Legal
Privacy Policy
Last updated: 16 August 2026
1. Controller
Run Forex Group ("we", "us") is the data controller for personal data processed through the run.forex website, customer portal and API (the "Service"). Contact:[email protected].
2. What we collect
Account data — name, email address, password (stored only as a hash), company name, country and, where required for invoicing, tax identification details.
Billing data — subscription plan, invoices and payment status. Card details are entered directly with our payment processor and are not stored by us. For crypto payments we store the transaction reference.
Technical and usage data — API request logs including timestamp, endpoint, response status, API key identifier and source IP address; the IP addresses you add to your allowlist; and basic website analytics.
We do not knowingly collect special categories of personal data, and the Service is not directed at children.
3. Why we use it, and our legal basis
- To provide the Service — authenticating keys, enforcing plan limits and IP allowlists, delivering data (performance of a contract).
- To bill you — subscriptions, invoices, payment reconciliation (performance of a contract; legal obligation for accounting records).
- To secure the Service — abuse detection, rate-limit enforcement, fraud prevention and incident investigation (legitimate interests).
- To support and inform you — service notices, incident and maintenance communications (legitimate interests / contract).
- Marketing — only where you have opted in; you can withdraw at any time (consent).
4. Who we share it with
We share personal data only with service providers acting on our instructions, including:iyzico (card payment processing), Cloudflare (hosting, content delivery and security), and email delivery providers. We may disclose data where required by law or to protect our legal rights. We do not sell personal data.
5. International transfers
Our infrastructure and providers may process data outside your country, including outside Türkiye and the European Economic Area. Where such transfers occur, we rely on appropriate safeguards such as standard contractual clauses or an equivalent lawful transfer mechanism.
6. Retention
Account and billing records are retained for the life of the account and afterwards for as long as required by tax and accounting law. API request logs are retained for up to twelve (12) months for security, troubleshooting and usage reporting, after which they are deleted or aggregated. Backups are rotated on a defined schedule.
7. Security
We apply technical and organisational measures appropriate to the risk, including encryption in transit (TLS), hashing of passwords and API keys (we never store raw keys — a key is shown once at creation and cannot be retrieved afterwards), IP allowlisting, least-privilege access to production systems and audit logging. No system can be guaranteed completely secure.
8. Your rights
Depending on your location, including under the Turkish Personal Data Protection Law (KVKK, Law No. 6698) and the EU/UK GDPR, you may have the right to access, rectify, erase, restrict or object to processing of your personal data, to data portability, and to withdraw consent. To exercise these rights contact[email protected]. You also have the right to lodge a complaint with your supervisory authority — in Türkiye, the Personal Data Protection Authority (KVKK).
9. Cookies
We use strictly necessary cookies to keep you signed in to the customer portal and to maintain security. We do not use advertising cookies. Where any non-essential analytics cookies are used, we ask for your consent first, and you can change your choice at any time through your browser settings.
10. Changes
We may update this policy. Material changes will be notified by email or through the portal. The "last updated" date above always reflects the current version.
11. Contact
Run Forex Group — privacy enquiries:[email protected] · security: [email protected]