tfc global markets

Legal document

Privacy Notice

v1.0 · 2026-07-11
Version
v1.0
Last updated
2026-07-11
Effective
2026-07-11
In plain English

We collect the data we need to run the brokerage, meet our AML obligations, and provide services. We don't sell personal data. This notice explains what we collect, how long we keep it, who we share it with, and how to exercise your rights under UK data protection law.

1. Data controller

The data controller responsible for personal data processed in connection with the services described in this notice is TFC Funder Ltd (Company No. 17173699), a company incorporated in England and Wales, trading as TFC Global Markets (the "firm", "we", "our", "us"). References in this notice to "you" or "the client" are references to the natural person whose personal data we process, whether as a prospective client, an account holder, an authorised representative of an account holder, or a visitor to our websites.

This notice applies to processing carried out by the firm through the website at https://www.tfcglobalmarkets.com and any subdomains, our trading platforms and mobile applications, our client onboarding tools, and our client communications channels.

2. Contact for data queries

Questions about this notice, requests to exercise the rights described in Section 10, and other data protection queries should be sent to our Data Protection contact at dpo@tfcglobalmarkets.com. General account and support queries should be sent to support@tfcglobalmarkets.com; matters relating to anti-money-laundering compliance should be sent to aml@tfcglobalmarkets.com; legal notices should be sent to legal@tfcglobalmarkets.com.

We aim to respond to data subject requests within one month of receipt. Where a request is complex or where we receive a number of requests from the same individual, we may extend this period by up to a further two months and will notify you of the extension and the reasons for it.

3. Categories of personal data we collect

We process the following categories of personal data:

3.1 Identity Data, including your full legal name, date of birth, nationality, country of residence, gender where you provide it, and government-issued identification numbers and images (passport, national identity card, driving licence).

3.2 Contact Data, including your residential address, email address, telephone number, and, where you provide them, alternative correspondence details.

3.3 Financial Data, including your source of funds and source of wealth information, employment and income details declared during onboarding, bank account and mobile-money wallet identifiers, card details tokenised by our payment processors, cryptocurrency wallet addresses used for deposits and withdrawals, deposit and withdrawal history, account balances, and equity and margin positions.

3.4 Trading Data, including order records, execution records, position history, profit and loss on realised and unrealised positions, use of leverage, contract for difference (CFD) exposures across the twenty currency-venue instruments and the in-house Volatility Indices (Alpha, Delta, and Sigma families) and Surge Indices (SRU 300 and 600, SRD 300 and 600) we offer, and any copy trading relationships you enter into as a follower or as a signal provider.

3.5 Communications Data, including the content and metadata of emails, in-application messages, chat transcripts, and where recording is disclosed, telephone conversations, together with support tickets and complaints correspondence.

3.6 Technical Data, including internet protocol (IP) address, device identifiers, browser type and version, operating system, time-zone setting, language preferences, referring pages, session identifiers, and platform telemetry generated by your use of our websites, platforms, and applications.

3.7 Marketing Preferences Data, including your opt-in and opt-out choices for direct marketing, product notifications, market commentary, and educational content, together with your interaction history with any marketing communications we send.

We do not knowingly collect special-category personal data, and we ask that you do not submit such data to us unless we specifically request it in the context of an accessibility need or an accommodation request.

4. How we collect personal data

We collect personal data from the following sources:

4.1 Directly from you, when you register for a demo account, complete an application for a real-money account, use our onboarding tools, contact our support team, respond to a client survey, or otherwise interact with the firm.

4.2 From third-party verification providers, in the course of identity verification, address verification, document authenticity checks, sanctions and politically-exposed-person screening, and adverse-media screening. These providers may in turn source data from public registers, credit reference bureaux, watchlist databases, and biometric verification technologies.

4.3 From payment rails and payment service providers, in the course of processing your deposits and withdrawals. This includes card processing through Stripe, mobile-money processing through Finivex across EcoCash, M-Pesa, MTN MoMo, Airtel Money, and Orange Money, and cryptocurrency settlement through NOWPayments.

4.4 Automatically, through cookies, similar technologies, and platform telemetry when you visit our websites or use our platforms. See Section 12 for further detail.

4.5 From publicly available sources and third parties, where we conduct due diligence, investigate suspected fraud, respond to a legal or regulatory request, or where a copy trading signal provider elects to make certain performance information available.

6. Purposes of processing

We process personal data for the following purposes:

6.1 Providing services, including account opening, account administration, quotation and pricing, order routing and execution, position management, margin calculation, close-out, funding, settlement, statement production, and reporting.

6.2 KYC and AML compliance, including identity and address verification, sanctions and politically-exposed-person screening, adverse-media screening, source-of-funds and source-of-wealth checks, ongoing customer due diligence, transaction monitoring, and reporting of suspicious activity where required. See our AML and KYC Policy at /legal/aml-kyc.

6.3 Order execution and settlement, including transmitting orders to liquidity venues for currency-venue instruments, generating quotes on the firm's synthetic price engine for the in-house Volatility Indices and Surge Indices, matching copy trading follower orders to signal-provider actions, and settling resulting positions. See our Order Execution Policy at /legal/order-execution-policy.

6.4 Client communications, including sending transactional notifications, service messages, statements, margin and close-out notifications, and responses to your queries.

6.5 Security and fraud prevention, including authentication, session management, detection of unauthorised access, detection and prevention of platform abuse, detection and prevention of payment fraud, and defence against cyber-attack.

6.6 Marketing, including sending product updates, market commentary, and educational content to clients and prospects who have consented to receive them, and measuring the effectiveness of marketing communications.

6.7 Product improvement, including the analysis of aggregated or anonymised usage data to understand how our platforms are used and to inform product development.

6.8 Regulatory or legal requests, including responding to court orders, subpoenas, requests from law-enforcement authorities acting within their jurisdiction, and requests from tax authorities where legally required.

7. Sharing with third parties

We share personal data with the following categories of recipient:

7.1 Payment processors. Stripe (card payments), Finivex (mobile-money rails), and NOWPayments (cryptocurrency settlement). Each processor receives the data necessary to authorise, capture, settle, and refund transactions.

7.2 KYC and verification providers. Identity verification, document authenticity, sanctions screening, and biometric verification providers. Each provider receives the data necessary to perform the check requested.

7.3 Hosting and infrastructure providers. Cloud hosting providers, content-delivery networks, database providers, email delivery providers, monitoring providers, and analytics providers, each of which processes personal data only in accordance with our instructions and under written data-processing terms.

7.4 Professional advisers. Auditors, accountants, tax advisers, lawyers, and other professional advisers, on terms of confidentiality.

7.5 Law-enforcement and regulatory bodies. Where we are required to do so by law, court order, or the lawful request of a competent authority, or where disclosure is necessary to protect the firm's rights, the safety of our clients, or the integrity of our services.

7.6 Successors in business. In the event of a corporate reorganisation, sale, merger, or transfer of all or a material part of the firm's business or assets, personal data may be transferred to the counterparty on terms consistent with this notice.

We do not sell personal data.

8. International transfers

The firm is incorporated in England and Wales, and our services are provided to clients in a wide range of jurisdictions. In the course of providing services, we transfer personal data to recipients located outside the United Kingdom, including in jurisdictions that have not received an adequacy decision from the United Kingdom.

Where such transfers occur, we rely on appropriate safeguards to protect your personal data, including the International Data Transfer Agreement or the International Data Transfer Addendum to the European Commission's standard contractual clauses, adequacy regulations where they apply, and, where relevant, additional technical, contractual, and organisational measures. Details of the safeguards applied to a particular transfer are available on request to dpo@tfcglobalmarkets.com.

9. Retention

We retain personal data only for as long as necessary for the purposes for which it was collected, subject to the following general periods:

9.1 Identity Data, Financial Data, and Trading Data relating to a client relationship are retained for seven years following the closure of the account, consistent with established anti-money-laundering record-keeping practice. Records subject to a pending investigation, complaint, or legal claim are retained for such longer period as is necessary.

9.2 Communications Data is retained for seven years following the closure of the account, or, in the case of prospects who did not open an account, for two years from the last communication.

9.3 Marketing Preferences Data is retained until you withdraw consent or object to marketing, and thereafter for a period sufficient to evidence the withdrawal.

9.4 Technical Data collected for security and platform-operations purposes is retained for shorter periods calibrated to the specific purpose, typically not exceeding twenty-four months, save where retained as part of a security investigation.

Following the applicable retention period, personal data is deleted or anonymised.

10. Data subject rights

Subject to the conditions and exceptions set out in UK data protection law, you have the following rights in respect of your personal data:

10.1 The right of access to a copy of the personal data we hold about you, together with information about how we process it.

10.2 The right to rectification of personal data that is inaccurate or incomplete.

10.3 The right to erasure of personal data, subject to our overriding obligations to retain records for legal, regulatory, or record-keeping purposes as described in Section 9.

10.4 The right to restriction of processing in certain circumstances, including where you contest the accuracy of the data or object to processing carried out on the basis of legitimate interests.

10.5 The right to portability of personal data you have provided to us in a structured, commonly used, and machine-readable format, where the processing is carried out on the basis of consent or contract and by automated means.

10.6 The right to object to processing carried out on the basis of legitimate interests, and an absolute right to object to processing for direct marketing purposes.

10.7 The right to withdraw consent to processing based on consent, without affecting the lawfulness of processing carried out before withdrawal.

10.8 The right to lodge a complaint with a supervisory authority. In the United Kingdom, the supervisory authority is the Information Commissioner's Office (ICO), whose contact details are published at ico.org.uk. You are also entitled to lodge a complaint with the supervisory authority in the country of your habitual residence.

To exercise any of these rights, please contact dpo@tfcglobalmarkets.com. We may need to verify your identity before responding, and we may charge a reasonable fee, or refuse to act, where a request is manifestly unfounded or excessive.

11. Automated decision-making

We use automated processing in the following limited contexts:

11.1 Sanctions, PEP, and adverse-media screening. Names and identifiers are matched against third-party screening databases. Positive or possible matches are reviewed by a member of the compliance team before any decision affecting the client is taken.

11.2 Risk-scoring during onboarding. Onboarding data is used to produce an internal risk score that informs the level of due diligence applied to the account. The score itself does not determine account approval; approval decisions are taken with human review.

11.3 Transaction monitoring. Deposits, withdrawals, and trading activity are monitored for patterns that may indicate financial crime, market abuse, or platform abuse. Alerts are reviewed by a member of the compliance team before any action is taken against an account.

11.4 Platform-integrity signals. Automated signals are used to detect suspected fraudulent registrations, multi-account abuse, and unauthorised access. Actions such as account suspension pending review may be taken automatically to protect the firm and other clients; the affected client is given the opportunity to make representations before any final decision is confirmed.

We do not carry out solely automated decision-making that produces legal effects concerning you, or similarly significantly affects you, without human involvement, save where such processing is necessary for the entry into or performance of a contract with you or is authorised by law and is subject to suitable safeguards.

12. Cookies and similar technologies

Our websites and platforms use cookies and similar technologies for three purposes:

12.1 Essential cookies, which are strictly necessary to provide the services you have requested (including authentication, session management, and load-balancing). These cookies cannot be disabled without impairing the operation of our services.

12.2 Analytics cookies, which help us understand how our websites and platforms are used, on an aggregated basis, so that we can improve them. These cookies are set only with your consent.

12.3 Marketing cookies, which support the delivery and measurement of marketing communications. These cookies are set only with your consent.

You may accept or reject non-essential cookies through the cookie banner presented on first visit and through the cookie preferences control available on the website. You may also manage cookies through your browser settings. Rejecting non-essential cookies does not prevent you from opening or operating an account.

13. Children

Our services are not directed at, or offered to, persons under the age of eighteen, and we do not knowingly process the personal data of children. If we become aware that we have collected personal data from a person under the age of eighteen, we will close the account, delete the data in accordance with our retention practice, and, where applicable, reverse any transactions carried out on the account.

14. Security measures

We maintain a range of technical and organisational measures designed to protect personal data against unauthorised or unlawful processing and against accidental loss, destruction, or damage. These include:

14.1 Encryption in transit for communications between clients, our websites, our platforms, our internal services, and our processors.

14.2 Encryption at rest for personal data held in our databases and object storage, using industry-standard cryptographic controls.

14.3 Access controls, including role-based access, least-privilege provisioning, multi-factor authentication for personnel and administrative interfaces, and periodic access reviews.

14.4 Audit logs of privileged actions on production systems, retained for security-investigation purposes.

14.5 Segregation of client funds from the firm's operating accounts as a matter of operational practice, and segregation of production data from development and testing environments.

14.6 Personnel measures, including confidentiality obligations, security training, and background screening proportionate to role.

No system of security is impregnable, and we cannot guarantee the absolute security of personal data. Where a personal-data breach is likely to result in a risk to the rights and freedoms of affected individuals, we will notify the Information Commissioner's Office and, where required, affected individuals, in accordance with UK data protection law.

15. Changes to this notice

We may update this notice from time to time to reflect changes in our services, our processing practices, applicable law, or third-party arrangements. Where a change is material, we will notify clients by email or through an in-application notification in advance of the change taking effect. The version in force at any time is the version published at /legal/privacy, together with the "Last updated" date shown at the top of this notice.

16. Contact

Data protection queries and requests to exercise the rights described in Section 10 should be addressed to dpo@tfcglobalmarkets.com. Postal correspondence may be sent to TFC Funder Ltd (Company No. 17173699), England and Wales, marked for the attention of the Data Protection contact. General enquiries should be addressed to support@tfcglobalmarkets.com.

This document is in draft pending review by UK financial services counsel. Sections marked with an amber Draft badge contain placeholder text and are not final. Finalized versions go live before we open to traders. Questions: compliance@tfcglobalmarkets.com.