Who operates OryxQuant
The OryxQuant service and software licence are operated by Alex Lama, Entrepreneur individuel (EI), at 5 RUE DU DOCTEUR CHARCOT, 92500 RUEIL-MALMAISON, FRANCE. For privacy requests, contact contact@oryxquant.com.
Public website and technical logs
The public pages showcase OryxQuant. Our hosting infrastructure processes request metadata such as IP address, timestamp, requested path, user agent, response status, and security events to deliver and protect the service. We do not use advertising cookies.
Cookies and local storage
Only after you select Accept, the public marketing pages load Google Analytics 4, provided by Google. We use it to understand aggregated visits, page use, and audience trends so we can improve the website. The Google tag and any analytics transmission remain blocked before consent. Advertising storage, advertising user data, ad personalization, and Google Signals are disabled.
Analytics may process a pseudonymous browser identifier, session information, device and browser characteristics, approximate location derived from the connection, referring page, pages viewed, and interactions with the public website. Do not enter personal or confidential information into public-page URLs. Google processes Analytics data under its own privacy policy and service terms.
The strictly necessary oq_analytics_consent cookie records only whether you accepted or rejected audience measurement and expires after six months. If you accept, Google Analytics may set the first-party cookies _ga and _ga_9YVZD6HY45 to distinguish visits and retain session state; their configured lifetime is up to six months and is not extended on each page load. If you reject, those analytics cookies are not created. You can withdraw or grant consent at any time through Cookie settings in the footer. Withdrawing consent disables measurement and removes accessible Google Analytics cookies from this domain.
Other website storage is used only to provide features requested by you. The strictly necessary oq_session authentication cookie keeps signed-in customers connected for up to 30 days. The oryxquant.preferredCurrency local-storage entry is written when you choose a currency on the pricing or account pages and remains until you change it or clear your browser storage. Neither is used for audience measurement or advertising.
Accounts, billing, and licensing
When customer commerce is available, we process your name, verified email address, password hash, account sessions, selected plan and currency, subscription and invoice identifiers, licence key, activated-machine identifier, support history, and security audit events. Stripe processes payment details and returns customer, subscription, payment-status, and hosted-invoice information; OryxQuant does not store full card details. Account cookies are HttpOnly, Secure in production, SameSite=Strict, and used only to keep you signed in.
Purposes and legal bases
We use account, subscription, licence, and support data to perform the requested service and licence agreement; security and limited technical logs to protect the service and pursue legitimate operational interests; and invoices or other records where necessary to meet legal obligations. Audience measurement is based on your consent, which you may withdraw as easily as you grant it.
Local research data
The OryxQuant service and research workspace run locally on the Windows computer. Strategy code, market data, backtest results, and research jobs are stored there. This showcase does not receive that research workspace.
AI Research and LLM providers
When you start AI Research, the locally running OryxQuant application sends your research objectives, selected symbols, run settings, acceptance criteria, candidate summaries, and generated or repaired strategy code directly to the LLM provider you configured. This content does not pass through the OryxQuant company site. OryxQuant supports OpenAI-compatible APIs, Claude API, Codex, and Claude Agent through the user's installed Claude Code CLI. For OpenAI-compatible APIs that support stored Responses, session continuity is enabled by default and can be disabled; OryxQuant requests deletion of stored responses when a job ends. Claude API sends context with each request and has no provider session continuity. Codex and Claude Agent can reuse a temporary local conversation within a job; OryxQuant closes it without saving a CLI transcript. Local CLI use still sends research content to the provider's online service. Provider support, operational logs, and retention terms still apply.
The LLM provider processes this content under its own privacy, retention, training, security, and international-transfer terms and your account settings. OryxQuant does not control those practices and does not guarantee zero retention. Do not submit personal, confidential, sensitive, regulated, or third-party proprietary information. Research requests, logs, returned strategies, generated code, and machine-readable provider/model/time provenance are retained locally in the OryxQuant user-data folder until you remove them.
Recipients and international transfers
Infrastructure, email, Stripe billing, Google Analytics when consented to, and professional advisers receive only the data needed for their role. Their locations and transfer safeguards depend on the selected provider and contract, and processing may occur outside your country. We do not sell personal information or disclose local research data to the company site.
Retention
Account data is retained while the account is active and removed after account deletion except where billing, fraud-prevention, dispute, security, or legal records must be retained. Session, reset, and verification tokens expire automatically. Technical and security logs are retained only for operational need. The analytics consent choice and Google Analytics cookies are configured to expire after no more than six months; aggregated Analytics reports may be retained separately according to the Analytics property settings. Stripe and Google retain data under their own policies and legal duties.
Your choices and rights
Depending on applicable law, you may request access, correction, deletion, restriction, objection, or portability and may complain to your data-protection authority. Use the privacy contact above. We may need to verify your identity before acting on a request.
Security and changes
We use email verification, hashed passwords and tokens, HTTPS, restricted administration, signed licences, and access controls. No system is completely secure. Material changes will be published here with a revised effective date; a new acceptance will be requested when required.