Privacy Policy
Last Updated: April 16, 2025
FineroLab ("we", "us", "our") is committed to protecting your personal data. This Privacy Policy explains how we collect, use, share, and protect your information when you visit finerolab.com and complete our quiz and registration process.
This policy complies with:
- EU General Data Protection Regulation (GDPR)
- UK General Data Protection Regulation (UK GDPR) & Data Protection Act 2018
- Canadian Anti-Spam Legislation (CASL) & PIPEDA
- ePrivacy Directive
1. Data Controller — Who We Are
FineroLab is an educational platform providing structured learning content about financial markets, trading, and investing.
Controller: FineroLab
Website: finerolab.com
Email: privacy@finerolab.com
DPO: dpo@finerolab.com
2. Personal Data We Collect
2.1 Data you provide directly
Through our quiz and registration form, we collect:
- First and last name
- Email address
- Phone number
- Quiz responses: age range, market interests (Forex/Crypto/Stocks), goals, experience level, available capital range, time availability, barriers to starting
- Consent preferences and timestamp
2.2 Automatically collected data
- IP address and approximate geolocation (country/city)
- Browser type, version and operating system
- Pages visited and time spent on site
- Referring URL and traffic source (UTM parameters)
- Device type and unique identifiers
2.3 Data from advertising platforms
If you arrive via Meta Lead Ads (Facebook/Instagram) or TikTok Lead Ads, data you enter is transmitted to us by those platforms. Such data is subject to both this Privacy Policy and the respective platform's Privacy Policy.
3. Purposes of Processing & Legal Basis
| Purpose | Data Used | Legal Basis (Art. 6 GDPR) |
|---|---|---|
| Delivering your personalized education plan | Name, email, quiz answers | Art. 6(1)(b) — Pre-contractual measures |
| Contacting you via phone/email/WhatsApp | Name, phone, email | Art. 6(1)(a) — Explicit consent |
| Marketing & educational communications | Name, email | Art. 6(1)(a) — Explicit consent (separate opt-in) |
| Lead management (Google Sheets CRM) | All form data | Art. 6(1)(b) — Contract performance |
| Meta & TikTok advertising campaigns | Email (hashed), pixel data | Art. 6(1)(a) — Cookie consent / Art. 6(1)(f) — Legitimate interest |
| Website analytics & improvement | Usage data, IP | Art. 6(1)(f) — Legitimate interest |
| Legal compliance | As required | Art. 6(1)(c) — Legal obligation |
Where processing is based on consent, you may withdraw it at any time by writing to privacy@finerolab.com or clicking "Unsubscribe" in any email. Withdrawal does not affect the lawfulness of prior processing.
4. Lead Generation — Transparency Notice
FineroLab operates as a lead generation and educational referral service. We collect personal data through our website quiz and, with your explicit consent, our education specialists will contact you to discuss your personalized learning plan.
4.1 How contact works
When you complete the quiz and registration form, you are clearly informed before submission that:
- Our education specialists may contact you by phone, email, or WhatsApp
- Your data will be stored securely in our internal CRM (Google Sheets)
- Contact occurs only after obtaining your clear, affirmative consent
4.2 Specialist obligations
All education specialists who access your data are contractually required to:
- Process it only for the stated educational purpose
- Comply with GDPR, UK GDPR, CASL, and applicable law
- Not share your data with unauthorized third parties
4.3 CASL compliance (Canadian users)
For users in Canada, all commercial electronic messages are sent only with express consent under CASL. Consent records include: date/time, acquisition mechanism, identity of consenting party, and stated purpose. Opt-out requests are processed within 10 business days.
5. Meta & TikTok Advertising
5.1 Meta Pixel (Facebook/Instagram)
We use the Meta Pixel to measure advertising campaign effectiveness and build Custom Audiences (using only hashed emails). The Pixel is activated only with your cookie consent. You can disable it via our cookie banner or through Meta Ad Preferences.
5.2 TikTok Pixel
We use TikTok Pixel to measure campaign performance and optimize our educational content advertising. Activated only with cookie consent. You can opt out via TikTok's privacy settings.
5.3 Native Advertising Networks
We run campaigns on native advertising platforms (including Taboola, Outbrain, MGID). These platforms may use cookies to measure campaign performance. Activated only with your cookie consent.
5.4 Advertising compliance
FineroLab does not promote:
- Guaranteed financial returns or income promises
- Misleading claims about trading results
- Deceptive or manipulative advertising practices
All advertisements comply with Meta, TikTok, and applicable native advertising platform policies, as well as EU, UK, and Canadian consumer protection regulations.
6. Cookies & Tracking Technologies
| Type | Purpose | Duration | Consent Required |
|---|---|---|---|
| Strictly Necessary | Website operation, security, session management | Session | No |
| Functional | Remember user preferences and quiz progress | Max 1 year | Yes |
| Analytics | Traffic analysis — Google Analytics | Max 2 years | Yes |
| Marketing/Advertising | Meta Pixel, TikTok Pixel, Native Ad networks | Max 180 days | Yes |
| Consent Record | Records your cookie consent choice | Max 1 year | No |
Manage your preferences through:
- The cookie banner displayed on your first visit
- Your browser settings
- Your Online Choices (EU): youronlinechoices.eu
- Meta Ad Preferences: facebook.com/ads/preferences
- TikTok Privacy Settings
7. Data Sharing
We do not sell your personal data. We share it only in these circumstances:
- Education specialists — internal team who will contact you about your personalized plan, with your explicit consent
- Service providers — hosting, email delivery, analytics — all bound by Data Processing Agreements (DPAs)
- Advertising platforms — Meta, TikTok, native ad networks — for campaign management, only anonymized/hashed data
- Google Workspace — your lead data is stored in Google Sheets for internal CRM management
- Competent authorities — where required by applicable law
- Business transfers — in event of merger or acquisition, with prior notice to affected users
8. Data Retention
| Category | Retention Period |
|---|---|
| Registration form & quiz data | 24 months from collection |
| Active lead records | 24 months from last interaction |
| Inactive contacts | Deleted after 12 months of no engagement |
| Consent records | 5 years (GDPR/CASL compliance) |
| Marketing communication records | 3 years from last interaction |
| Website analytics data | 26 months |
| Legal/accounting records | 10 years (legal obligation) |
Once applicable retention periods expire, data is securely deleted or anonymized.
9. International Data Transfers
Your data may be transferred and processed outside the European Economic Area (EEA). In such cases, we ensure appropriate safeguards:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Adequacy decisions where applicable
- Equivalent contractual protections for transfers to Canada under PIPEDA
For information on specific safeguards, contact: privacy@finerolab.com
10. Your Rights — EU & UK Users (GDPR / UK GDPR)
| Right | Description |
|---|---|
| Access (Art. 15) | Obtain a copy of personal data we hold about you |
| Rectification (Art. 16) | Request correction of inaccurate or incomplete data |
| Erasure (Art. 17) | Request deletion of your data ("right to be forgotten") |
| Restriction (Art. 18) | Request limitation of how we process your data |
| Portability (Art. 20) | Receive your data in a machine-readable format |
| Objection (Art. 21) | Object to processing based on legitimate interest |
| Withdraw Consent | Withdraw consent at any time without penalty |
To exercise your rights, contact: privacy@finerolab.com. We will respond within 30 days.
You have the right to lodge a complaint with your local Data Protection Authority (DPA).
11. Your Rights — Canadian Users (PIPEDA / CASL)
Canadian users have the right to:
- Access the personal data we hold about you
- Request corrections to inaccurate information
- Withdraw consent, subject to legal or contractual limitations
- Challenge our PIPEDA compliance
Every commercial electronic message includes a working unsubscribe mechanism. Requests handled within 10 business days.
Complaints may be filed with:
- Office of the Privacy Commissioner: priv.gc.ca
- CRTC (CASL complaints): fightspam.gc.ca
12. Data Security
We implement appropriate technical and organizational measures including:
- SSL/TLS encryption for all data in transit
- Role-based access controls for internal data
- Secure Google Workspace environment for lead storage
- Periodic security assessments
- Staff training on data protection
- Data Processing Agreements with all vendors
In the event of a high-risk data breach, we will notify affected individuals and the competent supervisory authority within 72 hours, in accordance with Articles 33–34 GDPR.
13. Results Disclaimer
FineroLab is an educational platform. We do not guarantee any specific outcome related to trading performance, financial results, or income generation. All educational content is provided for learning purposes only. Individual results depend on numerous factors beyond our control, including personal effort, market conditions, and prior experience.
14. Minors
This service is intended exclusively for individuals aged 18 or older. We do not knowingly collect data from minors. If you believe we have inadvertently collected data from a person under 18, contact us immediately at privacy@finerolab.com.
15. Changes to This Policy
We may update this Privacy Policy from time to time. In the event of material changes, we will:
- Update the "Last Updated" date at the top of this page
- Notify registered users by email where applicable
- Display a prominent notice on the website
Continued use after changes take effect constitutes acceptance. Where changes require fresh consent, we will obtain it beforehand.
16. Contact & Data Protection Officer
Controller: FineroLab — Privacy Team
Email: privacy@finerolab.com
DPO: dpo@finerolab.com
Website: finerolab.com
Response time: Within 30 days (GDPR) / Within 10 business days (CASL/PIPEDA)