01Who is responsible for your data
Apex Markets Ltd, registered number 148271, of Arch. Makariou III 205, 3030 Limassol, Republic of Cyprus, is the controller of the personal data described in this policy. Our data protection officer can be reached at privacy@apex.markets, or by post at the registered office marked for their attention.
This policy covers our website, our trading platform, our client portal and our communications with you. It does not cover third-party websites we link to, or the practices of an introducing broker who referred you — they are a separate controller for the data you give them directly.
02What we collect
Data you give us
- Identity and contact data: name, date of birth, nationality, email, telephone number, residential address.
- Verification data: images of identity documents, proof of address, a selfie taken with your document, and where required, evidence of source of funds or wealth.
- Financial and suitability data: employment status, income band, net worth band, trading experience and knowledge answers given during onboarding.
- Payment data: the masked card number, bank account details or crypto wallet address you use to fund and withdraw.
- Correspondence: the content of support tickets, contact forms, emails and recorded telephone calls with the dealing desk.
Data generated by your use of our services
- Trading data: orders, positions, deals, balances, margin levels and statements.
- Technical data: IP address, device and browser characteristics, session timestamps and the pages you visit.
- Security data: sign-in events, including the IP address, user agent and country from which they originated, and two-factor authentication events.
Data from third parties
We receive data from identity verification and sanctions-screening providers, from payment processors and acquiring banks (including chargeback notices), from introducing brokers and affiliates who refer you, and from publicly available sources such as sanctions and politically-exposed-person lists.
We do not ask for, and you should never send us, your account password, the full unmasked number of a payment card, or a card security code. No member of our staff will ever ask you for them.
03Why we use it, and on what legal basis
| Purpose | Lawful basis |
|---|---|
| Opening and operating your account, executing your orders, settling payments | Performance of a contract |
| Identity verification, sanctions screening, anti-money-laundering and transaction monitoring | Legal obligation |
| Appropriateness assessment and client categorisation | Legal obligation |
| Record keeping, trade and transaction reporting, responding to a regulator | Legal obligation |
| Fraud prevention, platform security, abuse detection and recovering debts | Legitimate interests |
| Improving the platform, aggregate analytics and service quality monitoring | Legitimate interests |
| Marketing about products and services you do not already hold | Consent, withdrawable at any time |
| Non-essential cookies and third-party analytics | Consent, withdrawable at any time |
Where we rely on legitimate interests we have balanced those interests against your rights and freedoms, and we will provide the balancing assessment on request. Where we rely on consent you may withdraw it at any time without affecting the lawfulness of what we did before you withdrew it.
Telephone calls with the dealing desk are recorded, and those recordings are retained, because we are required to record communications that relate to the reception, transmission and execution of orders. You will be told at the start of the call.
04Automated decisions
Two of our processes are partly automated. Identity verification runs an automated document and biometric check before a human reviewer sees the result, and payments are screened automatically against fraud and sanctions rules. An automated check can result in your account being restricted pending review.
No account is permanently closed, and no verification is finally refused, on the basis of an automated decision alone: a member of the compliance team reviews every negative outcome. You have the right to obtain human intervention, to express your point of view and to contest a decision — write to privacy@apex.markets.
06International transfers
Our primary infrastructure is hosted within the European Economic Area. Some of our processors operate from the United Kingdom, Switzerland, the United States and Singapore. Where data leaves the EEA we rely on an adequacy decision where one exists, and otherwise on standard contractual clauses supplemented by technical measures including encryption in transit and at rest, and access controls limited to named personnel.
You may request a copy of the safeguards applicable to a specific transfer by writing to privacy@apex.markets.
07How long we keep it
| Category | Retention period |
|---|---|
| Account, identity and verification records | Five years after the account is closed, extendable to seven where a regulator requires it |
| Trading records, orders, deals and statements | Seven years from the date of the transaction |
| Payment and anti-money-laundering records | Five years from the transaction or the end of the relationship, whichever is later |
| Recorded telephone calls with the dealing desk | Five years, or seven where required by a regulator |
| Support tickets and correspondence | Three years from resolution |
| Website analytics and technical logs | Thirteen months |
| Marketing consent records | Until consent is withdrawn, plus two years to evidence the withdrawal |
At the end of a retention period data is deleted or irreversibly anonymised. Where a legal hold applies — an ongoing investigation, a complaint or litigation — the relevant records are retained until the matter is concluded.
08Your rights
- (a)Access — obtain confirmation of whether we hold data about you, and a copy of it.
- (b)Rectification — have inaccurate data corrected and incomplete data completed.
- (c)Erasure — have data deleted where we no longer have a lawful reason to hold it. Regulatory record-keeping obligations mean we usually cannot erase trading and verification records before their retention period expires.
- (d)Restriction — require us to stop processing data while a dispute about its accuracy or our basis for holding it is resolved.
- (e)Portability — receive the data you gave us in a structured, machine-readable format, or have it sent to another controller.
- (f)Objection — object to processing based on legitimate interests, and object at any time to direct marketing, which we will stop immediately and unconditionally.
- (g)Withdraw consent — where we rely on it, at any time, from the account settings or by writing to us.
Write to privacy@apex.markets to exercise any of these. We respond within one month, extendable by two further months for complex requests, and we will tell you if we need the extension. There is no charge unless a request is manifestly unfounded or excessive. We may ask you to verify your identity before we act.
If you are unhappy with how we have handled your data you may complain to the data protection authority in your country of residence or in Cyprus. We would rather you told us first, but you are not required to.
10How we protect it
- Passwords are stored as bcrypt hashes and are never logged, emailed or recoverable in plain text.
- Sessions are signed tokens backed by a revocable server-side record, so a session can be terminated centrally.
- Two-factor authentication using time-based one-time passwords is available on sign-in and can be required for withdrawals.
- Staff access is governed by a role-based permission matrix, enforced on the server for every action, and every staff access to or change of client data writes an immutable audit record.
- Data is encrypted in transit and at rest; verification documents are stored in a separate access-controlled vault.
No system is perfectly secure. If we become aware of a breach that is likely to result in a risk to your rights and freedoms, we will notify the supervisory authority within 72 hours and tell you directly without undue delay where the risk is high.
11Changes to this policy
We update this policy when our processing changes. The effective date and version at the top of this page always reflect the current text, and we notify account holders by email of any change that materially affects how their data is used, at least ten business days before it takes effect.
Questions about anything in this policy should go to privacy@apex.markets. We answer them.