Draft text. It will be reviewed by legal counsel before launch; fields in square brackets are to be completed.
Controller
The controller is [Legal Entity Name], established at [address]. The data protection officer can be reached at [e-mail].
Data we collect
Identity and contact details (name, e-mail, phone, country of residence), identity documents, financial data (deposits, withdrawals, trading history) and technical data (IP address, device and browser, cookies).
We obtain this data from you, from identity-verification providers and from the trading platform.
Purposes and legal basis
Opening the account and performing the client agreement; know-your-customer and anti-money-laundering obligations; fraud prevention and security; service communication; marketing communication with your consent.
Processing required by law does not depend on consent; marketing consent can be withdrawn at any time.
Sharing
Data is shared with identity-verification and payment providers, liquidity providers, cloud and hosting suppliers, and authorities entitled by law, only to the extent the purpose requires.
Your data is never sold to third parties.
International transfers
Some suppliers may be located abroad. Transfers rely on the safeguards the applicable law provides (standard contractual clauses or an adequacy decision).
Retention
Client records are kept for the period the law requires after the relationship ends ([period]), then deleted or anonymised.
Your rights
You have the right to access, rectify, erase, restrict, port and object. Send requests to [e-mail]; if you are not satisfied you may complain to the supervisory authority.
Security
Data is encrypted in transit, access is role-based and logged. In the event of a breach we notify you and the authority within the period the law sets.
Questions: [email protected]