Privacy
Last updated October 2026
This policy explains what information the OilTradeConnector desk holds, why it holds it, and what you can require us to do with it. Commercial confidentiality is a core part of the service, not an afterthought.
What we collect
We collect only what the engagement requires.
- Account data: your name, work email, company, role and authentication credentials.
- Mandate data: the products, regions, limits and boundaries you set for the desk.
- Transaction data: counterparties, terms, documents, stages and settlement records.
- Counterparty contact data: business contact details for the organisations the desk engages on your behalf.
- Technical data: access times, IP address and user agent, retained for security and audit.
How your commercial information is isolated
Your counterparties, terms and positions are segregated to your organisation. They are not disclosed to, aggregated with, or used to inform the position of any other participant we serve. This separation is enforced at the data layer, not merely in the interface.
Staff access is role-gated and least-privilege. Access to records is itself recorded.
Why we process it
To operate the desk on your behalf under your mandate; to screen counterparties for compliance risk; to produce and retain transaction documentation; to process and confirm settlement; to secure the platform; and to meet our own legal and record-keeping obligations.
Counterparty contact data and outreach
When the desk contacts an organisation on your behalf, it processes business contact data for that purpose. Two rules govern this absolutely.
- We never invent a contact address. Where a verified address is not available, no message is sent.
- An opt-out is honoured immediately, permanently and centrally across the whole platform. It is not something that has to be requested twice.
Sharing
We do not sell personal data and we do not share it for advertising. We disclose information only to the infrastructure providers required to operate the service — hosting and database, payment processing, email delivery and model inference — each acting under contract and only for that purpose.
We disclose information to a counterparty only to the extent a transaction requires it, and your identity is disclosed when you are ready to contract rather than at first approach.
Retention
Transaction records, executed documents and settlement confirmations are retained for as long as the audit trail requires, because an audit trail you have deleted is of no use to you.
Counterparty contact data is retained only while it serves an active engagement. Suppression records are retained indefinitely, because that is the only way an opt-out can be guaranteed to persist.
Security
Data is encrypted in transit and at rest. Credentials are never held in client-side code. Administrative surfaces are role-gated and are not reachable from the user application. Privilege escalation is blocked at the data layer. Security-relevant events are recorded and reviewed.
No system is immune. We tell you promptly if an incident affects your data.
Your rights
Subject to our record-keeping obligations, you may request access to the personal data we hold about you, correction of inaccuracies, deletion where no legal obligation requires retention, export of your transaction record, and that we stop contacting you.
Requests are made through the contact page and are actioned without charge.
Contact
Questions about this policy, or about the handling of a specific record, should be sent to the desk through the contact page.