Personal Data Processing Policy
General Provisions
This Personal Data Processing Policy (hereinafter referred to as the “Policy”) establishes the procedure, principles, and legal basis for the collection, use, storage, transfer, and protection of personal data by the Operator. The Operator is committed to ensuring the processing of personal data in compliance with the Data Protection Act 2018 and the UK General Data Protection Regulation (UK GDPR), as applicable within Great Britain.
Legal Basis for Data Processing
The Operator processes personal data strictly in accordance with the following legal grounds, as determined by the UK GDPR:
- Fulfilment of contractual obligations with the data subject;
- Compliance with legal obligations to which the Operator is subject;
- Legitimate interests pursued by the Operator, provided that such interests are not overridden by the interests or fundamental rights and freedoms of the data subject;
- Consent of the data subject, where required for specific purposes.
Categories of Personal Data Processed
The Operator may process the following categories of personal data:
- Identification data (e.g. full name, date of birth, nationality);
- Contact details (e.g. residential address, email address, phone number);
- Financial information (e.g. bank account details, payment data);
- Verification documents (e.g. copies of identity cards or passports, proof of address);
- Log and technical data (IP addresses, device information, login details);
- Records of communication and correspondence with the Operator.
Purposes of Personal Data Processing
Personal data are processed exclusively for the following purposes:
- Establishment, performance, and termination of contractual relationships with users;
- Compliance with legal and regulatory obligations, including anti-money laundering (AML) and counter-terrorist financing (CTF) requirements;
- Identification and verification of users, including age and identity checks;
- Processing of transactions and provision of related services;
- Prevention of fraud, abuse, and other prohibited activities;
- Handling user inquiries and requests;
- Maintenance of records as required by law;
- Fulfilment of obligations to supervisory and regulatory authorities.
Data Retention
Personal data are stored for no longer than necessary for the purposes for which they were collected, or as required by applicable law. The retention periods are determined in accordance with the statutory and regulatory requirements, including those imposed by the Data Protection Act 2018 and other relevant legislation.
Rights of Data Subjects
Data subjects have the following rights in relation to their personal data, in accordance with the UK GDPR:
- The right to access their personal data held by the Operator;
- The right to rectification of inaccurate or incomplete data;
- The right to erasure (‘right to be forgotten’) where applicable;
- The right to restrict processing of personal data in accordance with the law;
- The right to data portability in applicable circumstances;
- The right to object to processing based on legitimate interests or direct marketing;
- The right to withdraw consent at any time where processing is based on consent;
- The right to lodge a complaint with the Information Commissioner’s Office (ICO).
Disclosure and Transfer of Personal Data
Personal data may be disclosed to:
- Regulatory and supervisory authorities as required by applicable law;
- Third-party service providers engaged by the Operator for the performance of contractual obligations, subject to appropriate safeguards;
- Other recipients only with the data subject’s consent or as otherwise permitted by law.
Transfers of personal data outside the United Kingdom are conducted in full compliance with UK data protection legislation and are subject to appropriate safeguards to ensure the security of personal data.
Data Security
The Operator implements appropriate technical and organisational measures to ensure the security and confidentiality of personal data against unauthorised or unlawful processing, accidental loss, destruction or damage, in accordance with Article 32 of the UK GDPR.
Contact Information
For any questions regarding the processing of personal data or to exercise data subject rights, please contact:
Data Protection Officer
Operator Ltd.
1 Temple Avenue, London, EC4Y 0HA, United Kingdom
Email: [email protected]
Telephone: +44 20 7946 0857
Policy Updates
This Policy may be amended or updated to reflect changes in legislation or internal procedures. Any amendments will be published on this page from the date they come into force.
Date of last revision: 9 June 2024