Legal Centre

Privacy Policy

Last updated: 30 June 2026


1. Introduction

This Privacy Policy explains how Finotive One Limited and relevant Finotive group entities collect, use, store, share, transfer, and protect personal data when you visit Finotive.com, create a Finotive One account, complete onboarding or KYC, upload documents, access Finotive platforms, use Finotive services, communicate with us, or otherwise interact with the Finotive group.

This Privacy Policy should be read together with the Legal Disclosure, Finotive One Account, KYC and Data Sharing Notice, Cookie Policy, Website Terms of Use, Risk Disclosure, Restricted Jurisdictions page, and any product-specific terms that apply to the Finotive service you use.

2. Who we are

Finotive One Limited is a Cyprus-registered company with company number HE481670 and registered office at Office 113, Block A, Agios Pavlos Ct, 228 Archbishop Makarios III Ave, 3030 Limassol, Cyprus.

Finotive One Limited operates the central Finotive account, login, onboarding, identity verification, KYC, compliance, customer data, and group-access infrastructure used across the Finotive group.

The Finotive group includes Finotive Markets (MU) Limited, Finotive Pay (CY) Limited, Finotive Funding Technologies Limited, Finotive Futures Technologies Limited, and other group entities from time to time.

3. Controllers, joint controllers, and processors

For the creation and administration of the Finotive One account and for central account, KYC, compliance, customer-data, and group-access infrastructure, Finotive One Limited will generally act as a controller of your personal data.

Where a Finotive group entity determines why and how personal data is processed for its own product, account, legal obligation, regulatory obligation, payment activity, customer-support process, or risk-management function, that group entity may act as an independent controller or joint controller.

Where Finotive One Limited processes personal data only on documented instructions of another group entity, Finotive One Limited may act as a processor. Where two or more group entities jointly determine the purposes and means of processing, they may act as joint controllers and will determine their respective responsibilities as required by applicable law.

Data-protection contact: privacy@finotive.com

Data Protection Officer, if appointed: [insert DPO details or state “not appointed” after legal review]

4. Scope of this Privacy Policy

This Privacy Policy applies to personal data processed in connection with:

Product-specific privacy notices may apply to particular products or entities. Where a product-specific privacy notice applies, it should be read together with this Privacy Policy.

5. Personal data we collect

We may collect and process the following categories of personal data:

6. Sources of personal data

We may collect personal data directly from you, from your use of our website or platforms, from Finotive group entities, from identity-verification and KYC providers, from sanctions and fraud-screening providers, from payment providers, from trading-platform providers, from public sources, from business partners, from regulators or authorities, and from service providers that support Finotive services.

7. Purposes and legal bases

Where the GDPR or similar law applies, we rely on one or more legal bases for processing personal data. These may include performance of a contract, steps taken before entering into a contract, compliance with legal obligations, legitimate interests, consent, establishment or defence of legal claims, and, where applicable, substantial public interest or other lawful bases for special-category data.

PurposeExamples of data usedTypical legal basis
Account creation, login, authentication, and account administrationAccount data, contact data, technical dataContract; legitimate interests; security obligations
Onboarding, identity verification, KYC, AML, sanctions, PEP, adverse-media, and fraud checksIdentification data, KYC data, compliance data, technical dataLegal obligation; contract; legitimate interests; substantial public interest where applicable
Product eligibility and service accessAccount data, KYC data, jurisdiction data, product dataContract; legitimate interests; legal obligation
Payment administration, invoicing, refunds, and payoutsPayment data, tax data, account data, KYC dataContract; legal obligation; legitimate interests
Customer support and complaint handlingContact data, communications, account data, product dataContract; legitimate interests; legal obligation
Platform integrity, fraud prevention, cybersecurity, and risk managementTechnical data, account data, compliance data, usage dataLegitimate interests; legal obligation
Compliance with laws, regulations, court orders, law-enforcement requests, audits, and tax obligationsAccount data, KYC data, payment data, legal recordsLegal obligation; legitimate interests; legal claims
Service improvement, analytics, reporting, and internal governanceUsage data, technical data, account data, aggregated dataLegitimate interests; consent where required for non-essential cookies
Marketing communicationsContact data, preferences, usage dataConsent where required; legitimate interests where permitted; opt-out rights
Cookie and tracking technologiesCookie IDs, device data, analytics dataConsent for non-essential cookies; legitimate interests for strictly necessary cookies

8. Special-category and biometric data

Some KYC, liveness, fraud-prevention, or identity-verification processes may involve sensitive data, biometric-related information, or special-category data where applicable law treats such information as special-category data. We will process such data only where a lawful basis and any required additional condition applies, such as legal obligation, substantial public interest, explicit consent where required, prevention of fraud, establishment or defence of legal claims, or other permitted grounds under applicable law.

9. How we share personal data

We may share personal data with:

10. International transfers

Finotive One Limited is based in Cyprus. Finotive group entities and service providers may be located in Mauritius, the United Arab Emirates, the Dubai International Financial Centre, the European Economic Area, the United Kingdom, the United States, and other countries.

Where personal data is transferred outside the European Economic Area or another jurisdiction with transfer restrictions, we will use legally recognised transfer mechanisms where required. These may include adequacy decisions, standard contractual clauses, intra-group data-transfer arrangements, transfer risk assessments, contractual commitments, encryption, access controls, or other safeguards recognised by applicable law.

11. Retention

We retain personal data only for as long as necessary for the purposes for which it was collected or otherwise processed, including to provide services, maintain your account, comply with legal and regulatory obligations, complete audits, resolve disputes, prevent fraud, enforce agreements, and establish, exercise, or defend legal claims.

Retention periods depend on the type of data, the service used, the entity involved, legal and regulatory obligations, limitation periods, tax and accounting requirements, fraud-prevention needs, security requirements, audit requirements, and whether an account, complaint, investigation, dispute, or legal hold remains open.

Where we no longer need personal data, we will delete, anonymise, or securely archive it in accordance with applicable law and our retention procedures.

12. Security

We use technical and organisational measures designed to protect personal data against unauthorised access, loss, misuse, alteration, disclosure, or destruction. These measures may include access controls, authentication controls, encryption, monitoring, logging, network security, staff confidentiality obligations, vendor due diligence, incident-response processes, and data minimisation controls.

No online system is completely secure. You are responsible for keeping your login credentials secure and for notifying us promptly if you believe your account has been compromised.

13. Automated decision-making and profiling

We may use automated tools to support account security, identity verification, KYC, sanctions screening, PEP checks, fraud detection, duplicate-account detection, restricted-jurisdiction screening, payment review, payout review, account-rule monitoring, and eligibility assessment.

Automated checks may result in a request for more information, manual review, account restriction, service refusal, payout review, or account suspension. Where applicable law grants you rights in relation to solely automated decisions that produce legal or similarly significant effects, you may request human intervention, express your point of view, and contest the decision.

14. Marketing communications

We may send marketing communications where permitted by law. Where consent is required, we will ask for consent. You may opt out of marketing communications at any time by using the unsubscribe link in our emails or by contacting us at privacy@finotive.com. Service, account, legal, security, and transactional communications are not marketing communications and may continue where necessary.

15. Cookies

We use cookies and similar technologies as described in the Cookie Policy. Strictly necessary cookies are used to operate and secure the website and services. Non-essential cookies, such as analytics or marketing cookies, will be used where required only with your consent.

16. Your rights

Depending on your location and applicable law, you may have rights to:

These rights may be subject to limitations, exemptions, identity-verification requirements, and Finotive’s legal, regulatory, fraud-prevention, tax, accounting, audit, contractual, or legal-claims obligations.

To exercise rights, contact: privacy@finotive.com.

17. Complaints

If you have concerns about how we process your personal data, contact us first at privacy@finotive.com. You may also have the right to lodge a complaint with the relevant data-protection authority. For Cyprus, the supervisory authority is the Office of the Commissioner for Personal Data Protection.

18. Children

Finotive services are not intended for children or persons under the minimum age required to use the relevant service. We do not knowingly collect personal data from children. If we become aware that a child has provided personal data without appropriate authorisation, we may delete the data and restrict the account.

19. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. The updated version will be effective when published, unless otherwise stated. Where required by law, we may notify you of material changes.

20. Contact

Data-protection contact: privacy@finotive.com

Legal contact: legal@finotive.com

Support contact: support@finotive.com