How Easyfortunetrades complies with the EU General Data Protection Regulation, what rights you have as a data subject, and how to exercise them.
The General Data Protection Regulation (GDPR) is a European Union law that governs how organizations collect, use, and protect the personal data of individuals in the EU, EEA, UK, and Switzerland.
Easyfortunetrades is committed to full GDPR compliance. This page explains what data we process, why we process it, and what rights you have over it. It works alongside our Privacy Policy, which describes our broader data practices.
For the purposes of GDPR, Easyfortunetrades acts as the data controller for the personal information we collect through our platform. This means we determine why and how your data is processed, and we are accountable for protecting it.
When we use third-party services (such as cloud hosting providers or KYC verification partners), those third parties act as data processors. They process data only on our instructions and under contracts that require GDPR-compliant safeguards.
Contact details for data protection matters are listed in the Data Protection Officer section at the end of this page.
We process the following categories of personal data. Each category has a clear purpose and a defined retention period.
| Category | Examples | Purpose |
|---|---|---|
| Identity Data | Name, date of birth, government ID, selfie | KYC verification, AML compliance |
| Contact Data | Email, phone, country | Account communication, verification |
| Financial Data | Deposit/withdrawal history, trades, balances, wallet addresses | Trade execution, regulatory reporting |
| Technical Data | IP address, browser, device, session timestamps | Security, fraud detection, analytics |
| Communication Data | Support tickets, chat logs, emails | Customer support, dispute resolution |
| Usage Data | Pages viewed, features used, session duration | Platform improvement |
Under GDPR Article 6, every processing activity must have a legal basis. Here is how each of our processing activities maps to a legal basis:
If you withdraw consent for processing that has another legal basis (like compliance with AML laws), we may still be required to process certain data.
If you are in the EU/EEA, UK, or Switzerland, you have the following rights over your personal data. We honor these rights for all users, regardless of location.
Exercising your rights is straightforward. Choose whichever method works for you:
To protect your data, we may need to verify your identity before fulfilling a request. This is done to prevent someone else from accessing your data. The verification process is quick and typically involves confirming details we already have on file.
We handle all GDPR requests promptly and within the timelines required by law.
If we cannot fulfill a request (for example, because we are legally required to retain certain data), we will explain the reason in writing.
Some of our service providers process data outside the EU/EEA. When this happens, we ensure your data remains protected by using one or more of the following safeguards:
You can request more information about the specific safeguards used for any transfer by contacting us. We will provide the relevant contract details on request.
We retain personal data only as long as necessary for the purpose it was collected, plus any period required by law.
| Data Type | Retention Period | Reason |
|---|---|---|
| Account details | While account is active + 5 years | Financial record-keeping laws |
| KYC documents | 5 years after account closure | AML/CTF regulations |
| Transaction records | 7 years | Tax and AML compliance |
| Support tickets | 3 years | Dispute resolution |
| Security logs | 12 months | Fraud detection and incident response |
| Marketing consent records | Until consent withdrawn + 1 year | Proof of consent |
When a retention period ends, we either delete the data permanently or anonymize it so it can no longer be linked to you.
GDPR Article 32 requires appropriate technical and organizational measures to protect personal data. The measures we implement include:
Our platform is not directed to children and we do not knowingly process data from anyone under 18. If you are a parent or guardian and believe your child has provided us with personal data, contact us immediately.
If we learn that we have collected personal data from a minor without verified parental consent, we will delete it as quickly as possible.
If you believe we have violated your data protection rights, we would prefer you contact us first so we can resolve the issue directly. However, you always have the right to lodge a complaint with your local data protection authority.
In the EU, this is typically the supervisory authority in the country where you live, work, or where the alleged violation occurred. You can find your national authority through the European Data Protection Board's website.
We cooperate fully with all supervisory authorities. If you file a complaint, we will respond promptly to any inquiries from the authority handling your case.
If you have questions about how we handle your personal data under GDPR, or you want to exercise any of your rights, you can reach out to our data protection team.
Email: [email protected]
Contact form: our contact page
Please include "GDPR" in the subject line of your email so your request is routed to the right team and processed within the required timelines.
We may update this GDPR compliance page as our practices evolve or as regulations change. When we do:
Continuing to use the platform after a change means you accept the updated terms. If you do not agree, you can close your account and request deletion of your data (subject to legal retention obligations).
Contact our data protection team and we will process your request within GDPR timelines.