1. About This Policy
This Privacy Policy describes:
- What personal data we collect about you
- How and why we use that data
- The lawful basis for each type of processing
- Who we share your data with
- How long we keep it
- Your rights under UK data protection law
- How to contact us or complain
We comply with the UK General Data Protection Regulation ("UK GDPR") and the Data Protection Act 2018 ("DPA 2018"). For users in the European Economic Area, we also act in accordance with the equivalent provisions of the EU GDPR.
Terms defined in our Terms of Service and Risk Disclaimer have the same meaning in this Privacy Policy unless we state otherwise.
2. Who We Are
The Service is operated by:
Michiko Academy LtdRegistered in England and Wales
Company Number: 16985497
Registered Office: 167-169 Great Portland Street, 5th Floor, London, United Kingdom, W1W 5PF
Email: michiko@michikofx.com
We are the data controller responsible for your personal data in connection with the Service. Under UK GDPR, this means we decide how and why your personal data is processed.
We are registered with the UK Information Commissioner's Office (ICO) under registration number ZC161050.
We have not appointed a Data Protection Officer. We are not legally required to do so under UK GDPR Article 37. For all data protection enquiries, please contact michiko@michikofx.com.
Michiko Academy Ltd also operates michikofx.com, a separate education and content platform. Where this Privacy Policy refers to michikofx.com (for example, in respect of marketing communications), it refers to the same legal entity.
3. Personal Data We Collect
We collect the following categories of personal data about you. Some of this data you provide directly; some is generated automatically when you use the Service.
3.1 Account and Identity Data
Collected via Clerk when you sign up for an Account:
- Full name
- Email address
- Password (encrypted by Clerk; we cannot view it)
- Profile preferences and settings
- Account creation date and login activity
3.2 Billing and Payment Data
Processed by Stripe when you subscribe to the Service:
- Billing name and address
- Payment card details (processed directly by Stripe; we do not see or store full card numbers)
- Subscription tier and billing cycle
- Transaction history and invoices
- Stripe Identity verification documents (where collected for age verification)
3.3 Usage and Service Data
Generated automatically when you use the Service:
- Pages and features you access within the Terminal
- Workspace configurations, saved layouts, and preferences
- Session timestamps and activity duration
3.4 Device and Technical Data
- IP address
- Browser type and version
- Operating system and device type
- Referring URL
- Time zone and approximate geographic location (city or region level)
3.5 Community Data (Discord)
If you join our Discord community server, we and Discord process:
- Discord username and user ID
- Messages you post in our Discord server
- Roles, reactions, and channel participation
You can leave the Discord server at any time. Joining is optional and not required to use the Terminal.
3.6 Communications Data
- Emails you send to us and our replies
- Support tickets and queries
- Marketing email engagement (opens, clicks, unsubscribes) if you opt in to marketing communications
3.7 Consent Records
- Whether you have opted in to receive Division1 product updates
- Whether you have opted in to receive michikofx.com updates and announcements
- Date and time of your consent
- Records of any withdrawal of consent
3.8 Special Category Data
We do notcollect any special category data (sometimes called "sensitive personal data") under UK GDPR Article 9, including racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic data, biometric data, health data, or data concerning sexual orientation. The Service does not require or request this information.
4. How and Why We Use Your Personal Data
We process your personal data only where we have a lawful basis under UK GDPR Article 6. The lawful bases we rely on are set out below.
4.1 Performance of a Contract (Article 6(1)(b))
We need to process certain personal data to provide the Service you have subscribed to. This includes:
- Creating and managing your Account
- Providing access to the Terminal and its features
- Processing your subscription payments via Stripe
- Sending you transactional emails (subscription confirmations, billing receipts, password resets, security notices, and service-critical announcements)
- Providing customer support
4.2 Legitimate Interests (Article 6(1)(f))
We rely on our legitimate interests to:
- Operate, maintain, secure, and improve the Service
- Detect, prevent, and respond to fraud, abuse, security threats, and breaches of our Terms
- Conduct anonymous, aggregated analytics about how the Service is used (using cookieless analytics tools)
- Defend our legal rights and resolve disputes
- Communicate with you about your Account and our Service for non-marketing purposes
In each case, we have weighed our legitimate interests against your rights and freedoms, and we believe our processing does not override those rights. You have the right to object to processing on this basis at any time. See Section 10.
4.3 Legal Obligation (Article 6(1)(c))
We process certain data to meet legal obligations, including:
- Maintaining accounting and tax records under UK law (Companies Act 2006, Finance Acts, HMRC requirements)
- Verifying that users are 18 years of age or older, via Stripe Identity where required
- Responding to lawful requests from regulators, courts, or law enforcement
- Complying with court orders
4.4 Consent (Article 6(1)(a))
We rely on your specific, informed, opt-in consent to:
- Send you Division1 product updates and marketing communications
- Send you michikofx.com updates and announcements
You may withdraw either or both consents at any time. See Section 5 for details. Withdrawal does not affect the lawfulness of processing before withdrawal.
5. Marketing Communications
5.1 Opt-In Consent
We will only send you marketing emails if you have given us your specific, opt-in consent. Pre-ticked boxes are not used.
When you create an Account, you may choose to opt in to one or both of the following separate communication streams:
- Division1 updates - product announcements, new features, market commentary, and Division1 promotions
- michikofx.com updates- broader communications from Michiko's wider platform, including educational content and michikofx.com news
Each consent is separate and specific. Opting in to one does not opt you in to the other.
5.2 Withdrawing Consent
You can withdraw either or both marketing consents at any time:
- By clicking "unsubscribe" in any marketing email
- By updating your preferences in your Account settings (where available)
- By emailing michiko@michikofx.com
Withdrawal takes effect promptly. You may continue to receive transactional emails (billing receipts, security notices, service-critical announcements) for as long as you have an active Account, because these are sent on the basis of contract performance, not marketing consent.
5.3 Email Service Provider
When we send marketing communications, we use Kit(formerly known as ConvertKit, operated by Kit, Inc.) as our email service provider. Kit processes your email address and engagement data (opens, clicks, unsubscribes) on our behalf as a data processor. Kit's privacy policy is available at https://kit.com/privacy.
6. Cookies and Tracking Technologies
We use only the minimum cookies and similar technologies necessary to operate the Service securely.
6.1 Strictly Necessary Cookies
These cookies are essential for the Service to function. Under the UK Privacy and Electronic Communications Regulations (PECR), we do not need your consent to use them. They include:
- Authentication cookies set by Clerk to keep you logged in
- Session cookies set by Supabase and the Terminal to remember your current session
- Payment cookies set by Stripe during checkout to process your payment securely
6.2 Anonymous Analytics
We use Vercel Web Analytics and Vercel Speed Insights to understand how the Service is used and to monitor performance. These tools are cookieless and anonymous by design. They do not store personal identifiers in your browser and do not use cookies or local storage to track individuals across sessions or websites.
Because Vercel's analytics are cookieless and anonymous, no cookie consent banner is required for them, and no specific consent is needed before they run.
Vercel's privacy policy is available at https://vercel.com/legal/privacy-policy.
6.3 No Tracking or Advertising Cookies
We do not use any tracking cookies, advertising cookies, or third-party tracking pixels. We do not run advertising on the Service. We do not sell, share, or otherwise make your personal data available to advertisers.
6.4 Future Changes
If we ever add cookies that require your consent under PECR (for example, marketing tracking or third-party advertising), we will update this Policy and present you with a cookie consent banner before setting any such cookies.
7. Who We Share Your Data With
We share your personal data only with the processors and third parties listed below, and only to the extent strictly necessary for them to provide their services to us. We do not sell your personal data to anyone.
7.1 Service Providers (Data Processors)
We use the following service providers to operate the Service. Each is bound by a data processing agreement where required by UK GDPR Article 28 and operates under their own published privacy policies.
- Clerk - authentication and account management (United States)
- Stripe - payment processing and identity verification (United States)
- Supabase - database hosting and server infrastructure (United States or EU, region-dependent)
- Vercel - web hosting, edge delivery, and anonymous analytics (United States)
- Kit (formerly ConvertKit) - marketing email delivery, when active (United States)
- Discord - community server hosting, if you join (United States)
- Cloudflare (planned) - edge security, DDoS protection, and rate limiting (United States)
We may add or change service providers from time to time. Material changes to our list of processors will be reflected in this Policy.
7.2 Legal Disclosures
We may disclose your personal data:
- To comply with a legal obligation, court order, or lawful request from a regulator or law enforcement body
- To enforce our Terms of Service or other agreements
- To protect the rights, property, or safety of Michiko Academy Ltd, our users, or others
- To investigate fraud, security incidents, or other unlawful activity
7.3 Business Transfers
If Michiko Academy Ltd is involved in a merger, acquisition, asset sale, restructuring, or insolvency proceeding, your personal data may be transferred to the relevant party. We will notify affected users in advance and give you a reasonable opportunity to object before your data becomes subject to a different privacy policy.
7.4 No Sale of Personal Data
We do not sell your personal data to any third party for advertising, marketing, profiling, or any other purpose.
8. International Data Transfers
Many of our service providers are based in the United States or operate global infrastructure. This means your personal data may be transferred outside the United Kingdom and the European Economic Area.
When we transfer personal data outside the UK or EEA, we ensure appropriate safeguards are in place under UK GDPR Chapter V. These safeguards include:
- Adequacy decisions where the destination country has been recognised by the UK government as providing adequate data protection (for example, the UK-US Data Bridge for participating US organisations)
- UK International Data Transfer Agreement (UK IDTA) or EU Standard Contractual Clauses (SCCs) together with the UK Addendum, signed with each processor where adequacy does not apply
- Supplementary measures such as encryption in transit and at rest, and access controls
You can request a copy of the safeguards in place for any specific transfer by emailing michiko@michikofx.com.
9. How Long We Keep Your Data
We keep your personal data only as long as necessary for the purposes set out in this Policy. Our retention periods by data category are set out below.
- Account data (name, email, profile, preferences) - retained while your Account is active. Deleted or anonymised within 90 days of subscription cancellation, unless we are required to retain it longer by law or legitimate business need.
- Billing and transaction records (held by Stripe) - retained for 10 years from collection. This exceeds the UK HMRC minimum of 6 years for tax records under the Companies Act 2006 and Finance Acts.
- Stripe Identity verification documents (where collected for age verification) - retained for 10 years from collection. This supports our audit requirements for confirming that users are 18 or over.
- Workspace and usage data (held in Supabase) - tied to your Account lifecycle. Deleted with your Account.
- Server and access logs - retained for approximately 30 days for security monitoring and troubleshooting, then deleted or aggregated.
- Anonymous analytics data (Vercel Web Analytics, Vercel Speed Insights) - aggregated and anonymous; retained in line with Vercel's published retention practices.
- Discord community messages- retained on Discord's infrastructure for as long as the server exists. You can delete your own messages at any time. Leaving the Discord server does not retroactively remove messages you posted; you would need to delete them yourself first.
- Marketing email list and engagement data (when Kit is active) - retained while your consent stands. Deleted within 30 days of unsubscribe or other consent withdrawal.
- Support emails and conversations - retained for 2 years from the last contact.
- Records of consent (when you consented, what you consented to, and any withdrawal) - retained for 6 years from withdrawal to evidence our compliance under UK GDPR Article 7(1).
After the relevant retention period ends, we either delete the data or anonymise it so that it can no longer be linked to you. Some data may be retained longer if required by law, regulatory request, ongoing legal proceedings, or tax investigation.
10. Your Rights Under UK Data Protection Law
Under UK GDPR and the DPA 2018, you have the following rights regarding your personal data.
10.1 Right of Access (Article 15)
You can request a copy of the personal data we hold about you, together with information about how we use it. This is often called a Subject Access Request or SAR.
10.2 Right to Rectification (Article 16)
You can ask us to correct any inaccurate or incomplete personal data we hold about you.
10.3 Right to Erasure (Article 17)
You can ask us to delete your personal data in certain circumstances, including where the data is no longer needed for the purposes for which it was collected, where you withdraw your consent, or where you object to processing. Some data must be kept under legal obligations (for example, tax records held by Stripe under HMRC requirements).
10.4 Right to Restrict Processing (Article 18)
You can ask us to stop using your data in certain circumstances, for example while we investigate a complaint or dispute about its accuracy.
10.5 Right to Data Portability (Article 20)
You can request a copy of the personal data you have provided to us in a structured, commonly used, machine-readable format, and ask us to transmit it to another data controller where technically feasible.
10.6 Right to Object (Article 21)
You can object to our processing of your personal data on the basis of legitimate interests (Section 4.2 above), and to direct marketing at any time. We will stop processing for direct marketing immediately on your request.
10.7 Right to Withdraw Consent (Article 7(3))
Where we rely on your consent (for marketing communications), you can withdraw your consent at any time. Withdrawal does not affect the lawfulness of any processing carried out before withdrawal.
10.8 Rights Relating to Automated Decision-Making (Article 22)
We do not make automated decisions about you that produce legal or similarly significant effects. The Service produces analytical signals about foreign exchange markets, not decisions about you as an individual. You are not subject to automated profiling that affects your legal rights or significantly impacts you. The trading bias signals, conviction scores, and other outputs of the Terminal are tools for your own analysis. Any trading decisions are made by you, not by us.
10.9 How to Exercise Your Rights
To exercise any of your rights, please email michiko@michikofx.com.
We will respond within one month of receiving your request. This period may be extended by up to two further months for complex requests, in which case we will tell you within the first month and explain why.
We may need to verify your identity before responding to your request, to protect your data from unauthorised disclosure. We will not charge you a fee unless your request is manifestly unfounded or excessive.
10.10 Right to Complain to the ICO
If you are unhappy with how we have handled your personal data, you have the right to lodge a complaint with the UK Information Commissioner's Office:
Information Commissioner's OfficeWycliffe House, Water Lane
Wilmslow, Cheshire SK9 5AF
United Kingdom
Helpline: 0303 123 1113
Website: https://ico.org.uk
We would appreciate the chance to address your concerns directly before you contact the ICO. Please email michiko@michikofx.com first if you have any concerns; we will do our best to resolve them.
11. Security Measures
We take the security of your personal data seriously and have implemented appropriate technical and organisational measures to protect it, including:
- Encryption in transit using TLS 1.2 or higher for all data flowing between your device and the Service
- Encryption at rest for sensitive data stored by our processors
- Access controls restricting personal data access to those who need it for their work
- Authentication via Clerk using industry-standard password hashing, with multi-factor authentication available on administrator accounts
- Payment security via Stripe, which is PCI-DSS Level 1 certified; we do not see or store full payment card details
- Edge security including DDoS protection and rate limiting (Cloudflare integration is planned)
- Anti-virus and anti-malware protection on systems used to access personal data
- Regular reviews of our security posture, processor agreements, and software dependencies
No internet transmission or storage system is 100% secure. While we take reasonable steps to protect your personal data, we cannot guarantee absolute security.
If we become aware of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours where required by UK GDPR Article 33, and inform affected users without undue delay where required by UK GDPR Article 34.
12. Children's Data
The Service is not intended for, marketed to, or made available to anyone under the age of 18. You must be at least 18 years old to create an Account and use the Service. Where appropriate, we use Stripe Identity verification to confirm that users meet this age requirement.
We do not knowingly collect personal data from anyone under the age of 18. If we learn that we have collected personal data from a person under 18, we will delete that data promptly.
If you believe a person under 18 has provided us with personal data, please contact michiko@michikofx.com and we will take prompt action.
13. Notice to United States Users
Our Service is available worldwide, but Michiko Academy Ltd is based in the United Kingdom, and our practices are primarily designed to comply with UK and EU data protection law. If you are a resident of the United States or any US state with its own privacy law (for example, the California Consumer Privacy Act, the Virginia Consumer Data Protection Act, or other state privacy frameworks), you may have additional or different rights under those laws.
We do not separately guarantee compliance with each US state's specific privacy framework. By using the Service, you acknowledge that your rights under US law may not be addressed in the same terms as in this Policy, and that you use the Service at your own discretion.
If you are a US resident and would like to exercise any data protection right described in Section 10, please contact michiko@michikofx.com and we will respond consistent with our UK GDPR obligations and any applicable US legal requirements.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will publish the updated version on the Website and update the Last Updated date at the top of this document.
If we make material changes (for example, adding new categories of data we collect, adding new processors, or changing the purposes of processing), we will notify you by email or by a prominent notice within the Service before the changes take effect.
Your continued use of the Service after the effective date of any update constitutes your acceptance of the updated Policy. If you do not agree with the changes, you must stop using the Service and may cancel your Account. Cancellation does not entitle you to a refund.
15. How to Contact Us
For any questions, concerns, or requests about this Privacy Policy or your personal data, please contact us:
Michiko Academy Ltd167-169 Great Portland Street, 5th Floor
London, United Kingdom, W1W 5PF
Email: michiko@michikofx.com
We aim to respond to all data protection enquiries within 30 days.