Policies

Privacy Policy

What personal information we collect, why, how long we keep it and your rights.

Version 1.0 · Effective 2 October 2026 · Last updated 2 October 2026

This Privacy Policy explains how Quant HFT AI (“Quant HFT AI”, “we”, “us”, “our”) collects, uses, stores and protects personal information when you use quanthftai.com (the “website”), contact us, create an account or apply for a role. It reflects the systems this website actually uses. It is not legal advice, and it does not override rights you may have under the law that applies to you.

Who we are and how to contact us

Quant HFT AI is a technology company with a presence in Australia, Dubai (United Arab Emirates) and India. For any privacy question or request, email info@quanthftai.com with the subject line “Privacy request”.

Information we collect

We collect only what each feature needs.

When you send an enquiry

Your name, email address and message; the topic you select; and, if you choose to provide them, your phone number, company and country. We also record when you confirmed you had read this policy (and which version), the page you used, and a keyed hash of your IP address. The hash lets us detect abuse without storing your IP address in readable form.

When you apply for a role

Your name, email address, country, CV/résumé file and confirmation of our Recruitment Privacy Notice; and, if you choose to provide them, your phone number, city, LinkedIn or portfolio links and a cover message. See the Recruitment Privacy Notice for details.

When you create an account

Your name, email address and a password. We never store your password itself: we store a one-way Argon2id hash. We also keep:

  • sign-in sessions: a hashed session identifier, the IP address and browser user agent used, and timestamps;
  • security records: for example, sign-ins, password changes and administrative actions, with the related IP address and user agent;
  • policy acceptance: which versions of our Terms and this policy you accepted.

When you choose a new password, we check whether it appears in known data breaches using the Have I Been Pwned “range” service. Only the first five characters of a one-way (SHA-1) hash of the password leave our server, so neither your password nor its full hash is disclosed.

When you browse the website

Our web server records technical information for security and reliability: IP address, date and time, requested page, response status, referring page and browser user agent. These logs are kept for up to 14 days unless they are needed to investigate a security incident.

Cookies and similar technologies

We use only strictly necessary cookies by default. See our Cookie Policy. We will not place analytics or advertising cookies unless we have enabled them and you have opted in.

How we use information

  • To respond to enquiries and provide the services you ask about.
  • To assess job applications and communicate with candidates.
  • To create, secure and operate accounts, including email verification and password resets.
  • To protect the website, our users and our systems: rate limiting, abuse prevention, fraud and security monitoring.
  • To meet legal obligations and to establish, exercise or defend legal claims.

We do not sell personal information. We do not use enquiry, application or account data for automated decisions that have legal or similarly significant effects on you.

Who we share information with

We share personal information only with service providers that help us run the website, and only as needed:

  • Hosting: our website and database run on a virtual private server provided by Contabo.
  • Email: our business email and outgoing website email are provided by Hostinger.
  • Password breach checks: Have I Been Pwned, operated with Cloudflare, receives only the anonymous five-character hash prefix described above.

If you choose to contact us on WhatsApp, the conversation takes place on WhatsApp, a service provided by Meta, and WhatsApp’s own terms and privacy policy apply. We may also disclose information where the law requires it, or to protect rights, safety and security.

International transfers

Our team works across Australia, the United Arab Emirates and India, and our service providers may process data in other countries. Where information moves between countries, we take reasonable steps to keep it protected in line with this policy and applicable law.

How long we keep information

Information Retention
Enquiries Up to 24 months after our last contact, unless an ongoing business relationship requires longer
Job applications and CVs Up to 12 months after the application is received, then deleted (see the Recruitment Privacy Notice)
Accounts While the account is active; deleted or anonymised after closure, except records we must keep by law
Sign-in sessions Until they expire or you sign out (at most 14 days; 8 hours for administrative accounts)
Security and audit records Up to 12 months
Web server logs Up to 14 days

How we protect information

Security measures include:

  • encrypted connections (HTTPS);
  • Argon2id password hashing;
  • rate limiting and bot mitigation;
  • strict access controls, with multi-factor authentication for administrators;
  • audit logging;
  • application files stored privately, outside the public web root;
  • encrypted backups;
  • monitoring.

No system is perfectly secure. If a breach affects your personal information, we will notify you and the relevant authorities where the law requires it.

Your choices and rights

Depending on where you live, you may have rights to:

  • access, correct or delete your personal information;
  • object to or restrict certain processing;
  • withdraw consent where we rely on it;
  • receive a copy of your information.

To make a request, email info@quanthftai.com. We may need to verify your identity first, and we will respond within the time required by applicable law.

If you have a concern, please contact us first so we can try to resolve it. You may also complain to your local data-protection authority. Examples include the Office of the Australian Information Commissioner, the authority in your country of residence in the European Economic Area or United Kingdom, and India’s Data Protection Board once it is operating.

Children

This website and our services are not directed to children under 18, and we do not knowingly collect their personal information.

Changes to this policy

We will update this policy when our practices change. The version number and date at the top of this page show the current version; earlier versions are listed in the version history.

These documents are provided for transparency and are not legal advice. Questions? Email info@quanthftai.com.