Cookie Policy
Information about cookies, similar technologies, consent choices, tracking controls, and how we protect your privacy.
About This Policy
This Cookie Policy explains how GTC Global Trading Ltd uses cookies and similar technologies on the GTCFX /en-intl website and on another digital service that expressly links to this Policy. It describes the choices available to visitors and clients and must be read with the Privacy Policy.
The policy text, cookie-consent interface and actual configuration must remain consistent. Publishing this Policy does not by itself make a website compliant if a non-essential analytics or advertising technology loads before a valid choice, if a rejection is ineffective, or if the live cookie register is incomplete.
Strictly necessary technologies may operate without consent only where an applicable legal exception permits it and the technology is genuinely necessary for the requested service or its security.
Where consent is required, analytics, advertising, social-media and other non-essential technologies must remain inactive until the user makes an affirmative choice.
Rejecting non-essential technologies must be as easy as accepting them, and withdrawing consent must be as easy as giving it.
Cookies must never contain a plaintext password, PIN, one-time authentication code, full card-security code, recovery phrase or digital-wallet private key.
Browser settings are an additional control, not a substitute for a website-level Cookie Settings tool where applicable requirements require prior consent.
Company and Scope
Legal name: GTC Global Trading Ltd (the "Company", "we", "us" or "our")
Company number: 16283
Legal form and jurisdiction: A private limited company incorporated under the laws of the Autonomous Island of Anjouan, Union of the Comoros
Licence: Licence no. L16283/GTC issued by the Anjouan Offshore Finance Authority ("AOFA")
Registered address: Boulevard de Coalancanthe, Mutsamudu, Anjouan, Union of the Comoros
Website: https\://www\.gtcfx.com/en-intl/
This Policy applies to the Company's operation of the GTCFX /en-intl website. "GTCFX" is a brand reference and is not a separate legal person. A cookie, tag, analytics provider or other technology vendor does not become the visitor's or client's contracting entity merely because it supports the website.
This Policy concerns storage and access technologies and the related information flows. The Privacy Policy explains the wider processing of personal data, legal bases, retention, international transfers and rights. The Client Agreement identifies the contracting entity for financial services. Neither a group company nor a service provider may rely on this Policy as authority for processing outside its stated scope.
In this Policy, "Applicable Requirements" means the privacy, electronic-communications, consumer-protection and other laws, regulations, binding authority directions and licence conditions applicable to the Company, visitor, client, technology or processing activity. AOFA licensing does not replace data-protection or cookie obligations that may apply where a website is offered or accessed.
Core Rules and Consent Standard
Where Applicable Requirements require consent, the Company must obtain a freely given, specific, informed and unambiguous affirmative choice before activating a non-essential technology. Continuing to browse, silence, inactivity, a pre-selected option or a browser's default acceptance setting is not treated as consent.
The first layer of the consent interface should provide clear and similarly prominent options to accept all non-essential technologies, reject them, or open granular settings. It must not use misleading colours, repeated prompts, unnecessary clicks, obstructive design or another practice that makes refusal materially harder than acceptance.
Consent is requested by purpose or category at an appropriate level of detail. Refusing one category must not activate a differently labelled technology that performs substantially the same purpose. Consent for analytics is not consent for targeted advertising, and consent for one provider is not automatically consent for every other provider.
The Company records the choice, date, consent-policy version, applicable categories and a suitable pseudonymous identifier for accountability. It does not keep consent indefinitely. Consent should be requested again where purposes or providers materially change, the previous choice can no longer be demonstrated, or a reasonable renewal period has elapsed.
Where consent is not legally required, the Company still applies transparency, data-minimisation, security and purpose-limitation controls and provides an objection or opt-out where Applicable Requirements require it. Consent under this Policy does not waive a mandatory privacy or consumer right.
Strictly Necessary, Security and Fraud Controls
Strictly necessary technologies support a service expressly requested by the user or a function without which the relevant website or authenticated service cannot be delivered securely. They may include load balancing, network security, authentication, session management, consent-preference storage and controls necessary to protect an account or transaction.
Authentication cookies should contain a random or otherwise protected session token rather than the user's password. Where technically appropriate, security attributes such as Secure, HttpOnly and SameSite are applied, session identifiers are rotated, access is restricted and tokens expire after a proportionate period.
Fraud, account-takeover, sanctions, abuse and financial-crime controls may use proportionate device, browser, network, location, account-linkage or behavioural indicators. However, describing a technology as useful for security, fraud prevention or AML does not automatically make it strictly necessary. Each technology must be assessed against the legal exception and its actual technical function.
A security purpose must not be used to activate advertising, cross-site profiling or unrelated analytics without the choice required by Applicable Requirements. Where a necessary control cannot operate, the relevant secure account feature may be unavailable, but refusing non-essential technologies should not prevent access to general public content or require a client to close an account.
No cookie or similar technology should contain a plaintext account password, online-banking password, PIN, one-time authentication code, full CVV or CVC, recovery phrase, private key or another secret that would permit account or payment compromise.
Functionality Technologies
Functionality technologies remember choices or provide optional features, such as language, region, interface preferences, accessibility settings, chat availability or media features. The exact classification depends on whether the user requested the feature and whether the technology is necessary to deliver it.
Where consent is required, functionality technologies remain disabled until selected. Refusal may remove personalisation or require a user to repeat a preference, but it should not be described as disabling the entire website unless that result is technically accurate and necessary.
A feature supplied by a third party may allow that provider to receive device, page, account-state or interaction information. The Company must assess the provider, configure the feature to minimise data and disclose any material third-party role before activation.
Analytics and Performance Technologies
Analytics and performance technologies help measure visits, pages, navigation paths, referral sources, errors, latency, interaction patterns and campaign or content effectiveness. They may use persistent identifiers and may allow a provider to recognise a browser or device across sessions.
Where Applicable Requirements require consent, these technologies must not load, write identifiers, read existing identifiers or send analytics events before consent. Merely configuring a provider for aggregated reporting, IP truncation, consent mode or reduced data does not automatically remove the consent requirement.
The Company should collect only the events and parameters necessary for documented measurement purposes. Sensitive account, KYC, payment or trading information must not be placed in analytics URLs, page titles, event labels or custom parameters unless a documented lawful basis, necessity assessment and appropriate safeguards support the processing.
Where practical, analytics configurations should reduce identifier use, exclude authenticated or sensitive areas, limit retention, restrict advertising features and prevent a provider from using Company data for unrelated purposes.
Third-Party and Embedded Services
A third-party provider may supply analytics, advertising, social-media, reviews, market-content, chat, security or other embedded functionality. Depending on the service and law, the provider may act as a processor, independent controller, joint controller or another legally defined role. That role must be assessed and accurately reflected in the Privacy Policy, contracts and provider disclosures.
An embedded service should be blocked or replaced with a privacy-preserving placeholder until the required choice is made where it can set or access non-essential identifiers. A user's deliberate request to open a video, chat, review or market-content feature may be treated separately only where Applicable Requirements permit and the user receives clear information.
Third-party privacy notices may explain the provider's own processing, but they do not replace the Company's duty to give clear information about the Company's purposes and choices. The Company remains responsible for selecting and configuring vendors, limiting access, maintaining contracts and reviewing changes within its control.
Tag-management and server-side tools do not create an exemption. The Company must control the tags, events and destinations they activate and prevent an unapproved tag from bypassing the user's recorded choice.
Current Technology Providers
Depending on the page, jurisdiction, consent choice and feature used, the website may use technologies supplied by the following providers. The live Cookie Settings register must identify the technologies actually configured at the time of a visit and is authoritative for the specific cookie or storage name, domain, category and duration.
Google: Google Tag Manager, Google Analytics and Google Ads measurement or conversion services for tag control, analytics and advertising attribution.
Meta: Meta Pixel or related event technologies for advertising measurement, attribution and audience controls.
TikTok: TikTok Pixel or related event technologies for advertising measurement, attribution and audience controls.
Microsoft: Microsoft Clarity for website-performance, interaction and usability analysis.
Umami: Website analytics used to measure traffic and content performance according to its configured mode.
Trustpilot: Review, invitation or trust-content functionality that may receive page, device or interaction data.
MQL5 or MetaQuotes-related content: Market-platform or embedded content functionality where used on a relevant page.
Website chat provider: Chat and support functionality that may receive device, page, conversation and contact information when the feature is used.
A provider name in this section does not authorise every service offered by that provider or guarantee that the provider is active on every page. Before adding a provider or materially changing its purpose, the Company must update the technical configuration, consent category, live register, vendor assessment and privacy disclosures as necessary.
Data Collected, Sharing and International Transfers
Depending on the technology and choice, information may include IP address, browser and device type, operating system, language, approximate location, referrer, page URL, date and time, interaction or error events, advertising or pseudonymous identifiers, consent status and limited account-state information. The Company must not describe pseudonymous data as anonymous where re-identification or linkage remains reasonably possible.
Information may be disclosed to the technology providers identified in the live register, hosting and security suppliers, professional advisers, group service companies and competent authorities where there is an appropriate lawful and necessary basis. A disclosure is limited to the purpose and protected through access controls, contractual restrictions and other appropriate safeguards.
Providers may process information in countries other than the visitor's location or Anjouan. The Privacy Policy explains the applicable international-transfer safeguards and rights. A provider's global infrastructure does not remove the Company's responsibility to assess the transfer and provide required information.
The Company does not authorise a provider to use account, KYC, payment or trading data for its independent advertising merely because the provider also supplies analytics or advertising technology. Provider use beyond the Company's documented instructions must have a separate lawful basis and transparent disclosure.
Security, Privacy Rights and Browser Signals
The Company uses proportionate technical and organisational measures for cookie and tracking data, including access restrictions, secure transmission, vendor controls, data minimisation, retention limits and monitoring. No internet or browser technology is completely secure, and users should protect their devices, browsers and account credentials.
Privacy rights concerning personal data collected through these technologies are described in the Privacy Policy. Depending on Applicable Requirements, rights may include access, correction, deletion, restriction, objection, portability, withdrawal of consent and a right to complain to a competent authority. These rights are subject to lawful conditions and exceptions.
Browser-level Do Not Track signals are not interpreted consistently across the industry. Where an applicable law requires recognition of the Global Privacy Control or another legally effective preference signal, the Company will apply the required response. Users should use Cookie Settings for a direct website-level choice and should not assume that every browser signal controls every technology.
Questions or requests should not include passwords, PINs, one-time authentication codes, private keys or unmasked card-security data. The Company may need reasonable information to verify an authenticated privacy request without collecting excessive information.
Changes and Contact
The Company may update this Policy to reflect changes in law, technology, providers, website functions or processing. The revised version will display its last-updated date. Where a change materially affects a consented purpose or is otherwise significant, the Company will provide an appropriate notice and obtain a new choice where required.
A policy update cannot retroactively validate a non-essential technology that was activated without a required consent. Historical configuration, consent and remediation records should be preserved for accountability for the appropriate period.
Questions about cookies, similar technologies or the operation of Cookie Settings may be sent to support\@gtcfx.com. Requests concerning personal data should follow the process in the Privacy Policy. Users should confirm that a communication channel is genuine before providing account information.
The English version controls if a translation is inconsistent, to the extent permitted by Applicable Requirements. Mandatory rights and remedies remain unaffected.
Contact support for cookie or privacy questions
If you have questions about cookies, similar technologies, consent choices, or privacy settings, please contact the support team.
