Applicability depends on the relationship
The GDPR may apply because of the operator’s establishment, the location of an individual or the nature of the services offered or monitored. Where another privacy law applies, equivalent or additional rights may be available under that law.
01Our GDPR commitment
the website operator aims to process personal data responsibly, securely and transparently. The GDPR framework is applied where legally relevant to the MT4 Trading Platform website, client area, MT4 account-support operations, identity verification, communications, payment requests and related administration.
This statement explains the governance measures used to support compliance. The Privacy Policy provides the main notice about personal-data categories, purposes, recipients, retention and individual rights.
02Controller, processor and accountability roles
The entity that determines the purposes and essential means of processing acts as a controller. A service provider that processes personal data only on documented instructions may act as a processor. Some providers, such as banks or authorities, may act as independent controllers for their own legal purposes.
We maintain responsibility through assigned roles, policies, access controls, provider due diligence, record keeping, incident procedures and periodic review. Where required, a data-protection officer or responsible privacy contact is designated with appropriate independence and access to management.
03Principles applied to personal-data processing
- Lawfulness, fairness and transparency
- Processing must have a lawful basis, must not be used unfairly and must be explained in a clear and accessible manner.
- Purpose limitation
- Personal data is collected for specified purposes and is not reused incompatibly without a valid basis and appropriate notice.
- Data minimisation
- Only information that is adequate, relevant and reasonably necessary for the purpose should be collected.
- Accuracy
- Reasonable steps are taken to keep relevant information accurate and to correct or remove inaccurate data.
- Storage limitation
- Identifiable data is not kept longer than necessary, subject to legal retention and dispute requirements.
- Integrity and confidentiality
- Security measures are used to protect against unauthorised or unlawful processing, loss, destruction or damage.
- Accountability
- The operator must be able to demonstrate compliance through decisions, records, controls and evidence.
04How lawful bases are selected
A legal basis is identified before processing begins and is reviewed if the purpose changes. The basis is not selected merely for convenience and may differ between activities involving the same person.
| Legal basis | When it may apply | Examples in the service |
|---|---|---|
| Contract | Processing is necessary to enter into or perform a contract requested by the individual. | Registration, account administration, support, requests and client communications. |
| Legal obligation | Processing is required by applicable law. | Identity verification, AML controls, accounting, regulatory reporting and record retention. |
| Legitimate interests | Processing is necessary for a legitimate purpose and is not overridden by the individual’s rights. | Security, fraud prevention, service improvement, legal claims and appropriate business administration. |
| Consent | The individual gives a freely given, specific, informed and unambiguous choice that can be withdrawn. | Optional marketing, certain analytics or optional cookies where required. |
| Vital interests or public task | Processing is necessary to protect life or perform a legally assigned public-interest function. | Exceptional situations only, where the legal conditions are met. |
05Privacy notices and transparent information
Privacy information is presented through this statement, the Privacy Policy, the Cookies Policy and service-specific notices. We aim to use concise and understandable language while still explaining the information required for informed decisions.
Where personal data is obtained from another source, information is provided within the time and circumstances required by law unless an exemption applies. Material changes are communicated through an updated notice and, where appropriate, a direct message.
06Data protection by design and by default
Privacy considerations are included in the design and review of forms, account workflows, integrations, access roles, notifications, exports, logging and data retention. Default settings should limit processing to what is reasonably necessary for the stated purpose.
- Define the purpose, data fields, access roles and retention before launching a new process.
- Avoid collecting sensitive or unnecessary information through open text fields where a structured field is sufficient.
- Apply least-privilege access and separate administrative functions where practical.
- Use secure transmission, validation, logging and error handling appropriate to the risk.
- Review providers and contracts before personal data is made available to them.
- Test whether changes create new risks for individuals and document the outcome.
07Records of processing and data-protection impact assessments
Where required, we maintain records describing processing purposes, categories of individuals and data, recipients, transfers, retention and security measures. These records support oversight and responses to regulators or audits.
A data-protection impact assessment may be completed before processing that is likely to create a high risk to individuals, particularly when new technology, systematic monitoring, sensitive information or large-scale profiling is involved. The assessment identifies necessity, proportionality, risks and mitigating controls.
08Handling data-subject rights
Where the GDPR applies, individuals may have rights of access, rectification, erasure, restriction, objection, portability, withdrawal of consent and protection against certain solely automated decisions. They may also complain to a competent supervisory authority.
Requests are logged, identity and authority are verified, relevant systems are searched and exemptions are assessed. We respond within the statutory period or explain a lawful extension. A request may be refused or limited where it is manifestly unfounded or excessive, conflicts with another person’s rights, or retention is required by law.
- Submit a clear request using the contact details on this page.
- Provide enough information to identify the relevant profile, account or interaction.
- Complete reasonable identity verification to protect against unauthorised disclosure.
- Receive our response, any requested information and an explanation of applicable limitations.
- Escalate a concern through the complaints process or to a supervisory authority where legally available.
09Processor and service-provider management
Providers that process personal data on our behalf are selected with regard to service capability, security, location, confidentiality and compliance. Where required, a written processing agreement defines subject matter, duration, instructions, confidentiality, security, subprocessors, assistance, deletion and audit rights.
Provider access is limited to the data and functions reasonably required. Material providers may be reviewed periodically, and access should be removed when the service ends or is no longer needed.
10International transfer safeguards
Personal data may be processed in countries outside the European Economic Area because of hosting, MT4 infrastructure, support, payment or verification services. Where the destination is not recognised as providing adequate protection, an approved transfer mechanism and supplementary measures may be required.
- Adequacy decisions adopted by the competent authority.
- Approved standard contractual clauses or another recognised contractual mechanism.
- Binding corporate rules for eligible group transfers.
- A limited statutory derogation for a specific situation where legally permitted.
- Technical, contractual and organisational supplementary measures appropriate to the transfer risk.
11Security controls and personal-data breach response
Security measures are selected according to the nature, scope, context and risk of processing. They may include access controls, authentication, encryption, monitoring, backups, vulnerability management, secure development, provider controls and staff confidentiality.
A personal-data breach is assessed promptly to determine affected data, individuals, likely consequences and containment measures. Where the legal threshold is met, the competent supervisory authority is notified within the required period. Affected individuals are informed when the breach is likely to result in a high risk and no lawful exception applies.
Users should contact support immediately if they suspect account compromise, misdirected information, unauthorised disclosure or loss of a device containing client information.
12Storage limitation, deletion and legal holds
Retention schedules consider contractual need, AML and financial-services obligations, accounting rules, limitation periods, complaints, security and the need to establish or defend legal claims. Different records therefore have different retention periods.
When retention expires, data is deleted, anonymised or restricted from ordinary use. Deletion from active systems may not immediately remove every encrypted backup copy; backups are protected, rotated and removed under the normal backup lifecycle. A legal hold may suspend deletion for relevant information while an investigation or dispute is active.
13Profiling and automated decisions
Automated tools may support fraud detection, security alerts, sanctions screening, risk classification, request routing and service analytics. We assess whether a process constitutes profiling and whether it creates a legal or similarly significant effect.
Where Article 22 or an equivalent rule applies, a solely automated significant decision is used only with an available legal basis and required safeguards. Those safeguards may include meaningful information about the logic, human intervention, the opportunity to express a view and the ability to contest the result.
14Training, monitoring and continuous improvement
Personnel with access to personal data receive guidance appropriate to their role. Compliance may be reviewed through access checks, incident reviews, provider assessments, policy reviews, audit, quality assurance and remediation tracking.
The GDPR compliance framework is updated when services, laws, guidance, technology or risk materially change. Evidence of decisions and improvements is retained where appropriate to demonstrate accountability.
15Questions, complaints and supervisory authorities
You are encouraged to contact us first so a privacy concern can be investigated and, where appropriate, corrected. This does not limit your right to complain to the data-protection authority competent for your location or the relevant establishment.
When submitting a complaint, include the relevant account or contact reference, the processing activity concerned, the outcome you seek and any supporting correspondence. Do not include unnecessary sensitive information.
Contact us about this document
Include the document title and the relevant section when you contact the team. Do not send passwords or payment-card security codes.
Contact support