Legal Center: Privacy, Cookies, Terms

Transparent policies for international investors, aligned with GDPR/ePrivacy 2026 and MiFID II communication standards. Our research is for informational purposes only, not financial advice.

GDPR 2026
MiFID II aligned
Secure lock symbolizing data protection for investors

Privacy Policy

MindBrainFlow Ltd (MindBrainFlow.space) provides AI-driven research on investment trends for 2026, including cross-asset forecasts and ESG-focused insights. This Privacy Policy explains how we collect, use, share, and secure personal data of international investors who browse our site, subscribe to premium research, or interact with our tools. We comply with applicable Uzbek commercial law and the GDPR/ePrivacy framework updated for 2026.

Controller: MindBrainFlow Ltd, 45 Navoi Street, Tashkent 100000, Uzbekistan. Company Registration No.: 2026-UZ-100000. Uzbekistan Taxpayer Identification Number (INN): 308765432. Contact: [email protected], +998 71 200 2026. For privacy inquiries you can write to the above address, referencing “Data Protection”.

Personal data we process

Account and subscription data: name, email, password hash, billing country, and plan selection. Investor profile data: optional subscription profiles, portfolio trackers that you configure, and research preferences such as asset classes, sectors, risk tolerance ranges, ESG filters, and alert thresholds. Payment data: handled by Stripe for USD/EUR payments; we receive limited billing identifiers, last four digits of card, and transaction metadata. We do not store full card numbers or CVV.

Usage and device data: logs and telemetry to keep our services secure and reliable, including IP address, timestamps, user agent, and coarse location. Analytics: aggregated metrics on page performance, research topic engagement, and conversion funnels, collected only with consent. Communications: emails and support tickets that help us resolve issues and improve service quality.

Purposes and legal bases

Service delivery and account management, including instant digital delivery of research, performed under contract necessity. Billing and fraud prevention, performed under legal obligations and legitimate interests. Product improvement and audience measurement, performed with your consent where required. Marketing communications about new insights and features, performed with consent; you may opt out anytime. Where we rely on legitimate interests, we balance our interests against your rights and reasonable expectations.

Cross-border processing and safeguards

We serve an international audience and may process data in the EEA, the United Kingdom, the United States, and Uzbekistan. When data leaves your jurisdiction, we use GDPR-approved safeguards such as Standard Contractual Clauses, supplementary encryption, and vendor diligence. Our core processors include Stripe (payments), cloud hosting, and analytics providers. Each processor is bound by written data processing agreements that include confidentiality, security, and subprocessor controls.

Your rights under GDPR/ePrivacy 2026

You have the right to access your personal data, request rectification of inaccuracies, and receive a copy in a portable format. You may request erasure, restrict or object to certain processing (including profiling for marketing), and withdraw consent at any time without affecting prior lawful processing. To exercise rights, contact [email protected] and verify your account. We respond within one month, subject to allowable extensions for complex requests. You may lodge a complaint with your local supervisory authority.

Data retention

Account and subscription records are retained for the life of your account and up to seven years afterward where required for tax, accounting, or regulatory purposes. Analytics and telemetry data are retained for the shortest period that enables service quality and security, typically 12 months or less where consented. Marketing preferences are kept until you opt out or delete your account. We pseudonymize or anonymize datasets whenever feasible.

Security of financial and research data

Security includes encryption in transit and at rest, strong key management, and restricted administrative access. Stripe processes cardholder data under PCI DSS; we never receive full card numbers. Access to portfolio trackers and research preferences is role-limited and monitored. We conduct risk assessments, maintain incident response procedures, and notify users and regulators of notifiable breaches according to law.

Children and sensitive data

Our services target professional and retail investors over the age of 18. We do not knowingly collect data from children. We do not seek to collect special-category data, and you should avoid uploading such information to our platform.

International investors and MiFID II clarity

MindBrainFlow provides investment research and educational analysis. We do not execute trades, hold client funds, or provide personalized investment advice. All materials are for informational purposes only and should not be relied upon as financial advice. Past performance does not guarantee future results.

Contact

MindBrainFlow Ltd, 45 Navoi Street, Tashkent 100000, Uzbekistan. Email: [email protected]. Phone: +998 71 200 2026. If we make material changes to this Policy, we will update the date and highlight the key changes in this page.

Transparency that supports smarter investing

We keep our policies clear and respect your choices. Manage cookie preferences anytime, export your data, and contact us for rights requests. All research remains informational, not financial advice.