Legal document
Privacy Notice
v1.0 · 2026-07-11- Version
- v1.0
- Last updated
- 2026-07-11
- Effective
- 2026-07-11
We collect the data we need to run the brokerage, meet our AML obligations, and provide services. We don't sell personal data. This notice explains what we collect, how long we keep it, who we share it with, and how to exercise your rights under UK data protection law.
1. Data controller
The data controller responsible for personal data processed in connection with the services described in this notice is TFC Funder Ltd (Company No. 17173699), a company incorporated in England and Wales, trading as TFC Global Markets (the "firm", "we", "our", "us"). References in this notice to "you" or "the client" are references to the natural person whose personal data we process, whether as a prospective client, an account holder, an authorised representative of an account holder, or a visitor to our websites.
This notice applies to processing carried out by the firm through the website at https://www.tfcglobalmarkets.com and any subdomains, our trading platforms and mobile applications, our client onboarding tools, and our client communications channels.
2. Contact for data queries
Questions about this notice, requests to exercise the rights described in Section 10, and other data protection queries should be sent to our Data Protection contact at dpo@tfcglobalmarkets.com. General account and support queries should be sent to support@tfcglobalmarkets.com; matters relating to anti-money-laundering compliance should be sent to aml@tfcglobalmarkets.com; legal notices should be sent to legal@tfcglobalmarkets.com.
We aim to respond to data subject requests within one month of receipt. Where a request is complex or where we receive a number of requests from the same individual, we may extend this period by up to a further two months and will notify you of the extension and the reasons for it.
3. Categories of personal data we collect
We process the following categories of personal data:
3.1 Identity Data, including your full legal name, date of birth, nationality, country of residence, gender where you provide it, and government-issued identification numbers and images (passport, national identity card, driving licence).
3.2 Contact Data, including your residential address, email address, telephone number, and, where you provide them, alternative correspondence details.
3.3 Financial Data, including your source of funds and source of wealth information, employment and income details declared during onboarding, bank account and mobile-money wallet identifiers, card details tokenised by our payment processors, cryptocurrency wallet addresses used for deposits and withdrawals, deposit and withdrawal history, account balances, and equity and margin positions.
3.4 Trading Data, including order records, execution records, position history, profit and loss on realised and unrealised positions, use of leverage, contract for difference (CFD) exposures across the twenty currency-venue instruments and the in-house Volatility Indices (Alpha, Delta, and Sigma families) and Surge Indices (SRU 300 and 600, SRD 300 and 600) we offer, and any copy trading relationships you enter into as a follower or as a signal provider.
3.5 Communications Data, including the content and metadata of emails, in-application messages, chat transcripts, and where recording is disclosed, telephone conversations, together with support tickets and complaints correspondence.
3.6 Technical Data, including internet protocol (IP) address, device identifiers, browser type and version, operating system, time-zone setting, language preferences, referring pages, session identifiers, and platform telemetry generated by your use of our websites, platforms, and applications.
3.7 Marketing Preferences Data, including your opt-in and opt-out choices for direct marketing, product notifications, market commentary, and educational content, together with your interaction history with any marketing communications we send.
We do not knowingly collect special-category personal data, and we ask that you do not submit such data to us unless we specifically request it in the context of an accessibility need or an accommodation request.
4. How we collect personal data
We collect personal data from the following sources:
4.1 Directly from you, when you register for a demo account, complete an application for a real-money account, use our onboarding tools, contact our support team, respond to a client survey, or otherwise interact with the firm.
4.2 From third-party verification providers, in the course of identity verification, address verification, document authenticity checks, sanctions and politically-exposed-person screening, and adverse-media screening. These providers may in turn source data from public registers, credit reference bureaux, watchlist databases, and biometric verification technologies.
4.3 From payment rails and payment service providers, in the course of processing your deposits and withdrawals. This includes card processing through Stripe, mobile-money processing through Finivex across EcoCash, M-Pesa, MTN MoMo, Airtel Money, and Orange Money, and cryptocurrency settlement through NOWPayments.
4.4 Automatically, through cookies, similar technologies, and platform telemetry when you visit our websites or use our platforms. See Section 12 for further detail.
4.5 From publicly available sources and third parties, where we conduct due diligence, investigate suspected fraud, respond to a legal or regulatory request, or where a copy trading signal provider elects to make certain performance information available.
5. Legal bases for processing
We process personal data on the following legal bases, as those bases are defined in the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018:
5.1 Performance of a contract. Processing of Identity Data, Contact Data, Financial Data, and Trading Data to the extent necessary to enter into, perform, and administer the Client Agreement, to open and maintain accounts, to execute orders, and to settle transactions.
5.2 Compliance with a legal obligation. Processing of Identity Data, Contact Data, Financial Data, Trading Data, and Communications Data to the extent necessary to comply with anti-money-laundering and counter-terrorist-financing record-keeping practice, tax reporting where applicable, court orders, and lawful requests from law-enforcement or regulatory authorities.
5.3 Legitimate interests. Processing of Trading Data, Communications Data, and Technical Data for the purposes of fraud prevention, security, safeguarding of the firm's systems and clients, dispute resolution, internal reporting and management, product improvement using aggregated or anonymised data, and defence of legal claims. Where we rely on legitimate interests, we have assessed that our interests are not overridden by your rights and freedoms; you may object to this processing as described in Section 10.
5.4 Consent. Processing of Marketing Preferences Data for direct marketing that requires consent, use of non-essential cookies, and any other processing for which consent is the appropriate basis. Consent may be withdrawn at any time without affecting the lawfulness of processing carried out before withdrawal.
Where you decline to provide personal data that is necessary for the performance of a contract or for compliance with a legal obligation, we may be unable to open or continue your account.
6. Purposes of processing
We process personal data for the following purposes:
6.1 Providing services, including account opening, account administration, quotation and pricing, order routing and execution, position management, margin calculation, close-out, funding, settlement, statement production, and reporting.
6.2 KYC and AML compliance, including identity and address verification, sanctions and politically-exposed-person screening, adverse-media screening, source-of-funds and source-of-wealth checks, ongoing customer due diligence, transaction monitoring, and reporting of suspicious activity where required. See our AML and KYC Policy at /legal/aml-kyc.
6.3 Order execution and settlement, including transmitting orders to liquidity venues for currency-venue instruments, generating quotes on the firm's synthetic price engine for the in-house Volatility Indices and Surge Indices, matching copy trading follower orders to signal-provider actions, and settling resulting positions. See our Order Execution Policy at /legal/order-execution-policy.
6.4 Client communications, including sending transactional notifications, service messages, statements, margin and close-out notifications, and responses to your queries.
6.5 Security and fraud prevention, including authentication, session management, detection of unauthorised access, detection and prevention of platform abuse, detection and prevention of payment fraud, and defence against cyber-attack.
6.6 Marketing, including sending product updates, market commentary, and educational content to clients and prospects who have consented to receive them, and measuring the effectiveness of marketing communications.
6.7 Product improvement, including the analysis of aggregated or anonymised usage data to understand how our platforms are used and to inform product development.
6.8 Regulatory or legal requests, including responding to court orders, subpoenas, requests from law-enforcement authorities acting within their jurisdiction, and requests from tax authorities where legally required.
8. International transfers
The firm is incorporated in England and Wales, and our services are provided to clients in a wide range of jurisdictions. In the course of providing services, we transfer personal data to recipients located outside the United Kingdom, including in jurisdictions that have not received an adequacy decision from the United Kingdom.
Where such transfers occur, we rely on appropriate safeguards to protect your personal data, including the International Data Transfer Agreement or the International Data Transfer Addendum to the European Commission's standard contractual clauses, adequacy regulations where they apply, and, where relevant, additional technical, contractual, and organisational measures. Details of the safeguards applied to a particular transfer are available on request to dpo@tfcglobalmarkets.com.
9. Retention
We retain personal data only for as long as necessary for the purposes for which it was collected, subject to the following general periods:
9.1 Identity Data, Financial Data, and Trading Data relating to a client relationship are retained for seven years following the closure of the account, consistent with established anti-money-laundering record-keeping practice. Records subject to a pending investigation, complaint, or legal claim are retained for such longer period as is necessary.
9.2 Communications Data is retained for seven years following the closure of the account, or, in the case of prospects who did not open an account, for two years from the last communication.
9.3 Marketing Preferences Data is retained until you withdraw consent or object to marketing, and thereafter for a period sufficient to evidence the withdrawal.
9.4 Technical Data collected for security and platform-operations purposes is retained for shorter periods calibrated to the specific purpose, typically not exceeding twenty-four months, save where retained as part of a security investigation.
Following the applicable retention period, personal data is deleted or anonymised.
10. Data subject rights
Subject to the conditions and exceptions set out in UK data protection law, you have the following rights in respect of your personal data:
10.1 The right of access to a copy of the personal data we hold about you, together with information about how we process it.
10.2 The right to rectification of personal data that is inaccurate or incomplete.
10.3 The right to erasure of personal data, subject to our overriding obligations to retain records for legal, regulatory, or record-keeping purposes as described in Section 9.
10.4 The right to restriction of processing in certain circumstances, including where you contest the accuracy of the data or object to processing carried out on the basis of legitimate interests.
10.5 The right to portability of personal data you have provided to us in a structured, commonly used, and machine-readable format, where the processing is carried out on the basis of consent or contract and by automated means.
10.6 The right to object to processing carried out on the basis of legitimate interests, and an absolute right to object to processing for direct marketing purposes.
10.7 The right to withdraw consent to processing based on consent, without affecting the lawfulness of processing carried out before withdrawal.
10.8 The right to lodge a complaint with a supervisory authority. In the United Kingdom, the supervisory authority is the Information Commissioner's Office (ICO), whose contact details are published at ico.org.uk. You are also entitled to lodge a complaint with the supervisory authority in the country of your habitual residence.
To exercise any of these rights, please contact dpo@tfcglobalmarkets.com. We may need to verify your identity before responding, and we may charge a reasonable fee, or refuse to act, where a request is manifestly unfounded or excessive.
11. Automated decision-making
We use automated processing in the following limited contexts:
11.1 Sanctions, PEP, and adverse-media screening. Names and identifiers are matched against third-party screening databases. Positive or possible matches are reviewed by a member of the compliance team before any decision affecting the client is taken.
11.2 Risk-scoring during onboarding. Onboarding data is used to produce an internal risk score that informs the level of due diligence applied to the account. The score itself does not determine account approval; approval decisions are taken with human review.
11.3 Transaction monitoring. Deposits, withdrawals, and trading activity are monitored for patterns that may indicate financial crime, market abuse, or platform abuse. Alerts are reviewed by a member of the compliance team before any action is taken against an account.
11.4 Platform-integrity signals. Automated signals are used to detect suspected fraudulent registrations, multi-account abuse, and unauthorised access. Actions such as account suspension pending review may be taken automatically to protect the firm and other clients; the affected client is given the opportunity to make representations before any final decision is confirmed.
We do not carry out solely automated decision-making that produces legal effects concerning you, or similarly significantly affects you, without human involvement, save where such processing is necessary for the entry into or performance of a contract with you or is authorised by law and is subject to suitable safeguards.
13. Children
Our services are not directed at, or offered to, persons under the age of eighteen, and we do not knowingly process the personal data of children. If we become aware that we have collected personal data from a person under the age of eighteen, we will close the account, delete the data in accordance with our retention practice, and, where applicable, reverse any transactions carried out on the account.
14. Security measures
We maintain a range of technical and organisational measures designed to protect personal data against unauthorised or unlawful processing and against accidental loss, destruction, or damage. These include:
14.1 Encryption in transit for communications between clients, our websites, our platforms, our internal services, and our processors.
14.2 Encryption at rest for personal data held in our databases and object storage, using industry-standard cryptographic controls.
14.3 Access controls, including role-based access, least-privilege provisioning, multi-factor authentication for personnel and administrative interfaces, and periodic access reviews.
14.4 Audit logs of privileged actions on production systems, retained for security-investigation purposes.
14.5 Segregation of client funds from the firm's operating accounts as a matter of operational practice, and segregation of production data from development and testing environments.
14.6 Personnel measures, including confidentiality obligations, security training, and background screening proportionate to role.
No system of security is impregnable, and we cannot guarantee the absolute security of personal data. Where a personal-data breach is likely to result in a risk to the rights and freedoms of affected individuals, we will notify the Information Commissioner's Office and, where required, affected individuals, in accordance with UK data protection law.
15. Changes to this notice
We may update this notice from time to time to reflect changes in our services, our processing practices, applicable law, or third-party arrangements. Where a change is material, we will notify clients by email or through an in-application notification in advance of the change taking effect. The version in force at any time is the version published at /legal/privacy, together with the "Last updated" date shown at the top of this notice.
16. Contact
Data protection queries and requests to exercise the rights described in Section 10 should be addressed to dpo@tfcglobalmarkets.com. Postal correspondence may be sent to TFC Funder Ltd (Company No. 17173699), England and Wales, marked for the attention of the Data Protection contact. General enquiries should be addressed to support@tfcglobalmarkets.com.
This document is in draft pending review by UK financial services counsel. Sections marked with an amber Draft badge contain placeholder text and are not final. Finalized versions go live before we open to traders. Questions: compliance@tfcglobalmarkets.com.