GDPR Compliance.

How Easyfortunetrades complies with the EU General Data Protection Regulation, what rights you have as a data subject, and how to exercise them.

Last updated: January 15, 2026
If you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, you have specific rights over your personal data. This page explains them and how to use them.
1

Overview

The General Data Protection Regulation (GDPR) is a European Union law that governs how organizations collect, use, and protect the personal data of individuals in the EU, EEA, UK, and Switzerland.

Easyfortunetrades is committed to full GDPR compliance. This page explains what data we process, why we process it, and what rights you have over it. It works alongside our Privacy Policy, which describes our broader data practices.

Full GDPR compliance
We honor every data subject right under GDPR, including access, correction, deletion, portability, and objection — with clear response timelines and no unnecessary friction.
2

Who We Are

For the purposes of GDPR, Easyfortunetrades acts as the data controller for the personal information we collect through our platform. This means we determine why and how your data is processed, and we are accountable for protecting it.

When we use third-party services (such as cloud hosting providers or KYC verification partners), those third parties act as data processors. They process data only on our instructions and under contracts that require GDPR-compliant safeguards.

Contact details for data protection matters are listed in the Data Protection Officer section at the end of this page.

3

Data We Process

We process the following categories of personal data. Each category has a clear purpose and a defined retention period.

Category Examples Purpose
Identity Data Name, date of birth, government ID, selfie KYC verification, AML compliance
Contact Data Email, phone, country Account communication, verification
Financial Data Deposit/withdrawal history, trades, balances, wallet addresses Trade execution, regulatory reporting
Technical Data IP address, browser, device, session timestamps Security, fraud detection, analytics
Communication Data Support tickets, chat logs, emails Customer support, dispute resolution
Usage Data Pages viewed, features used, session duration Platform improvement
We only process what we need
Every data point we collect has a specific purpose. We do not collect data "just in case" or for future use we have not defined.
5

Your Rights Under GDPR

If you are in the EU/EEA, UK, or Switzerland, you have the following rights over your personal data. We honor these rights for all users, regardless of location.

Right to Access
Request a copy of all personal data we hold about you, along with details of how we use it.
Right to Rectification
Ask us to correct inaccurate or incomplete information. You can update most fields directly in your account settings.
Right to Erasure
Request deletion of your personal data, subject to legal retention obligations under AML and financial laws.
Right to Portability
Receive your personal data in a structured, machine-readable format and transfer it to another service.
Right to Object
Object to processing based on legitimate interests or direct marketing at any time. We will stop unless we have compelling grounds.
Right to Restriction
Ask us to temporarily stop processing your data while a dispute is being resolved.
Right to Withdraw Consent
Withdraw any consent you previously gave us, at any time. Marketing consent withdrawal is instant.
Right to Complain
Lodge a complaint with your local data protection authority if you believe we have violated your rights.
6

How to Exercise Your Rights

Exercising your rights is straightforward. Choose whichever method works for you:

  • Self-service: log in and update most of your personal data directly in your account settings.
  • Data export: request a full export of your data using the contact form or by email. We will send it to you in a structured format.
  • Email request: contact us directly at the address listed in the Data Protection Officer section below.
  • Contact form: use our contact page and select "Account & Login" or "Other" as the subject.

To protect your data, we may need to verify your identity before fulfilling a request. This is done to prevent someone else from accessing your data. The verification process is quick and typically involves confirming details we already have on file.

What to include in your request
Tell us which right you want to exercise, what data it concerns, and (if you are writing on behalf of someone else) provide proof of authorization. That is all we need to begin.
7

Response Time and Process

We handle all GDPR requests promptly and within the timelines required by law.

  • Acknowledgment: within 3 business days of receiving your request.
  • Full response: within 30 days. This is the legal maximum under GDPR.
  • Extension: for complex requests, we may extend the response time by up to 60 additional days. We will always notify you if this happens and explain why.
  • Free of charge: we do not charge for handling legitimate GDPR requests. Excessive or repetitive requests may incur a reasonable administrative fee.

If we cannot fulfill a request (for example, because we are legally required to retain certain data), we will explain the reason in writing.

8

International Data Transfers

Some of our service providers process data outside the EU/EEA. When this happens, we ensure your data remains protected by using one or more of the following safeguards:

  • Adequacy decisions: transfers to countries that the European Commission has determined provide an adequate level of protection.
  • Standard Contractual Clauses (SCCs): legally binding contracts approved by the European Commission that require the recipient to protect your data to EU standards.
  • Supplementary technical measures: additional encryption, pseudonymization, and access controls where needed.

You can request more information about the specific safeguards used for any transfer by contacting us. We will provide the relevant contract details on request.

9

Data Retention

We retain personal data only as long as necessary for the purpose it was collected, plus any period required by law.

Data Type Retention Period Reason
Account details While account is active + 5 years Financial record-keeping laws
KYC documents 5 years after account closure AML/CTF regulations
Transaction records 7 years Tax and AML compliance
Support tickets 3 years Dispute resolution
Security logs 12 months Fraud detection and incident response
Marketing consent records Until consent withdrawn + 1 year Proof of consent

When a retention period ends, we either delete the data permanently or anonymize it so it can no longer be linked to you.

10

Security Measures

GDPR Article 32 requires appropriate technical and organizational measures to protect personal data. The measures we implement include:

  • Encryption in transit: TLS 1.2+ with strong cipher suites for all network communication.
  • Encryption at rest: sensitive data such as passwords and KYC documents are encrypted with strong algorithms.
  • Access controls: role-based permissions ensure only authorized staff can access customer data, and only when necessary.
  • Two-factor authentication: available for all accounts and required for withdrawals.
  • Continuous monitoring: security monitoring detects and responds to anomalous access patterns in real time.
  • Regular audits: independent security audits validate our controls against current threats.
Breach notification commitment
If a data breach affects your rights or freedoms, we will notify you and the relevant data protection authority within 72 hours of becoming aware of the breach, as required by GDPR Article 33.
11

Children's Data

Our platform is not directed to children and we do not knowingly process data from anyone under 18. If you are a parent or guardian and believe your child has provided us with personal data, contact us immediately.

If we learn that we have collected personal data from a minor without verified parental consent, we will delete it as quickly as possible.

12

Lodging a Complaint

If you believe we have violated your data protection rights, we would prefer you contact us first so we can resolve the issue directly. However, you always have the right to lodge a complaint with your local data protection authority.

In the EU, this is typically the supervisory authority in the country where you live, work, or where the alleged violation occurred. You can find your national authority through the European Data Protection Board's website.

We cooperate fully with all supervisory authorities. If you file a complaint, we will respond promptly to any inquiries from the authority handling your case.

13

Data Protection Officer

If you have questions about how we handle your personal data under GDPR, or you want to exercise any of your rights, you can reach out to our data protection team.

Email: [email protected]

Contact form: our contact page

Please include "GDPR" in the subject line of your email so your request is routed to the right team and processed within the required timelines.

Response timeline
We acknowledge every GDPR request within 3 business days and provide a full response within 30 days. Complex requests may take up to 90 days with prior notice to you.
14

Changes to This Page

We may update this GDPR compliance page as our practices evolve or as regulations change. When we do:

  • The "Last updated" date at the top of this page changes.
  • Material changes are announced to registered users by email.
  • We will always maintain our commitment to protecting your data and honoring your rights.

Continuing to use the platform after a change means you accept the updated terms. If you do not agree, you can close your account and request deletion of your data (subject to legal retention obligations).

Need to exercise a data right?

Contact our data protection team and we will process your request within GDPR timelines.