HarvestGroup360
Empowering quantitative research with high-frequency market data and analytics.
Effective Date: June 2026
This Institutional Privacy & Data Security Policy details how HarvestGroup360 protects the sensitive information, custom algorithms, and corporate data of our enterprise clients. This policy applies to all interactions with our APIs, terminals, and infrastructure.
We understand that quantitative models are the lifeblood of our clients' operations. All code deployed to our execution environments is sandboxed within isolated Docker containers. HarvestGroup360 utilizes container isolation techniques to ensure strict boundaries between tenant environments. Our employees, engineers, and support staff do not have access to client source code or trading logic. Any telemetry data collected for system health monitoring is strictly aggregated and anonymized.
During enterprise onboarding, we collect essential Know Your Business (KYB) data. This includes Certificates of Incorporation, Legal Entity Identifiers (LEI), details of Ultimate Beneficial Owners (UBOs), and authorized signatory information. This data is stored on encrypted, air-gapped servers located in Tier-4 data centers and is only accessible to authorized compliance personnel. We utilize AES-256 encryption for data at rest and TLS 1.3 for all data in transit.
We collect essential operational telemetry to ensure the stability of our infrastructure, including API request volumes, latency metrics, and connection drops. Execution logs and API request histories are retained for a period of 5 years to comply with international financial regulations. Clients may request automated log purging beyond the mandatory regulatory retention periods via our compliance portal.
HarvestGroup360 complies fully with the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA) regarding the handling of any personal data associated with corporate representatives. Data Protection Agreements (DPAs) are available upon request for EU-based institutions. We do not sell, rent, or lease corporate data to third parties under any circumstances.
To provide our services, we may engage sub-processors (such as Tier-1 cloud providers or specialized cybersecurity firms). All sub-processors are subjected to rigorous security audits and are bound by strict confidentiality agreements. A full list of active sub-processors is available to Enterprise clients upon request.
In the highly unlikely event of a data breach or unauthorized access to our infrastructure, HarvestGroup360 has a comprehensive Incident Response Plan. Affected enterprise clients will be notified within 24 hours of breach confirmation, detailing the scope of the incident, the data affected, and the immediate mitigation steps taken by our cybersecurity team.