GDPR Compliant

GDPR Compliance

Easyfortunetrades is fully committed to protecting your personal data in accordance with the General Data Protection Regulation (GDPR). This page explains your rights and how we uphold them.

Last updated: June 15, 2026

1. What is GDPR?

The General Data Protection Regulation (GDPR) is a comprehensive data protection law that came into effect on May 25, 2018, across the European Union and European Economic Area. It establishes strict rules for how organizations collect, process, store, and transfer personal data of individuals within the EU/EEA. GDPR grants individuals significant rights over their personal data and imposes substantial penalties for non-compliance up to €20 million or 4% of global annual turnover, whichever is higher.

Although Easyfortunetrades serves clients globally, we extend GDPR-level protections to all our users regardless of their location, because we believe privacy is a universal right.

2. Our Commitment

Easyfortunetrades is committed to the following GDPR principles:

  • Lawfulness, Fairness & Transparency: We process personal data lawfully, fairly, and in a transparent manner.
  • Purpose Limitation: Data is collected for specified, explicit, and legitimate purposes only.
  • Data Minimization: We collect only the data that is adequate, relevant, and limited to what is necessary.
  • Accuracy: We maintain accurate and up-to-date personal data, with mechanisms to rectify errors promptly.
  • Storage Limitation: Data is kept no longer than necessary for the purposes for which it was collected.
  • Integrity & Confidentiality: We process data securely using appropriate technical and organizational measures.
  • Accountability: We take responsibility for compliance and can demonstrate it at any time.

3. Your Rights Under GDPR

GDPR grants you the following rights regarding your personal data:

Right of Access

You can request a copy of all personal data we hold about you, along with information about how it is processed.

Right to Rectification

You can request correction of inaccurate or incomplete personal data without undue delay.

Right to Erasure

Also known as the "right to be forgotten," you can request deletion of your data where there is no compelling reason for continued processing.

Right to Restriction

You can request that we limit how your data is processed in certain circumstances, such as while a dispute is being resolved.

Right to Data Portability

You can receive your personal data in a structured, commonly used, machine-readable format and transmit it to another controller.

Right to Object

You can object to processing based on legitimate interests, direct marketing, or processing for research/statistical purposes.

Automated Decision-Making

You have the right not to be subject to decisions based solely on automated processing that produce legal effects concerning you.

Right to Complain

You have the right to lodge a complaint with a supervisory authority if you believe your data protection rights have been violated.

5. Data We Collect

We collect only the personal data necessary to provide our services and comply with legal obligations:

  • Identity Data: Full name, date of birth, nationality, government ID numbers.
  • Contact Data: Email address, phone number, residential address.
  • Financial Data: Bank account details, wallet addresses, transaction history, portfolio data.
  • Technical Data: IP address, browser type, device identifiers, login timestamps.
  • Verification Data: KYC documents (passport, driver's license, utility bills).
  • Usage Data: Platform interaction data, feature usage patterns, preference settings.

For complete details, please review our Privacy Policy.

6. How We Use Your Data

We process your personal data for the following specific purposes:

  • Creating, maintaining, and securing your investment account.
  • Processing deposits, withdrawals, and all financial transactions.
  • Conducting KYC verification and ongoing AML monitoring.
  • Communicating service updates, security alerts, and account notifications.
  • Providing customer support and responding to inquiries.
  • Improving platform features, performance, and user experience.
  • Detecting and preventing fraud, unauthorized access, and illegal activities.
  • Complying with legal and regulatory obligations in applicable jurisdictions.

7. International Data Transfers

As a global platform, your data may be transferred to and processed in countries outside the EU/EEA. When we transfer data internationally, we ensure appropriate safeguards are in place, including:

  • Adequacy Decisions: Transfers to countries recognized by the EU Commission as providing adequate data protection.
  • Standard Contractual Clauses (SCCs): EU-approved model contracts ensuring equivalent data protection standards.
  • Binding Corporate Rules: Internal data protection policies approved by EU supervisory authorities.
  • Technical Measures: Encryption, pseudonymization, and access controls applied to all transferred data.

You may request a copy of the specific safeguards applicable to your data by contacting our Data Protection Officer.

8. Data Protection Officer

We have appointed a Data Protection Officer (DPO) responsible for overseeing our GDPR compliance and serving as your primary contact for data protection matters. The DPO's responsibilities include:

  • Monitoring compliance with GDPR and other data protection laws.
  • Advising on data protection impact assessments (DPIAs).
  • Serving as the point of contact for data subjects and supervisory authorities.
  • Managing and responding to data subject access requests (DSARs).
  • Overseeing data breach response and notification procedures.
  • Conducting regular data protection training for all staff members.

DPO Contact

[email protected]

Response Time

Within 30 days (as required by GDPR)

9. Breach Notification

In the event of a personal data breach, we have established procedures to detect, investigate, and respond promptly. Under GDPR, we are required to notify the relevant supervisory authority within 72 hours of becoming aware of a breach that poses a risk to individuals' rights and freedoms. If the breach is likely to result in high risk to your rights and freedoms, we will notify you without undue delay, describing the nature of the breach, likely consequences, and measures taken to address it.

All breaches are documented in an internal register, regardless of whether notification is required.

10. How to Exercise Your Rights

To exercise any of your GDPR rights, follow these steps:

  1. Submit Your Request

    Email us at [email protected] with the subject line "GDPR Request - [Your Right]" (e.g., "GDPR Request - Right of Access"). Include your full name and registered email address.

  2. Identity Verification

    We will verify your identity to protect your data from unauthorized access. This may require providing additional documentation.

  3. Processing Your Request

    We will respond within 30 calendar days. Complex or numerous requests may require an extension of up to 60 days, in which case we will inform you within the first 30 days.

  4. No Fee (Generally)

    Requests are free of charge. However, we may charge a reasonable fee or refuse to act on requests that are manifestly unfounded, excessive, or repetitive.

Submit GDPR Requests

[email protected]

Supervisory Authority

Your local EU data protection authority

GDPR Response Deadline

Within 30 calendar days

Your data, your rights, our responsibility

We're committed to protecting your privacy and upholding the highest data protection standards.

Fully compliant with GDPR and global privacy regulations.