GoFX
  • Home
  • About
  • Trading
    • Account Types
    • Our Products
    • Trading Platforms
  • Legal
    • Privacy Policy
    • Client Agreement
    • Order Execution Policy
    • Risk Disclosure
  • Contact
  • English
  • Bahasa Indonesia
  • Tiếng Việt
  • ไทย
  • ລາວ
Log In Open Account
  • Home
  • About
  • Trading
    • Account Types
    • Our Products
    • Trading Platforms
  • Legal
    • Privacy Policy
    • Client Agreement
    • Order Execution Policy
    • Risk Disclosure
  • Contact
Log In Open Account
EnglishBahasa IndonesiaTiếng Việtไทยລາວ

Legal Information

Privacy Policy

GOFX is committed to protecting the privacy and security of our clients' personal data. This Privacy Policy explains the principles, procedures, and standards applied by the Company in the collection, use, storage, disclosure, and protection of personal data, as well as the rights of data subjects under applicable laws and regulatory requirements.

The Company is committed to processing personal data in a transparent, appropriate, and secure manner. Personal data is collected and processed only to the extent necessary for the provision of our services, compliance with legal and regulatory obligations, and the protection of our systems and client accounts.

Personal data protection and information security

Table of Contents

  1. Section 1 — Introduction and Scope of the Policy
    1. 1.1 Introduction
    2. 1.2 Purpose of the Policy
    3. 1.3 Relationship with the Client Agreement and Related Documents
    4. 1.4 Scope of Application
    5. 1.5 Acceptance of the Policy
  2. Section 2 — Definitions and Interpretation
    1. 2.1 Introduction
    2. 2.2 Definitions
    3. 2.3 Rules of Interpretation
    4. 2.4 Relationship with the Client Agreement
  3. Section 3 — Personal Data Collected by the Company
    1. 3.1 General Principles
    2. 3.2 Identity Information
    3. 3.3 Contact Information
    4. 3.4 Financial Information
    5. 3.5 Payment Information
    6. 3.6 Trading Information
    7. 3.7 Technical Information
    8. 3.8 Location Information
    9. 3.9 Communication Information
    10. 3.10 Information Obtained from Third Parties
    11. 3.11 Information the Company Does Not Intend to Collect
  4. Section 4 — Methods of Collecting Personal Data
    1. 4.1 General Principles
    2. 4.2 Information Provided Directly by the Client
    3. 4.3 Information Collected Through the Website
    4. 4.4 Information Collected Through the Trading Platform
    5. 4.5 Communications
    6. 4.6 Information Received from Third Parties
    7. 4.7 Automatically Collected Information
    8. 4.8 Verification of Information
    9. 4.9 Updating Information
    10. 4.10 Accuracy of Information
  5. Section 5 — Purposes and Legal Bases for Processing Personal Data
    1. 5.1 General Principles
    2. 5.2 Pre-Contractual Activities and Service Provision
    3. 5.3 Performance of the Client Agreement
    4. 5.4 Know Your Customer (KYC)
    5. 5.5 Compliance with AML / CTF Requirements
    6. 5.6 Risk Management
    7. 5.7 Information Security
    8. 5.8 Client Support
    9. 5.9 Communications with Clients
    10. 5.10 Service Analysis and Improvement
    11. 5.11 Compliance with Requests from Competent Authorities
    12. 5.12 Marketing Communications
    13. 5.13 Changes to the Purpose of Processing
  6. Section 6 — Use and Disclosure of Personal Data
    1. 6.1 General Principles
    2. 6.2 Internal Use of Personal Data
    3. 6.3 Disclosure to Group Companies
    4. 6.4 Disclosure to Service Providers
    5. 6.5 Disclosure to Regulatory Authorities and Government Agencies
    6. 6.6 Disclosure for the Prevention of Fraud and Financial Crime
    7. 6.7 Disclosure in Connection with Corporate Transactions
    8. 6.8 Disclosure Based on Consent
    9. 6.9 Anonymised and Aggregated Information
    10. 6.10 Confidentiality of Personal Data
    11. 6.11 Limitations on Disclosure
  7. Section 7 — International Transfer of Personal Data
    1. 7.1 General Principles
    2. 7.2 Purposes of International Data Transfers
    3. 7.3 Overseas Data Recipients
    4. 7.4 Safeguards for International Transfers
    5. 7.5 Use of Cloud Service Providers
    6. 7.6 Compliance with the Laws of the Recipient Jurisdiction
    7. 7.7 Disclosure Pursuant to Requests from Foreign Authorities
    8. 7.8 Transfers Within the Group of Companies
    9. 7.9 Changes to Data Processing Locations
    10. 7.10 Client Responsibilities
  8. Section 8 — Retention and Disposal of Personal Data
    1. 8.1 General Principles
    2. 8.2 Factors Used to Determine Retention Periods
    3. 8.3 Retention of Information for Active Clients
    4. 8.4 Retention Following Account Closure
    5. 8.5 Retention of Transaction Records
    6. 8.6 Backup and Disaster Recovery
    7. 8.7 Deletion and Disposal of Personal Data
    8. 8.8 Suspension of Deletion
    9. 8.9 Monitoring Compliance with the Retention Policy
    10. 8.10 Review of Retention Periods
  9. Section 9 — Cookies and Similar Technologies
    1. 9.1 General Principles
    2. 9.2 What Are Cookies?
    3. 9.3 Purposes of Using Cookies
    4. 9.4 Types of Cookies Used by the Company
    5. 9.5 Third-Party Cookies
    6. 9.6 Managing Cookies
    7. 9.7 Consent for Cookies
    8. 9.8 Changes to the Use of Cookies
    9. 9.9 Relationship with the Cookie Policy
  10. Section 10 — Rights of Data Subjects
    1. 10.1 General Principles
    2. 10.2 Right of Access
    3. 10.3 Right to Rectification
    4. 10.4 Right to Erasure
    5. 10.5 Right to Restrict Processing
    6. 10.6 Right to Object
    7. 10.7 Withdrawal of Consent
    8. 10.8 Right to Data Portability
    9. 10.9 Exercising Rights Through an Authorised Representative
    10. 10.10 Submitting a Request
    11. 10.11 Response Time
    12. 10.12 Refusal of Requests
    13. 10.13 Complaints
  11. Section 11 — Information Security Measures
    1. 11.1 General Principles
    2. 11.2 Access Control
    3. 11.3 Information Systems Security
    4. 11.4 Protection of Data at Rest and in Transit
    5. 11.5 Personnel Security
    6. 11.6 Third-Party Security Management
    7. 11.7 Security Incident Management
    8. 11.8 Business Continuity
    9. 11.9 Client Responsibilities
    10. 11.10 Review and Continuous Improvement
  12. Section 12 — Contact Information, Amendments and Version Control
    1. 12.1 Contacting the Company
    2. 12.2 Identity Verification
    3. 12.3 Fees
    4. 12.4 Interpretation of this Policy
    5. 12.5 Severability
    6. 12.6 No Waiver
    7. 12.7 Amendments to this Privacy Policy
    8. 12.8 Effective Date
    9. 12.9 Language
Section 1

Introduction and Scope of the Policy

1.1 Introduction

This Privacy Policy (the "Policy") is issued by GOFX LIMITED (the "Company," "GOFX," "we," "our," or "us") to explain the principles, procedures, and standards applied by the Company in the collection, use, recording, storage, disclosure, transfer, deletion, and other processing of personal data relating to clients, account applicants, website users, trading platform users, individuals who communicate with the Company, and other persons who interact with the Company's services (collectively referred to as "Clients" or "you").

The Company recognises the importance of protecting personal data and respecting the privacy of its Clients. We are committed to processing personal data in a lawful, transparent, fair, and appropriate manner, using such data only to the extent necessary for the provision of our services, compliance with applicable legal and regulatory obligations, risk management, and the operation of our business.

This Policy explains the categories of personal data that the Company may collect, the sources from which such data is obtained, the purposes for which personal data is processed, the circumstances under which personal data may be disclosed to third parties, international data transfers, data retention periods, the rights of data subjects, and the technical and organisational measures implemented to protect personal data.

The Company may process personal data where necessary for the provision of financial trading services, the opening and administration of client accounts, identity verification, compliance with applicable Anti-Money Laundering and Counter-Terrorist Financing (AML/CTF) requirements, fraud prevention, information security, and other legitimate business purposes.

This Policy is intended to describe the Company's practices relating to the processing of personal data. It does not amend, modify, expand, or limit the rights and obligations of either the Client or the Company under the Client Agreement, except where expressly stated or where otherwise required by applicable law.

1.2 Purpose of the Policy

This Policy has been prepared for the following purposes:

  • To explain the Company's principles and practices relating to the collection, use, disclosure, and processing of personal data.
  • To inform Clients of the categories of personal data that the Company may collect and the sources from which such information may be obtained.
  • To explain the purposes and legal bases on which personal data is processed.
  • To describe the circumstances in which personal data may be disclosed to Group companies, service providers, business partners, regulatory authorities, government agencies, or other third parties as required or permitted by law.
  • To explain the measures implemented by the Company to protect the security and confidentiality of personal data.
  • To inform data subjects of their rights under applicable data protection laws.
  • To establish principles governing the retention, deletion, and secure disposal of personal data once it is no longer required.
  • To support the Company's compliance with applicable laws, regulations, and recognised standards relating to the protection of personal data.

1.3 Relationship with the Client Agreement and Related Documents

This Privacy Policy forms an integral part of the Client Agreement of GOFX LIMITED and should be read together with the Company's other agreements, policies, and legal documents, including but not limited to:

  • Client Agreement
  • Order Execution Policy
  • Risk Disclosure Statement
  • AML / KYC Policy
  • Cookie Policy
  • Trading Conditions
  • Product Specifications
  • Any notices, terms, policies, or guidelines published by the Company through its website, trading platform, Client Area, or other official communication channels.

These documents collectively form part of the Company's legal and operational framework and may refer to this Policy where appropriate.

In the event of any inconsistency between this Policy and the Client Agreement, the Client Agreement shall prevail unless otherwise required by applicable law.

1.4 Scope of Application

This Policy applies to the processing of personal data relating to:

  • Account applicants
  • Current Clients
  • Former Clients
  • Authorised signatories of corporate entities
  • Ultimate Beneficial Owners (UBOs)
  • Authorised representatives
  • Introducing Brokers (IBs), where applicable
  • Website visitors
  • Client Area users
  • Trading platform users
  • Individuals who communicate with the Company through email, telephone, online forms, or any other communication channels designated by the Company

This Policy applies to personal data obtained directly from Clients, from third parties, from external service providers, or through the use of the Company's services, including information collected through automated systems, websites, applications, trading platforms, and electronic devices used in connection with the Company's services.

1.5 Acceptance of the Policy

Clients acknowledge and agree that any of the following actions constitutes acknowledgement and acceptance of this Privacy Policy:

  • Applying to open an account
  • Submitting information or documents to the Company
  • Accessing or using the Client Area
  • Accessing or using the Company's website
  • Accessing or using the trading platform
  • Making deposits or withdrawals
  • Using any products or services provided by GOFX LIMITED

Acceptance of this Policy does not constitute a waiver of any rights available to Clients under applicable law, nor does it restrict the Company's right to process personal data on any lawful basis permitted under applicable laws and regulations.

Section 2

Definitions and Interpretation

2.1 Introduction

Unless the context otherwise requires, capitalised terms used in this Privacy Policy shall have the meanings assigned to them in the Client Agreement of GOFX LIMITED and shall bear the same meaning throughout this Policy unless expressly defined otherwise herein.

The definitions contained in this Policy are intended to:

  • provide clear meanings for terms relating to the processing of personal data;
  • minimise ambiguity in the interpretation of this Policy;
  • define the respective rights and obligations of the Company and Clients in relation to the processing of personal data; and
  • provide the basis for the interpretation and application of this Policy.

Words importing the singular include the plural and vice versa where the context so requires.

2.2 Definitions

For the purposes of this Policy, the following terms shall have the meanings set out below:

"Company" means GOFX LIMITED, including its directors, officers, employees, authorised representatives, affiliated companies, service providers, contractors, and any person appointed by the Company to perform functions relating to the provision of its services or the processing of personal data.

"Client" means any natural person or legal entity, including an account applicant, account holder, website user, trading platform user, authorised representative, authorised signatory, agent, Ultimate Beneficial Owner ("UBO"), or any other person who has a relationship with the Company through the use of its services or communications with the Company.

"Personal Data" means any information relating to an identified or identifiable natural person, whether contained in documents, electronic records, images, audio recordings, video recordings, or any other digital format, including information that may identify an individual when combined with other available information.

"Sensitive Personal Data" means personal data that is afforded enhanced protection under applicable law, including, where applicable, biometric data, health information, racial or ethnic origin, religious or philosophical beliefs, political opinions, or any other category of sensitive personal data recognised under applicable law.

The Company will process Sensitive Personal Data only where necessary and where a valid legal basis exists.

"Processing" means any operation or set of operations performed on Personal Data, whether by automated or non-automated means, including but not limited to:

  • collection;
  • recording;
  • organisation;
  • storage;
  • adaptation or modification;
  • use;
  • analysis;
  • disclosure;
  • transmission;
  • transfer;
  • combination;
  • restriction of processing;
  • deletion; and
  • destruction.

"Collection" means obtaining Personal Data from Clients, third parties, or other lawful sources, whether directly or indirectly, including through websites, trading platforms, applications, forms, documents, emails, telephone communications, or other electronic communication channels.

"Third Party" means any natural person or legal entity other than the Client or the Company that may receive, disclose, or process Personal Data as permitted or required by applicable law or contractual arrangements, including service providers, regulatory authorities, financial institutions, technology providers, identity verification providers, and other system providers.

"Service Provider" means any natural person or legal entity appointed by the Company to perform services on its behalf, including technology providers, cloud service providers, data hosting providers, cybersecurity providers, KYC service providers, document verification providers, payment service providers, auditors, legal advisers, and other service providers supporting the Company's business operations.

"Website" means the GOFX website and any other website, domain, or online service owned, operated, or controlled by the Company, including those used for client services and account registration.

"Client Area" means the secure online client portal provided by the Company through which Clients may open and manage accounts, submit documents, make deposits and withdrawals, communicate with the Company, and access other services.

"Trading Platform" means any software, application, or electronic trading system made available by the Company for trading financial instruments, including MetaTrader, WebTrader, mobile applications, or any other trading platform supported by the Company.

"Cookies" means small data files or similar technologies stored on a user's device for the purpose of remembering preferences, analysing website usage, improving website performance, and facilitating the Company's services.

"AML / CTF" means the laws, regulations, policies, and procedures relating to anti-money laundering, counter-terrorist financing, international sanctions compliance, and other related regulatory requirements applicable to the Company.

"KYC" means the Company's Know Your Customer procedures, including identity verification, document verification, source of funds verification, Ultimate Beneficial Owner verification, and any other due diligence measures required by applicable laws and regulatory requirements.

"Applicable Law" means any applicable law, regulation, rule, order, directive, guideline, regulatory standard, or requirement issued by a governmental authority, regulatory body, or international organisation that applies to the Company's business activities or the processing of Personal Data.

2.3 Rules of Interpretation

Unless the context otherwise requires:

  • references to any law or regulation include any amendment, replacement, extension, consolidation, or re-enactment thereof;
  • headings are included for convenience only and shall not affect the interpretation of this Policy;
  • the words "including," "such as," or similar expressions shall be construed as illustrative only and shall not limit the general meaning of the words preceding them;
  • where any provision of this Policy conflicts with Applicable Law, such provision shall be interpreted and applied only to the extent permitted by Applicable Law; and
  • if any provision of this Policy is held to be invalid, unenforceable, or unlawful, the remaining provisions shall continue in full force and effect to the maximum extent permitted by Applicable Law.

2.4 Relationship with the Client Agreement

Any capitalised term not expressly defined in this Policy shall have the meaning assigned to it in the Client Agreement of GOFX LIMITED, unless the context requires otherwise.

Where any inconsistency exists between the definitions contained in this Policy and those contained in the Client Agreement, the definitions in this Policy shall prevail solely for matters relating to the processing of Personal Data, while the definitions contained in the Client Agreement shall continue to apply to all other matters relating to the Company's products and services.

Section 3

Personal Data Collected by the Company

3.1 General Principles

The Company may collect Personal Data only to the extent necessary and relevant for the provision of its services, the conduct of its business, compliance with Applicable Law, and the other purposes described in this Policy.

Personal Data may be collected before, during, or after the opening of an account, throughout the Client's relationship with the Company, and following the termination of such relationship where the Company is required or permitted by Applicable Law to retain such information.

The Company will collect only Personal Data that is reasonably necessary for its legitimate business purposes and will not collect excessive or unnecessary Personal Data unless required by Applicable Law or where the Client's consent is required and has been obtained.

3.2 Identity Information

The Company may collect information used to identify a Client, including but not limited to:

  • Title
  • First name
  • Middle name (where applicable)
  • Last name
  • Former name (where applicable)
  • Date of birth
  • Age
  • Gender (where applicable)
  • Nationality
  • Country of residence
  • Country of tax residence
  • Passport number
  • National identification number
  • Government-issued identification number
  • Residence permit number
  • Company registration number (for corporate entities)
  • Tax identification number (where applicable)

The Company may also request supporting documentation, including but not limited to:

  • Passport
  • National identity card
  • Driver's licence
  • Residence permit
  • Certificate of Incorporation
  • Memorandum of Association
  • Power of Attorney
  • Ultimate Beneficial Owner (UBO) documentation

3.3 Contact Information

The Company may collect contact information including:

  • Residential address
  • Registered address
  • Correspondence address
  • Country
  • Province or State
  • City
  • Postal or ZIP code
  • Telephone number
  • Mobile number
  • Email address
  • Client account username or identifier
  • Any other contact details provided by the Client

Clients are responsible for promptly notifying the Company of any changes to their contact information.

3.4 Financial Information

To provide its services, the Company may collect financial information including:

  • Income
  • Source of income
  • Source of wealth
  • Source of funds
  • Estimated assets
  • Investment experience
  • Investment objectives
  • Risk tolerance
  • Employment status
  • Occupation
  • Employer
  • Business activities

Such information may be used for:

  • Client suitability assessments
  • KYC and AML/CTF due diligence
  • Risk management
  • Compliance with Applicable Law

3.5 Payment Information

The Company may collect payment-related information, including:

  • Bank account name
  • Bank account number
  • Bank name
  • Country of the bank
  • SWIFT code
  • IBAN (where applicable)
  • Electronic wallet details
  • Digital asset wallet information used for deposits or withdrawals
  • Deposit history
  • Withdrawal history
  • Transaction details
  • Payment methods

The Company does not retain credit card information or payment credentials beyond what is necessary where payment processing is performed by independent third-party payment service providers.

3.6 Trading Information

The Company may collect information relating to a Client's trading activities, including:

  • Trading account number
  • Account type
  • Trading platform
  • Order type
  • Order submission time
  • Order execution time
  • Execution price
  • Trade volume
  • Margin
  • Equity
  • Balance
  • Free Margin
  • Leverage
  • Commission
  • Swap
  • Profit or loss
  • Trading history
  • Trading platform login history

Such information may be processed for order execution, risk management, fraud prevention, transaction monitoring, internal audit, and compliance with the Company's Order Execution Policy.

3.7 Technical Information

When Clients use the Company's website or trading platforms, the Company may collect technical information including:

  • IP address
  • MAC address (where applicable)
  • Device ID
  • Browser type
  • Operating system
  • Language settings
  • Device model
  • Session ID
  • Cookies
  • Log files
  • Crash reports
  • Time zone
  • Referrer URL
  • Network information

This information may be used to:

  • maintain the security of the Company's systems;
  • detect suspicious or unauthorised activities;
  • improve website and platform performance;
  • analyse website and platform usage; and
  • prevent unauthorised access.

3.8 Location Information

The Company may collect location-related information derived from:

  • IP address
  • GPS data (where permission has been granted)
  • Network information
  • Country of connection
  • Time zone

Such information may be used to:

  • verify jurisdictional eligibility;
  • prevent fraud;
  • comply with international sanctions and regulatory requirements; and
  • prevent access from jurisdictions where the Company's services are restricted or unavailable.

3.9 Communication Information

The Company may collect information relating to communications between the Client and the Company, including:

  • Email correspondence
  • Live Chat communications
  • Support tickets
  • Telephone conversations
  • Online meetings
  • Contact forms
  • Complaints
  • Enquiries
  • Communications through any other channels designated by the Company

Subject to Applicable Law, the Company may monitor and record telephone conversations, online meetings, and electronic communications for evidential purposes, quality assurance, staff training, dispute resolution, internal audit, regulatory compliance, and the prevention of fraud and financial crime.

3.10 Information Obtained from Third Parties

The Company may obtain information relating to Clients from third parties where necessary for the provision of services or compliance with Applicable Law, including:

  • KYC service providers
  • Sanctions screening providers
  • AML screening providers
  • Financial institutions
  • Payment service providers
  • Technology service providers
  • Regulatory authorities
  • Government agencies
  • Group companies
  • Introducing Brokers (IBs) or business partners, where applicable

The Company will use such information only where necessary and only to the extent permitted by Applicable Law.

3.11 Information the Company Does Not Intend to Collect

The Company does not request or intentionally collect Personal Data that is not relevant or necessary for the provision of its services. Clients are requested not to submit information unrelated to account opening or the use of the Company's services, including medical information, political opinions, or other categories of Sensitive Personal Data, unless such information is required by Applicable Law or is reasonably necessary for identity verification, regulatory compliance, or other lawful purposes.

Section 4

Methods of Collecting Personal Data

4.1 General Principles

The Company may collect Personal Data from various sources and through multiple channels, including directly from Clients, through the use of the Company's services, from third parties, or from other lawful sources. Personal Data is collected only to the extent necessary for the provision of services, compliance with Applicable Law, risk management, information security, and the other purposes described in this Policy.

The Company collects Personal Data by lawful, fair, and transparent means and will take reasonable steps to ensure that only Personal Data necessary for the relevant processing purposes is collected.

4.2 Information Provided Directly by the Client

The Company may collect Personal Data directly from Clients when they:

  • apply to open a trading account;
  • complete forms on the Company's website;
  • register or access the Client Area;
  • submit identity verification documents;
  • submit proof of address documentation;
  • provide financial information;
  • complete suitability or appropriateness assessments (where applicable);
  • make deposits or withdrawals;
  • contact the Company's client support team;
  • submit complaints;
  • exercise their rights under applicable data protection laws; or
  • participate in Company events, seminars, promotional activities, or other marketing initiatives.

Clients represent and warrant that all information provided to the Company is accurate, complete, and up to date and agree to notify the Company promptly of any material changes.

4.3 Information Collected Through the Website

When Clients access the Company's website, certain information may be collected automatically, including:

  • IP address;
  • browser type;
  • operating system;
  • language preferences;
  • date and time of access;
  • pages visited;
  • duration of visits;
  • Referrer URL;
  • clickstream data;
  • device information; and
  • session information.

This information may be used to:

  • ensure the proper operation of the website;
  • improve website functionality and performance;
  • analyse website usage;
  • detect unusual or suspicious activity;
  • protect against cyber threats; and
  • enhance the overall user experience.

4.4 Information Collected Through the Trading Platform

When Clients use the Company's trading platform, the system may automatically generate and retain operational records, including:

  • login and logout times;
  • IP address;
  • Device ID;
  • server connection details;
  • trading logs;
  • order logs;
  • execution logs;
  • error logs;
  • order submission history;
  • order modification history;
  • order cancellation history;
  • position closing history;
  • Expert Advisor (EA) activity logs; and
  • API connection records (where supported).

Such information may be processed for:

  • order execution;
  • dispute resolution;
  • technical support and troubleshooting;
  • fraud detection;
  • system monitoring; and
  • performance improvement.

4.5 Communications

The Company may collect information relating to communications with Clients through various channels, including:

  • email;
  • telephone;
  • Live Chat;
  • support tickets;
  • official social media channels;
  • video conferences;
  • online forms;
  • postal correspondence; and
  • meetings with Company personnel.

To maintain service quality, comply with Applicable Law, support internal audit functions, prevent fraud, and resolve disputes, the Company may monitor and record telephone conversations, online meetings, and other communications to the extent permitted by Applicable Law.

4.6 Information Received from Third Parties

The Company may receive Personal Data from third parties where necessary for the provision of services or compliance with Applicable Law, including:

  • KYC service providers;
  • document verification providers;
  • sanctions screening providers;
  • AML screening providers;
  • fraud prevention service providers;
  • payment service providers;
  • banks;
  • financial institutions;
  • Group companies;
  • Introducing Brokers (IBs) or business partners;
  • regulatory authorities;
  • government agencies; and
  • information technology service providers.

The Company will use such information only where necessary and only to the extent permitted by Applicable Law.

4.7 Automatically Collected Information

The Company may use automated technologies to collect certain information, including:

  • Cookies;
  • Web Beacons;
  • Pixels;
  • Software Development Kits (SDKs);
  • Device Fingerprinting;
  • Local Storage technologies;
  • Session Cookies; and
  • analytics tools.

Such technologies may be used to:

  • remember login sessions;
  • retain user preferences;
  • analyse website usage statistics;
  • detect unusual or suspicious activity;
  • improve website performance; and
  • support the security of the Company's systems.

Further information regarding the Company's use of Cookies and similar technologies is available in the Cookie Policy.

4.8 Verification of Information

The Company may verify the accuracy of information provided by Clients by comparing it with:

  • documents submitted by the Client;
  • publicly available databases;
  • KYC service provider databases;
  • AML screening databases;
  • sanctions lists;
  • Politically Exposed Person (PEP) databases; and
  • other reliable sources permitted under Applicable Law.

Where the Company considers that the available information is insufficient, inconsistent, unclear, or necessary to satisfy legal or regulatory obligations, it may request additional information or supporting documentation.

4.9 Updating Information

Clients are responsible for notifying the Company without undue delay of any material changes to their Personal Data, including:

  • name;
  • residential or correspondence address;
  • telephone number;
  • email address;
  • passport or other identification documents;
  • tax residency status;
  • country of residence;
  • authorised signatories;
  • Ultimate Beneficial Owners (UBOs); and
  • material changes to financial information.

The Company may require appropriate supporting documentation before updating its records.

4.10 Accuracy of Information

Clients represent and warrant that all information, documents, and other materials provided to the Company are true, accurate, complete, current, and not misleading.

Where the Company reasonably believes that information provided by a Client is false, incomplete, inaccurate, misleading, or may create legal, regulatory, compliance, or AML/CTF risks, the Company may take any action permitted under the Client Agreement, including requesting additional information, suspending or restricting services, refusing to process transactions, or taking any other measures considered appropriate under Applicable Law and the Company's internal policies.

Section 5

Purposes and Legal Bases for Processing Personal Data

5.1 General Principles

The Company processes Personal Data only to the extent necessary and proportionate for the provision of its services, the operation of its business, compliance with Applicable Law, risk management, fraud prevention, and the other purposes described in this Policy.

The Company will not process Personal Data in a manner that is incompatible with the purposes for which it was originally collected unless such processing is permitted or required by Applicable Law or supported by another lawful basis.

5.2 Pre-Contractual Activities and Service Provision

The Company may process Personal Data for activities necessary prior to entering into a contractual relationship and for the provision of its services, including:

  • receiving account applications;
  • conducting preliminary assessments and due diligence;
  • evaluating an applicant's eligibility;
  • creating client profiles;
  • opening trading accounts;
  • creating Client Area accounts;
  • assigning system access permissions; and
  • preparing and delivering the Company's services.

Processing under this section is necessary for taking steps at the Client's request prior to entering into a contract or for the performance of the contractual relationship between the Client and the Company.

5.3 Performance of the Client Agreement

The Company may process Personal Data where necessary to perform its obligations under the Client Agreement and related documents, including:

  • executing trading orders;
  • administering trading accounts;
  • processing deposits and withdrawals;
  • calculating commissions, fees, and charges;
  • processing payments;
  • monitoring transactions;
  • managing account status;
  • providing trading platform services; and
  • responding to Client instructions and requests.

Personal Data will be processed only to the extent necessary for the performance of the contractual relationship between the Client and the Company.

5.4 Know Your Customer (KYC)

The Company may process Personal Data for identity verification and customer due diligence purposes, including:

  • verifying the Client's identity;
  • verifying supporting documentation;
  • confirming age;
  • verifying residential address;
  • verifying legal status;
  • verifying authorised representatives of corporate entities;
  • verifying Ultimate Beneficial Owners (UBOs); and
  • verifying authorised signatories.

The Company may request additional information or documentation where existing information is insufficient, inconsistent, incomplete, or where there are reasonable grounds to question its accuracy or authenticity.

5.5 Compliance with AML / CTF Requirements

The Company may process Personal Data to comply with Applicable Law, regulatory obligations, and internal compliance requirements relating to:

  • Anti-Money Laundering (AML);
  • Counter-Terrorist Financing (CTF);
  • sanctions screening;
  • Politically Exposed Person (PEP) screening;
  • regulatory reporting;
  • statutory record retention requirements; and
  • cooperation with competent regulatory authorities and government agencies.

Where required by Applicable Law, the Company may suspend or decline to provide services or temporarily suspend the processing of transactions until the required verification or compliance procedures have been completed.

5.6 Risk Management

The Company may process Personal Data for risk management purposes, including:

  • assessing client risk;
  • monitoring unusual or suspicious transactions;
  • preventing fraud;
  • preventing unauthorised or improper use of accounts;
  • preventing money laundering and financial crime;
  • detecting system anomalies;
  • assessing technology and operational risks;
  • supporting business continuity planning; and
  • protecting the Company's assets, infrastructure, and information systems.

5.7 Information Security

The Company may process Personal Data to maintain the security and integrity of its systems, including:

  • preventing cyber attacks;
  • preventing unauthorised access;
  • monitoring security incidents;
  • reviewing system log files;
  • analysing abnormal events;
  • monitoring login activities;
  • detecting malware and other cybersecurity threats; and
  • restoring systems following security incidents or operational disruptions.

5.8 Client Support

The Company may process Personal Data for the purpose of providing client support, including:

  • responding to enquiries;
  • providing technical assistance;
  • handling complaints;
  • investigating operational issues;
  • communicating the outcome of requests;
  • providing account-related information;
  • providing transaction-related information; and
  • notifying Clients of changes to products, services, or contractual terms.

5.9 Communications with Clients

The Company may use a Client's contact details to:

  • send service notifications;
  • communicate account-related information;
  • notify Clients of events that may affect the use of the Company's services;
  • send security-related communications;
  • notify Clients of unusual login activity;
  • notify Clients of changes to account information;
  • verify identity; and
  • request additional information where required.

The Company will endeavour to limit communications to those necessary for the provision of services, regulatory compliance, and account security, unless the Client has separately elected to receive marketing communications.

5.10 Service Analysis and Improvement

The Company may process Personal Data to:

  • analyse website usage;
  • analyse trading platform usage;
  • develop and improve products and services;
  • improve system performance;
  • enhance the client experience;
  • investigate system errors;
  • test new systems and technologies; and
  • plan future service enhancements.

Where appropriate, the Company may use aggregated, pseudonymised, or anonymised information for analytical, statistical, research, and service improvement purposes.

5.11 Compliance with Requests from Competent Authorities

The Company may process or disclose Personal Data where necessary to comply with:

  • Applicable Law;
  • court orders;
  • search warrants;
  • subpoenas or lawful requests;
  • instructions issued by regulatory authorities;
  • requests from competent government authorities; or
  • international legal or regulatory obligations applicable to the Company.

Any disclosure will be limited to the extent necessary and permitted under Applicable Law.

5.12 Marketing Communications

The Company may use a Client's contact information to provide information about its products, services, promotions, educational materials, or events.

Where consent is required under Applicable Law, the Company will obtain the Client's consent before sending marketing communications.

Clients may opt out of marketing communications at any time using the methods made available by the Company. Opting out will not affect communications that are necessary for the provision of services, account security, regulatory compliance, or other operational purposes.

5.13 Changes to the Purpose of Processing

Where the Company intends to process Personal Data for a purpose that differs from the purposes described in this Policy, it will assess whether the new purpose is compatible with the original purpose of collection and will comply with Applicable Law.

Where required, the Company will provide appropriate notice to the Client and obtain additional consent before processing Personal Data for the new purpose.

Section 6

Use and Disclosure of Personal Data

6.1 General Principles

The Company will use and disclose Personal Data only to the extent necessary for the purposes described in this Policy, the Client Agreement, and other applicable agreements or policies, as well as for compliance with Applicable Law, regulatory obligations, and lawful requests from competent authorities.

The Company does not sell, rent, lease, or otherwise disclose Personal Data for unauthorised commercial purposes and will not disclose Personal Data to third parties except where a lawful basis exists or where such disclosure is permitted or required under this Policy or Applicable Law.

6.2 Internal Use of Personal Data

The Company may use Personal Data internally for purposes including:

  • client account administration;
  • execution of trading orders;
  • identity verification and customer due diligence;
  • transaction monitoring;
  • risk management;
  • fraud prevention;
  • internal controls;
  • internal audit;
  • information security;
  • client support;
  • product and service development;
  • complaint handling; and
  • compliance with Applicable Law and regulatory requirements.

Access to Personal Data within the Company is restricted to personnel who require such information to perform their duties and is governed by the principles of Need-to-Know and Least Privilege.

6.3 Disclosure to Group Companies

The Company may disclose Personal Data to its affiliated companies or entities under common control where necessary for:

  • group administration;
  • technology and operational support;
  • client services;
  • risk management;
  • legal and regulatory compliance;
  • internal audit;
  • external audit;
  • prevention of money laundering and financial crime; and
  • fraud prevention.

The Company will require recipients to process Personal Data only for authorised purposes and to implement appropriate technical and organisational safeguards.

6.4 Disclosure to Service Providers

The Company may disclose Personal Data to third-party service providers appointed to perform services on its behalf, including:

  • trading platform providers;
  • technology infrastructure providers;
  • cloud service providers;
  • data centre providers;
  • cybersecurity service providers;
  • KYC service providers;
  • AML and sanctions screening providers;
  • payment service providers;
  • banks and financial institutions;
  • external auditors;
  • legal advisers;
  • communication service providers;
  • document storage providers; and
  • technical support providers.

The Company undertakes appropriate due diligence when selecting service providers and requires them to comply with contractual obligations relating to confidentiality, information security, and the protection of Personal Data.

6.5 Disclosure to Regulatory Authorities and Government Agencies

The Company may disclose Personal Data where necessary to comply with Applicable Law or in response to lawful requests from competent authorities, including:

  • financial services regulators;
  • courts;
  • law enforcement authorities;
  • tax authorities;
  • anti-money laundering authorities; and
  • other governmental or regulatory bodies with lawful authority.

Any disclosure will be limited to the information reasonably necessary to satisfy the relevant legal or regulatory requirement.

6.6 Disclosure for the Prevention of Fraud and Financial Crime

The Company may use or disclose Personal Data where necessary to:

  • detect suspicious transactions;
  • prevent money laundering;
  • prevent terrorist financing;
  • prevent fraud and financial crime;
  • prevent unauthorised use of client accounts;
  • protect against cyber threats;
  • detect forged or fraudulent documentation; and
  • support lawful investigations, regulatory inquiries, or enforcement actions.

Such processing and disclosure will be carried out in accordance with Applicable Law and relevant regulatory requirements.

6.7 Disclosure in Connection with Corporate Transactions

In the event of a merger, acquisition, business transfer, sale of assets, corporate restructuring, financing transaction, or other similar corporate event, the Company may disclose or transfer Personal Data to prospective or actual counterparties, advisers, or other relevant parties to the extent reasonably necessary for the transaction.

Any recipient of such information will be required to maintain appropriate confidentiality and use Personal Data only for lawful purposes associated with the transaction.

Where required by Applicable Law, the Company will provide appropriate notice to Clients if such transaction materially affects the processing of their Personal Data.

6.8 Disclosure Based on Consent

Where Applicable Law requires the Client's consent before Personal Data may be disclosed, the Company will obtain such consent prior to the disclosure.

Clients may withdraw their consent at any time using the methods provided by the Company. Withdrawal of consent shall not affect the lawfulness of any processing carried out prior to the Company's receipt of the withdrawal request.

6.9 Anonymised and Aggregated Information

The Company may use Anonymised Data, Aggregated Data, or statistical information for purposes including research, analytics, business planning, product development, service improvement, and reporting.

Such information cannot reasonably be used to identify any individual Client.

6.10 Confidentiality of Personal Data

The Company requires its directors, officers, employees, authorised representatives, contractors, service providers, and other authorised personnel with access to Personal Data to maintain the confidentiality of such information.

Such persons must not use, disclose, or otherwise process Personal Data for any purpose other than those authorised by the Company or permitted under Applicable Law.

To strengthen the protection of Personal Data, the Company may implement additional safeguards, including:

  • confidentiality or non-disclosure agreements (NDAs);
  • mandatory data protection and information security training;
  • role-based access controls; and
  • technical and organisational security measures designed to prevent unauthorised access, disclosure, alteration, or loss of Personal Data.

6.11 Limitations on Disclosure

The Company will not disclose Personal Data to third parties unless:

  • such disclosure is necessary for the provision of the Company's services;
  • such disclosure is necessary for the performance of a contractual obligation;
  • such disclosure is required or permitted by Applicable Law;
  • the Client's consent has been obtained where required by Applicable Law; or
  • such disclosure is necessary to protect the rights, legitimate interests, or safety of the Company, its Clients, or other persons as permitted by Applicable Law.

In all cases, the Company applies the principle of Data Minimisation, disclosing only the Personal Data that is reasonably necessary for the relevant purpose and only to the extent permitted by Applicable Law or applicable contractual obligations.

Section 7

International Transfer of Personal Data

7.1 General Principles

As the Company operates internationally and provides services to Clients in multiple jurisdictions, Personal Data may be stored, accessed, processed, or disclosed in countries or jurisdictions other than the country in which the Client resides or from which the Personal Data was originally provided.

Such international transfers may be necessary to enable the Company to provide its services efficiently, comply with Applicable Law, maintain business operations, and protect the security and integrity of its information systems.

The Company will transfer Personal Data internationally only where necessary and will implement appropriate safeguards to ensure that such transfers comply with Applicable Law.

7.2 Purposes of International Data Transfers

The Company may transfer Personal Data internationally for purposes including:

  • providing trading platform services;
  • administering client accounts;
  • Know Your Customer (KYC) verification;
  • AML / CTF compliance;
  • risk management;
  • processing deposits and withdrawals;
  • information technology services;
  • cloud hosting and data storage;
  • data backup and disaster recovery;
  • technical support;
  • internal audit;
  • external audit; and
  • compliance with Applicable Law or lawful requests from competent authorities.

7.3 Overseas Data Recipients

Personal Data may be transferred or disclosed to recipients located outside the Client's country of residence, including:

  • Group companies;
  • trading platform providers;
  • cloud service providers;
  • data centre providers;
  • identity verification providers;
  • AML and sanctions screening providers;
  • payment service providers;
  • banks and financial institutions;
  • external auditors;
  • legal advisers;
  • information technology service providers;
  • cybersecurity service providers;
  • regulatory authorities; and
  • government agencies or other competent authorities.

The Company will disclose only the Personal Data reasonably necessary for the relevant purpose.

7.4 Safeguards for International Transfers

Where Personal Data is transferred internationally, the Company will take reasonable steps to ensure that recipients maintain an appropriate level of protection for Personal Data.

Such safeguards may include:

  • contractual confidentiality obligations;
  • contractual data protection obligations;
  • technical and organisational security measures;
  • access control mechanisms;
  • encryption of Personal Data during transmission where appropriate;
  • due diligence prior to engaging service providers; and
  • ongoing monitoring and periodic assessment of service providers, where appropriate.

The Company may impose additional contractual or operational requirements to ensure that Personal Data is processed in accordance with the Company's standards and Applicable Law.

7.5 Use of Cloud Service Providers

The Company may engage cloud service providers and data centre providers located in various jurisdictions to support its business operations, data storage, backup services, trading platform infrastructure, disaster recovery, and business continuity.

Such providers may operate data centres in multiple countries and may process Personal Data across different jurisdictions. The Company undertakes appropriate due diligence when selecting such providers, taking into account their security standards, reliability, and ability to protect Personal Data.

7.6 Compliance with the Laws of the Recipient Jurisdiction

Clients acknowledge that where Personal Data is transferred internationally, such information may become subject to the laws of the destination jurisdiction, which may provide a different level of data protection from that available in the Client's country of residence.

The Company will take reasonable steps to select recipients that maintain appropriate safeguards and will conduct international transfers in accordance with Applicable Law.

7.7 Disclosure Pursuant to Requests from Foreign Authorities

Where the Company receives a lawful request or order from a court, regulatory authority, law enforcement agency, or other competent governmental authority in a relevant jurisdiction, it may disclose Personal Data to the extent required or permitted by Applicable Law.

Before making such disclosure, the Company may assess the legal validity and scope of the request and, where permitted by Applicable Law, take reasonable steps to protect the rights and legitimate interests of its Clients.

7.8 Transfers Within the Group of Companies

Where Personal Data is shared among companies within the GOFX Group, such transfers will be made only for legitimate business purposes, including:

  • group administration;
  • risk management;
  • corporate governance;
  • internal audit;
  • technology and operational support;
  • regulatory compliance; and
  • client services.

The Company will require each Group company receiving Personal Data to process such information only for authorised purposes and to maintain appropriate technical and organisational safeguards.

7.9 Changes to Data Processing Locations

The Company may change the countries or locations in which Personal Data is stored or processed in order to support business expansion, infrastructure improvements, operational efficiency, or information security requirements.

Any such changes will not materially reduce the level of protection afforded to Personal Data and will be implemented in accordance with Applicable Law.

7.10 Client Responsibilities

Clients acknowledge and agree that the use of the Company's services may involve the international transfer of Personal Data as described in this Policy.

Clients are encouraged to consider the implications of such transfers before using the Company's services and may contact the Company through the designated communication channels should they require further information regarding the processing or international transfer of their Personal Data.

Section 8

Retention and Disposal of Personal Data

8.1 General Principles

The Company will retain Personal Data only for as long as is necessary to fulfil the purposes described in this Policy, perform its obligations under the Client Agreement, provide its services, comply with Applicable Law, and protect the Company's legal rights and legitimate interests.

Once Personal Data is no longer required for these purposes, the Company will securely delete, destroy, anonymise, or otherwise dispose of such information using appropriate methods consistent with Applicable Law and recognised information security practices.

8.2 Factors Used to Determine Retention Periods

In determining the appropriate retention period for Personal Data, the Company may consider various factors, including:

  • the purpose for which the Personal Data was collected;
  • the duration of the Client's relationship with the Company;
  • the age and status of the Client's account;
  • the Company's contractual obligations under the Client Agreement;
  • applicable legal and regulatory requirements;
  • statutory accounting and tax record retention obligations;
  • AML / KYC recordkeeping requirements;
  • regulatory reporting and compliance obligations;
  • the need to establish, exercise, or defend legal claims; and
  • the resolution of disputes, investigations, or legal proceedings.

Different categories of Personal Data may be retained for different periods where justified by the applicable legal, regulatory, or operational requirements.

8.3 Retention of Information for Active Clients

Throughout the Client's relationship with the Company, the Company may retain information necessary for the provision of its services, including:

  • identity information;
  • KYC documentation;
  • contact information;
  • financial information;
  • trading account information;
  • trading history;
  • deposit and withdrawal records;
  • login history;
  • communications with the Company; and
  • account opening documentation.

Such information may be updated where appropriate following notification from the Client or where the Company receives relevant new information.

8.4 Retention Following Account Closure

Following the closure of a Client's account or the termination of the business relationship, the Company may continue to retain certain Personal Data where necessary for purposes including:

  • compliance with Applicable Law;
  • compliance with regulatory obligations;
  • internal audit;
  • external audit;
  • anti-money laundering compliance;
  • fraud prevention;
  • protection of the Company's legal rights and legitimate interests;
  • dispute resolution or legal proceedings; and
  • responding to lawful requests from competent authorities.

8.5 Retention of Transaction Records

The Company may retain records relating to Client transactions, including:

  • trading orders;
  • order execution records;
  • system log files;
  • transaction confirmations;
  • deposit records;
  • withdrawal records;
  • account information changes;
  • password reset history;
  • login records; and
  • communications with client support.

Such records may be retained for audit purposes, dispute resolution, internal investigations, regulatory compliance, and the fulfilment of legal obligations.

8.6 Backup and Disaster Recovery

The Company may maintain backup copies of Personal Data and other business records to support business continuity, disaster recovery, system restoration, and information security.

Personal Data contained within backup systems will be protected using appropriate security measures and will be securely deleted, overwritten, or otherwise removed in accordance with the Company's backup management procedures once retention is no longer required.

8.7 Deletion and Disposal of Personal Data

Upon expiry of the applicable retention period, the Company will take appropriate measures to securely dispose of Personal Data, which may include:

  • deleting electronic records;
  • securely destroying paper documents;
  • securely destroying storage media;
  • anonymising Personal Data; or
  • applying other irreversible methods that prevent Personal Data from being reconstructed or used to identify an individual.

The disposal method selected will be appropriate to the nature of the Personal Data and the associated level of risk.

8.8 Suspension of Deletion

Even where a Client requests the deletion of Personal Data, the Company may be unable to erase certain information immediately where there is a lawful basis for continued retention, including where:

  • AML / CTF verification or investigations are ongoing;
  • a regulatory or governmental investigation is pending;
  • legal proceedings or dispute resolution processes are ongoing;
  • Applicable Law requires continued retention; or
  • retention is necessary to establish, exercise, or defend the Company's legal rights.

In such circumstances, the Company will restrict the processing of the relevant Personal Data to the extent necessary and will securely delete or dispose of the information once the lawful basis for retention no longer exists.

8.9 Monitoring Compliance with the Retention Policy

The Company may conduct periodic internal reviews and audits to verify that the retention, deletion, and disposal of Personal Data are carried out in accordance with this Policy, Applicable Law, and the Company's information security standards.

The findings of such reviews may be used to improve the Company's data governance practices and reduce risks associated with the processing of Personal Data.

8.10 Review of Retention Periods

The Company periodically reviews the necessity of retaining Personal Data and may revise applicable retention periods where appropriate to reflect:

  • changes in Applicable Law;
  • updated regulatory requirements;
  • changes to the Company's products or services;
  • developments in technology or cybersecurity risks; and
  • recognised industry standards and best practices relating to data protection.

Any revisions to retention periods will be implemented in accordance with the principles of necessity, proportionality, and transparency.

Section 9

Cookies and Similar Technologies

9.1 General Principles

The Company uses Cookies and similar technologies to support the operation of its website, Client Area, online platforms, and other digital services.

These technologies enable the Company to provide its services efficiently, remember user preferences, enhance security, analyse website usage, and continuously improve the quality and performance of its services.

Further information regarding the types of Cookies used, their purposes, retention periods, and available management options is set out in the Company's Cookie Policy, which forms an integral part of the Company's service documentation.

9.2 What Are Cookies?

Cookies are small text files that are stored on a user's device, such as a computer, mobile phone, or tablet, when the user visits a website.

In addition to Cookies, the Company may use other technologies serving similar purposes, including:

  • Web Beacons;
  • Pixels;
  • Local Storage;
  • Session Storage;
  • Software Development Kits (SDKs);
  • Device Identifiers; and
  • Log Files.

These technologies assist the Company in providing its services, maintaining security, and analysing the use of its digital platforms.

9.3 Purposes of Using Cookies

The Company may use Cookies and similar technologies for purposes including:

  • supporting the essential operation of the website;
  • authenticating users;
  • maintaining login sessions;
  • remembering user preferences and settings;
  • improving the user experience;
  • analysing website performance;
  • identifying and resolving system issues;
  • preventing unauthorised or improper use of the Company's services;
  • detecting potentially fraudulent activities; and
  • enhancing the security of the Company's websites and digital services.

9.4 Types of Cookies Used by the Company

The Company may use various categories of Cookies where appropriate.

(a) Strictly Necessary Cookies

These Cookies are essential for the operation of the Company's website and online services, including:

  • user authentication;
  • secure login;
  • identity verification;
  • session management; and
  • protection against Cross-Site Request Forgery (CSRF) attacks.

Without these Cookies, certain features or functions of the Company's services may not operate properly.

(b) Performance Cookies

Performance Cookies collect statistical information regarding the use of the Company's website, including:

  • the number of visitors;
  • the most frequently visited pages;
  • the duration of website visits;
  • website response times; and
  • system errors.

Such information is generally collected in an aggregated or anonymised form and is not intended to identify individual users directly.

(c) Functional Cookies

Functional Cookies enable the Company to remember user preferences and customised settings, including:

  • preferred language;
  • country or region;
  • time zone;
  • display preferences; and
  • website presentation settings.

These Cookies help provide a more personalised and efficient browsing experience.

(d) Analytics Cookies

The Company may use analytics technologies to evaluate the performance of its websites and services, including analysing user behaviour, visitor traffic, usage trends, and service performance.

Analytics services may be provided either by the Company or by authorised third-party service providers acting on the Company's behalf.

Where analytics technologies involve the processing of Personal Data, the Company will implement appropriate safeguards and ensure that such processing complies with Applicable Law and this Policy.

9.5 Third-Party Cookies

The Company's websites may incorporate services or components provided by third parties, including analytics providers, cybersecurity providers, communication service providers, or other technology partners.

Such third parties may place or access Cookies and similar technologies in accordance with their own privacy and cookie policies.

The Company does not control Cookies managed by third parties, and Clients are encouraged to review the applicable privacy and cookie policies of those providers where appropriate.

9.6 Managing Cookies

Users may manage their Cookie preferences through the settings of their web browser or device, including by:

  • accepting Cookies;
  • refusing Cookies;
  • deleting existing Cookies; or
  • receiving notifications before Cookies are stored.

Please note that disabling certain Cookies may affect the functionality, availability, or performance of parts of the Company's website or services.

9.7 Consent for Cookies

Where Applicable Law requires consent before certain categories of Cookies may be stored or accessed, the Company will obtain such consent through an appropriate mechanism, such as a Cookie banner or a Consent Management Platform (CMP).

Users may modify or withdraw their Cookie preferences at any time using the mechanisms provided by the Company.

Withdrawal of consent will not affect the lawfulness of any processing carried out prior to the withdrawal taking effect.

9.8 Changes to the Use of Cookies

The Company may introduce, remove, or modify the categories of Cookies and similar technologies used on its websites from time to time to reflect changes in its services, technological developments, or legal and regulatory requirements.

Where appropriate, the Company will update its Cookie Policy and related notices accordingly.

9.9 Relationship with the Cookie Policy

This section provides a general overview of the Company's use of Cookies and similar technologies.

More detailed information regarding the categories of Cookies used, the third-party providers involved, retention periods, legal bases, and available Cookie management options is set out in the Company's Cookie Policy, which forms an integral part of the documentation governing the Company's products and services.

Section 10

Rights of Data Subjects

10.1 General Principles

The Company respects the rights of Data Subjects and is committed to responding to requests relating to the processing of Personal Data in accordance with Applicable Law.

The rights described in this section may vary depending on the Client's country of residence, nationality, or the data protection laws applicable to the relationship between the Client and the Company.

Each request will be assessed individually, taking into account Applicable Law, the rights and freedoms of other individuals, information security considerations, and the Company's legal and regulatory obligations to retain or process Personal Data.

10.2 Right of Access

A Client may have the right to request confirmation as to whether the Company processes the Client's Personal Data and, where applicable, to obtain access to such Personal Data together with information regarding:

  • the categories of Personal Data being processed;
  • the purposes of processing;
  • the categories of recipients to whom Personal Data has been disclosed;
  • the applicable retention period, where reasonably available; and
  • the rights available to the Client in relation to such Personal Data.

The Company may refuse or restrict access where permitted by Applicable Law, including where disclosure would adversely affect the rights of others, compromise information security, interfere with regulatory obligations, or otherwise be prohibited by law.

10.3 Right to Rectification

Where a Client believes that Personal Data held by the Company is inaccurate, incomplete, or outdated, the Client may request that the Company correct or update such information.

The Company may request supporting documentation or other evidence to verify the accuracy of the requested amendments before making any changes.

10.4 Right to Erasure

Where permitted under Applicable Law, a Client may request that the Company erase Personal Data.

However, the Company may be unable to comply with such a request where continued processing or retention is necessary, including where:

  • the Personal Data remains necessary for the provision of services;
  • retention is required by Applicable Law;
  • legal proceedings or dispute resolution are ongoing;
  • AML / CTF investigations or regulatory reviews are in progress;
  • retention is necessary to establish, exercise, or defend legal claims; or
  • retention is required pursuant to a lawful request or order from a competent authority.

Where Applicable Law permits, the Company may restrict the processing of the relevant Personal Data instead of deleting it.

10.5 Right to Restrict Processing

In certain circumstances, Clients may request that the Company restrict the processing of their Personal Data, including where:

  • the accuracy of the Personal Data is being verified;
  • an objection to processing is under consideration;
  • the Personal Data is required for legal proceedings; or
  • Applicable Law otherwise provides for such restriction.

During the period of restriction, the Company may continue to retain the relevant Personal Data but will process it only where permitted by Applicable Law or where necessary for the relevant lawful purpose.

10.6 Right to Object

Where processing is based on the Company's legitimate interests or another lawful basis recognised by Applicable Law, Clients may have the right to object to such processing.

Upon receiving an objection, the Company will assess whether compelling legitimate grounds exist that override the interests, rights, and freedoms of the Client, or whether continued processing is necessary for the establishment, exercise, or defence of legal claims.

10.7 Withdrawal of Consent

Where the Company processes Personal Data on the basis of the Client's consent, the Client may withdraw that consent at any time using the methods designated by the Company.

Withdrawal of consent will not affect the lawfulness of any processing carried out before the Company received the withdrawal request.

Please note that withdrawing consent may prevent the Company from providing certain products, services, or functionalities where such processing is necessary for their operation.

10.8 Right to Data Portability

Where required by Applicable Law, Clients may have the right to receive their Personal Data in a structured, commonly used, and machine-readable format, or to request that such Personal Data be transmitted directly to another data controller where technically feasible and where doing so does not adversely affect the rights and freedoms of others.

10.9 Exercising Rights Through an Authorised Representative

A Client may appoint an authorised representative to exercise the rights described in this section on the Client's behalf.

Before processing such a request, the Company may require documentation sufficient to verify the identity of both the Client and the authorised representative, as well as evidence of the representative's authority to act on the Client's behalf.

10.10 Submitting a Request

Clients may submit requests relating to their Personal Data through the communication channels designated by the Company, including:

  • email;
  • the Client Area;
  • online request forms;
  • written correspondence; or
  • any other communication channel published by the Company.

To protect the security of Personal Data, the Company may verify the identity of the requester before responding to any request.

10.11 Response Time

The Company will consider and respond to requests relating to Personal Data within a reasonable period and in accordance with Applicable Law.

Where a request is particularly complex, requires additional verification, or involves coordination with third-party service providers or competent authorities, the Company may extend the response period where permitted by Applicable Law and will notify the Client where appropriate.

10.12 Refusal of Requests

The Company may refuse, in whole or in part, a request relating to Personal Data where:

  • Applicable Law does not require the Company to comply;
  • compliance would adversely affect the rights or freedoms of another person;
  • compliance would be contrary to Applicable Law;
  • compliance would compromise AML / CTF obligations, fraud prevention measures, cybersecurity, or the security of the Company's systems; or
  • the request is manifestly unfounded, repetitive, excessive, or otherwise unreasonable.

Where the Company refuses a request, it will provide an explanation to the extent permitted by Applicable Law.

10.13 Complaints

If a Client believes that the Company has failed to comply with Applicable Law relating to the protection of Personal Data, the Client is encouraged to contact the Company through the designated communication channels so that the matter may be reviewed and, where appropriate, resolved.

Nothing in this section limits the Client's right to lodge a complaint with a competent supervisory authority or to pursue any other remedy available under Applicable Law.

Section 11

Information Security Measures

11.1 General Principles

The Company places great importance on maintaining the confidentiality, integrity, and availability of Personal Data, as well as information relating to account opening, trading services, and the Company's business operations.

The Company implements appropriate technical, organisational, and physical security measures designed to protect Personal Data against unauthorised access, use, disclosure, alteration, loss, destruction, or other forms of unlawful or accidental processing, while reducing risks arising from cybersecurity and information security threats.

These measures are reviewed and updated periodically to reflect the nature of the Company's services, technological developments, evolving industry standards, and changes in the information security risk landscape.

11.2 Access Control

The Company implements access control measures to ensure that Personal Data is accessible only to personnel who require such access for the performance of their authorised duties.

Such measures may include:

  • individual user accounts;
  • role-based access control (RBAC);
  • Multi-Factor Authentication (MFA) where appropriate;
  • password management policies;
  • periodic review of user access rights; and
  • timely revocation of access privileges when no longer required.

Access to Personal Data is governed by the principles of Need-to-Know and Least Privilege.

11.3 Information Systems Security

The Company may implement various information security measures to protect its information systems, including:

  • intrusion prevention mechanisms;
  • security monitoring and detection systems;
  • network segmentation where appropriate;
  • malware protection;
  • vulnerability management;
  • timely installation of security patches and updates; and
  • continuous monitoring of security events.

Where appropriate, the Company may conduct periodic security assessments, vulnerability assessments, penetration testing, or other security evaluations to support effective risk management and the continuous improvement of its systems.

11.4 Protection of Data at Rest and in Transit

The Company may implement appropriate technical safeguards to protect Personal Data during storage and transmission, including:

  • encryption where appropriate;
  • secure communication channels;
  • integrity verification mechanisms;
  • backup and recovery procedures; and
  • access controls for files, databases, and storage systems.

The specific safeguards employed will depend upon the nature of the Personal Data, the associated risks, and available technologies.

11.5 Personnel Security

The Company may implement personnel-related security measures, including:

  • clearly defining responsibilities relating to data protection and information security;
  • providing information security and privacy awareness training;
  • promoting confidentiality awareness throughout the organisation;
  • requiring confidentiality obligations under employment contracts or other contractual arrangements; and
  • applying appropriate disciplinary measures where Company policies or information security requirements are violated.

11.6 Third-Party Security Management

Where the Company engages third-party service providers to process or store Personal Data, it may conduct appropriate due diligence to assess the suitability of such providers.

The Company may also require service providers to comply with contractual obligations relating to confidentiality, information security, and the protection of Personal Data.

Where appropriate, the Company may periodically review or monitor the security practices of service providers, taking into account the nature of the services provided and the associated level of risk.

11.7 Security Incident Management

The Company may maintain procedures for detecting, reporting, assessing, responding to, and managing security incidents that may affect Personal Data or the Company's information systems.

Where a security incident occurs, the Company may take appropriate actions, including:

  • containing the impact of the incident;
  • investigating its cause;
  • restoring affected systems;
  • strengthening preventive measures; and
  • notifying competent authorities, affected individuals, or other relevant parties where required by Applicable Law.

11.8 Business Continuity

The Company may implement business continuity and disaster recovery measures designed to support the continued availability of its services during unexpected events.

Such measures may include:

  • backup procedures;
  • disaster recovery processes;
  • redundant or failover systems;
  • emergency response plans; and
  • periodic testing of business continuity and disaster recovery arrangements.

These measures are intended to minimise service disruption and maintain the availability and integrity of Personal Data.

11.9 Client Responsibilities

Clients are responsible for taking reasonable precautions to protect the credentials and devices used to access the Company's services, including:

  • usernames;
  • passwords;
  • authentication codes or verification credentials;
  • devices used to access the Company's systems; and
  • communication channels used to receive authentication codes.

Clients should not disclose such information to any third party and should notify the Company without undue delay if they suspect that their login credentials have been lost, compromised, disclosed, or used without authorisation.

11.10 Review and Continuous Improvement

The Company periodically reviews and enhances its information security measures, taking into consideration:

  • technological developments;
  • changes in Applicable Law;
  • emerging cybersecurity threats;
  • internal audit findings;
  • information security risk assessments; and
  • actual security incidents and lessons learned.

These reviews are intended to ensure that the Company's information security framework remains appropriate, effective, and aligned with recognised industry practices for the protection of Personal Data.

Section 12

Contact Information, Amendments and Version Control

12.1 Contacting the Company

If a Client has any questions regarding this Privacy Policy or wishes to exercise any rights relating to Personal Data, the Client may contact the Company through the communication channels published on the Company's official website.

The Company may provide various communication channels, including:

  • email;
  • online contact forms;
  • the Client Area;
  • Customer Support; and
  • any other communication channels designated by the Company.

To protect Personal Data, the Company may request additional information or supporting documentation to verify the identity of the requester before responding to any request.

12.2 Identity Verification

To safeguard Personal Data, the Company may verify the identity of a requester before:

  • disclosing Personal Data;
  • correcting or updating Personal Data;
  • deleting Personal Data;
  • restricting the processing of Personal Data; or
  • taking any other action relating to Personal Data.

Where the Company is unable to verify the identity of the requester or reasonably believes that complying with the request may expose Personal Data to unauthorised access or otherwise create a security risk, the Company may refuse or delay processing the request until sufficient verification has been obtained.

12.3 Fees

The Company will generally process requests relating to Personal Data free of charge.

However, where a request is:

  • repetitive;
  • manifestly unfounded;
  • excessive in scope or frequency; or
  • likely to impose a disproportionate administrative burden on the Company,

the Company may charge a reasonable administrative fee or refuse to comply with the request where permitted by Applicable Law.

12.4 Interpretation of this Policy

This Privacy Policy should be read together with the following documents, where applicable:

  • Client Agreement;
  • Order Execution Policy;
  • AML / KYC Policy;
  • Risk Disclosure Statement;
  • Cookie Policy;
  • Trading Conditions; and
  • any other notices, policies, or terms published by the Company from time to time.

If any provision of this Privacy Policy conflicts with Applicable Law, that provision shall be interpreted only to the extent necessary to comply with such law, while the remaining provisions shall continue in full force and effect.

12.5 Severability

If any provision of this Privacy Policy is determined by a court or other competent authority to be invalid, unlawful, unenforceable, or ineffective, such provision shall be deemed modified or severed only to the extent necessary.

The validity and enforceability of the remaining provisions of this Privacy Policy shall not be affected.

12.6 No Waiver

Any failure or delay by the Company in exercising any right or remedy under this Privacy Policy shall not constitute a waiver of that right or remedy.

Any single or partial exercise of a right shall not prevent any further or subsequent exercise of that right or any other right available to the Company.

12.7 Amendments to this Privacy Policy

The Company reserves the right to amend, update, supplement, or replace this Privacy Policy from time to time in order to reflect, among other things:

  • changes in Applicable Law;
  • changes to the Company's products or services;
  • technological developments;
  • operational or business process changes;
  • regulatory guidance or supervisory requirements; and
  • information security or risk management considerations.

The revised Privacy Policy will be published on the Company's website or through other communication channels considered appropriate by the Company.

Where required by Applicable Law or where the amendments materially affect the processing of Personal Data, the Company may provide additional notice to Clients before the revised Privacy Policy becomes effective.

Continued use of the Company's products or services after the effective date of the revised Privacy Policy may constitute acceptance of the updated Privacy Policy, to the extent permitted by Applicable Law.

12.8 Effective Date

This Privacy Policy shall become effective on the date specified by the Company and supersedes any previous version of the Company's Privacy Policy, where applicable.

12.9 Language

This Privacy Policy may be published in multiple languages for the convenience of Clients.

In the event of any inconsistency or discrepancy between different language versions, the English version shall prevail unless otherwise required by Applicable Law.

The website www.gofx.com is owned and operated by GOFX LIMITED, which is responsible for its management and operations. The information on this website may only be reproduced with the explicit written consent of GOFX LIMITED.

GOFX LIMITED is a Business Company registered in St. Vincent and the Grenadines with Registration Number 25865 BC 2020, authorized by the St. Vincent and the Grenadines Financial Services Authority (SVGFSA). The registered office of GOFX LIMITED is located at Beachmont Business Centre, 330, Kingstown, Saint Vincent and the Grenadines.

GOFX LIMITED has its physical address at: Kavalas 24, Flat 301, 2044 Strovolos, Nicosia, Cyprus.

GOFX LIMITED strictly does not provide services to individuals or entities who are residents or located in the following jurisdictions: the United States of America, Canada, Japan, South Korea, the United Kingdom, member countries of the European Union, Iran, North Korea, Syria, Sudan, Cuba, Russia, Thailand, Belarus, Myanmar, Afghanistan, Yemen, Zimbabwe, Mauritius, Haiti, Suriname, Puerto Rico, Brazil, the Occupied Area of Cyprus, Hong Kong, and any other jurisdictions that are subject to international sanctions, restrictions, or embargoes imposed by the United Nations, the European Union, the United States of America, or other competent authorities.

Risk Warning :

Our services involve complex derivative products known as Contracts for Difference (CFDs), which are traded over-the-counter (OTC). These products carry a high risk of rapid loss of invested capital due to the use of leverage and may not be suitable for all investors.

CFDs on major currency pairs such as XAU/USD, EUR/USD, GBP/USD, USD/JPY, USD/CHF, USD/CAD, AUD/USD, and NZD/USD are highly volatile and can result in substantial financial losses.

Under no circumstances shall GOFX LIMITED be held liable to any individual or entity for any loss of capital, whether partial or total, arising from or related to any investment activities.

Trading CFDs involves significant risk, and you may lose all of your invested capital. Please ensure you fully understand the risks involved before engaging in any trading activities.

Disclaimer :

Communication between you and this website is considered personal and voluntary on the part of the individual accessing the site. Please note that this website and its content do not constitute an invitation to enter into any contract and/or purchase financial services or products of GOFX LIMITED.

Official contact channels of GOFX LIMITED :

  • Legal & Compliance Center : legal@gofx.com
  • Abuse Report Center : abuse@gofx.com
  • Contact Center : contact@gofx.com
  • International Phone : +357 22 250 352
GoFX

Global Multi-Asset CFD Trading Platform

Access global markets through a single platform.
Gold · Indices · Energy · Currency CFDs

Open a Free Account

Products

  • Gold & Precious Metals
  • Currency CFDs
  • Indices
  • Energy

Company

  • Account Types
  • Platforms
  • About Us
  • Contact Us

Legal

  • Privacy Policy
  • Client Agreement
  • Order Execution Policy
  • Risk Disclosure

Trading Platforms

  • MetaTrader 4 & MetaTrader 5 for Windows
  • MetaTrader 4 & MetaTrader 5 for iPhone
  • MetaTrader 4 & MetaTrader 5 for Android

© 2026 GOFX LIMITED. All rights reserved.