Define Your Risk

Privacy Policy

1. Scope and Application

DYR Capital Group LLC (the “Company,” “we,” “us,” or “our”) provides the Define Your Risk application and related account services, application programming interfaces, and integrations (collectively, the “Services”). This Privacy Policy describes the collection, use, disclosure, retention, and protection of personal information in connection with the Services. “Personal information” means information that identifies, relates to, or can reasonably be associated with an individual, as defined under applicable law.

This Privacy Policy applies to individual customers and individuals who access the Services on behalf of a business or other organization. Where the Company processes information on behalf of a business under a separate written agreement, that processing is also subject to the applicable agreement. No provision of this Privacy Policy limits rights or obligations that cannot be excluded under applicable law.

For inquiries, contact DYR Capital Group LLC by email at support@defineyourrisk.com or by mail at 180 Vineyard Rd, Cotuit, MA 02635, United States.

2. Information Collected

The Company collects information provided by customers, information generated through use of the Services, and information received from third-party services that customers authorize the Company to access. The categories and extent of information collected depend on the Services used and the permissions granted.

Account and Contact Information

Account information includes email addresses, account identifiers, subscription details, preferences, and information supplied during account administration. The Company also receives the contents of communications submitted in connection with support requests, billing inquiries, feedback, and other correspondence.

User Content and Connected Accounts

The Company receives information entered, uploaded, saved, or otherwise made available through the Services (“User Content”). User Content may include portfolio positions, balances, transaction histories, watchlists, trading scenarios, and related financial records. Information obtained from a connected brokerage or other external service depends on the connection authorized by the customer, the permissions granted, and the functionality requested.

Customers are responsible for having the authority to submit information concerning other individuals or organizations. An authorized connection does not permit the Company to obtain information beyond the scope of that connection.

Payment and Transaction Information

In connection with paid subscriptions, the Company maintains records of customer and subscription identifiers, subscription status, and payment-related events. Payment card details submitted through the designated checkout interfaces are collected and processed directly by Stripe, the Company’s payment processor, in accordance with Stripe’s privacy policy. The Company receives information necessary to administer subscriptions, reconcile transactions, and address billing inquiries. Complete payment card numbers and card security codes are not collected by the Company’s application servers through those interfaces.

Technical and Usage Information

The Company collects information concerning access to and use of the Services, including browser and device characteristics, request and session information, interactions with pages and features, and diagnostic records relating to errors and performance. Technical and usage records may be associated with an account or session and are not necessarily anonymous.

3. Purposes of Processing

The Company uses personal information to establish and administer customer accounts, provide requested functionality, maintain saved portfolios and histories, manage subscriptions and payments, and respond to customer communications. Information may also be used to authenticate access, investigate errors, maintain service reliability, prevent fraud or misuse, and protect the security of the Services.

The Company may process eligible User Content and service information for research, analytics, testing, evaluation, product development, and the development and improvement of software, algorithms, artificial intelligence, and machine learning technologies. These activities may support existing or future products and services and are not restricted to the features available when information is initially collected. Such processing remains subject to the purposes disclosed to customers, applicable legal requirements, required permissions, and relevant contractual restrictions.

Personal information may also be processed to maintain required business records, comply with legal obligations, investigate disputes, enforce applicable agreements, and establish, exercise, or defend legal claims. Service communications concerning accounts, transactions, security, and material changes may be sent when necessary to administer the customer relationship.

Before commencing a materially different use of personal information, the Company provides the disclosures and obtains any additional permission required by applicable law. General references to research, development, or business purposes do not override statutory privacy rights or prior commitments concerning information already collected.

4. Artificial Intelligence and Model Development

The Company may use eligible User Content and service information to develop, train, fine tune, test, validate, evaluate, and improve its own models and technologies. Processing information to deliver a requested calculation or response is distinct from retaining or using that information for model development. The Company establishes an appropriate legal basis for the particular processing and obtains specific consent where required.

User Content remains subject to confidentiality and access restrictions when used for model development. Such use does not authorize disclosure of private customer records to other customers, whether through direct access, a model response, or another service output. Passwords, access secrets, and brokerage account numbers are excluded from model training datasets.

External providers engaged to support the Company’s AI processing or development may process private customer information only to perform services for the Company under appropriate contractual restrictions. They are not permitted to use that information to train their independent general-purpose models. Contractual provisions concerning AI inputs, outputs, ownership, and use appear in Article 20 of the Terms of Service.

5. Confidentiality, Authorized Access, and Customer Sharing

Private account information and non-public User Content are not made available to other customers by default. Access to a Define Your Risk account does not authorize access to another customer’s private information.

Company personnel, contractors, and service providers may access information only where authorized and reasonably necessary for their assigned responsibilities and the purposes described in this Privacy Policy. Such access is subject to appropriate access restrictions and confidentiality obligations. Employment by the Company or assignment of a staff or engineering role does not, by itself, authorize unrestricted access to customer records.

Where the Services offer sharing functionality, disclosure to other customers or external recipients requires an affirmative action by the customer or a person authorized to act on the customer’s behalf. Sharing is disabled by default, and the relevant feature identifies the information and intended audience. Recipients may retain copies of information previously shared with them.

6. Disclosure of Information

The Company may disclose personal information to providers engaged to perform hosting, storage, authentication, payment processing, analytics, communications, support, and other functions necessary to operate or develop the Services. Providers receive information reasonably necessary for their functions and are subject to appropriate contractual, confidentiality, and security requirements.

Information may also be disclosed to a brokerage, integration provider, or other recipient at the customer’s direction or pursuant to an authorized connection. Independently operated services process information under their own terms and privacy notices. Customers should review those notices when enabling a connection or directing a disclosure.

The Company may disclose information to professional advisers, public authorities, or other parties where required by law or reasonably necessary to investigate unlawful conduct, protect lawful rights, address security threats, or establish, exercise, or defend legal claims. Information may also be disclosed in connection with due diligence for a financing, merger, acquisition, reorganization, or transfer of the business, subject to appropriate protections and applicable law.

The Company does not sell or license identifiable customer information to third parties or provide such information for third-party advertising.

7. Aggregated and Anonymous Information

The Company may create aggregated or anonymized information through lawful processing. Where that information no longer identifies an individual and satisfies applicable anonymity requirements, the Company may use, retain, publish, disclose, license, and commercialize it for lawful business purposes, including research, benchmarks, product development, and model development, subject to applicable licenses and confidentiality obligations.

Information treated as anonymous is maintained in that form, and the Company does not attempt to reidentify individuals from it. Appropriate restrictions are applied to recipients. Removal of direct identifiers, aggregation, or incorporation into a model does not, by itself, establish that information is anonymous.

8. Cookies and Similar Technologies

The Services use cookies and similar browser storage to support authentication, maintain preferences, and operate relevant functionality. Analytics and diagnostic technologies may also be used to evaluate feature usage and investigate performance or reliability.

Where applicable law requires consent for optional tracking, the Company obtains that consent before the relevant technology is used. Customers may manage browser storage through their browser settings and may contact the Company concerning privacy preferences. Restricting storage necessary for authentication or other requested functionality may affect access to the Services.

The Company’s optional product analytics, where enabled in the application, do not capture events when a supported browser transmits a Do Not Track or Global Privacy Control signal. These signals do not disable processing necessary for authentication, security, or other requested functionality.

9. Retention, Broker Disconnection, and Account Closure

The Company retains saved portfolio information and history to provide the customer’s requested functionality and maintain continuity of the customer experience. A broker disconnection, expiration of authorization, or temporary connection failure does not, by itself, delete previously saved portfolio records. New synchronization ceases while the connection is unavailable, and retained history may support continued use or reconnection.

Personal information is retained only for as long as reasonably necessary for the purposes described in this Privacy Policy. Retention is determined by the nature and sensitivity of the information, the customer relationship, the functionality requested, security requirements, applicable recordkeeping obligations, and the need to resolve disputes or legal claims.

Customers may request closure of a Define Your Risk account by contacting the Company. An account closure request initiates the Company’s process for reviewing and deleting personal information associated with that account. Following closure or a valid erasure request, information that is no longer required is deleted or lawfully anonymized without undue delay, subject to applicable deadlines. A broker disconnection alone does not initiate that process.

Limited records may be retained where necessary for legal or accounting obligations, fraud prevention, security investigations, or legal claims, as permitted by applicable law. Retained records remain protected, are restricted to the purpose justifying retention, and are removed when that purpose no longer applies.

Copies in backups are removed through the applicable backup lifecycle. Copies awaiting removal are excluded from ordinary processing, and deletion instructions are reapplied following any restoration. Information in training datasets or models remains subject to applicable privacy obligations, and model incorporation does not automatically extinguish those obligations.

10. International Processing

The Company is established in the United States. Personal information may be processed in the United States and other countries in which the Company or its providers operate. The laws of those countries may differ from those of the customer’s jurisdiction.

Where applicable law requires safeguards for an international transfer, the Company applies an appropriate transfer mechanism and related protections. Customers may request information concerning the safeguards relevant to their personal information by contacting the Company.

Where applicable data protection law requires a legal basis, the Company processes personal information as necessary to perform its agreement with the customer, including providing requested account, portfolio, subscription, and integration functions. Processing required for statutory recordkeeping and other legal duties is based on compliance with applicable legal obligations.

The Company may rely on legitimate interests for proportionate security, fraud prevention, diagnostics, service improvement, and development activities where those interests are not overridden by the individual’s interests or fundamental rights. Research and model development are evaluated according to the actual purpose, information involved, reasonable expectations, and applicable requirements. Where consent is required, the Company relies on consent specific to the relevant activity. Acceptance of a general customer agreement does not replace consent where separate consent is legally required.

12. Privacy Rights and Requests

Depending on the individual’s location and applicable law, rights may include access to personal information, correction, erasure, portability, restriction of processing, objection to processing, withdrawal of consent, and protections relating to certain automated decisions or profiling. Applicable United States state laws may also provide rights to use an authorized agent, appeal a decision concerning a privacy request, or exercise choices concerning specified disclosures.

Requests may be submitted to support@defineyourrisk.com. The Company may seek information reasonably necessary to verify the requester’s identity or authority before disclosing, modifying, or deleting information. Requests are addressed within applicable statutory deadlines, and any permitted refusal or extension is explained as required by law.

Withdrawal of consent does not affect the lawfulness of processing conducted before withdrawal. Individuals may also lodge a complaint with the competent supervisory authority where applicable. The Company does not unlawfully discriminate against individuals for exercising privacy rights.

13. Security and Eligibility

The Company maintains technical, administrative, and organizational safeguards appropriate to the information processed and the relevant risks. These include measures designed to restrict unauthorized access, use, and disclosure. No method of transmission or storage can provide an absolute guarantee of security.

The Services are intended for individuals aged 18 or older. Anyone who believes that a person under 18 has provided personal information through the Services should contact the Company so that the circumstances can be reviewed and appropriate action taken.

14. Changes and Contact Information

This Privacy Policy may be amended to reflect changes in the Services, processing practices, or applicable requirements. Material amendments affecting account holders are communicated by email at least 30 days before taking effect, unless a shorter period is required by law. Additional notice or consent is provided where required before a materially different use of personal information begins. The revised policy identifies its effective date.

For inquiries, contact DYR Capital Group LLC by email at support@defineyourrisk.com or by mail at 180 Vineyard Rd, Cotuit, MA 02635, United States.