Privacy Policy
Last updated: August 3, 2026
Dalvox Global Systems S.L.U. ("Dalvox Capital", "we", "us", "our") is committed to protecting the privacy of the personal data it obtains from you, including the information collected during your navigation of this website and through the access application form for our products and services.
Please read this Privacy Policy carefully before submitting the application form or using our services. By submitting the access application form, you confirm that you have read and understood this Privacy Policy.
1. Data Controller
The controller responsible for processing your personal data is:
- Company name:
Dalvox Global Systems S.L.U. - Tax ID (CIF):
[CIF] - Registered address:
[STREET ADDRESS], [POSTAL CODE], Madrid, Spain - Contact email: contact@dalvoxcapital.com
- Website: dalvoxcapital.com
Dalvox Capital acts as the data controller for the data collected through the access application form and through navigation of the website. This means it is the party that determines the purposes and means of processing your personal data.
2. Commitment and Applicable Law
Dalvox Capital undertakes to process your personal data solely in accordance with this Privacy Policy and in compliance with:
- Regulation (EU) 2016/679 (General Data Protection Regulation, "GDPR").
- Spanish Organic Law 3/2018 of 5 December on the Protection of Personal Data and the guarantee of digital rights ("LOPDGDD").
- Where applicable based on the user's residence, the CCPA (California, USA) and PIPEDA (Canada).
3. What Data We Collect
When you complete the access application form, the contact form, or purchase a product, we may collect the following categories of personal data:
- Identification and contact data: full legal name, email address, country of residence and, for the application, your postal address (street address, region/state, and postal/zip code).
- Business data (if you apply or purchase as a business): company's legal name, tax/VAT identification number, and billing address, which are required to issue the invoice.
- Trader profile data: available trading capital (by range), years of trading experience, automated-trading experience, risk tolerance, investment objective, and any additional message you choose to include.
- How you found us: the referral source you select and, where applicable, the social platform(s) you indicate.
- Trading account number: if your application is approved and you activate a license, we store the trading account number you choose to bind to that license. This is necessary to enforce our "one trading account per license" rule. We do not collect your broker login credentials, passwords, account balance, or trading history.
- License-enforcement identifiers: when the software validates your license with our servers, it transmits your trading account number, your IP address, and a non-reversible device/installation fingerprint (a hash that identifies the machine running the software, not its files or contents). We use these strictly to enforce the one-account license, to detect license sharing or transfer, and to prevent, investigate and act on fraud or abuse — including linking and blocking accounts or identities that share these unambiguous identifiers.
- Identifier history: we keep a dated log of the identifiers that have been associated with your customer record over time — name, email address, trading account number, device fingerprint and IP address. We keep it so that changing one of them does not by itself break the link we need in order to enforce the one-account licence rule and to detect the use of multiple identities to circumvent it. This log is kept for every customer, not only for blocked ones. Apart from the device fingerprint, which is a non-reversible hash, these identifiers are stored as they are, in plain text — they are the same data already held in your customer record, so encoding them here would add no real protection.
- Technical, usage and attribution data (collected automatically): your IP address, browser and device information (user-agent), the pages you visit and duration of visit, and marketing-attribution data such as the referring URL and campaign parameters (UTM source, medium, campaign, term, and content). This data is described further in the Cookies section.
- Consent records: we keep a record of the declarations and consents you tick when submitting the form (including, where given, your consent to receive commercial communications), as proof of consent required by law.
We use the technical and attribution data to operate and secure the website, to understand how applicants reach us, and to keep a record of when and from where an application or activation was made (which also helps us prevent fraud and abuse of our licensing system).
Note: We do not collect more data than is necessary for the purposes described in Section 4. We do not request or store your broker credentials or any banking or card details; payment is handled entirely through our payment provider (see Section 5).
4. Purposes and Legal Basis for Processing
| Purpose | Legal basis |
|---|---|
| Evaluate your access application and assess product suitability | Pre-contractual measures taken at your request (Art. 6.1.b GDPR) |
| Manage the sale, issue the invoice, and deliver the product if your application is approved | Performance of a contract (Art. 6.1.b GDPR) |
| Comply with legal, tax, and accounting obligations | Legal obligation (Art. 6.1.c GDPR) |
| Send you commercial communications about our products | Your consent (Art. 6.1.a GDPR), which you may withdraw at any time |
| Improve the website and produce anonymized statistics | Legitimate interest and/or your consent for non-essential cookies (Art. 6.1.f / 6.1.a GDPR) |
| Verify licenses, prevent and investigate fraud or abuse, and enforce blocks — including linking and blocking accounts or identities that share unambiguous technical identifiers (trading account, device fingerprint, email, phone) | Legitimate interest in protecting our intellectual property and systems and in preventing fraud (Art. 6.1.f GDPR) |
The evaluation of your access application is not automated: it involves human review.
Automated decisions in licence enforcement. Some licence-enforcement and security decisions are, however, taken automatically, with no human intervention at the moment they take effect. In plain terms:
- if a licence key is used from a trading account or device that is already blocked, that licence key is blocked automatically;
- if a customer record is created or updated and it shares an unambiguous identifier (trading account number, device fingerprint or email address) with a blocked one, it is blocked automatically;
- if a single IP address or request signature requests six or more different non-existent pages within ten minutes, that IP address is blocked from this website automatically. A website block of this kind never takes away software you have already paid for: licence validation is deliberately exempt from IP blocks.
The possible consequence for you is the loss of access to the software and/or to this website. We do not use special categories of data (Art. 9 GDPR) for these decisions, and we do not disclose the specific technical parameters of our detection systems, because doing so would defeat their purpose.
Legal basis. For the two licence-enforcement decisions above we rely on Article 22(2)(a) GDPR: they are necessary to perform the licence contract. Licences are validated automatically, machine to machine, at a rate and speed that cannot in practice be reviewed case by case before the decision takes effect, and no less intrusive means would keep the one-account rule effective. The automatic IP block is different in kind: it protects a public website against scanning and abuse, it applies to visitors with whom we have no contract, and it never affects a product you have purchased. For that one we rely on our legitimate interest in the security of our systems (Art. 6(1)(f) GDPR).
Your safeguards. Where an automated decision affects your licence, you have the right under Article 22(3) GDPR to obtain human intervention, to express your point of view, to receive the general reasons for the decision, and to contest it. Write to support@dalvoxcapital.com. A member of our team — not an automated system — will look at your case and reply within 30 days, giving you the general reasons for the decision, and we will lift the block if we conclude it was not justified. The same route is open to you if an IP block is stopping you from reaching this website.
5. Sharing of Data with Third Parties and International Transfers
In order to provide our services, we may share your data with the following third parties, acting as data processors or as independent controllers:
- Payment provider (Whop): payment processing and invoice issuance are carried out through Whop. Under the tax-handling option we have enabled, Whop also calculates, collects, and remits applicable taxes on our behalf and is identified as the party handling those taxes. To process payment and issue the invoice, we share your name, email address, and country (and, where applicable, your company's tax details). Whop processes this data in accordance with its own privacy policy.
- Web hosting provider (Hostinger): the site is hosted and form data is securely stored on infrastructure provided by Hostinger.
- Email provider (Hostinger): for sending transactional and, subject to consent, commercial communications.
- Public or judicial authorities, where there is a legal obligation to disclose the data.
International transfers: some of these providers may be located outside the European Economic Area (for example, in the United States). In such cases, transfers are made under the safeguards provided for by the GDPR, such as the European Commission's Standard Contractual Clauses or recognized adequacy frameworks. You may request further information about these safeguards through our contact email.
We do not sell or transfer your personal data to third parties for their own commercial purposes.
6. How Long We Keep Your Data
We keep your personal data only for as long as necessary to fulfill the purposes for which it was collected:
- Applications not approved: kept for a maximum period of 12 months from receipt, unless you request earlier deletion.
- Customers (approved applications and purchases): kept for the duration of the contractual relationship and, thereafter, for the legal tax and commercial limitation periods applicable in Spain (generally up to 6 years for accounting records).
- Billing and payment records: the data supporting each transaction — invoicing details, payment references and amounts, taxes applied, and refund records including the reason for each refund — is kept for 6 years from the last accounting entry, as required by Article 30 of the Spanish Commercial Code and Spanish tax law. Because this retention fulfills a legal obligation (Art. 6.1.c GDPR), it applies even if you request erasure of your other personal data; during the retention period this data is kept blocked and used solely to meet those legal obligations.
- Marketing consent: until you withdraw your consent.
- Identifier history: the dated log of identifiers described in Section 3 is kept for as long as your customer record exists, and is deleted together with it — including when you exercise your right to erasure. Where a block is in force, the identifiers needed to keep that block effective are held separately, as described in the next point.
- Fraud-prevention / blocking data: where an account or identity has been blocked for breach of our Terms, the minimum identifiers strictly necessary to keep that block effective (e.g. trading account number, device fingerprint, email address) are retained for as long as the block remains necessary — even after deletion of the rest of your data — on the basis of our legitimate interest in preventing its circumvention. There is no fixed end date, because a block that expires on a calendar can simply be waited out; instead we review, at least every five (5) years, whether each block is still necessary, and delete the identifiers of any that is not. These identifiers are stored as they are, in plain text (except the device fingerprint, which is a non-reversible hash).
7. Your Rights
Under applicable law, you may exercise the following rights:
- Access: find out what data we hold about you and obtain a copy.
- Rectification: correct inaccurate or incomplete data.
- Erasure: request deletion of your data when it is no longer necessary.
- Objection: object to certain processing activities.
- Restriction: request that we restrict processing in certain circumstances.
- Portability: receive your data in a structured, commonly used format, or request its transmission to another controller.
- Withdrawal of consent: at any time, without affecting the lawfulness of processing carried out beforehand.
- Human intervention in automated decisions: where a block has been applied automatically (see Section 4), obtain human review of that decision, express your point of view, and contest it.
You may exercise these rights by writing to privacy@dalvoxcapital.com, indicating the right you wish to exercise. We may ask you to verify your identity.
Limit to the right of erasure: the right to erasure is not absolute. Where we have blocked an account or identity for breach of our Terms of Use, we may retain the minimum identifiers strictly necessary to keep that block effective and to prevent its circumvention, as described in Section 6, on the basis of our legitimate interest. Likewise, billing and payment records subject to the 6-year legal retention period described in Section 6 cannot be erased before that period expires; they remain blocked and are used only to comply with tax and commercial obligations. All other personal data is deleted as requested — including the identifier history described in Sections 3 and 6, which is erased together with your customer record.
If you believe your rights have not been properly addressed, you have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD), located at C/ Jorge Juan, 6, 28001 Madrid, or through its electronic headquarters at www.aepd.es.
8. California Residents (CCPA)
If you are a California resident, California law grants you additional rights:
- The right to know which categories of personal information we have collected, disclosed, or, where applicable, "sold" in the preceding 12 months.
- The right to request access to and deletion of your personal information.
- The right not to be discriminated against for exercising these rights.
- The right to opt out of the "sale" of your personal information.
As a general rule, Dalvox Capital does not sell your personal information. In the limited cases where sharing information with our providers might be considered a "sale" under California law, you may exercise your right to opt out by writing to privacy@dalvoxcapital.com.
9. Canadian Residents (PIPEDA)
If you reside in Canada, we process your data in accordance with PIPEDA principles: collection with your knowledge and consent, use limited to the disclosed purposes, retention for as long as necessary, and adoption of appropriate security measures. You may exercise your rights of access and rectification through our contact email.
10. Cookies and Local Storage
This website uses a small number of necessary cookies/local storage to function, and, only with your prior consent, Google Analytics to produce anonymized statistics about site usage. No non-essential cookie is set until you accept the cookie banner shown on your first visit, and you can withdraw your consent at any time using the cookie icon that remains visible in the bottom-left corner of the page.
| Type | Name | Set by | Purpose | Duration |
|---|---|---|---|---|
| Local storage (necessary) | dvx-theme | dalvoxcapital.com | Remembers your light/dark theme preference. Contains no identifier and is never transmitted to our servers. | Until you clear your browser data |
| Local storage (necessary) | dvx-consent | dalvoxcapital.com | Remembers your cookie-consent choice (accepted or declined) so we don't ask again on every visit. | Until you clear your browser data |
| Analytics (only if accepted) | _ga | Google Analytics | Distinguishes unique visitors to produce anonymized traffic statistics. IP addresses are anonymized. | Up to 13 months |
| Analytics (only if accepted) | _ga_<container-id> | Google Analytics | Persists session state for Google Analytics 4 reporting. | Up to 13 months |
You can decline analytics cookies without affecting your ability to use the site. Google's use of this data is governed by the Google Privacy Policy.
11. Links to Third Parties
This site may contain links to other websites. This Privacy Policy does not apply to those sites. We recommend reading the privacy policies of any third-party site you visit. We accept no responsibility for the privacy practices of external sites.
12. Security and Data Breach Notification
We apply appropriate technical and organizational measures to protect your personal data against unauthorized access, loss, or alteration. These measures include encryption of data in transit, authentication mechanisms, and access restricted only to personnel who need it.
Data breach notification. If, despite these measures, a personal data breach occurs (unauthorized access to, or loss, alteration, or disclosure of, personal data), we will act in accordance with Articles 33 and 34 GDPR:
- We will document the breach internally and assess the risk to those affected.
- Unless the breach is unlikely to result in a risk to your rights and freedoms, we will notify the Spanish Data Protection Agency (AEPD) without undue delay and, where feasible, within 72 hours of becoming aware of it.
- If the breach is likely to result in a high risk to your rights and freedoms, we will also inform you directly and without undue delay, by email to the address we hold on file, describing in clear language the nature of the breach, its likely consequences, the measures taken or proposed to address it, and a contact point for further information.
13. Changes to This Policy
We may update this Privacy Policy when necessary. We will publish the updated version on this website, indicating the date of last update. We recommend reviewing it periodically.