Legal
Privacy policy.
How CryptoTradePrime collects, uses, and safeguards your personal data — including cookie policies (advertising and security), confidentiality safeguards, and your rights as a client across the jurisdictions in which we operate.
Effective April 1, 2026
01 — Overview
What this policy covers.
This Privacy Policy explains how CryptoTradePrime (“CryptoTradePrime”, “we”, “us”) collects, uses, stores, and discloses personal information when you access our products, websites, and institutional services. It applies globally and complements the regional supplements we publish for specific jurisdictions such as the EU (GDPR), the United Kingdom (UK GDPR), California (CCPA/CPRA), Singapore (PDPA), and Switzerland (revFADP).
02 — What we collect
Data gathered at account opening and during trading.
We collect identity data (name, date of birth, government identifiers), contact data (email, phone), financial data (source-of-funds disclosures, transaction history), device and telemetry data (IP, device fingerprint, fraud signals), and support interactions. We do not collect private keys or the content of hardware-signed transactions.
- Identity & KYC documents
- Banking, wallet and blockchain-address information
- Trading, deposit and withdrawal history
- Communications with our support and desk teams
- Cookies, session analytics and device fingerprints
- Sanctions and adverse-media screening data
03 — How we use it
Lawful basis for processing.
We process personal data to provide our services, fulfill regulatory obligations (AML/CFT, sanctions screening, tax reporting), investigate fraud, improve security, and — with your explicit consent — tailor product communications. We do not sell your data. We rely on the following lawful bases depending on jurisdiction: contractual necessity, legal obligation, legitimate interest, and consent.
04 — Sharing & disclosure
Who sees your data, and why.
We share personal information with vetted service providers (cloud hosting, KYC vendors, payment rails), affiliates within the CryptoTradePrime group, auditors, professional advisors, and, where required by law, with regulators and law-enforcement bodies. Every vendor is bound by strict data-processing agreements.
- KYC and sanctions-screening vendors
- Cloud and infrastructure providers (encrypted, region-locked)
- Payment rails and banking partners
- Regulatory authorities when legally compelled
- Internal auditors and external legal counsel
05 — International transfers
Where your data travels.
Where personal data crosses borders, we rely on EU Standard Contractual Clauses, UK International Data Transfer Addenda, or equivalent safeguards recognised in your jurisdiction. We maintain a Transfer Impact Assessment for every destination country.
06 — Retention
How long we keep records.
Retention follows the longer of statutory minimums and six years post-closure. Trade-reconstruction records are kept for at least seven years. Anonymous analytics data may be retained indefinitely for product improvement.
07 — Your rights
Access, correction, erasure and portability.
Depending on your jurisdiction, you may request access to the personal data we hold, correct inaccuracies, request portability in a machine-readable format, or ask us to restrict processing. Some rights may be limited where we have overriding legal obligations (for example, continued AML record-keeping).
08 — Cookies
Strictly necessary, analytics and marketing.
Strictly-necessary cookies keep the platform functional and are set without consent. Analytics and marketing cookies are opt-in through the consent banner. You can revisit your preferences at any time through the footer link titled “Cookie Preferences”.
09 — Children
CryptoTradePrime is not directed at minors.
Our products are not intended for use by anyone under the age of 18. We do not knowingly collect personal data from minors. If we become aware that a minor has provided us with personal data, we will take reasonable steps to delete it.
10 — Contact
Reach the Data Protection Office.
Questions about this policy, data-subject requests, or incident reports can be directed to our Data Protection Office through the Contact page. We respond to verified requests within 30 days.
“Privacy is the default, not a feature you upgrade to.”
— The CryptoTradePrime Data Protection Office
For data-subject requests or incident reports, contact our Data Protection Office.
Contact the DPO