Legal
Privacy Policy
Stretus is software we license to financial firms. What data is collected, where it sits and who is in charge of it depends on how each customer sets the platform up. So this page explains the different setups instead of pretending there is only one.
Draft, pending legal review
This document establishes structure and states the technology-provider position accurately. It has not yet been reviewed by counsel and should not be relied upon as the final policy. Contractual terms in an executed agreement take precedence over anything on this page.
Effective
What this page covers
This page is about stretus.com, our website. It does not cover what happens inside a broker's own copy of the Stretus platform.
That difference matters. If you are reading this website, your relationship is with us. If you are using a broker's app that runs on Stretus, your relationship is with that broker, and their privacy policy applies to your data. Treating those as the same thing would give you the wrong answer about both.
What we collect on this website
Two things. What you type into the demo request form, and basic analytics about which pages get read.
The form collects your name, your organisation and your contact details, so we can reply to you. Analytics tell us which pages people read and where they arrived from.
We do not collect bank details, trading data, account numbers or holdings on this website. There is nowhere on stretus.com to enter any of that.
Data inside the platform depends on the setup
Data handling depends on customer deployment configuration and contractual agreement. Stretus does not store customer financial information by default.
There are two broad setups. In the first, the customer runs Stretus on their own servers. Their data never leaves their building, they hold the encryption keys, and we cannot see any of it unless they give us access for support.
In the second, we run it for them. Then things like which country the data sits in, how long it is kept, how backups work and who can reach it are all written into the agreement with that customer. They are not fixed defaults, which is why this page does not quote numbers it cannot know for your setup.
Who is legally in charge of the data
| Situation | Who is in charge | What that means |
|---|---|---|
| This website | We are | We decide what the form collects and why, and we answer for it |
| We run the platform for a customer | The customer is | We only do what they instruct us to do, under their agreement |
| The customer runs it themselves | The customer is, entirely | They operate the software. We handle no data unless they give us access |
The signed agreement for each setup is what actually decides this. The table is a summary of it, not a replacement.
How we protect it
Each customer's data is kept separate from every other customer's, and access is limited by role so people only reach what their job needs.
On credentials, the accurate answer depends on which credential. Broker API access works the way the rules require: per user, with a unique key, OAuth sign-in, two-factor verification, and a fixed IP address the broker has approved. Shared logins are not allowed and we do not use them. Where a customer chooses to supply their own AI provider key, that key is protected while stored and used only for requests that customer has authorised.
We should be equally clear about what we do not have. We hold no SOC 2 report and no ISO 27001 certificate, and we do not claim either.
If a customer's agreement says we have to tell them about a security incident within a certain time, we meet that deadline. Some of those deadlines come from Indian rules the customer is subject to.
How long we keep things
Enquiries from this website are kept as long as we need them to reply and to know the enquiry happened. Inside the platform, retention is set per customer.
Some trading records have to be kept by law. NSE circular NSE/INVG/67858 of 5 May 2025 requires order audit records to be available for at least five years. Where that applies, retention is set to meet it rather than to something shorter that suits us.
How to ask us about your data
Write to services@stretus.com. You can ask what we hold about you, ask us to correct it, or ask us to delete it.
One thing to check first. If your data is inside a broker's copy of Stretus, that broker is in charge of it and the request needs to go to them. We will help them answer if their agreement requires it, but we cannot act on your request directly without their instruction. Asking us first is not a problem, we will just point you to the right place.
If this page changes
We will update it here and change the date at the top. If you have a signed agreement with us, that agreement always takes priority over this page.
Questions about this document go to services@stretus.com. Stretus is a product of iMentus Technologies Private Limited, CIN U72900MP2022PTC060683, 303 Fortune Ambience, 4/2 South Tukoganj, Indore, Madhya Pradesh 452001, India.