Privacy Policy
Last updated: January 2025
At Opxem Rylox, we believe transparency matters. This policy explains what information we collect when you use our investment research platform, how we handle it, and what choices you have.
We're based in Ireland and follow Irish and European data protection rules. If you've got questions after reading this, reach out to us at [email protected].
1 Information We Collect
When you sign up for Opxem Rylox, we ask for basic details. Your name, email address, and the password you create. If you choose a paid subscription, we'll need billing information too—though we don't store full payment card numbers ourselves.
As you use the platform, we automatically collect some technical data. IP addresses, browser type, which pages you visit, and how long you spend reading research reports. This helps us spot problems and understand what content actually helps people.
Account Information
- Full name and email address
- Account credentials and security preferences
- Subscription tier and payment history
- Communication preferences
Usage Data
- Pages viewed and time spent on platform
- Research reports downloaded or bookmarked
- Search queries and filter preferences
- Device information and browser settings
- Access times and geographic location data
2 How We Use Your Information
Most of what we collect serves pretty straightforward purposes. We need your email to send you research updates and account notifications. Usage data helps us figure out which types of analysis our members find most valuable.
Sometimes we look at patterns across all users to improve our research focus. If everyone's searching for renewable energy stocks but nobody's reading our mining sector reports, that tells us something worth knowing.
| Purpose | Data Used | Legal Basis |
|---|---|---|
| Provide platform access | Account credentials, subscription status | Contract performance |
| Send research updates | Email address, preferences | Legitimate interest |
| Process payments | Billing information | Contract performance |
| Improve content | Usage patterns, feedback | Legitimate interest |
| Security monitoring | IP address, access logs | Legitimate interest |
3 Data Sharing and Disclosure
We don't sell your information to anyone. That's not our business model and never will be.
We do work with a few service providers who help run the platform. Our hosting company obviously has access to data stored on their servers. Our payment processor handles billing information. These companies are contractually required to protect your data and can't use it for their own purposes.
Third-Party Services: Our payment processing is handled by a PCI-DSS compliant provider. We use cloud hosting services based in the European Economic Area. Email communications are sent through a dedicated email service provider. All these partners are bound by strict confidentiality agreements.
If we're legally required to disclose information—say, in response to a valid court order—we'll do so. We'll notify you when possible unless prohibited by law.
4 Your Rights Under Irish and EU Law
European data protection rules give you real control over your information. These aren't just theoretical rights—we've built systems to actually honor them.
Access Your Data
Request a copy of all personal information we hold about you. We'll provide it in a readable format within one month.
Correct Inaccuracies
Update or fix any incorrect information in your account. Most details you can change yourself through account settings.
Delete Your Account
Request complete deletion of your account and associated data. Some financial records may need retention for legal compliance.
Restrict Processing
Limit how we use your data in certain situations, like when you're disputing information accuracy.
Data Portability
Receive your data in a machine-readable format to transfer to another service if you choose.
Object to Processing
Challenge our use of your data for direct marketing or other purposes based on legitimate interests.
To exercise any of these rights, email [email protected] with your request. We'll verify your identity and respond within the timeframes required by law. There's no fee unless your request is clearly excessive or repetitive.
5 Data Security Measures
We take reasonable precautions to protect your information. All data transmission uses TLS encryption. Passwords are hashed and salted using industry-standard algorithms. Our servers are located in secure data centers with physical access controls.
That said, no system is completely bulletproof. We can't guarantee absolute security, but we can promise to notify you promptly if we discover any breach that affects your data.
Technical Safeguards
- 256-bit SSL/TLS encryption for all data in transit
- Encrypted storage for sensitive information at rest
- Regular security audits and penetration testing
- Multi-factor authentication options for accounts
- Automated backup systems with secure offsite storage
- Restricted employee access on need-to-know basis
6 Data Retention Periods
We keep your account information as long as you're an active member. Usage logs are retained for 24 months for analytics and security monitoring. After you close your account, we'll delete most personal data within 90 days.
Some information needs longer retention for legal reasons. Financial transaction records are kept for seven years to comply with Irish tax law. If there's an ongoing dispute or legal matter, we'll hold relevant data until it's resolved.
Backup Systems: Deleted data may persist in backup systems for up to 90 additional days before permanent removal. These backups are encrypted and access-restricted for disaster recovery purposes only.
7 Cookies and Tracking
Our platform uses cookies—small text files stored on your device. Some are essential for the site to function properly, like remembering you're logged in. Others help us understand how people use the platform.
You can control cookie preferences through your browser settings. Blocking all cookies might break some features, but you'll still be able to access core research content.
We don't use advertising cookies or share data with ad networks. The analytics we collect stay with us and serve our own improvement efforts.
8 International Data Transfers
Your data is primarily stored on servers within the European Economic Area. If we need to transfer information outside the EEA—for instance, to a specialized service provider—we'll make sure appropriate safeguards are in place.
This might mean using standard contractual clauses approved by the European Commission, or working only with providers certified under recognized data protection frameworks.
9 Children's Privacy
Opxem Rylox is designed for adults making investment decisions. We don't knowingly collect information from anyone under 18. If we discover we've accidentally gathered data from a minor, we'll delete it immediately.
Parents or guardians who believe their child has provided us with personal information should contact us right away at [email protected].
10 Changes to This Policy
We'll update this privacy policy occasionally as our practices evolve or laws change. When we make significant changes, we'll notify active members by email and post a notice on the platform.
The "last updated" date at the top of this page always reflects the most recent revision. Continuing to use Opxem Rylox after changes take effect means you accept the updated terms.
11 Regulatory Oversight
Our data handling practices are subject to oversight by the Data Protection Commission in Ireland. If you're not satisfied with how we've addressed a privacy concern, you have the right to lodge a complaint with them.
You can reach the Data Protection Commission through their website at dataprotection.ie or by post at 21 Fitzwilliam Square South, Dublin 2, D02 RD28, Ireland.
Questions About This Policy?
If something here isn't clear, or you want to discuss your privacy rights, we're happy to talk.
Email: [email protected]
Phone: +353 21 486 6044
Post: Opxem Rylox, Cashel, Glencolumbkille, Co. Donegal, F94 XW98, Ireland
We aim to respond to all privacy inquiries within five business days. Complex requests might take longer, but we'll keep you updated on progress.