Legal Centre
Privacy Policy
Last updated: 30 June 2026
1. Introduction
This Privacy Policy explains how Finotive One Limited and relevant Finotive group entities collect, use, store, share, transfer, and protect personal data when you visit Finotive.com, create a Finotive One account, complete onboarding or KYC, upload documents, access Finotive platforms, use Finotive services, communicate with us, or otherwise interact with the Finotive group.
This Privacy Policy should be read together with the Legal Disclosure, Finotive One Account, KYC and Data Sharing Notice, Cookie Policy, Website Terms of Use, Risk Disclosure, Restricted Jurisdictions page, and any product-specific terms that apply to the Finotive service you use.
2. Who we are
Finotive One Limited is a Cyprus-registered company with company number HE481670 and registered office at Office 113, Block A, Agios Pavlos Ct, 228 Archbishop Makarios III Ave, 3030 Limassol, Cyprus.
Finotive One Limited operates the central Finotive account, login, onboarding, identity verification, KYC, compliance, customer data, and group-access infrastructure used across the Finotive group.
The Finotive group includes Finotive Markets (MU) Limited, Finotive Pay (CY) Limited, Finotive Funding Technologies Limited, Finotive Futures Technologies Limited, and other group entities from time to time.
3. Controllers, joint controllers, and processors
For the creation and administration of the Finotive One account and for central account, KYC, compliance, customer-data, and group-access infrastructure, Finotive One Limited will generally act as a controller of your personal data.
Where a Finotive group entity determines why and how personal data is processed for its own product, account, legal obligation, regulatory obligation, payment activity, customer-support process, or risk-management function, that group entity may act as an independent controller or joint controller.
Where Finotive One Limited processes personal data only on documented instructions of another group entity, Finotive One Limited may act as a processor. Where two or more group entities jointly determine the purposes and means of processing, they may act as joint controllers and will determine their respective responsibilities as required by applicable law.
Data-protection contact: privacy@finotive.com
Data Protection Officer, if appointed: [insert DPO details or state “not appointed” after legal review]
4. Scope of this Privacy Policy
This Privacy Policy applies to personal data processed in connection with:
- Finotive.com and related web pages;
- the Finotive One account and single sign-on;
- onboarding, KYC, AML, sanctions, fraud, and compliance checks;
- Finotive dashboards, portals, platforms, and apps;
- product access requests and service administration;
- payment administration, invoices, refunds, and payouts;
- customer support, complaints, legal notices, and communications;
- marketing, analytics, cookies, and website improvement; and
- group operations, risk management, security, audit, and legal compliance.
Product-specific privacy notices may apply to particular products or entities. Where a product-specific privacy notice applies, it should be read together with this Privacy Policy.
5. Personal data we collect
We may collect and process the following categories of personal data:
- identification data, including name, date of birth, nationality, citizenship, government ID, proof of identity, proof of address, tax residency, photographs, and verification results;
- contact data, including email address, postal address, phone number, communication preferences, and support details;
- account data, including login credentials, account ID, username, user profile, account status, linked services, authentication records, and policy acknowledgements;
- KYC and compliance data, including sanctions, PEP, adverse-media, AML, fraud, duplicate-account, jurisdiction, eligibility, liveness, device-risk, and document-verification outputs;
- payment and transaction data, including payment references, payment method tokens, invoices, transaction IDs, refunds, payouts, tax information, payment-provider responses, and reconciliation records;
- product and platform data, including selected services, account identifiers, trading-platform identifiers, evaluation status, dashboard activity, simulated or live account data where applicable, account-rule events, payout information, and service history;
- trading data where applicable, including orders, positions, balance, equity, margin, profit and loss, instruments, timestamps, risk metrics, account breaches, and trading rules;
- technical data, including IP address, browser type, device identifiers, operating system, cookie IDs, log data, approximate location, referral source, session data, and security events;
- communication data, including emails, chats, support tickets, call notes, complaint records, forms, survey responses, and messages; and
- legal and risk data, including legal notices, regulatory correspondence, audit logs, consent records, dispute records, investigation records, and risk-management notes.
6. Sources of personal data
We may collect personal data directly from you, from your use of our website or platforms, from Finotive group entities, from identity-verification and KYC providers, from sanctions and fraud-screening providers, from payment providers, from trading-platform providers, from public sources, from business partners, from regulators or authorities, and from service providers that support Finotive services.
7. Purposes and legal bases
Where the GDPR or similar law applies, we rely on one or more legal bases for processing personal data. These may include performance of a contract, steps taken before entering into a contract, compliance with legal obligations, legitimate interests, consent, establishment or defence of legal claims, and, where applicable, substantial public interest or other lawful bases for special-category data.
| Purpose | Examples of data used | Typical legal basis |
|---|---|---|
| Account creation, login, authentication, and account administration | Account data, contact data, technical data | Contract; legitimate interests; security obligations |
| Onboarding, identity verification, KYC, AML, sanctions, PEP, adverse-media, and fraud checks | Identification data, KYC data, compliance data, technical data | Legal obligation; contract; legitimate interests; substantial public interest where applicable |
| Product eligibility and service access | Account data, KYC data, jurisdiction data, product data | Contract; legitimate interests; legal obligation |
| Payment administration, invoicing, refunds, and payouts | Payment data, tax data, account data, KYC data | Contract; legal obligation; legitimate interests |
| Customer support and complaint handling | Contact data, communications, account data, product data | Contract; legitimate interests; legal obligation |
| Platform integrity, fraud prevention, cybersecurity, and risk management | Technical data, account data, compliance data, usage data | Legitimate interests; legal obligation |
| Compliance with laws, regulations, court orders, law-enforcement requests, audits, and tax obligations | Account data, KYC data, payment data, legal records | Legal obligation; legitimate interests; legal claims |
| Service improvement, analytics, reporting, and internal governance | Usage data, technical data, account data, aggregated data | Legitimate interests; consent where required for non-essential cookies |
| Marketing communications | Contact data, preferences, usage data | Consent where required; legitimate interests where permitted; opt-out rights |
| Cookie and tracking technologies | Cookie IDs, device data, analytics data | Consent for non-essential cookies; legitimate interests for strictly necessary cookies |
8. Special-category and biometric data
Some KYC, liveness, fraud-prevention, or identity-verification processes may involve sensitive data, biometric-related information, or special-category data where applicable law treats such information as special-category data. We will process such data only where a lawful basis and any required additional condition applies, such as legal obligation, substantial public interest, explicit consent where required, prevention of fraud, establishment or defence of legal claims, or other permitted grounds under applicable law.
9. How we share personal data
We may share personal data with:
- Finotive group entities, including Finotive Markets (MU) Limited, Finotive Pay (CY) Limited, Finotive Funding Technologies Limited, and Finotive Futures Technologies Limited;
- KYC, identity-verification, liveness, sanctions-screening, PEP-screening, adverse-media, fraud-prevention, and compliance providers;
- payment providers, banks, card processors, payout providers, tax providers, and reconciliation providers;
- trading platforms, dashboard providers, hosting providers, cloud providers, cybersecurity providers, analytics providers, customer-support tools, messaging providers, and operational technology providers;
- professional advisers, auditors, insurers, consultants, legal advisers, tax advisers, and corporate service providers;
- regulators, courts, law-enforcement authorities, tax authorities, government bodies, dispute-resolution bodies, and other authorities where required or permitted by law;
- potential buyers, investors, successors, lenders, or counterparties in connection with a merger, acquisition, restructuring, financing, sale, transfer, or corporate transaction; and
- other parties where you instruct us to share data or where sharing is necessary to provide a service.
10. International transfers
Finotive One Limited is based in Cyprus. Finotive group entities and service providers may be located in Mauritius, the United Arab Emirates, the Dubai International Financial Centre, the European Economic Area, the United Kingdom, the United States, and other countries.
Where personal data is transferred outside the European Economic Area or another jurisdiction with transfer restrictions, we will use legally recognised transfer mechanisms where required. These may include adequacy decisions, standard contractual clauses, intra-group data-transfer arrangements, transfer risk assessments, contractual commitments, encryption, access controls, or other safeguards recognised by applicable law.
11. Retention
We retain personal data only for as long as necessary for the purposes for which it was collected or otherwise processed, including to provide services, maintain your account, comply with legal and regulatory obligations, complete audits, resolve disputes, prevent fraud, enforce agreements, and establish, exercise, or defend legal claims.
Retention periods depend on the type of data, the service used, the entity involved, legal and regulatory obligations, limitation periods, tax and accounting requirements, fraud-prevention needs, security requirements, audit requirements, and whether an account, complaint, investigation, dispute, or legal hold remains open.
Where we no longer need personal data, we will delete, anonymise, or securely archive it in accordance with applicable law and our retention procedures.
12. Security
We use technical and organisational measures designed to protect personal data against unauthorised access, loss, misuse, alteration, disclosure, or destruction. These measures may include access controls, authentication controls, encryption, monitoring, logging, network security, staff confidentiality obligations, vendor due diligence, incident-response processes, and data minimisation controls.
No online system is completely secure. You are responsible for keeping your login credentials secure and for notifying us promptly if you believe your account has been compromised.
13. Automated decision-making and profiling
We may use automated tools to support account security, identity verification, KYC, sanctions screening, PEP checks, fraud detection, duplicate-account detection, restricted-jurisdiction screening, payment review, payout review, account-rule monitoring, and eligibility assessment.
Automated checks may result in a request for more information, manual review, account restriction, service refusal, payout review, or account suspension. Where applicable law grants you rights in relation to solely automated decisions that produce legal or similarly significant effects, you may request human intervention, express your point of view, and contest the decision.
14. Marketing communications
We may send marketing communications where permitted by law. Where consent is required, we will ask for consent. You may opt out of marketing communications at any time by using the unsubscribe link in our emails or by contacting us at privacy@finotive.com. Service, account, legal, security, and transactional communications are not marketing communications and may continue where necessary.
15. Cookies
We use cookies and similar technologies as described in the Cookie Policy. Strictly necessary cookies are used to operate and secure the website and services. Non-essential cookies, such as analytics or marketing cookies, will be used where required only with your consent.
16. Your rights
Depending on your location and applicable law, you may have rights to:
- request access to your personal data;
- request correction of inaccurate or incomplete personal data;
- request deletion of personal data;
- request restriction of processing;
- object to processing based on legitimate interests or direct marketing;
- request data portability;
- withdraw consent where processing is based on consent;
- request information about automated decision-making where applicable; and
- lodge a complaint with a data-protection supervisory authority.
These rights may be subject to limitations, exemptions, identity-verification requirements, and Finotive’s legal, regulatory, fraud-prevention, tax, accounting, audit, contractual, or legal-claims obligations.
To exercise rights, contact: privacy@finotive.com.
17. Complaints
If you have concerns about how we process your personal data, contact us first at privacy@finotive.com. You may also have the right to lodge a complaint with the relevant data-protection authority. For Cyprus, the supervisory authority is the Office of the Commissioner for Personal Data Protection.
18. Children
Finotive services are not intended for children or persons under the minimum age required to use the relevant service. We do not knowingly collect personal data from children. If we become aware that a child has provided personal data without appropriate authorisation, we may delete the data and restrict the account.
19. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. The updated version will be effective when published, unless otherwise stated. Where required by law, we may notify you of material changes.
20. Contact
Data-protection contact: privacy@finotive.com
Legal contact: legal@finotive.com
Support contact: support@finotive.com