Legal

Privacy Policy

This Privacy Policy explains how MARFIN collects, uses, stores, and protects personal data when you visit the website, interact with our content, use Telegram-delivered workflows, request access, communicate with us, subscribe to paid features, or use services made available through MARFIN.

MARFIN is offered through OÜ MegagroupEU.

Data controller

OÜ MegagroupEU

Registry code 16636817

Veskiposti tn 2-1002, 10138 Tallinn, Estonia

Privacy contact: info@marfin.me

1. Scope of this Policy

This Privacy Policy applies to the MARFIN website, landing pages, cookie and analytics preferences, Telegram workflows, subscription access flows, support communications, API or institutional access requests, and related interactions where personal data is processed by or on behalf of OÜ MegagroupEU.

It applies whether you are only visiting the public site, using a delayed public view, interacting with MARFIN through Telegram, requesting access to paid features, communicating with us about the product, or using subscription-related services.

This Policy does not automatically apply to third-party services that may be linked from MARFIN, including Telegram, payment providers, analytics providers, hosting providers, or external content platforms. Those providers may process data under their own privacy terms and policies.

2. Data minimisation and no suitability profiling

MARFIN is designed to collect only the personal data reasonably needed to operate the service, provide access, process payments, communicate with users, maintain security, and comply with legal obligations.

We do not require users to provide their real name, postal address, phone number, country of residence, investment objectives, portfolio, risk tolerance, tax position, financial situation, or legal constraints in order to use the Telegram workflow.

MARFIN does not use personal data to determine whether any model output, regime state, exposure category, instrument, trade, strategy, or market activity is suitable for a particular user.

3. What data we may collect

Depending on how you interact with MARFIN, we may collect:

  • contact details you provide, such as your email address, name, company name, or business contact information;
  • Telegram-related identifiers, such as Telegram user ID, username, chat ID, bot interaction records, command metadata, subscription status, access level, and service usage records;
  • account, plan, trial, subscription, access, billing status, or entitlement-related information;
  • communication content, including support requests, contact form submissions, legal requests, billing questions, or business correspondence;
  • device, browser, IP address, approximate technical location, server log, and technical usage data generated when you access the website or service;
  • cookie preference data and analytics data collected with your consent where analytics tools are enabled;
  • payment-related records from payment providers, such as payment status, plan purchased, renewal status, invoice references, billing country where provided by the payment provider, tax information where required, and payment-provider identifiers;
  • security and operational logs needed to protect the service, prevent abuse, enforce access controls, troubleshoot issues, and maintain service integrity.

We do not intentionally ask for special categories of personal data unless there is a specific legal and operational reason to do so.

Telegram identifiers, usernames, IP addresses, cookie identifiers, and similar online identifiers may constitute personal data under applicable privacy laws.

4. How we collect data

We may collect personal data in the following ways:

  • directly from you when you submit a form, request access, subscribe, contact us, or communicate with support;
  • through Telegram when you interact with the MARFIN bot or Telegram-delivered workflow;
  • automatically when you use the website, including through server logs, security logs, cookies, and consented analytics technologies;
  • from payment, billing, infrastructure, communication, or support providers involved in delivering the service;
  • from your ongoing interaction with MARFIN where access, operational, subscription, security, or support records need to be maintained.

5. Purposes of processing

We process personal data to:

  • operate the website and deliver the MARFIN product experience;
  • provide delayed public access, Telegram workflow access, subscription features, trial flows, API access where approved, and related service features;
  • identify Telegram users for access control, subscription entitlement, bot commands, support, and service operation;
  • process subscriptions, renewals, payment status, invoices, refunds, taxes, and billing-related matters;
  • communicate with users, prospects, partners, API users, or customers;
  • respond to support, privacy, legal, billing, technical, or access requests;
  • protect the service, detect abuse, prevent unauthorised access, troubleshoot issues, and maintain security;
  • understand website usage and improve the product where analytics consent has been given;
  • comply with legal, accounting, tax, consumer protection, sanctions, payment, and regulatory obligations;
  • enforce our terms, protect our rights, handle disputes, and manage legal or compliance risk.

We do not process personal data to provide personalized investment advice or to determine suitability for any particular user.

6. Legal bases for processing

Depending on the situation, we process personal data on one or more of the following legal bases:

  • performance of a contract, or steps taken at your request before entering into a contract, including providing access to MARFIN, subscriptions, Telegram workflows, support, and billing administration;
  • compliance with legal obligations, including accounting, tax, payment, consumer, and regulatory obligations;
  • our legitimate interests in operating, securing, improving, administering, protecting, and enforcing MARFIN, provided those interests are not overridden by your rights and interests;
  • your consent, where consent is required, including for non-essential analytics technologies and certain cookie-based processing.

Where processing is based on consent, you may withdraw that consent at any time for future processing.

7. Cookies and similar technologies

MARFIN uses strictly necessary technologies required for core site operation, security, access control, and preference storage. Where enabled, we may also use analytics technologies to understand site usage and improve the product.

Non-essential analytics technologies are only used where the relevant consent has been provided. You can change your preferences through cookie settings made available on the site.

More detail is available in the Cookie Policy.

8. Recipients and service providers

We may share personal data with trusted service providers and processors where reasonably necessary for operating MARFIN. These may include:

  • hosting and infrastructure providers;
  • Telegram or messaging-related service channels used to deliver MARFIN workflows;
  • analytics providers, where analytics processing has been consented to;
  • payment, billing, invoicing, tax, or subscription providers;
  • support, communication, or email service providers;
  • professional advisers where needed for legal, accounting, compliance, tax, or business administration purposes;
  • public authorities, regulators, courts, or law enforcement where required by applicable law or where necessary to protect legal rights.

We do not sell personal data in the ordinary meaning of the term. We only share data where there is a valid legal, operational, contractual, security, or compliance reason to do so.

9. Payment processing

Payments, subscriptions, checkout flows, invoices, renewals, and payment authentication may be handled by third-party payment providers.

MARFIN does not store full payment card numbers. Payment providers may process payment details, billing details, transaction records, tax information, fraud-prevention signals, and related data under their own terms and privacy policies.

We may receive payment status, subscription status, invoice references, plan information, customer identifiers, and related payment-provider records needed to provide access, support, accounting, tax, fraud-prevention, and compliance functions.

10. International data transfers

Some service providers used to operate MARFIN may process data outside the European Economic Area. This may include providers used for hosting, analytics, payment processing, messaging, infrastructure, security, or support.

Where this happens, we take reasonable steps to ensure that appropriate safeguards are in place under applicable data protection law.

Such safeguards may include contractual protections, standard contractual clauses where applicable, recognised adequacy frameworks, and provider-level security and compliance commitments.

11. Data retention

We retain personal data only for as long as reasonably necessary for the purposes described in this Policy, including legal, accounting, contractual, tax, security, and dispute-resolution purposes.

Retention periods may vary depending on the type of data:

  • contact and support correspondence may be retained for as long as needed to handle the request and maintain a support record;
  • Telegram identifiers, access records, subscription status, and service usage records may be retained while needed to provide the service, manage access, enforce plan limits, and maintain operational records;
  • subscription, billing, payment status, invoicing, and access records may be retained for legal, accounting, tax, audit, and dispute-resolution purposes;
  • security and operational logs may be retained for a limited period to maintain service integrity, investigate incidents, and prevent abuse;
  • analytics data retention depends on the settings used by the analytics provider and our internal review of necessity and proportionality.

Where data is no longer needed, we delete, anonymise, or otherwise reduce it where reasonably possible, subject to legal, accounting, security, and operational requirements.

12. Your rights

Subject to applicable law, you may have the right to request:

  • access to personal data we hold about you;
  • correction of inaccurate or incomplete data;
  • erasure of personal data in certain circumstances;
  • restriction of processing in certain circumstances;
  • objection to certain types of processing;
  • withdrawal of consent where processing is based on consent;
  • data portability where applicable;
  • the right to lodge a complaint with a competent data protection authority.

If you wish to exercise your rights, contact us using the details provided below. We may need to verify your identity before responding.

If your request relates to Telegram-based access, including a Telegram user ID or username in your request may help us locate the relevant records.

13. Security

We take reasonable technical and organisational measures to help protect personal data against unauthorised access, misuse, disclosure, loss, or destruction.

These measures may include access controls, secure hosting practices, logging, monitoring, transport encryption, and limitation of access to people and systems that need the data for operational, security, support, or compliance purposes.

No internet-based system can be guaranteed to be completely secure, but we aim to keep data handling proportionate, limited, and operationally responsible.

14. Third-party links and services

MARFIN may include links to third-party services such as Telegram, payment providers, analytics providers, hosting providers, external websites, or other service providers.

If you interact with those third-party services, your data may be processed under their own policies and terms.

We encourage you to review the privacy information of third-party services before using them.

15. Changes to this Policy

We may update this Privacy Policy from time to time to reflect changes in the service, legal requirements, provider changes, or operational practices.

The version published on this page is the current version. Where appropriate, material changes may also be reflected through site notices or related user-facing communications.

16. Contact

For privacy questions, requests, or concerns, contact:

OÜ MegagroupEU

Registry code 16636817

Veskiposti tn 2-1002, 10138 Tallinn, Estonia

Email: info@marfin.me

You may also contact the data protection authority in your country or, where applicable, the Estonian Data Protection Inspectorate if you believe your data protection rights have been infringed.

Last updated: 2026-04-27