraw consent at any time |
Response Time: 30 calendar days (extendable by 60 days for complex requests).
Contact: oleksandr.l@forneus.io (PGP-encrypted submissions accepted)
Cookie Policy & Tracking Technologies
| Cookie Type | Purpose | Duration | Consent |
|---|---|---|---|
| Strictly Necessary | Session management, CSRF, auth tokens | Session / 24h | No (Art. 5(3) exemption) |
| Functional | Language preferences, UI settings | 12 months | No (essential) |
| Analytics | Aggregated usage stats (self-hosted) | 90 days | Yes (opt-in) |
No Third-Party Marketing Cookies. Forneus Technologies does not deploy advertising pixels, retargeting beacons, or cross-site tracking.
DNT & GPC: We honor Do Not Track and Global Privacy Control signals.
Neural Entity Directive & Algorithmic Accountability
- AI Classification: KAIROS trading algorithms classified as high-risk AI systems under the EU AI Act (Regulation 2024/1689).
- Transparency: Users are informed when an AI decision affects their trading. Reasoning is logged and reviewable.
- Human Override: Users may disable automated trading at any time. No fully automated decision with legal effects without human oversight.
- No Global Model Training: Your data is never used to train global models or shared with third-party LLM providers.
Retention Policy & Automated Purge Protocol
| Data Category | Retention | Deletion Method |
|---|---|---|
| Account data | Active sub + 30 days | Automated purge |
| Trading statistics | Active sub + 6 months | Cascading delete |
| Server logs (IP) | 24h raw; 90 days anonymized | Log rotation + cryptographic shredding |
| Local AI context | User-controlled | Uninstall auto-purge |
| Encrypted messages | User-controlled / Burn-on-Read | Key destruction |
| Biometric templates | Managed by device OS | Forneus Technologies has zero access |
Cryptographic Shredding: Destruction of encryption keys rendering data permanently unrecoverable.
Incident Response & Breach Disclosure
- Detection: AI Sentinel provides continuous real-time anomaly detection with sub-50ms response.
- Authority Notification: Confirmed breaches reported within 72 hours (GDPR Art. 33).
- User Notification: High-risk breaches communicated without undue delay (GDPR Art. 34).
- Emergency Lockout: Rapid session lockout and volatile-key clearing target within 200 milliseconds.
Age Verification & AML/KYC
Forneus Technologies services are designed exclusively for institutional and professional operators aged 18+ (or 21+ depending on local jurisdiction). Access by minors is strictly prohibited.
As a Non-Custodial infrastructure provider (handling no client funds or digital assets), Forneus Technologies does not conduct traditional KYC asset checks. However, we continuously monitor network traffic to comply with global AML/CFT standards and reserve the right to instantly terminate nodes originating from sanctioned IP addresses or identified threat actors.
Government Requests & Data Sovereignty
- Warrant Canary: Cryptographically signed, updated quarterly. Confirms no secret subpoenas, NSLs, or FISA orders received.
- Architectural Impossibility: Zero-Knowledge architecture means Forneus Technologies physically cannot comply with most data handover demands.
- Transparency Reports: Annual public reports on government requests received, complied with, and rejected.
Modification Protocol
- Material Changes: Email + in-app notification 30 days before effective date.
- Non-Material: Typo fixes may be made without notice.
- Version Archive: All previous versions available from DPO on request.
Complaints & Legal Recourse
- Internal: Contact DPO — response within 30 days.
- Supervisory Authority: Lodge complaint with your local DPA (GDPR Art. 77). edpb.europa.eu
- Judicial Remedy: GDPR Art. 79 guarantees effective judicial remedy.
- Arbitration: ICC rules for disputes outside EU/EEA.
Governing Law & Arbitration
Any disputes regarding data processing, algorithmic execution, or privacy shall be resolved exclusively through binding arbitration in Zurich, Switzerland, under Swiss law, expressly waiving the right to participate in any class-action lawsuit. You agree to individualized arbitration as the sole remedy.
Data Protection Officer
For all privacy inquiries, data subject requests, and compliance communications:
PGP-encrypted submissions
accepted. Public key available upon request.
Response guaranteed within 30 calendar days (GDPR
Art. 12(3)).
