Data Protection & Privacy

PRIVACY POLICY

Your privacy is very important to us, and we make it our priority to safeguard and secure personal data and confidential information relating to individuals.

About This Policy

This Privacy Policy explains how GTC Global Trading Ltd collects, uses, discloses, protects and retains personal data in connection with the GTCFX /en-intl website, account-opening process, client portal, trading services, applications and communications that expressly link to this Policy. It applies to visitors, applicants, current and former clients, authorized representatives, beneficial owners, directors, partners, introducers and other individuals whose personal data is processed in these activities. It must be read with the applicable Client Agreement, KYC and Compliance Policy, Cookie Policy and other notices presented when data is collected.

It applies to visitors, applicants, current and former clients, authorized representatives, beneficial owners, directors, partners, introducers and other individuals whose personal data is processed in these activities.

GTC Global Trading Ltd is the controller for processing described in this Policy when it determines why and how personal data is used for the /en-intl service. GTCFX is a brand and is not a separate legal person.

Identity, financial, transaction, device, communications and compliance data may be required to open and operate an account, process payments, prevent fraud and meet legal or regulatory duties.

Facial images and derived biometric information may be processed only for identity verification, liveness testing, fraud prevention and compliance; they are not used for advertising or unrelated profiling.

Consent is used only where it is the appropriate legal basis. Withdrawing consent does not invalidate earlier processing and does not prevent processing required for a contract, legal duty, claim, security or legitimate interest.

Personal data may be processed in countries other than the country in which it was collected, subject to a lawful transfer mechanism and appropriate safeguards where required.

Privacy rights are not absolute. In particular, deletion or access may be limited by anti-money laundering, sanctions, fraud-prevention, legal-hold, confidentiality or reporting requirements.

01

COMPANY, CONTROLLER AND SCOPE

GTC Global Trading Ltd is a private limited company incorporated under the laws of the Autonomous Island of Anjouan, Union of the Comoros, with company number 16283. GTC Global Trading Ltd holds AOFA licence number L16283/GTC issued by the Anjouan Offshore Finance Authority. Its registered address is Boulevard de Coalancanthe, Mutsamudu, Anjouan, Union of the Comoros.

For processing described in this Policy, references to the “Company”, “we”, “us” or “our” mean GTC Global Trading Ltd. “GTCFX” refers to the brand under which the services are presented and is not a separate controller or contracting party.

The Company is the controller when it determines the purposes and means of processing for the /en-intl website and the accounts and services it provides. A service provider that processes data only on documented instructions normally acts as a processor. A bank, payment provider, identity-verification provider, trading-platform provider, regulator or professional adviser may act as a separate controller where it determines its own legal purposes. Its own privacy notice will then apply to that processing.

Other companies using the GTCFX brand are separate legal entities. They are not automatically controllers of data covered by this Policy. If another entity independently determines why and how it processes personal data, it must identify itself and provide its own privacy information. Group affiliation alone does not permit unrestricted access or sharing.

This Policy does not change the contracting entity stated in the applicable Client Agreement. If a collection point is operated by another entity or for another service, the notice shown at that collection point must identify the relevant controller before data is submitted.

“Applicable Data Protection Law” means the privacy, electronic communications, cybersecurity and data-protection requirements that apply to a particular processing activity, individual or territory. Rights and obligations in this Policy apply to the extent required by those laws, and the Company may provide additional local notices where necessary.

Incorporation or licensing in Anjouan does not, by itself, exclude a privacy law with extraterritorial scope. Before deliberately offering services to individuals in, or monitoring individuals located in, a territory that requires a local representative, data protection officer, registration or supplemental notice, the Company will determine whether that requirement applies and complete it before the relevant processing begins. Any required representative or officer details will be published in the applicable local notice and at the relevant collection point.

02

DATA PROTECTION PRINCIPLES

The Company aims to process personal data lawfully, fairly and transparently; collect it for specified and legitimate purposes; limit it to what is reasonably necessary; keep it accurate; retain it no longer than required; and protect it against unauthorized or unlawful processing, accidental loss, destruction or damage.

Access is limited according to role and business need. New uses, material changes in purpose, new recipients and new technologies are assessed before deployment. Where a proposed use is incompatible with the original purpose, the Company will identify a new lawful basis, provide additional notice and obtain consent where required before that use begins.

No privacy notice can guarantee absolute security or eliminate every risk. The Company remains responsible for applying proportionate technical and organizational controls and does not rely on a disclaimer to avoid duties that cannot lawfully be excluded.

03

PERSONAL DATA WE COLLECT

The data collected depends on the relationship, product, device, jurisdiction and stage of onboarding. The Company may collect the following categories when relevant and proportionate:

Identity and contact data: name, title, date and place of birth, nationality or citizenship, residential and mailing address, email address, telephone number, signature and account identifiers.

Verification data: passport, national identity card, driving licence, tax or national identification number, document images, proof of address, document authenticity results, liveness results and related verification metadata.

Facial and biometric data: facial images and, where enabled, a mathematical template, confidence score or other derived data used to compare a live image with an identity document or test liveness.

Financial and economic data: bank or payment-account details, payment method, wallet information, income, wealth, assets, liabilities, source of funds, source of wealth, tax residence and supporting documents.

Professional and business data: occupation, employer, business activities, ownership and control, directorships, authorized representatives, beneficial owners, partners and introducer relationships.

Suitability and experience data: knowledge and experience, investment objectives, risk tolerance, product preferences and information used for an appropriateness, eligibility or risk assessment where applicable.

Account and transaction data: applications, account status, balances, deposits, withdrawals, orders, positions, trading history, performance, instruments used, fees, rebates, referral attribution and transaction identifiers.

Compliance and risk data: sanctions and politically exposed person status, adverse-media results, fraud indicators, risk classifications, screening matches, payment verification, investigations and, where lawfully processed, information relating to alleged or actual offences.

Communications data: emails, webchat, telephone calls, complaints, support requests, survey responses, meeting notes and records of instructions, consents and notices.

Technical and usage data: IP address, device and browser type, operating system, language, time zone, general location inferred from IP, login and security events, referral source, pages viewed, clicks, session identifiers and diagnostic data.

Marketing and preference data: communication choices, campaign interaction, event attendance, lead source, advertising identifiers and suppression records.

Premises data: visitor records and CCTV images where an individual visits a Company-controlled location and clear local notice is provided.

The Company does not ask for or store a client’s online-banking password, one-time password, card PIN, card verification value, digital-asset private key or recovery phrase. Clients must not send these secrets in an application, email, chat or support message. Full card credentials should be entered only into the secure interface of the relevant payment provider.

04

SOURCES OF PERSONAL DATA

The Company collects personal data directly from an individual when a website is visited, a form is completed, an account is opened, a document is uploaded, a transaction is made, a communication is sent or a service is used.

Data may also be obtained from an authorized representative, employer, director, beneficial owner, introducing broker or other business partner; from banks, card networks, payment or wallet providers; from identity-verification, fraud-prevention and cybersecurity providers; from trading-platform and hosting providers; from public registers, company records, courts, regulators, sanctions lists, politically exposed person databases and credible public sources; and from other group companies only where a lawful and documented sharing basis exists.

Where data is not obtained from the individual, the Company will provide information about the source and relevant categories within the period and subject to the exceptions required by Applicable Data Protection Law. A person who provides information about another individual must have authority to do so and should direct that individual to this Policy.

05

PURPOSES AND LAWFUL BASES

The Company identifies a lawful basis for each purpose. A basis is not selected merely because it is convenient, and consent is not bundled into acceptance of a contract where the processing is not genuinely optional.

Account application and contract. To assess an application, create and administer an account, authenticate the user, provide the requested platform and services, execute instructions, manage deposits and withdrawals, deliver service communications and enforce the Client Agreement. The basis is taking steps at the individual’s request before a contract and performing the contract. Some verification and records are also required by law.

Legal and regulatory compliance. To perform KYC and customer due diligence, screen sanctions and politically exposed persons, monitor transactions, keep records, respond to lawful requests, make required reports, manage tax duties and prevent prohibited activity. The basis is compliance with applicable legal or regulatory obligations and, where an obligation does not directly apply but the control is necessary and proportionate, legitimate interests in maintaining a lawful and secure financial service.

Security, fraud and abuse prevention. To protect accounts, systems, staff and clients; detect unauthorized access, identity theft, payment abuse and cyber threats; investigate incidents; and preserve evidence. The basis is legal obligation where applicable and legitimate interests in security, fraud prevention and service integrity.

Service operation and improvement. To troubleshoot, measure performance, test changes, maintain business continuity, conduct quality assurance and improve products and support. The basis is contract where necessary to provide the service and otherwise legitimate interests, using aggregated or de-identified data where reasonably possible.

Complaints, disputes and claims. To investigate and respond to enquiries and complaints, establish facts, obtain advice, bring or defend legal claims and comply with dispute-resolution duties. The basis is legal obligation, contract and legitimate interests in resolving disputes and protecting legal rights.

Corporate administration. To conduct audits, risk management, accounting, governance, restructuring and due diligence for a prospective transaction. The basis is legal obligation and legitimate interests, with access and use limited to what is necessary.

Marketing and events. To send or personalize permitted communications, manage subscriptions and measure campaigns. The basis is consent where required by electronic-marketing or cookie law and otherwise legitimate interests for proportionate communications that an individual can reasonably expect. The individual can opt out at any time.

Optional features. To provide a feature that is genuinely optional and not necessary for the service, where the relevant notice asks for a specific choice. The basis is consent, which may be withdrawn as easily as it was given.

Where legitimate interests are relied upon, the Company considers the purpose, necessity and impact on the individual, including reasonable expectations and available safeguards. The Company will not rely on legitimate interests where the individual’s rights and interests override the proposed use.

06

KYC, AML, SANCTIONS AND FRAUD PREVENTION

The Company uses identity, ownership, financial, transaction, device and risk data to perform onboarding and ongoing due diligence; identify beneficial owners and authorized persons; verify source of funds and source of wealth where required; screen sanctions, politically exposed persons and adverse media; monitor transactions and account behaviour; investigate alerts; prevent fraud, money laundering, terrorist financing, proliferation financing and other prohibited activity; and make legally required reports.

Where information about criminal allegations, offences or convictions is subject to a separate statutory regime, the Company processes it only under official authority or under a law that authorizes the processing and provides the required safeguards. General commercial convenience or an undifferentiated legitimate-interest claim is not used as a substitute where Applicable Data Protection Law requires specific statutory authorization.

Screening may generate a possible match that requires further information or human review. The Company may delay, reject, suspend, restrict or close an application, payment or account where necessary to manage a verified risk, comply with law or protect the service. The Company may be prohibited from explaining a review, report or restriction if doing so would amount to unlawful disclosure or tipping-off.

KYC and compliance data may be shared with competent authorities, law-enforcement bodies, courts, auditors, banks, payment providers and specialist verification or screening vendors when necessary and lawful. It is not used for unrelated advertising.

A request to erase, restrict or disclose compliance data may be limited where retention, confidentiality, legal privilege, investigation, reporting or anti-tipping-off rules apply. Any refusal or limitation will be explained to the extent law permits.

07

FACIAL IMAGES AND BIOMETRIC INFORMATION

Identity verification may require a photograph, video, selfie, liveness check or comparison with an identity document. Depending on the technology, this may create biometric information because technical processing can uniquely verify an individual.

The Company currently uses specialist identity-verification providers, including Sumsub and IDWise where relevant to the selected verification route. The interface used for verification will identify the provider and provide any additional notice required before capture. A provider may process data on the Company’s documented instructions and may also have separate legal duties for limited processing it determines itself.

Facial and biometric information is processed only to verify identity, test liveness, prevent impersonation and identity fraud, and satisfy KYC, AML or related legal and regulatory requirements. It is not sold, rented, used to infer emotion or sensitive traits, or used for advertising, general analytics or unrelated profiling.

Where Applicable Data Protection Law treats biometric information as special-category or sensitive data, the Company identifies both a general lawful basis and the separate additional condition required for that data before processing begins. Under the EU or UK GDPR, biometric verification ordinarily requires an Article 6 basis and an Article 9 condition. Explicit consent is used only where it can be demonstrated to be specific, informed, unambiguous, freely given and capable of withdrawal. A substantial-public-interest condition is used only where a specific applicable law authorizes the processing and provides the required safeguards; financial-services licensing or a general fraud-prevention interest is not treated as sufficient by itself.

If no valid special-category condition applies, the Company will not use biometric verification for the individual concerned. It will provide a reasonably practicable non-biometric verification route or, where identity cannot otherwise be verified to the legally required standard, decline to provide the regulated service. A refusal to consent is not characterized as voluntary acceptance of biometric processing.

Before introducing or materially changing biometric verification or another processing activity likely to create a high risk to individuals, the Company completes the impact assessment required by Applicable Data Protection Law, documents necessity and proportionality, tests accuracy and bias risks, and confirms the provider’s role, security, deletion controls and restrictions on reuse.

Raw images, videos, liveness results and derived templates must not be kept indefinitely. They are retained only for the verification, fraud-prevention, audit, dispute or legal period that applies to the particular record, then securely deleted or irreversibly de-identified. The Company requires the relevant provider’s retention settings and contract to reflect the approved schedule and prohibits reuse for the provider’s own model training unless a separate lawful basis, notice and required choice exist.

08

ACCOUNT, TRADING, PAYMENT AND COMMUNICATIONS DATA

Account and trading records are used to provide the service, execute and evidence instructions, calculate balances and charges, manage exposure and operational risk, prevent market or account abuse, resolve disputes and meet recordkeeping and reporting duties.

Payments are generally processed with banks, card networks, e-wallets, payment institutions, payment gateways and fraud-prevention providers. The Company may receive payer name, masked account or card information, payment status, amount, currency, date, reference, origin, destination and risk indicators. A payment provider may be an independent controller for its own authorization, fraud, regulatory and retention activities. Its privacy notice applies to those activities.

The Company may record and monitor service-related telephone, electronic, webchat or other communications where lawful for instructions, quality assurance, training, security, complaints, fraud prevention, regulatory evidence and claims. A notice will be given where required. Recordings are not the Company’s unrestricted property: they remain personal data subject to applicable rights, confidentiality, access and retention controls.

Communications that are necessary to administer an account, confirm security events, deliver contractual information or issue legal and regulatory notices are service communications and may continue after a marketing opt-out.

10

MARKETING AND ADVERTISING CHOICES

The Company may send permitted information about products, services, events and education by email, telephone, SMS, messaging service or another selected channel. The communication will identify the sender and provide a practical method to opt out. The Company maintains a limited suppression record so that an opt-out can be respected.

Consent is obtained where required. Where legitimate interests may lawfully support direct marketing, the Company considers the existing relationship, content, channel, frequency and reasonable expectations and provides an unconditional right to object. Marketing consent is not a condition of opening or maintaining an account unless the communication is genuinely necessary to the service.

Advertising audiences, pixels, conversion measurement and cross-site tracking are used only where a lawful basis and any required cookie or similar-technology consent exist. The Company does not disclose identity documents, financial records, account balances or trading instructions for advertising. It does not sell personal data for monetary consideration. A disclosure treated as a “sale” or “sharing” under an applicable local law is subject to the choices that law requires.

Opting out of marketing does not stop security, transaction, contract, policy, risk or regulatory communications. A marketing preference can be changed through the unsubscribe method, Cookie Settings or by contacting the Company.

11

AUTOMATED TOOLS, PROFILING AND HUMAN REVIEW

The Company and its providers may use rules, scores and automated tools to verify documents, test liveness, detect sanctions or politically exposed person matches, assess fraud and payment risk, identify abnormal account or transaction activity, support product eligibility and prioritize security or compliance reviews.

An alert or score may influence whether more information is requested, whether an application or transaction is delayed, or whether a case is referred for review. These tools can produce false positives and are not treated as conclusive merely because they are automated.

Where a decision based solely on automated processing would produce a legal or similarly significant effect and Applicable Data Protection Law restricts it, the Company will not make that decision unless a permitted condition applies and required safeguards are provided. Those safeguards may include meaningful information about the factors used, the ability to express a view, challenge the outcome and request review by a person with authority to change it.

The Company will not disclose information that would compromise security, fraud controls, protected models, another person’s rights, confidential regulatory methods or anti-tipping-off duties. It will nevertheless provide the explanation required by law in a concise and intelligible form.

12

SHARING AND RECIPIENTS

Personal data is disclosed only where necessary for a stated purpose, proportionate to that purpose and supported by an appropriate legal basis. Access is not granted to every GTCFX-branded company merely because it belongs to the same group.

Depending on the service and event, recipients may include:

identity-verification, sanctions-screening, fraud-prevention, cybersecurity, hosting, cloud, communications, customer-support, document-management and business-continuity providers;

trading-platform, market-connectivity, liquidity, execution, reporting and technology providers to the extent necessary to operate the account or platform;

banks, card networks, payment institutions, e-wallets, payment gateways, correspondents and financial-crime control providers;

auditors, accountants, lawyers, insurers, consultants and other professional advisers bound by confidentiality and professional duties;

introducing brokers, affiliates or business partners where needed to administer an authorized relationship, attribution or remuneration, but not for their independent marketing without a separate lawful basis;

other group companies for documented support, security, compliance, audit or administration functions, subject to need-to-know access, contractual controls and transfer safeguards;

courts, regulators, tax authorities, financial-intelligence units, law-enforcement agencies and other competent bodies where disclosure is required or lawfully requested; and

a prospective buyer, investor, lender or restructuring adviser where necessary for a genuine corporate transaction and subject to confidentiality, minimization and due-diligence controls.

The Company does not disclose data merely because a third party requests it. It checks authority, scope and proportionality where legally permitted. An individual may authorize disclosure to another person, but the Company may verify the authorization and identity before acting.

13

SERVICE PROVIDERS AND THIRD-PARTY PLATFORMS

A provider engaged to process personal data for the Company is subject to due diligence and contractual controls appropriate to the service. These address documented instructions, confidentiality, security, sub-processors, assistance with rights and incidents, deletion or return, audit and international transfers where applicable.

Some providers determine their own purposes for part of the processing. For example, a bank may retain payment data for financial-crime duties, a platform provider may maintain its own security logs, or an advertising provider may act as a separate controller for an authorized feature. The Company will identify that role at the relevant point where Applicable Data Protection Law requires it.

Identity-verification providers currently named in the service include Sumsub and IDWise. Website and platform technologies may include the providers described in Section 9 and in the Cookie Policy. The active provider inventory may change. Before a new provider receives personal data, the Company confirms its purpose, role, location, data categories, retention, sub-processors, security, lawful basis and transfer mechanism, and updates the relevant notice when the change is material.

Links, widgets, plug-ins, social networks and services operated independently by third parties are governed by their own terms and privacy notices for processing they control. The Company is not responsible for a third party’s independent processing, but this does not exclude responsibility for the Company’s own selection, configuration or disclosure where Applicable Data Protection Law imposes it.

14

INTERNATIONAL TRANSFERS

Personal data may be accessed, hosted or otherwise processed in Anjouan, elsewhere in the Union of the Comoros, and in other countries where the Company, an authorized group function or a service provider operates. Those countries may not provide the same statutory privacy protections as the country in which the data was collected.

Where a restricted international transfer is subject to Applicable Data Protection Law, the Company uses a permitted mechanism appropriate to the transfer. This may include an adequacy decision, approved standard contractual clauses, a United Kingdom transfer agreement or addendum, binding corporate rules, another legally recognized safeguard, or a narrowly interpreted statutory exception. Consent is not used as a routine substitute for an available and more appropriate safeguard.

Where required, the Company assesses the destination, recipient, applicable laws and practical risks; applies supplementary contractual, technical and organizational measures; limits access and data fields; and reviews the arrangement when circumstances change. A person may request information about the applicable safeguard, subject to redaction for security, privilege and third-party confidentiality.

15

RETENTION, DELETION AND ACCOUNT CLOSURE

The Company retains personal data for the shortest period reasonably required for the purpose, taking account of legal and regulatory recordkeeping, the duration of the relationship, complaint and limitation periods, security and fraud risks, audit requirements, legal holds, the sensitivity of the data and whether the purpose can be achieved with aggregated or de-identified data.

As a general baseline, customer due-diligence documents and supporting account and transaction records are normally retained for at least five years after the business relationship ends, or longer where applicable law, a regulator, an investigation, a dispute, a sanctions restriction or a legal hold requires it. Communications, instructions and complaint records are retained for the applicable regulatory or claims period. An unsuccessful application may also be retained for a proportionate compliance, fraud-prevention or claims period.

Biometric-derived data follows the separate limits in Section 7. Optional marketing data is retained until consent is withdrawn, an objection is made or the campaign purpose expires; a minimal suppression record may then be kept to honor the choice. Cookie and online-identifier periods are described in the live Cookie Policy and cookie register. Security logs are retained for a period proportionate to detection, investigation and evidence needs.

Closing an account does not automatically delete records that the Company must keep. When a retention period expires and no exception applies, data is securely deleted, irreversibly de-identified or put beyond routine use pending secure deletion from protected backups. Backup copies follow the applicable backup cycle and are not restored for ordinary business use after deletion.

If retention is extended, the reason, affected data and review date are recorded. Data will not be kept indefinitely merely because storage is inexpensive or it may be useful in the future.

16

SECURITY AND PERSONAL DATA INCIDENTS

The Company applies risk-based technical and organizational measures intended to protect confidentiality, integrity and availability. Depending on the risk and system, these may include access control, least-privilege permissions, multifactor authentication for privileged access, encryption in transit and at rest, network and endpoint controls, secure development and change management, logging and monitoring, vulnerability management, backups, staff training, confidentiality obligations and provider oversight.

Clients are responsible for protecting their own credentials and devices and for promptly reporting suspected account compromise. This responsibility does not remove the Company’s duties for systems and processing under its control.

A suspected personal data incident is assessed, contained, investigated, documented and remediated under the Company’s response process. The Company will notify the competent authority and affected individuals where, when and in the form required by Applicable Data Protection Law. Where the EU or UK GDPR applies, a notifiable breach is reported to the competent authority without undue delay and, where feasible, within 72 hours after the Company becomes aware of it; affected individuals are notified without undue delay where the applicable high-risk threshold is met. Notification may be delayed or limited only where law-enforcement, security or legal requirements lawfully require it.

No method of transmission or storage is completely secure. The Company does not promise that an incident can never occur, but it will not use that fact or a user-conduct clause to disclaim responsibility that cannot lawfully be excluded.

17

YOUR RIGHTS AND HOW TO EXERCISE THEM

Depending on the law that applies, an individual may have the right to be informed; request access and a copy; correct inaccurate or incomplete data; request deletion; restrict processing; object to processing based on legitimate interests; object at any time to direct marketing; receive certain data in a structured, commonly used and machine-readable format; withdraw consent; request review of a qualifying automated decision; and complain to a competent privacy or data-protection authority.

A request may be made using the contact details in Section 19. It should describe the right and information concerned. The Company may ask for information reasonably necessary to verify identity, authority and scope. Sensitive identification should be submitted only through a secure method specified by the Company, not through an unrequested email attachment.

The Company responds within the period required by Applicable Data Protection Law and will explain any lawful extension, fee, refusal or limitation. Where the EU or UK GDPR applies, the ordinary response period is one month after receipt of a valid request, subject to any lawful extension for complexity or number of requests. A request is normally free, but a reasonable fee may be charged or a request refused where the law permits this because it is manifestly unfounded or excessive. The Company will not charge simply because a person exercises a right.

Rights may be limited where necessary to protect another person’s rights, confidentiality, legal privilege, security, fraud controls, regulatory duties, legal claims, records required by law, ongoing investigations or anti-tipping-off restrictions. The Company will separate exempt information and provide the remainder where reasonably possible.

Withdrawing consent affects future processing based on that consent only. Objecting to marketing does not close an account. A deletion request does not require deletion of records that must be retained, but those records will be restricted to the permitted purpose and deleted when the requirement ends.

18

CHILDREN, THIRD-PARTY SITES AND CHANGES

The services are not directed to persons under 18, and the Company does not knowingly open a trading account for a minor. If the Company learns that it collected a minor’s data without a lawful basis, it will take appropriate steps to close or restrict the application or account and delete the data unless retention is required by law or for protection and claims.

A link to a third-party site, application or platform does not make that third party’s processing subject to this Policy. Individuals should review the privacy information presented by the third party. The Company remains responsible for disclosures it makes and for technologies it selects or configures where the law imposes responsibility.

The Company may update this Policy to reflect changes in law, services, systems, recipients or processing. The current version and effective date will be published in the Legal Documents area. Where a change is material, the Company will provide additional notice by an appropriate channel before the change takes effect. If the new purpose requires consent, processing for that purpose will not begin until valid consent is obtained.

19

CONTACT AND COMPLAINTS

Privacy questions, requests and complaints may be sent to support\@gtcfx.com with the subject line “Privacy Request”. The Company may direct the sender to a secure verification channel before receiving identity documents or other sensitive information.

Postal correspondence may be addressed to: Privacy Request, GTC Global Trading Ltd, Boulevard de Coalancanthe, Mutsamudu, Anjouan, Union of the Comoros.

A complaint will be investigated and answered within the period required by Applicable Data Protection Law. An individual may also complain to a competent data-protection or privacy authority with jurisdiction over the relevant processing. Contacting the Company first may help resolve the issue, but it does not remove a right to approach that authority.

The Anjouan Offshore Finance Authority is identified above as the issuer of the Company’s financial-services licence. That financial-services role does not, by itself, make AOFA the competent privacy supervisory authority. A privacy complaint should be directed to the authority with jurisdiction under the Applicable Data Protection Law.

Need Assistance?

Contact support for privacy or data protection questions

If you have any questions or concerns regarding this Privacy Policy, please e-mail us at support@gtcfx.com

GTC Go

GTCFX: GTC Go – Trade & Invest