In one line: we hold your email, the strategies you build and the results they produce. We never touch your broker, your holdings, your password or your card. We do not sell anything to anyone.
About this notice
Imperial Quant LLP (Limited Liability Partnership) operates EdgeTest and is the Data Fiduciary for the personal data described here. This notice explains what we collect, why we collect it, who else processes it, how long we keep it, and the rights you have.
It is written to meet the requirements of the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025, and of the Information Technology Act, 2000 together with the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.
If you would prefer to receive this notice in Hindi, Gujarati, or any other language listed in the Eighth Schedule to the Constitution of India, write to support@edgetest.in and we will provide it.
What we collect, why, and which feature needs it
We collect only what a feature you use actually requires. The table sets this out item by item: the category of personal data, the purpose it is processed for, and the part of the service that depends on it.
| Data | Why we process it | Feature that needs it |
|---|---|---|
| Email address and name | To identify your account and send you messages you have asked for | Sign-in, daily signal email, support replies |
| Account and plan record | To apply the limits of your plan and restore your work when you return | Plans, saved strategies, usage counters |
| Strategies you build and save | To run, store and re-run the strategies you create | Strategy Terminal, Saved strategies |
| Backtest jobs and their results | To produce and keep your reports so you can revisit and compare them | Results, History, Compare |
| Tracked strategies and signal history | To re-simulate your strategy each evening and tell you what it would have done | Daily Strategy Signals |
| Text you type into the AI chat | To translate your description into a strategy, and to answer your support questions | Ella strategy builder, Ella support |
| Support tickets, chat transcripts and any screenshots you attach | To understand and resolve the problem you reported | Support |
| IP address | To apply rate limits, prevent abuse, and protect the service | All access to our API |
| Browser type, page address and crash reports | To diagnose faults and fix them | Error reporting |
| Last activity timestamp | To operate the service and understand aggregate usage | Account administration |
| Payment and billing details | To take payment for a paid plan. Handled entirely by our payment aggregator | Checkout, once paid plans are live |
What we never collect
We do not connect to your broking or demat account. We do not know your holdings, your positions, your orders or your trades, and we never ask for broker credentials.
We do not receive or store your Google password. Sign-in happens on Google's own systems, which release only your email address and name to us after you approve it.
We do not receive or store your card number, CVV, UPI PIN or bank credentials. When paid plans go live, those are collected and held by our payment aggregator, never by us.
We do not collect biometric data, government identifiers, health data, or your precise location. We do not buy personal data from data brokers.
The basis on which we process your data
We process your personal data on the basis of the consent you give when you create an account and use a feature, and for the certain legitimate uses permitted by the Digital Personal Data Protection Act, such as complying with a legal obligation or responding to a request you have made.
Consent is specific to the purposes in the table above. We do not use your data for a new and unrelated purpose without telling you and, where required, asking again.
We do not sell your personal data. We do not share it for advertising. We do not publish your strategies.
Who else processes your data
We use a small number of specialist providers to run the service. Each receives only what its function requires, and each is bound to process it on our instructions. Some are located outside India, which means your personal data may be transferred and processed outside India. We rely on the transfer permissions available under the Digital Personal Data Protection Act, 2023 and place contractual protections on each provider.
We describe each provider by what it does rather than by name. Publishing the exact list of suppliers tells an attacker which systems to target and is not something the law asks us for. What the law does ask for is below in full: what each one does, precisely what it receives, and where in the world it sits. If you want the named list for your own diligence, write to us and we will give it to you.
| What it does | What it receives | Where |
|---|---|---|
| Our application servers and database | Your account record, saved strategies, backtest jobs and results, support tickets | Bangalore, India |
| Sign-in and session management | Your email address and a user identifier. We never receive your password | Outside India |
| The sign-in provider you choose when you sign in with an existing account | Your email address and name, released by that provider only when you approve the sign-in | Outside India |
| The AI that turns your description into a strategy, and the Ella support assistant | The text you type into the strategy chat or support chat, and the strategy currently in your builder | United States |
| Sending transactional and daily-signal email | Your email address and the contents of the email | United States |
| Serving the website, plus cookieless usage analytics | Standard request data. The analytics set no cookies and no cross-site identifier | Global edge network |
| DNS, TLS, security filtering, and routing mail sent to our support address | Request metadata including IP address; the content of email you send us | Global edge network |
| Error monitoring: alerting us when the product crashes, so we can fix it | Crash reports: error message, stack trace, the page address where it happened, and browser type. We have turned OFF the option to send IP addresses and request headers | European Union (Germany) |
| Payment processing, once paid plans are live | Payment and billing details, handled entirely by the payment processor. We never see or store card details | India |
What we share, and what we do not
Beyond the providers listed above, we share personal data only where we are legally required to: in response to a valid order from a court, regulator or law enforcement agency, to establish or defend a legal claim, or to protect the safety, rights or property of our users or of EdgeTest.
If EdgeTest is ever acquired, merged or reorganised, your data may transfer to the successor entity, which will remain bound by a policy no less protective than this one. We will tell you before that happens.
Cookies and local storage
We use a session cookie to keep you signed in. That is the only cookie required for the service to work.
We use your browser's local storage to remember things on your own device, such as your chat history, your current strategy, and layout preferences. That information stays on your device and is not a cookie.
Our usage analytics are cookieless: they set no cookie and no cross-site identifier, and they cannot be used to follow you across other websites. We run no advertising trackers, no retargeting pixels, and no third-party marketing scripts.
You can clear local storage and cookies through your browser at any time. Clearing them signs you out and forgets your saved builder state on that device; nothing stored on our servers is affected.
How long we keep it
We keep personal data only for as long as the purpose it was collected for requires, and then delete it.
| What | How long |
|---|---|
| Account record (email, plan, preferences) | Until you ask us to delete your account |
| Saved strategies | Until you delete them, or your account is deleted |
| Backtest results, Free plan | 30 days from the run, then automatically deleted |
| Backtest results, paid plans | Retained while your account is active |
| Daily-signal history for a tracked strategy | While the strategy is tracked, then deleted with it |
| Support tickets and any screenshots you attach | 24 months from the date the ticket is closed |
| Billing and tax records | As long as Indian tax law requires, currently 8 years |
| Security and administrative audit records | Up to 3 years, for accountability |
| Server logs | Rotated automatically; retained no longer than 90 days |
Your rights
Under the Digital Personal Data Protection Act, 2023 you have the following rights, and we will honour a request within 30 days:
- Access: ask us for a summary of the personal data we hold about you and how it is being processed.
- Correction: ask us to correct data that is inaccurate or misleading, and to complete data that is incomplete.
- Erasure: ask us to delete your personal data, unless we are required by law to keep it. Deleting your account removes your strategies, backtests and tracked strategies.
- Withdraw consent: withdraw your consent at any time, as easily as you gave it. Withdrawal does not affect processing already carried out, and some features will stop working without the data they need.
- Nomination: nominate another person to exercise your rights on your behalf if you die or become incapable of exercising them yourself.
- Grievance redressal: complain to us about how your data has been handled, using the route in the next section.
How to exercise a right, or raise a grievance
Write to support@edgetest.in from the email address on your account, telling us what you want to do. Asking for account deletion, a copy of your data, a correction, or the withdrawal of consent all go to the same address.
We will acknowledge your request within 48 hours and resolve it within 30 days, which is the period required by the Information Technology (Reasonable Security Practices) Rules, 2011 and the Consumer Protection (E-Commerce) Rules, 2020.
If you are not satisfied with how we have handled a data-protection grievance, you may escalate it to the Data Protection Board of India, which is the statutory authority established under the Digital Personal Data Protection Act, 2023.
Our full grievance mechanism, including the officer responsible, is published on our Contact page.
How we protect your data
Security is not a promise here, it is a set of specific measures. All traffic is encrypted in transit with TLS. Our database is not reachable from the public internet. Our servers accept administrative access only by cryptographic key, with automated blocking of repeated failed attempts, and our application origin accepts traffic only through our security proxy.
Access to the administration console is restricted to named founder accounts, protected by single sign-on at a separate hostname, and every administrative action is written to an append-only audit record showing who did what and when.
We never handle your password or your card details, which removes the two most damaging categories of breach entirely. Backups are taken nightly and validated. Rate limits apply per client to contain abuse.
No system is perfectly secure, and we do not claim otherwise. If you believe you have found a vulnerability, please report it to support@edgetest.in and we will respond promptly.
If there is a data breach
If a personal data breach occurs, we will notify each affected user without undue delay, describing what happened, the data involved, the likely consequences, what we are doing about it, and what you can do to protect yourself.
We will also report the breach to the Data Protection Board of India within the timeframe required by the Digital Personal Data Protection Rules, 2025.
Children
EdgeTest is intended for users aged 18 and over. We do not knowingly collect personal data from children, and we do not create accounts for them.
If you believe a child has provided us with personal data, write to support@edgetest.in and we will delete it.
Changes to this notice
We will update this notice as the product and the law change. The date at the top always shows when it was last revised, and material changes will be notified through the platform or by email before they take effect.
Contact
For any question about this notice or about your personal data, write to support@edgetest.in. This is the address for data-protection matters, and it is monitored by the founders directly.