1. Roles
This notice describes how personal data is processed in the licensed Software and how deletion works. It supplements the Privacy policy and Terms of use. The processor named here is 1591011 B.C. LTD, trading as OneProp. For trader, applicant, affiliate, and staff records in a production tenant, you are the controller (or “business” under CCPA) and OneProp is the processor (or “service provider”). For leads on the marketing Site that we actually receive, OneProp is the controller — see the Privacy policy.
We process Client Data only to provide, secure, support, and bill the Services, to create de-identified statistics, and to comply with law. We do not sell Client Data. We do not use Client Data to serve ads to End Users. We do not use Client Data to train unrelated public generative models.
2. Instructions
Your instructions are: (a) the Order and these policies; (b) configuration you apply in the admin interfaces; (c) documented API calls you make; and (d) written instructions from an authorised contact. We will inform you if, in our opinion, an instruction infringes GDPR (or equivalent), unless law prohibits that notice.
You warrant that your instructions are lawful, that you have provided notices and obtained consents End Users require, and that you will not submit special-category data or children’s data unless the DPA expressly covers it.
3. Data-processing addendum
A DPA is available on request for customers who need Article 28 GDPR terms, including:
- Subject matter, duration, nature, and purpose of processing (prop-firm operations software).
- Types of personal data (identity, contact, account, trading and evaluation events, payout metadata, support content) and categories of data subjects (your staff, End Users, affiliates).
- Our duty to process only on instructions, ensure confidentiality, implement security, assist with data-subject rights, assist with DPIAs and breach notification, and delete or return data at the end of services.
- Audit rights in a reasonable form (questionnaires, certifications, or on-site review on notice, not more than once per year except after a material incident).
- International transfer mechanisms (SCCs or adequacy).
- A list of sub-processors and a notice method for changes.
Until a DPA is signed, this notice and the Privacy policy describe our practices. The DPA prevails on processing terms if it conflicts with this notice. Request a DPA at admin@oneprop.shop.
4. Security measures (summary)
We implement technical and organisational measures appropriate to a B2B operations platform, including encryption in transit (TLS), access control and MFA on operator seats, tenant isolation as designed, logging of privileged actions on risk and payouts, and least-privilege staff access. Details are on the Security page and may be elaborated in the DPA. You are responsible for configuring geo rules, KYC vendors, and staff permissions, and for securing exported files.
5. Sub-processors
We may use sub-processors for hosting, email delivery, error monitoring, and similar infrastructure. A current list will be attached to the DPA and, when a production stack is public, summarised here. You authorise us to appoint sub-processors under written terms no less protective than the DPA, with notice of material changes and a right to object as the DPA states. You remain responsible for vendors you contract with directly (KYC, PSP, broker, data).
On this marketing Site, infrastructure sub-processors are the static host (Vercel), DNS, CDN, Google Fonts, and the mail relay that delivers form submissions to admin@oneprop.shop, as described in the Privacy policy and cookie notice.
6. Deletion and export
During the Subscription Term you may export and delete End User records using product tools, subject to your own retention duties (do not delete records you are legally required to keep).
On termination or expiry of an Order:
- We will, on written request received within thirty (30) days, provide an export of Client Data in an ordinary machine-readable format (for example CSV/JSON for tabular records).
- After that window, or after you confirm deletion, we will delete or irreversibly anonymise Client Data from production systems within thirty (30) days, except (a) data we must retain by law, (b) data in encrypted backups that expire on the backup rotation cycle, and (c) de-identified statistics.
- Backup copies remain subject to confidentiality and are not restored into production except for disaster recovery, after which deletion is re-applied.
If you do not request an export within thirty days, we may delete production Client Data without further notice, consistent with the Order. We recommend you export before you give notice of non-renewal.
Erasure requests from End Users must go to you as controller. We will assist by providing tools or, where the data cannot be deleted in-product, by carrying out deletion you instruct in writing, unless law requires us to keep a copy.
7. Marketing-site deletion
If you submitted a lead, request deletion at admin@oneprop.shop. We will delete or anonymise the lead unless we must keep it (for example an ongoing contract, a legal claim, or an accounting record). Opting out of marketing is not always the same as erasure of billing records.
Exercising erasure as a customer may make it impossible to continue providing the Software. We may treat a complete erasure instruction covering all account data as a request to terminate the Order, with the fee consequences in the Terms and Refunds policy.
8. How to request deletion
Controllers: email admin@oneprop.shop from an authorised domain with tenant identifier, the scope of data, and whether you want export before deletion. Individuals: see Privacy policy rights. We will verify the requester. We aim to complete verified controller deletion instructions within thirty days after the export window, unless a longer legal period applies.
These documents are in English only. They describe a technology provider’s website and software licence practices. They are not legal, tax, or regulatory advice, and they are not a substitute for a signed Order or data-processing addendum. The contracting entity is 1591011 B.C. LTD, a British Columbia company trading as OneProp. A registered office, if required, is stated in the Order. Notices: admin@oneprop.shop.
Related policies
- Legal centre
- Terms of use
- Privacy policy
- Cookie and storage notice
- Legal information and disclaimers
- Acceptable use policy
- AML and KYC notice
- Data processing and deletion
- Refunds and billing
- Complaints
Questions: admin@oneprop.shop.