CFDs are complex instruments and come with a high risk of losing money rapidly due to leverage. You should consider whether you understand how CFDs work and whether you can afford to take the high risk of losing your money.

PRIVACY POLICY

ATFX Global Markets (CY) Limited (hereinafter “Company”) is incorporated in Cyprus under registration
number HE340674 through the Department of Registrar of Companies and Official Receiver.

The Company is authorised and regulated by the Cyprus Securities and Exchange Commission
(hereinafter “CySEC”) to act as a Cyprus Investment Firm with license N.285/15. The Company operates
under the Provision of Investment Services and Activities and Regulated Markets Law of 2017
(L.87(I)/2017, as amended)

1. Scope and application

This Privacy Policy is addressed to the existing and potential clients of ATFX Global Markets (CY) Limited.

The Company is committed to protect individuals’ personal data in line with the requirements of
applicable law.

The Company’s commitment applies to all individuals whose personal data it may process

“Personal Data” means any information relating to an identified or identifiable natural person. The
Company acts as controller in relation to such personal data.

This Privacy Policy describes what types of personal data the Company collects about its clients when
the clients choose to use Company’s services, how the Company will use their personal data, when and
with whom the Company will share it and how will keep it safe. It also details clients’ rights in respect
of Company’s processing of their personal information and how the clients may exercise them.

The Company may amend this Policy from time to time, and it is important that clients
check this Policy for any updates.

Any personal information the Company holds will be governed by Company’s most current Privacy
Policy. If the Company amends it, and it is considered to be important, the Company will communicate
amendments to its clients.

2. Personal Data that we may collect:

When a clients open an account with the Company, it is require to provide client’s first and last name,
e-mail address, details about client’s financial status, residential address, phone number, date of birth,
a copy of identification document (passport or identity card), copy of recent utility bill or a bank
statement or other evidence of residential address, bank card details, tax residence and tax number,
professional and employment details, knowledge and experience in trading, risk tolerance and risk
profile and other information considered relevant to the clients functions and activities that would
permit the Company to provide its services to the client.

If the Company requests personal data and the client fails to provide it, the Company may not be in a
position to provide a service and/or enter into an agreement with those potential client. In this case
the client will be informed accordingly.

The abovementioned data is collected by the Company upon opening of a trading account and is
required by the AML Law (the Prevention and Suppression of Money laundering and Terrorist Financing
Law of 2007 as amended from time to time) and CySEC’s AML Directive.

The Company collects the necessary data for verifying client’s identity, constructing client’s economic
profile, monitoring the account and verifying the source of funds (when it is necessary).

Additionally, the Company uses this data to set up and administer client’s trading account, provide
technical and customer support.

The Company uses cookies to store and collect information about clients’ use of Company’s Website.
Cookies are small text files stored by the browser on clients equipment’s hard drive. They send
information stored on them back to Company’s web server when the clients access the Company’s
Website. These cookies enable the Company to put in place personal settings and load the personal
preferences to improve client’s experience.

More about cookies is available in “Cookie Policy Disclosure” on Company’s Website.

In relation to a corporate client, the Company requires information about the legal entity (e.g. corporate
and constitutional documents), additional personal information on the shareholders, directors and
other officers that is deemed necessary for the Company to be compliant with the legal and regulatory
requirements.

Any communication, electronic, by telephone, in person or otherwise, between the client and the
Company in relation to the services provided, may be recorded. These recordings will be Company’s
sole property and will constitute evidence of communication held.

It should be noted that the Company is obliged by Law 87(I)/2017 to keep the records of all telephone
conversations and electronic communications related to transactions concluded and the provision of
client order services that relate to the reception, transmission and execution of client orders.

3. Legal Ground for personal Data processing:

The Company may process clients personal data for one or more lawful bases of processing (“Lawful
Basis”) depending on the specific purpose for which clients data is being used.

The Lawful Basis are considered the following:

  • to perform the contractual obligations towards the clients
  • to be compliant with applicable legal and regulatory requirements
  • to pursue Company’s legitimate interests

Where the Company’s use of clients personal information does not fall under one of the above
mentioned Lawful Basses, the Company is required to obtain clients consent. Such consent shall be
freely given by the clients, and they will have the right to withdraw their consent at any time by
contacting the Company using the contact details set out in this Privacy Policy or by unsubscribing from
the email lists. 

4. How we use your personal data:

Client information, which the Company holds, is to be treated by the Company as confidential and will
not be used for any purpose other than in connection with the provision, administration and improvement of the Services, anti-money laundering and due diligence checks, for research and
statistical purposes and for marketing purposes.
Information already available in the public domain or already possessed by the Company without a duty
of confidentiality will not be regarded as confidential.
The Company has the right to disclose Client information (including recordings and documents of a
confidential nature, card details) in the following circumstances:

  1. where required by law or a court order by a competent Court.
  2. where requested by CySEC or any other regulatory authority having control or jurisdiction over
    the Company or the Client or their associates or in whose territory the Company has Clients.
  3. to government bodies and law enforcement agencies where required by law and in response
    to other legal and regulatory requests;
  4. to relevant authorities to investigate or prevent fraud, money laundering or other illegal
    activity;
  5. where necessary in order for the Company to defend or exercise its legal rights to any court or
    tribunal or arbitrator or Ombudsman or governmental authority;
  6. to such an extent as reasonably required so as to execute Orders and for purposes ancillary to
    the provision of the Services;
  7. to payment service providers and banks processing your transactions;
  8. to auditors or contractors or other advisers auditing, assisting with or advising on any of our
    business purposes; provided that in each case the relevant professional shall be informed about
    the confidential nature of such information and commit to the confidentiality herein
    obligations as well;
  9. only to the extent required and only the contact details to other service providers who create,
    maintain or process databases (whether electronic or not), offer record keeping services, email
    transmission services, messaging services or similar services which aim to assist the Company
    collect, storage, process and use Client information or get in touch with the Client or improve
    the provision of the Services under this Agreement.
  10. to a Trade Repository or similar under the Regulation (EU) No 648/2012 of the European
    Parliament and of the Council of 4 July 2012 on OTC derivatives, central counterparties (CCPs)
    and trade repositories (TRs) (EMIR).
  11. only to the extent required, to other service providers for statistical purposes in order to
    improve the Company’s marketing, in such a case the data will be provided in an aggregate
    form.
  12. where necessary in order for the Company to defend or exercise its legal rights to any court or
    tribunal or arbitrator or Ombudsman or governmental authority.
  13. to anyone authorised by you.
  14. any other company in the same group of the Company.
  15. to any third-party where such disclosure is required in order to enforce or apply our Terms and
    Conditions or other relevant agreements.
  16. to successors or assignees or transferees or buyers, with ten Business Days prior Written Notice
    to the Client; this will happen in the event that the Company decides to sell, transfer, assign or
    novate to a third party any or all of its rights, benefits or obligations under the Agreement with
    you or the performance of the entire Agreement subject to providing 15 Business Days Prior
    Written Notice to the Client. This may be done without limitation in the event of merger or
    acquisition of the Company with a third party, reorganisation of the Company, winding up of the Company or sale or transfer of all or part of the business or the assets of the Company to a
    third party 
  17. Client Information is disclosed in relation to US taxpayers to the Inland Revenue in Cyprus,
    which will in turn report this information to the IRS of the US according to the Foreign Account
    Tax Compliance Act (FATCA) of the USA and the relevant intergovernmental agreement
    between Cyprus and the US.

5. The safety of your personal data

The Company takes the appropriate measures to ensure a level of security appropriate to protect any
personal data provided to us form accidental or unlawful destruction, loss, alteration, unauthorised
disclosure of, or access to personal data transmitted, stored or otherwise processed.

The Company implements appropriate technical and organisational measures such as data encryption,
access management procedure, clean desk policy, business continuity and disaster recovery, IT systems
risk assessment, physical and logical access segregation, process in case of personal data breach policy
etc. Additionally, the Company limits access to the Client’s personal data to those employees, agents,
contractors and other third parties who have a business need to know. They will only process the
Client’s personal data on the Company’s instructions, and they are subject to a duty of confidentiality.
Client’s personal data may be stored electronically or in paper form.

6. Automated decision – making and Profiling

To enable communication and comply with Law 87(I)/2017 and the relevant Circulars issued by CySEC,
the provision of investment services requires an assessment of clients’ knowledge and experience,
financial situation, and investment objectives.

The Company will fulfil the above requirements through the following tools:

Appropriateness Test

This process takes place upon registration as a client of the Company. An assessment is conducted to
determine suitability for the Company’s services and products through an appropriateness test
covering knowledge, financial background, and experience in financial services. Based on the resulting
score, eligibility to receive services, client status, and the maximum level of leverage permitted are
determined. The purpose of this assessment is to ensure that the services offered are appropriate and
aligned with the client’s best interestsThe scorings above are monitored by the Compliance department
of the Company.

During these processes, the Company takes all the technical and operational measures to correct
inaccuracies and minimise the risk of errors, to prevent any discrimination and to secure personal data
of the client.

7. How the Company treats clients’ personal data for marketing activities and whether profiling is used for such activities

The Company may process clients’ personal data to provide information about products,
services, and offers that may be of interest to them or their business.

The personal data processed for this purpose includes information provided by clients, as well
as data collected and/or inferred through the use of the Company’s services. This information
supports the improvement of services, the customization of the user experience, and the communication of additional products, services, or promotions relevant to clients. In some cases, profiling may be applied, whereby data is processed automatically to evaluate certain personal aspects in order to deliver targeted marketing information.

Personal data is used for marketing purposes only where explicit consent has been obtained or, where applicable, where such processing is considered to be in the Company’s legitimate interest.

Clients have the right to object at any time to the processing of their personal data for
marketing purposes, including profiling, by contacting the Company’s designated GDPR contact
person via email: [email protected]

8. How long we store your personal data for

Personal data is retained only for as long as necessary to fulfil legal or business purposes,
subject to a maximum period of five (5) years following the execution of transactions or the
termination of the business relationship. In determining retention periods, consideration is
given to applicable laws, contractual obligations, and customer expectations and
requirements. Once personal data is no longer required, it is securely deleted or destroyed.

The Company is subject to investment services and anti-money laundering legislation, which
requires the retention of records such as identity verification documentation, information on
sources of income and wealth, transaction monitoring data, records of telephone, chat, and
email communications, order and trade history, complaint handling records, and evidence
demonstrating compliance with regulatory conduct requirements. These records must
generally be maintained for five years after the end of the business relationship, or longer if
required by regulators.

Where a client has opted out of receiving marketing communications, relevant details are
retained on a suppression list to ensure that such communications are no longer sent. 

9. Transfers of personal data to third countries

Copies of agreements may be transferred to and stored at banking institutions located outside
the European Economic Area (EEA). Personal data may also be processed by staff operating
outside the EEA who work for suppliers or affiliated companies. All such transfers are carried
out in accordance with applicable laws and, where required, subject to appropriate safeguards.
Information regarding these safeguards may be obtained by contacting the Company.

Where personal data is transferred to third parties outside the EEA, such transfers are
conducted in compliance with the General Data Protection Regulation (Regulation (EU)
2016/679). This may involve reliance on a European Commission adequacy decision,
appropriate safeguards such as standard contractual clauses or binding corporate rules, or
other mechanisms permitted under the GDPR.

Further information regarding the applicable safeguards may be obtained by contacting the
Company.

10. Clients’ rights as a data subject

The following rights apply in relation to the processing of personal data:

Right of access – the right to request a copy of the personal data held.

Right of rectification – the right to request correction of inaccurate or incomplete personal data.

Right to erasure – the right, in certain circumstances, to request the deletion of personal data. Where applicable, and provided no legal obligation requires its retention under Cypriot or EU
law, the Company, acting as data controller, will erase the personal data.

Right to restriction of processing – the right, under certain conditions, to request the restriction
of the processing of personal data.

Right to data portability – the right, under certain conditions, to request the transfer of
personal data to another organization. Where applicable, personal data will be provided in a
structured, commonly used, and machine-readable format. This right applies only to
automated data provided on the basis of consent or for the performance of a contract.

Right to object – the right to object, on grounds relating to a particular situation, to certain
types of processing, including direct marketing or processing based on legitimate interests. In some cases, processing may continue where compelling legitimate grounds override these interests.

Right to withdraw consent – where processing is based on consent, the right to withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out prior to withdrawal. It may, however, affect the ability to provide certain products or services.

Requests relating to these rights will be reviewed and, where applicable, personal data will be provided, corrected, amended, or deleted. Requests may be submitted via the designated
email address.

A reasonable fee may be charged where a request is manifestly unfounded, excessive, or repetitive, or where additional copies of data are requested. In such cases, a fee notification will be provided prior to processing the request. Alternatively, the request may be refused under these circumstances. 

11. Contact regarding this Policy or complaints

For any queries regarding the content of this Policy, to notify of changes or corrections to
personal data, to request a copy of personal data, or to submit a complaint or comment,
contact may be made using the details provided below:

[email protected]

Requests are generally addressed within five (5) business days. Where a request requires
more than one month to process, notification will be provided along with updates on its
progress. Information provided in response to the exercise of data subject rights is generally
free of charge. However, where requests are manifestly unfounded or excessive, particularly
due to their repetitive nature, the Company may either:

  1. charge a reasonable fee reflecting the administrative costs of providing the information
    or taking the requested action; or
  2. refuse to act on the request.

If the response is not satisfactory or if the request is not handled within the specified timeframes, a
complaint may be lodged with the supervisory authority, the Cyprus Data Protection Commissioner. Alternatively, a complaint may be submitted to the data protection authority in the country of residence.

Information on how to contact the Cyprus Data Protection Commissioner is available at:
http://www.dataprotection.gov.com/

Important Information

ATFX CONNECT EU does not offer services to retail clients. The information and contact details provided on this website are intended for professional clients’ use only.

⚠️ Fraud Warning

We are aware of scams involving individuals and websites impersonating our company.
ATFX Global Markets (Cy) Ltd only communicates via official emails and phone numbers listed on our website.
We do not operate any other websites other than: www.atfxgm.eu, www.atfxconnect.com/en-eu/.
We do not use WhatsApp, Telegram or social media to contact clients.
If you suspect any fraudulent activity, please contact us immediately at [email protected].

Stay vigilant – protect your information.

Important Information

ATFX CONNECT EU does not offer services to retail clients. The information and contact details provided on this website are intended for professional clients’ use only.