LEGAL FRAMEWORK // PUBLIC ACCESS

Privacy & Data Protection

Global Compliance Protocol // Forneus Technologies

This document governs the collection, processing, storage, and protection of personal data across the entire Forneus Technologies ecosystem — including KAIROS, GARM, PHANES, ELIGOS, and AUTHENTICATOR platforms.

Document Version: 3.1.0 // Effective: March 1, 2025 // Last Reviewed: March 5, 2025

01 // CONTROLLER IDENTIFICATION & SCOPE

Data Controller & Legal Entity

Legal Entity: Forneus Technologies (hereinafter “Forneus Technologies”, “We”, “Us”, “the Company”).

Data Protection Officer (DPO): oleksandr.l@forneus.io

Scope of Application: This Privacy Policy applies to all personal data processed by Forneus Technologies through:

  • The corporate website (forneus.io) and all subdomains
  • KAIROS — Autonomous Neural Trading Ecosystem
  • GARM — Zero-Knowledge Encrypted Communication Platform
  • PHANES — Decentralized Identity & Authentication Framework
  • ELIGOS — Autonomous Defense & Tactical Intelligence System
  • AUTHENTICATOR — Hardware-Bound Multi-Factor Authentication Module
  • All APIs, SDKs, cloud services, and infrastructure operated by Forneus Technologies
GDPR COMPLIANT CCPA / CPRA ePrivacy Directive PIPEDA LGPD (Brazil) POPIA (South Africa) APPI (Japan)
02 // LEGAL BASIS FOR PROCESSING

Lawful Grounds Under GDPR Art. 6 & Art. 9

We process personal data exclusively under the following legal bases as defined by Regulation (EU) 2016/679 (GDPR):

Legal Basis GDPR Article Data Categories Purpose
Contractual Necessity Art. 6(1)(b) Account credentials, trading parameters, license keys Service delivery for KAIROS, GARM, PHANES, ELIGOS
Legitimate Interest Art. 6(1)(f) Usage analytics, performance telemetry, error logs System improvement, fraud detection, security hardening
Legal Obligation Art. 6(1)(c) Transaction records, compliance audit trails AML/CFT compliance, tax reporting obligations
Explicit Consent Art. 6(1)(a) Marketing communications, optional telemetry Newsletters, product announcements (opt-in only)
Special Categories Art. 9(2)(a) Biometric identifiers (AUTHENTICATOR) Hardware-bound authentication; processed exclusively in device Secure Enclave

Balancing Test (Art. 6(1)(f)): Where we rely on legitimate interest, we conduct and document a Legitimate Interest Assessment (LIA). You may request a copy of any LIA by contacting our DPO.

03 // DATA COLLECTION & CATEGORIES

Comprehensive Data Inventory

The following details every category of personal data processed across the Forneus Technologies ecosystem:

3.1 — Cross-Platform Data (All Products)

Data Type Storage Encryption Retention
Email address Firebase Auth (Cloud) TLS 1.3 in transit, AES-256 at rest Until account deletion + 30 days
Hashed password Firebase Auth (Cloud) Argon2id hashing Until account deletion
IP address Server logs (ephemeral) Anonymized after 24h 24 hours raw; 90 days anonymized
Device fingerprint Local + Cloud SHA-256 hash only Duration of active session

3.2 — KAIROS (Neural Trading Ecosystem)

Data Type Storage Encryption Retention
MT5 broker credentials Local device only AES-256-GCM, Hardware Keystore User-controlled; wiped on uninstall
Trading history Cloud sync (Firebase) TLS 1.3 + AES-256 at rest Active subscription + 6 months
AI conversation context Local Vector DB AES-256, device-bound key User-controlled; never uploaded
Voice commands (Vosk/Whisper) RAM only (ephemeral) N/A — never stored <2 seconds
Screen analysis (YOLO) VRAM only N/A — never stored Duration of frame processing
Psychographic profile Local encrypted DB AES-256 / ISO 27001 Never leaves device

3.3 — GARM (Encrypted Communications)

Data Type Storage Encryption Retention
Message content End-to-End Encrypted Double Ratchet + X3DH + AES-256-GCM User-controlled; Burn-on-Read available
Message metadata Zero metadata policy N/A — not collected Not retained
Key exchange material Local Secure Element X25519 + Kyber-1024 hybrid Ephemeral; rotated per session

3.4 — PHANES & AUTHENTICATOR

Data Type Storage Encryption Retention
Biometric templates Device Secure Enclave (TEE) Hardware-isolated; Forneus Technologies receives pass/fail only Managed by OS; Forneus Technologies has zero access
TOTP/HOTP secrets Hardware Security Module TPM-bound, non-extractable Until user revocation
Recovery seed phrases User responsibility only Never transmitted to Forneus Technologies Forneus Technologies has zero knowledge

3.5 — ELIGOS (Tactical Intelligence)

Data Type Storage Encryption Retention
Tactical operation parameters Air-gapped local system AES-256-GCM + ChaCha20-Poly1305 Mission duration only; auto-wiped
Sensor/telemetry feeds Edge device VRAM Processed in-memory; never persisted Real-time only
Operator credentials Hardware Security Module TPM-sealed, non-exportable Operator assignment period
04 // DATA SOVEREIGNTY & SECURITY ARCHITECTURE

Military-Grade Protection Framework

Forneus Technologies implements a 7-layer defense architecture to protect all personal data:

  • Layer 7 — Post-Quantum Encryption: Kyber-1024 + X25519 hybrid key exchange; AES-256-GCM symmetric encryption.
  • Layer 6 — Zero-Knowledge Authentication: TPM-bound biometric fusion with neural risk scoring.
  • Layer 5 — Hardware-level isolation Isolation: Hardware-level vault below OS kernel. Self-destructs in <200ms.
  • Layer 4 — VRAM-Only Rendering: Sensitive data via DirectX 12 / Vulkan to GPU VRAM. Never touches CPU RAM.
  • Layer 3 — AI Sentinel (Edge ML): Local NVIDIA TensorRT models. Sub-50ms threat response.
  • Layer 2 — Decentralized Mesh Network: P2P routing with onion-style encryption. Zero metadata leakage.
  • Layer 1 — Hardware Silicon Binding: Cryptographic binding to TPM/HSM unique silicon ID.

Certification Roadmap: SOC 2 Type II, ISO/IEC 27001:2022, FIPS 140-3, Common Criteria EAL4+.

05 // NON-CUSTODIAL ARCHITECTURE & FINANCIAL DATA

Zero-Knowledge Financial Protocol

  • Broker Credentials (MT5/MT4): Encrypted via AES-256-GCM and stored exclusively in the device’s Hardware-Backed Keystore (NIST SP 800-53). Forneus Technologies has Zero Knowledge.
  • On-Device Cryptographic Keys: Private keys generated and stored locally using standard cryptographic frameworks. Forneus Technologies never has access.
  • Trading Execution: All orders pass directly from client to broker. Forneus Technologies is not an intermediary.
  • Algorithmic Risk Management: Circuit Breakers modeled on SEC Rule 15c3-5 and MiFID II RTS 6.

No Profit Guarantee: Forneus Technologies does not guarantee profits. Primary directive: Capital Preservation.

06 // ALGORITHMIC EXECUTION & AI PROFILING

Automated Decision-Making (GDPR Art. 22)

The KAIROS ecosystem utilizes a decentralized AI consortium (Risk Engine) for autonomous trade execution and lot recalculation. By utilizing the platform, you acknowledge and explicitly consent to automated processing that carries financial consequences, voluntarily waiving the right to mandatory "human intervention" prior to individual trade execution.

Our algorithms assess market volatility and execute decisions based strictly on mathematical parameters without subjective bias or hidden profiling.

07 // INTELLECTUAL PROPERTY & DATA INGESTION

Data License for Machine Learning

Forneus Technologies enforces strict separation between Local Processing and Global Telemetry to protect your intellectual property:

  • Local Processing: Uploaded strategies (RAG Pipeline) and visual data (Computer Vision screenshots) are processed and vectorized strictly within your isolated local instance. They are never transmitted, stored, or reviewed by Forneus Technologies servers.
  • Global Telemetry: Only anonymized, obfuscated mathematical weightings are synced to the cloud. We do not ingest your proprietary trading setups to train global models for other clients.
08 // PLATFORM LIABILITY & THIRD-PARTY RISKS

Zero-Knowledge Credential Management

KAIROS acts purely as an infrastructure layer integrating with external brokerages (e.g., MetaTrader 5) and proprietary trading firms. We employ Zero-Knowledge Credential Management, meaning Forneus Technologies cannot access, intercept, or modify your API keys or funds.

Forneus Technologies acts exclusively as a Software Provider. We bear zero liability for broker downtime, infrastructure hacks at the broker level, or account bans initiated by third-party proprietary firms resulting from algorithmic configurations (e.g., HFT detection limits).

09 // NO FINANCIAL ADVICE & BROKERAGE DISCLAIMER

Software Infrastructure Classification

Forneus Technologies processes technical data and telemetry to provide algorithmic infrastructure. We are not a broker, financial advisor, or asset manager.

The routing of trading signals via the KAIROS or PHANES protocols constitutes raw data transmission, not financial instruction or advisory services. All financial risks remain the sole responsibility of the operator.

10 // STEALTH MODULE TELEMETRY

Defensive Network Optimization

To ensure protocol integrity and bypass latency arbitrage restrictions (Execution Jittering), our systems collect micro-telemetry including ping variations, execution timestamps, and packet routing metrics. This data is end-to-end encrypted and used strictly for defensive node optimization (Project GARM) to protect execution quality.

11 // THIRD-PARTY PROCESSORS & SUB-PROCESSORS

Authorized Data Processors

Processor Purpose Data Shared Jurisdiction Safeguard
Google Firebase Authentication, Cloud Firestore Email, UID, encrypted sync data EU/US SCCs + DPA
Cloudflare DDoS protection, CDN IP addresses (transit only) Global SCCs + DPA
Hetzner / OVH Dedicated server infrastructure Encrypted database backups EU GDPR Art. 28 DPA

No Data Sales: Forneus Technologies does not sell, rent, lease, or trade personal data to any third party for any purpose.

12 // DATA SUBJECT RIGHTS

Your Rights Under GDPR, CCPA/CPRA & Global Privacy Laws

Right GDPR CCPA Description
Access Art. 15 §1798.100 Obtain a copy of all personal data we process
Rectification Art. 16 §1798.106 Correct inaccurate data
Erasure Art. 17 §1798.105 Request deletion of personal data
Restriction Art. 18 Restrict processing during disputes
Portability Art. 20 Receive data in JSON/CSV format
Objection Art. 21 Object to legitimate interest processing
Automated Decision Review Art. 22 Request human review of AI decisions
Withdraw Consent Art. 7(3) Withdraw consent at any time

Response Time: 30 calendar days (extendable by 60 days for complex requests).

Contact: oleksandr.l@forneus.io (PGP-encrypted submissions accepted)

13 // COOKIES, TRACKING & ePRIVACY

Cookie Policy & Tracking Technologies

Cookie Type Purpose Duration Consent
Strictly Necessary Session management, CSRF, auth tokens Session / 24h No (Art. 5(3) exemption)
Functional Language preferences, UI settings 12 months No (essential)
Analytics Aggregated usage stats (self-hosted) 90 days Yes (opt-in)

No Third-Party Marketing Cookies. Forneus Technologies does not deploy advertising pixels, retargeting beacons, or cross-site tracking.

DNT & GPC: We honor Do Not Track and Global Privacy Control signals.

14 // AI GOVERNANCE & AUTOMATED DECISION-MAKING

Neural Entity Directive & Algorithmic Accountability

  • AI Classification: KAIROS trading algorithms classified as high-risk AI systems under the EU AI Act (Regulation 2024/1689).
  • Transparency: Users are informed when an AI decision affects their trading. Reasoning is logged and reviewable.
  • Human Override: Users may disable automated trading at any time. No fully automated decision with legal effects without human oversight.
  • No Global Model Training: Your data is never used to train global models or shared with third-party LLM providers.
15 // DATA RETENTION & DELETION

Retention Policy & Automated Purge Protocol

Data Category Retention Deletion Method
Account data Active sub + 30 days Automated purge
Trading statistics Active sub + 6 months Cascading delete
Server logs (IP) 24h raw; 90 days anonymized Log rotation + cryptographic shredding
Local AI context User-controlled Uninstall auto-purge
Encrypted messages User-controlled / Burn-on-Read Key destruction
Biometric templates Managed by device OS Forneus Technologies has zero access

Cryptographic Shredding: Destruction of encryption keys rendering data permanently unrecoverable.

16 // BREACH NOTIFICATION PROTOCOL

Incident Response & Breach Disclosure

  • Detection: AI Sentinel provides continuous real-time anomaly detection with sub-50ms response.
  • Authority Notification: Confirmed breaches reported within 72 hours (GDPR Art. 33).
  • User Notification: High-risk breaches communicated without undue delay (GDPR Art. 34).
  • Emergency Lockout: Rapid session lockout and volatile-key clearing target within 200 milliseconds.
17 // CHILDREN'S PRIVACY

Age Verification & AML/KYC

Forneus Technologies services are designed exclusively for institutional and professional operators aged 18+ (or 21+ depending on local jurisdiction). Access by minors is strictly prohibited.

As a Non-Custodial infrastructure provider (handling no client funds or digital assets), Forneus Technologies does not conduct traditional KYC asset checks. However, we continuously monitor network traffic to comply with global AML/CFT standards and reserve the right to instantly terminate nodes originating from sanctioned IP addresses or identified threat actors.

18 // WARRANT CANARY & LAW ENFORCEMENT

Government Requests & Data Sovereignty

  • Warrant Canary: Cryptographically signed, updated quarterly. Confirms no secret subpoenas, NSLs, or FISA orders received.
  • Architectural Impossibility: Zero-Knowledge architecture means Forneus Technologies physically cannot comply with most data handover demands.
  • Transparency Reports: Annual public reports on government requests received, complied with, and rejected.
19 // POLICY UPDATES & VERSIONING

Modification Protocol

  • Material Changes: Email + in-app notification 30 days before effective date.
  • Non-Material: Typo fixes may be made without notice.
  • Version Archive: All previous versions available from DPO on request.
20 // DISPUTE RESOLUTION & SUPERVISORY AUTHORITY

Complaints & Legal Recourse

  • Internal: Contact DPO — response within 30 days.
  • Supervisory Authority: Lodge complaint with your local DPA (GDPR Art. 77). edpb.europa.eu
  • Judicial Remedy: GDPR Art. 79 guarantees effective judicial remedy.
  • Arbitration: ICC rules for disputes outside EU/EEA.

Governing Law & Arbitration

Any disputes regarding data processing, algorithmic execution, or privacy shall be resolved exclusively through binding arbitration in Zurich, Switzerland, under Swiss law, expressly waiving the right to participate in any class-action lawsuit. You agree to individualized arbitration as the sole remedy.

21 // CONTACT & COMPLIANCE CHANNEL

Data Protection Officer

For all privacy inquiries, data subject requests, and compliance communications:

oleksandr.l@forneus.io

PGP-encrypted submissions accepted. Public key available upon request.
Response guaranteed within 30 calendar days (GDPR Art. 12(3)).