Privacy Policy
1. What Data We Collect and Why
We collect personal data to provide a secure and legally compliant digital asset trading environment. This includes:
- Identity Data: Full name, date of birth, government-issued ID (for KYC/AML compliance).
- Contact Data: Email address, physical address, phone number (for account security and communication).
- Financial Data: Bank account details, crypto wallet addresses, transaction history (to process deposits, trades, and withdrawals).
- Technical Data: IP address, device information, browser type, log data (to prevent fraud and ensure platform security).
2. Legal Basis for Processing (GDPR Compliance)
We process your data under the following legal bases:
- Contractual Necessity: To fulfill our Terms of Service (e.g., executing trades).
- Legal Obligation: To comply with international Anti-Money Laundering (AML) and Counter-Terrorism Financing (CTF) laws.
- Legitimate Interest: To protect the platform against fraud, maintain security, and improve our services.
- Consent: For marketing communications and non-essential cookies (which you can withdraw at any time).
3. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes outlined in this policy. Due to financial regulations, we are legally required to retain KYC data and transaction history for a minimum of five (5) years after account closure. Once the retention period expires, your data is securely deleted or anonymized.
4. Third-Party Data Sharing
We do not sell your data. We only share data with trusted third parties necessary for our operations:
- Identity Verification (KYC) Providers: To verify your identity and check against global watchlists.
- Payment Processors & Banks: To facilitate fiat deposits and withdrawals.
- Law Enforcement: When legally compelled by a valid court order or regulatory authority.
5. Your User Rights
Under the GDPR and global privacy standards, you have the right to:
- Access: Request a copy of the personal data we hold about you.
- Correction: Request correction of inaccurate or incomplete data.
- Deletion ("Right to be Forgotten"): Request deletion of your data (subject to our legal retention obligations).
- Data Portability: Receive your data in a structured, machine-readable format.
- Objection: Object to processing based on legitimate interests.
To exercise these rights, contact privacy@primemeridianmarkets.com.
6. Cookie Policy
We use essential cookies to maintain your active session, enforce security (such as CSRF protection), and remember your preferences. We also use analytics cookies to understand platform usage and improve our services. You can manage cookie preferences through your browser settings, but disabling essential cookies may prevent the platform from functioning properly.
7. Data Breach Notification
In the unlikely event of a data breach that compromises your personal information, we are committed to notifying affected users and the relevant supervisory authorities within 72 hours of becoming aware of the breach. We will provide details on the nature of the breach, the data affected, and the steps we are taking to mitigate any risks.