← Virtual Risk DeskLEGAL / CUSTOMER INFORMATION

UK GDPR / PRIVACY

Privacy Notice

How we collect, use, secure and retain personal data when you visit the site or operate a Risk Desk.Last updated: 25 August 2026
Pre-incorporation noticeVirtual Risk Desk is currently a pre-incorporation product and trading name. Direct checkout will not open until the legal identity and geographic address of the contracting operator are displayed. These documents are working commercial drafts and should receive a final UK legal review before sales begin.

1. Who is responsible for your data

Virtual Risk Desk is currently a pre-incorporation product and trading name operating through virtualriskdesk.com. Privacy enquiries may be sent to hello@virtualriskdesk.com.

Before account registration, telemetry connection or direct payment processing opens, this notice will be updated to identify the individual or incorporated entity acting as data controller and provide its geographic contact address. Until then, the website is informational and you should not send live account credentials, payment-card details or sensitive personal information by email.

2. Information we collect

  • Identity and contact information, including name, email and organisation.
  • Account, licence, order, payment status and support history. Card details are normally handled by the payment provider rather than stored by VRD.
  • MT5 and strategy information, including account identifiers, broker/server, balances, equity, margin, positions, baskets, exposure, drawdown and operational telemetry.
  • Files and assumptions you submit, including backtest reports, Risk Passports and configuration information.
  • Technical and usage information, including device, browser, IP address, security logs, feature use and diagnostic events.
  • Marketing preferences, enquiry source and interactions with our communications.

3. Why we use it

  • To enter into and perform our contract with you: accounts, licences, analysis, monitoring, support and deployment.
  • For legitimate interests: securing and improving VRD, detecting misuse, understanding product performance and supporting customers.
  • To meet legal, tax, accounting and regulatory obligations.
  • With consent where required, including non-essential cookies and direct electronic marketing.

4. Automated analysis

VRD uses deterministic models and AI-assisted analysis to produce risk classifications, alerts and recommended actions. These outputs support your decision-making; they do not make legally significant decisions about you without human involvement. You may ask us to explain the principal data used in an output.

5. Who receives information

We may use carefully selected hosting, database, authentication, payment, email, analytics, customer-support and professional-adviser providers. We share only what is reasonably necessary and require processors to protect the data. We may disclose information where required by law or in connection with a business sale or restructuring.

We do not sell personal data.

6. International transfers

Some providers may process information outside the UK. Where required, we use an adequacy decision, the UK International Data Transfer Agreement or approved UK addendum, and appropriate security measures.

7. Retention

Enquiries are normally retained for up to 24 months after the last meaningful contact. Contract, payment and tax records may be retained for up to seven years. Security logs are normally retained for up to 12 months. When live services launch, product settings or the customer agreement will state the applicable retention period for backtests and detailed telemetry. We may retain information longer where reasonably necessary for a dispute, fraud prevention or legal obligation, and may retain anonymised information that no longer identifies anyone.

8. Security

We use access controls, encryption in transit, logging, backups and proportionate organisational measures. No internet service is completely secure; you must also protect your terminals, VPS, credentials and connected accounts.

9. Your rights

Depending on the circumstances, you may have rights of access, correction, deletion, restriction, objection and data portability, and the right to withdraw consent. To exercise a right, email hello@virtualriskdesk.com. We may need to verify your identity. You may complain to the UK Information Commissioner’s Office at ico.org.uk.

Your right to object: you may object at any time to direct marketing and, in some circumstances, to processing based on legitimate interests.

10. Cookies

Essential technologies may be used for security, authentication and service operation. Analytics or advertising cookies will not be placed where consent is required until you choose to allow them. A cookie control will provide equivalent accept and reject choices when non-essential cookies are enabled.

11. Marketing

You can unsubscribe from marketing at any time using the link in an email or by contacting us. Service and security messages are not marketing and may still be sent while you have an account.

12. Changes

We may update this notice as the product and suppliers change. Material changes will be highlighted through the site or account communications.

Virtual Risk Deskvirtualriskdesk.com · Pre-incorporation product
TermsPrivacyRisk disclosureRefunds