1. Who is responsible for your data
"GCC Brokers Limited" is the name of two separate companies, and the one that holds your account is the controller of your personal data:
| GCC Brokers Limited (Mauritius) | Company number 193243. Licensed by the Financial Services Commission of Mauritius, Investment Dealer licence GB22200739. |
| GCC Brokers Limited (Saint Vincent and the Grenadines) | Company number 25578 BC 2019. |
If you are only browsing our website and do not hold an account, the Mauritius company is the controller.
Contact details for data protection enquiries are published on our website.
2. The law we work to
Where the Mauritius company is the controller, we process personal data in accordance with the Mauritius Data Protection Act 2017 and the requirements of the Financial Services Commission.
Where the EU or UK General Data Protection Regulation applies to our processing of your data — for example because you are in the EU or the UK — we also apply its requirements. We apply the same standards of protection to clients of both companies regardless of which one holds the account.
3. What we collect
3.1 Information you give us
- Identity — name, date of birth, nationality, gender, and the identity documents you provide.
- Contact — address, email address, telephone number.
- Financial and suitability — employment, income and net worth information, source of funds and source of wealth, trading knowledge and experience, and bank or payment details.
- Correspondence — everything you send us, including support messages, complaints and the content of dealing instructions.
3.2 Information generated by your use of our services
- Trading — orders, executions, positions, balances, statements.
- Technical — IP address, device and browser information, operating system, and time zone.
- Usage — pages visited, links followed, and how you navigate our site.
3.3 Recordings. We record telephone calls, and messages on any digital dealing channel we have approved for your account, together with the full order history retained by the trading platform. Clause 7.5 of the Client Agreement sets out why and how those records may be used.
3.4 Information from third parties — identity verification and sanctions screening providers, credit and fraud prevention agencies, payment providers, introducing brokers who refer you, and publicly available sources.
4. Why we use it, and on what basis
| What for | Basis |
|---|---|
| Opening and operating your account; executing your orders; processing payments | Performance of our contract with you |
| Identity verification, sanctions and PEP screening, transaction monitoring, suspicious activity reporting, record keeping | Compliance with our legal and regulatory obligations |
| Fraud prevention, securing our systems, managing risk, enforcing our rights, and establishing or defending legal claims | Our legitimate interests |
| Improving our services, and analysing how our website is used | Our legitimate interests |
| Sending you marketing about our services | Your consent, or our legitimate interests where the law permits |
Where our basis is legitimate interests, we have considered whether those interests are overridden by your rights, and you may object — see Section 8.
We do not make decisions producing legal or similarly significant effects about you by automated means without human involvement.
5. Who we share it with
- Service providers — technology and trading platform providers, hosting, identity verification and sanctions screening providers, communications and live-chat providers, all bound by confidentiality and permitted to use your data only as we instruct.
- Analytics and advertising providers — our website uses Google Analytics, and the Meta (Facebook) Pixel for advertising measurement. Data collected by the Meta Pixel is shared with Meta, who may combine it with information they already hold about you. Our Cookie Policy names every such service and explains how to control it.
- Banks and payment providers, to process deposits and withdrawals.
- Liquidity providers, where necessary in connection with our hedging — ordinarily without identifying you.
- Introducing brokers or affiliates connected to your account, limited to what is necessary for that relationship.
- Professional advisers — lawyers, auditors, accountants.
- Regulators, financial intelligence units, law enforcement, courts and tax authorities, where we are required or permitted to provide it. We may be legally prohibited from telling you when we have done so.
We do not sell your personal data.
6. Sending data outside Mauritius
Some of our service providers are located outside the jurisdiction of your controlling entity, where data protection law may differ.
Where we transfer your personal data internationally we do so only where a lawful basis for the transfer exists, and we take steps to ensure it remains appropriately protected — including contractual protections with the recipient.
7. How long we keep it
| Category | Period |
|---|---|
| Identity and verification records, transaction records, correspondence and internal financial-crime reports | At least 7 years after the end of the business relationship or completion of the transaction, as required by Mauritian law and our licence conditions |
| Call and message recordings of dealing instructions | Retained for the period required by applicable law and our record-keeping obligations |
| Applications that do not proceed to an account | Retained only as long as necessary to evidence our decision and meet our obligations |
| Website analytics and cookie data | See Section 10 |
We keep data for longer only where a legal claim, investigation or regulatory requirement makes it necessary. When it is no longer needed we delete it or anonymise it.
A request to delete your data cannot override the seven-year retention requirement. That is a legal obligation, not a choice.
8. Your rights
Subject to applicable law and to the limits below, you may:
- ask for a copy of the personal data we hold about you;
- ask us to correct data that is inaccurate or incomplete;
- ask us to delete data we no longer have a reason to hold;
- object to, or ask us to restrict, processing based on our legitimate interests;
- ask for your data in a portable form, where the right applies;
- withdraw consent at any time, where we rely on it; and
- complain to a data protection authority — for the Mauritius company, the Data Protection Office of Mauritius.
Limits. We cannot delete or stop processing data we are required to keep for identity verification, financial crime, record-keeping or regulatory reporting, and we may be unable to tell you about data connected to a suspicious activity report. We will always explain what we can.
To exercise a right, contact us using the details on our website. We will respond within one month. Where a request is complex we may extend that, and we will tell you if we do. We may need to verify your identity first, and we do not charge for a request unless it is manifestly unfounded or excessive.
9. Marketing
Where you receive marketing from us, every message contains a way to unsubscribe, and unsubscribing takes effect promptly. You may also tell us at any time to stop.
Opting out of marketing does not stop service messages — margin notices, statements, security alerts, policy changes and other communications we are required or need to send you about your account.
10. Cookies
We use cookies and similar technologies for functionality, security, preferences, analytics and advertising measurement. Our Cookie Policy sets out which cookies we use, what each is for, and how to control them. Most browsers allow you to block or delete cookies — though doing so may stop parts of our website working.
11. Third-party websites
Our website links to and embeds content from third parties, including charting, market data, review and analytics providers. Their handling of your data is governed by their own privacy policies, not this one, and we are not responsible for it.
12. Security
We maintain technical and organisational measures to protect personal data, including access controls, encryption in transit, and staff confidentiality obligations. No system is completely secure, and we cannot guarantee the security of information you send us over the internet — in particular unencrypted email is not a secure channel.
You are responsible for keeping your account credentials confidential. Clause 15.2 of the Client Agreement sets out how responsibility is allocated.
13. Children
Our services are not offered to anyone under 18, and we do not knowingly collect personal data from children.
14. Changes to this Policy
We may amend this Policy at any time by publishing an updated version on our website. Where a change is material we will tell you. The version published at the relevant time applies.
15. Contact
Data protection enquiries and requests can be sent to us using the details published on our website.