Data management
Last updated 30 September 2026
This page sets out how fxapis, operated by El Wizard (business ID 207370523), Jacó, Puntarenas 61101, Costa Rica (“fxapis”, “we”) manages the data in the Service. It forms part of our Terms of service and, where we process personal data on your behalf, it is the data processing agreement between you (the controller) and us (the processor). Our Privacy policy covers data we control ourselves, such as your account and billing details.
1. Customer data and its ownership
“Customer Data” means the data you and your systems provide to the Service and the records the Service creates about your use of it, including:
- connected MT5 accounts: account numbers, broker servers, labels, settings reported by the broker, and encrypted passwords;
- trading records: orders, outcomes, deals, positions and multi-account orders;
- workspace records: members, invitations, API keys (as hashes), usage counts and the audit log.
You own Customer Data. We use it only to provide, secure and support the Service, as you instruct through your use of the Service, your configuration and these terms. We do not sell it, use it to trade, use it for advertising, or use it to train models for anyone else's benefit.
2. Processing on your behalf
Where Customer Data contains personal data of people other than you — for example, the MT5 accounts of your own customers:
- Subject matter and duration: providing the Service, for as long as you use it and the retention periods below.
- Nature and purpose: storing credentials to log accounts in at their brokers, transmitting trading instructions, recording and reporting outcomes.
- Types of personal data: MT5 account identifiers and credentials, trading activity, and any names or labels you choose to attach.
- Data subjects: your end users and account holders, and your team members.
As your processor, we will:
- process personal data only on your documented instructions, and tell you if we believe an instruction breaks data protection law;
- ensure everyone who can access it is bound by confidentiality;
- apply the security measures in section 5;
- use subprocessors only as described in section 4;
- help you respond to requests from data subjects, and with security, breach notification and impact assessments, taking into account what information is available to us;
- delete or return personal data at the end of the Service, as described in section 7;
- make available the information needed to demonstrate compliance with these obligations, and allow for reasonable audits — normally by answering a written questionnaire, and otherwise at your cost, on reasonable notice, no more than once a year unless required by a regulator or following a breach.
You are responsible for having a lawful basis to share this data with us, for the notices you give your end users, and for the instructions you give us. Where the European Commission's Standard Contractual Clauses are needed for a transfer, they are incorporated by reference (module 2 or 3, as applicable).
3. Where data is stored
Our application servers, database and cache are hosted by Railway in the European Union (Amsterdam, the Netherlands). Traffic reaches them through Cloudflare's global network. When you connect an MT5 account, the Service communicates with your broker's trade servers wherever the broker operates them.
4. Subprocessors
| Subprocessor | Service | Data involved |
|---|---|---|
| Railway Corporation | Hosting of servers, database and workers (EU) | All Customer Data |
| Cloudflare, Inc. | DNS, TLS and network protection | Traffic in transit, IP addresses |
| Resend | Transactional email | Email addresses and message content |
| ONVO | Card payments | Billing contact and payment details (account owner only) |
| NOWPayments | Cryptocurrency payments | Payment details (account owner only) |
Brokers are not our subprocessors: you choose them, and they receive credentials and orders because you instruct us to connect to them. We will give at least 30 days' notice of a new subprocessor that handles Customer Data by updating this page and emailing workspace owners who have asked to be told. You may object on reasonable data-protection grounds; if we cannot address the objection, you may end the affected part of the Service and receive a pro-rata refund of prepaid fees for it.
5. Security measures
Encryption
- All connections to our websites and API use TLS. Internal services authenticate each other with mutual TLS on a private network.
- Each broker password is encrypted with its own data key using AES-256-GCM; data keys are themselves encrypted with a key held outside the database, and each encrypted password is bound to the account it belongs to, so it cannot be decrypted elsewhere.
- API keys and account passwords are stored only as one-way hashes. API keys are shown once at creation and cannot be recovered.
Isolation and access
- Every workspace's data is separated at the query level; one customer's key or session cannot reach another's data, and attempts return “not found”.
- API keys carry scopes, including read-only and reduce-only scopes, and can be revoked with immediate effect.
- Broker passwords are released only to the process logging that account in, on a short-lived, single-use authorisation over mutual TLS, and each release is audited.
- Our staff's access to Customer Data is limited to what is needed to run and support the Service, requires an authenticated session, is refused to API keys, and every action staff take on a workspace is written to that workspace's audit log.
- Broker passwords are never shown in the console, returned by the API, written to logs, or included in error messages — to anyone, including our staff.
Operations
- Each MT5 account runs in its own isolated process, and at most one process operates an account at a time.
- Rate limits, idempotency keys and duplicate-order protection guard against runaway or repeated instructions.
- Changes to the Service are reviewed and tested before release; dependencies are kept up to date.
- Database backups are kept with our hosting provider in the same region. The key that decrypts broker passwords is never stored in the database, so a copy of the database — a backup included — does not reveal them.
6. Retention
| Data | Kept |
|---|---|
| Broker passwords | Until the account is disconnected or the workspace closed — then erased immediately |
| Connected accounts, trading records, usage, audit log | For the life of the workspace; deleted within 30 days after it is closed |
| Removed team members | Sign-in access and password removed at once; their name stays on records they created, so the history keeps its author |
| Sign-in sessions | Up to 14 days after last use |
| Idempotency records | 24 hours |
| Invoices and payment records | As long as tax and accounting law requires (typically up to 10 years), even after the workspace is closed |
| Technical logs | Up to 30 days |
| Backups | Overwritten on a rolling schedule; deleted data expires from backups as they rotate |
7. Export and deletion
Export
You can retrieve your data at any time through the API — accounts, orders, deals, positions and multi-account orders — in JSON. On request to [email protected] we will provide a complete export of your workspace in a machine-readable format within 30 days.
Deletion
- Disconnecting an MT5 account erases its stored password immediately; its trading history remains until you ask for it to be deleted or close the workspace.
- To close your workspace and delete its data, the workspace owner emails [email protected] from the owner's address. We confirm the request, cancel any paid plan, and delete Customer Data within 30 days, except invoices and records we must keep by law, which we keep only for that purpose.
- On request we confirm deletion in writing.
8. Security incidents
If we become aware of a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Customer Data, we will notify affected workspace owners without undue delay, and in any case within 72 hours of confirming it. The notice will describe what happened, the data affected, the likely consequences, and what we have done and recommend you do. We will keep you updated as we learn more and cooperate with your own notification obligations.
If you suspect a compromise on your side — a leaked API key or a lost device — revoke the key or sign the member out everywhere in the console, and tell us at [email protected].
9. Requests from authorities
If a government or court asks us for Customer Data, we will require a valid legal process, disclose only what is legally required, and notify you before disclosing unless the law forbids it. We will challenge requests we believe are unlawful or overbroad.
10. Contact
Data protection questions: [email protected]. Security reports: [email protected]. Export and deletion requests: [email protected].