Privacy Policy
1. Introduction
This Privacy Policy explains how Phyxtrade Ltd. (“Phyxtrade”, “we”, “us”, “our”) collects, uses, shares, and safeguards personal data when you visit our websites, use our mobile or web applications, open an account, or access our trading platforms and related services (collectively, the “Services”).
2. Scope & Definitions
Scope. This Policy applies to personal data processed by Phyxtrade as a controller, including data collected online and offline.
Personal Data. Any information that identifies or can reasonably be linked to an identified or identifiable natural person.
Processing. Any operation performed on personal data (e.g., collection, storage, use, disclosure, deletion).
3. Data We Collect
- Identity & KYC Data: name, date of birth, nationality, government IDs, selfies/biometrics (where lawful), address, risk profile.
- Contact Data: email, phone number, mailing address.
- Financial Data: bank details, payment records, deposit/withdrawal history, trading balances and activity.
- Technical Data: device identifiers, IP address, browser type, OS, app version, log files, crash reports.
- Usage Data: page views, clicks, session duration, referral URLs, feature usage, interaction with support.
- Communications: support tickets, call recordings (where permitted), chat messages, surveys.
- Marketing Preferences: consents, opt-ins/opt-outs.
Sources. We collect data directly from you, from your use of the Services, from public databases, sanctions/PEP screening providers, credit/identity verification partners, and, where lawful, from affiliates and marketing partners.
Sensitive Data. We may process certain sensitive data (e.g., identity documents, biometrics used for KYC) strictly for compliance and fraud prevention, where permitted by law and with appropriate safeguards.
4. How We Use Data
- Provide Services: create and manage accounts, process transactions, execute trades, provide support.
- Compliance: KYC/AML, anti-fraud, sanctions screening, reporting to regulators, record keeping.
- Improve & Personalize: diagnostics, analytics, product development, user experience, accessibility.
- Marketing: send service announcements and, where permitted, promotional communications; honor opt-outs.
- Security: detect, prevent, and investigate security incidents or abuse.
- Legal: enforce terms, defend legal claims, protect rights and safety.
Legal Bases (GDPR/UK GDPR): performance of a contract; compliance with legal obligations; legitimate interests (e.g., service improvement, security); consent, where required; protection of vital interests; establishment, exercise, or defense of legal claims.
5. Cookies & Tracking
We use cookies, SDKs, pixels, and similar technologies to operate and improve the Services, remember preferences, measure performance, and provide relevant content. You can manage preferences via your browser settings and, where available, our cookie banner or preferences center.
- Strictly Necessary: essential for login, security, load balancing.
- Performance/Analytics: traffic measurement, diagnostics (e.g., proprietary analytics).
- Functional: language, region, UI preferences.
- Advertising (where applicable): frequency capping, attribution, and interest-based ads (subject to consent where required).
“Do Not Track” (DNT): We currently do not respond to DNT signals. You may use opt-out tools where applicable.
6. Sharing & Disclosure
- Service Providers: identity verification, cloud hosting, analytics, payments, customer support—bound by contracts.
- Affiliates: for operational support and compliance, subject to appropriate safeguards.
- Regulators & Law Enforcement: where required by law, court order, or to protect rights and safety.
- Business Transfers: merger, acquisition, financing, or sale of assets (with reasonable notice where required).
- With Your Direction or Consent: third-party integrations or features you enable.
We do not sell personal data in the ordinary sense. Where “sale” or “share” is broadly defined (e.g., under CPRA), we honor applicable opt-out rights.
7. International Transfers
Your data may be transferred to and processed in countries outside of your country of residence. Where required, we rely on appropriate safeguards, such as the European Commission’s Standard Contractual Clauses (SCCs) or UK IDTA/Addendum, and implement technical and organizational measures to protect data.
8. Data Retention
We retain personal data for as long as necessary to fulfill the purposes outlined in this Policy, including to comply with legal, accounting, or reporting requirements (e.g., AML/record-keeping obligations). Retention periods vary by data category and jurisdictional requirements.
9. Security
We implement administrative, technical, and physical safeguards designed to protect personal data (e.g., encryption in transit and at rest where appropriate, access controls, monitoring). However, no method of transmission or storage is completely secure.
10. Your Rights (GDPR/UK GDPR)
Subject to conditions and exemptions, you may have the right to: access; rectify; erase; restrict; object to processing; data portability; withdraw consent at any time; and lodge a complaint with a supervisory authority. We may verify your identity before responding.
11. U.S. Privacy (CCPA/CPRA)
California residents may have the right to: know/access; correct; delete; opt out of “sale”/“sharing” of personal information; limit use/disclosure of sensitive personal information; and be free from discrimination for exercising rights.
12. Children’s Privacy
The Services are not directed to children under 13 (or as defined by local law). We do not knowingly collect personal data from such children. If you believe a child has provided personal data, please contact us so we can take appropriate action.
13. Changes to this Policy
We may update this Policy from time to time. When we do, we will revise the “Last Updated” date above and, where appropriate, provide additional notice.
14. How to Contact Us
If you have questions or want to exercise your rights, please submit a request via our Privacy Requests Portal or write to: [Insert Data Protection Contact / DPO]. We will respond in accordance with applicable law.
