Loading…
Cookies & Privacy

Cookie Policy

Information about cookies, similar technologies, consent choices, tracking controls, and how we protect your privacy.

About This Policy

This Cookie Policy explains how GTC Global Trading Ltd uses cookies and similar technologies on the GTCFX /en-intl website and on another digital service that expressly links to this Policy. It describes the choices available to visitors and clients and must be read with the Privacy Policy.

The policy text, cookie-consent interface and actual configuration must remain consistent. Publishing this Policy does not by itself make a website compliant if a non-essential analytics or advertising technology loads before a valid choice, if a rejection is ineffective, or if the live cookie register is incomplete.

Key Notice

Strictly necessary technologies may operate without consent only where an applicable legal exception permits it and the technology is genuinely necessary for the requested service or its security.

Where consent is required, analytics, advertising, social-media and other non-essential technologies must remain inactive until the user makes an affirmative choice.

Rejecting non-essential technologies must be as easy as accepting them, and withdrawing consent must be as easy as giving it.

Cookies must never contain a plaintext password, PIN, one-time authentication code, full card-security code, recovery phrase or digital-wallet private key.

Browser settings are an additional control, not a substitute for a website-level Cookie Settings tool where applicable requirements require prior consent.

01

Company and Scope

Legal name: GTC Global Trading Ltd (the "Company", "we", "us" or "our")

Company number: 16283

Legal form and jurisdiction: A private limited company incorporated under the laws of the Autonomous Island of Anjouan, Union of the Comoros

Licence: Licence no. L16283/GTC issued by the Anjouan Offshore Finance Authority ("AOFA")

Registered address: Boulevard de Coalancanthe, Mutsamudu, Anjouan, Union of the Comoros

Website: https\://www\.gtcfx.com/en-intl/

This Policy applies to the Company's operation of the GTCFX /en-intl website. "GTCFX" is a brand reference and is not a separate legal person. A cookie, tag, analytics provider or other technology vendor does not become the visitor's or client's contracting entity merely because it supports the website.

This Policy concerns storage and access technologies and the related information flows. The Privacy Policy explains the wider processing of personal data, legal bases, retention, international transfers and rights. The Client Agreement identifies the contracting entity for financial services. Neither a group company nor a service provider may rely on this Policy as authority for processing outside its stated scope.

In this Policy, "Applicable Requirements" means the privacy, electronic-communications, consumer-protection and other laws, regulations, binding authority directions and licence conditions applicable to the Company, visitor, client, technology or processing activity. AOFA licensing does not replace data-protection or cookie obligations that may apply where a website is offered or accessed.

02

Cookies and Similar Technologies

A cookie is a small text file or data item stored on or accessed from a browser or device. A session cookie normally expires when the browser session ends. A persistent cookie remains for a stated period or until it is removed. A first-party cookie is set for the GTCFX domain; a third-party cookie is set or accessed by another provider.

This Policy also covers technologies that perform a comparable storage, access, recognition or tracking function, including local or session storage, pixels, tags, web beacons, scripts, software development kits, device identifiers, link decoration, conversion APIs, server-side event forwarding and fingerprinting techniques. A technology is not outside this Policy merely because it does not use a conventional browser cookie.

These technologies can support authentication, security, language or interface preferences, website measurement, referral attribution, personalised content, advertising measurement and fraud detection. The applicable category depends on the technology's actual purpose and operation, not the label selected by a vendor or by the Company.

Some information collected through these technologies may identify or single out a browser, device, account or individual and may therefore be personal data. Pseudonymous identifiers remain protected where they can be linked to a person, account or device.

04

Strictly Necessary, Security and Fraud Controls

Strictly necessary technologies support a service expressly requested by the user or a function without which the relevant website or authenticated service cannot be delivered securely. They may include load balancing, network security, authentication, session management, consent-preference storage and controls necessary to protect an account or transaction.

Authentication cookies should contain a random or otherwise protected session token rather than the user's password. Where technically appropriate, security attributes such as Secure, HttpOnly and SameSite are applied, session identifiers are rotated, access is restricted and tokens expire after a proportionate period.

Fraud, account-takeover, sanctions, abuse and financial-crime controls may use proportionate device, browser, network, location, account-linkage or behavioural indicators. However, describing a technology as useful for security, fraud prevention or AML does not automatically make it strictly necessary. Each technology must be assessed against the legal exception and its actual technical function.

A security purpose must not be used to activate advertising, cross-site profiling or unrelated analytics without the choice required by Applicable Requirements. Where a necessary control cannot operate, the relevant secure account feature may be unavailable, but refusing non-essential technologies should not prevent access to general public content or require a client to close an account.

No cookie or similar technology should contain a plaintext account password, online-banking password, PIN, one-time authentication code, full CVV or CVC, recovery phrase, private key or another secret that would permit account or payment compromise.

05

Functionality Technologies

Functionality technologies remember choices or provide optional features, such as language, region, interface preferences, accessibility settings, chat availability or media features. The exact classification depends on whether the user requested the feature and whether the technology is necessary to deliver it.

Where consent is required, functionality technologies remain disabled until selected. Refusal may remove personalisation or require a user to repeat a preference, but it should not be described as disabling the entire website unless that result is technically accurate and necessary.

A feature supplied by a third party may allow that provider to receive device, page, account-state or interaction information. The Company must assess the provider, configure the feature to minimise data and disclose any material third-party role before activation.

06

Analytics and Performance Technologies

Analytics and performance technologies help measure visits, pages, navigation paths, referral sources, errors, latency, interaction patterns and campaign or content effectiveness. They may use persistent identifiers and may allow a provider to recognise a browser or device across sessions.

Where Applicable Requirements require consent, these technologies must not load, write identifiers, read existing identifiers or send analytics events before consent. Merely configuring a provider for aggregated reporting, IP truncation, consent mode or reduced data does not automatically remove the consent requirement.

The Company should collect only the events and parameters necessary for documented measurement purposes. Sensitive account, KYC, payment or trading information must not be placed in analytics URLs, page titles, event labels or custom parameters unless a documented lawful basis, necessity assessment and appropriate safeguards support the processing.

Where practical, analytics configurations should reduce identifier use, exclude authenticated or sensitive areas, limit retention, restrict advertising features and prevent a provider from using Company data for unrelated purposes.

07

Advertising, Targeting and Social-Media Technologies

Advertising and targeting technologies may attribute registrations or other conversions, build or suppress audiences, control advertising frequency, personalise adverts, measure campaigns or link activity across websites, applications or devices. Social-media technologies may also allow a platform to recognise a user or measure interaction with its services.

These technologies are not required for general website access and must remain inactive until valid consent where Applicable Requirements require it. A user who rejects them should still receive access to general website content, although advertising seen elsewhere may be less relevant and conversion attribution may be limited.

The Company must not upload or disclose KYC documents, passwords, financial-account credentials, private keys, unmasked payment data or detailed trading information to an advertising platform. Audience matching using contact or account information requires a separate documented purpose, lawful basis, notice, suppression controls and vendor assessment; it is not authorised merely by a general cookie choice.

Some privacy laws may describe advertising-related disclosure as a sale, sharing or targeted advertising even where no money is paid. Where such rules apply, the Company will provide the required notice and opt-out and will not use contractual labels to defeat a statutory right.

08

Third-Party and Embedded Services

A third-party provider may supply analytics, advertising, social-media, reviews, market-content, chat, security or other embedded functionality. Depending on the service and law, the provider may act as a processor, independent controller, joint controller or another legally defined role. That role must be assessed and accurately reflected in the Privacy Policy, contracts and provider disclosures.

An embedded service should be blocked or replaced with a privacy-preserving placeholder until the required choice is made where it can set or access non-essential identifiers. A user's deliberate request to open a video, chat, review or market-content feature may be treated separately only where Applicable Requirements permit and the user receives clear information.

Third-party privacy notices may explain the provider's own processing, but they do not replace the Company's duty to give clear information about the Company's purposes and choices. The Company remains responsible for selecting and configuring vendors, limiting access, maintaining contracts and reviewing changes within its control.

Tag-management and server-side tools do not create an exemption. The Company must control the tags, events and destinations they activate and prevent an unapproved tag from bypassing the user's recorded choice.

09

Current Technology Providers

Depending on the page, jurisdiction, consent choice and feature used, the website may use technologies supplied by the following providers. The live Cookie Settings register must identify the technologies actually configured at the time of a visit and is authoritative for the specific cookie or storage name, domain, category and duration.

Google: Google Tag Manager, Google Analytics and Google Ads measurement or conversion services for tag control, analytics and advertising attribution.

Meta: Meta Pixel or related event technologies for advertising measurement, attribution and audience controls.

TikTok: TikTok Pixel or related event technologies for advertising measurement, attribution and audience controls.

Microsoft: Microsoft Clarity for website-performance, interaction and usability analysis.

Umami: Website analytics used to measure traffic and content performance according to its configured mode.

Trustpilot: Review, invitation or trust-content functionality that may receive page, device or interaction data.

MQL5 or MetaQuotes-related content: Market-platform or embedded content functionality where used on a relevant page.

Website chat provider: Chat and support functionality that may receive device, page, conversation and contact information when the feature is used.

A provider name in this section does not authorise every service offered by that provider or guarantee that the provider is active on every page. Before adding a provider or materially changing its purpose, the Company must update the technical configuration, consent category, live register, vendor assessment and privacy disclosures as necessary.

12

Data Collected, Sharing and International Transfers

Depending on the technology and choice, information may include IP address, browser and device type, operating system, language, approximate location, referrer, page URL, date and time, interaction or error events, advertising or pseudonymous identifiers, consent status and limited account-state information. The Company must not describe pseudonymous data as anonymous where re-identification or linkage remains reasonably possible.

Information may be disclosed to the technology providers identified in the live register, hosting and security suppliers, professional advisers, group service companies and competent authorities where there is an appropriate lawful and necessary basis. A disclosure is limited to the purpose and protected through access controls, contractual restrictions and other appropriate safeguards.

Providers may process information in countries other than the visitor's location or Anjouan. The Privacy Policy explains the applicable international-transfer safeguards and rights. A provider's global infrastructure does not remove the Company's responsibility to assess the transfer and provide required information.

The Company does not authorise a provider to use account, KYC, payment or trading data for its independent advertising merely because the provider also supplies analytics or advertising technology. Provider use beyond the Company's documented instructions must have a separate lawful basis and transparent disclosure.

13

Security, Privacy Rights and Browser Signals

The Company uses proportionate technical and organisational measures for cookie and tracking data, including access restrictions, secure transmission, vendor controls, data minimisation, retention limits and monitoring. No internet or browser technology is completely secure, and users should protect their devices, browsers and account credentials.

Privacy rights concerning personal data collected through these technologies are described in the Privacy Policy. Depending on Applicable Requirements, rights may include access, correction, deletion, restriction, objection, portability, withdrawal of consent and a right to complain to a competent authority. These rights are subject to lawful conditions and exceptions.

Browser-level Do Not Track signals are not interpreted consistently across the industry. Where an applicable law requires recognition of the Global Privacy Control or another legally effective preference signal, the Company will apply the required response. Users should use Cookie Settings for a direct website-level choice and should not assume that every browser signal controls every technology.

Questions or requests should not include passwords, PINs, one-time authentication codes, private keys or unmasked card-security data. The Company may need reasonable information to verify an authenticated privacy request without collecting excessive information.

14

Changes and Contact

The Company may update this Policy to reflect changes in law, technology, providers, website functions or processing. The revised version will display its last-updated date. Where a change materially affects a consented purpose or is otherwise significant, the Company will provide an appropriate notice and obtain a new choice where required.

A policy update cannot retroactively validate a non-essential technology that was activated without a required consent. Historical configuration, consent and remediation records should be preserved for accountability for the appropriate period.

Questions about cookies, similar technologies or the operation of Cookie Settings may be sent to support\@gtcfx.com. Requests concerning personal data should follow the process in the Privacy Policy. Users should confirm that a communication channel is genuine before providing account information.

The English version controls if a translation is inconsistent, to the extent permitted by Applicable Requirements. Mandatory rights and remedies remain unaffected.

Need Assistance?

Contact support for cookie or privacy questions

If you have questions about cookies, similar technologies, consent choices, or privacy settings, please contact the support team.

GTC Go

GTCFX: GTC Go – Trade & Invest