Privacy Policy

Your privacy is important to us. This Privacy Policy explains how we collect, use, and protect your information when you use our trading platform.

Last Updated: September 2025
Trading Risk Warning

Trading CFDs and other leveraged products involves significant risk and can result in the loss of your invested capital. This Privacy Policy applies to our data practices only and does not constitute financial advice. Please read our Risk Disclosure for information about trading risks.

Table of Contents
  • 1
    Information We Collect
  • 2
    How We Use Your Information
  • 3
    Information Sharing and Disclosure
  • 4
    Data Security
  • 5
    Cookies and Tracking
  • 6
    Your Rights and Choices
  • 7
    Data Retention
  • 8
    Policy Updates

1
Information We Collect

1.1 Personal Information

When you register for a MitheralFX account or use our services, we collect personal information that you voluntarily provide, including:

  • Identity Information: Full name, date of birth, and contact details
  • Contact Information: Email address, phone number, and physical address
  • Financial Information: Bank account details and payment method information
  • Trading Information: Account activity and transaction history

1.2 Automatically Collected Information

We automatically collect certain information when you use our platform:

  • Device Information: IP address, browser type, and operating system
  • Usage Data: Pages visited and time spent on our platform
  • Technical Data: Log files and error reports for system maintenance

1.3 Third-Party Information

We may obtain information from third-party sources for verification and compliance purposes:

  • Identity verification services for account verification
  • Payment processors for transaction processing

2
How We Use Your Information

2.1 Service Provision

We use your information to provide and maintain our trading services:

  • Account registration and verification
  • Processing deposits and withdrawals
  • Providing access to trading tools

2.2 Legal and Regulatory Compliance

We process your information to comply with legal obligations:

  • Identity verification procedures
  • Record-keeping requirements
  • Compliance with applicable regulations

2.3 Communication and Support

We use your contact information for:

  • Account notifications and security alerts
  • Customer support and technical assistance
  • Important policy and service changes
Data Processing Legal Basis

We process your personal data based on: (1) your consent, (2) performance of our contract with you, (3) compliance with legal obligations, and (4) our legitimate interests in providing trading services.

3
Information Sharing and Disclosure

3.1 Service Providers

We share information with trusted third-party service providers who assist in our operations:

  • Payment Processors: For processing deposits and withdrawals
  • Identity Verification Services: For account verification
  • Cloud Infrastructure Providers: For secure data storage
  • Customer Support Tools: For providing customer service

3.2 Regulatory and Legal Requirements

We may disclose your information when required by law or regulation:

  • To regulatory authorities and government agencies
  • To law enforcement agencies for legitimate investigations
  • In response to valid legal process
  • To prevent fraud or other illegal activities

3.3 Business Transfers

In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of the transaction. We will notify you of any such transfer and any changes to this Privacy Policy.

No Sale of Personal Data

We do not sell, rent, or lease your personal information to third parties for their marketing purposes. All data sharing is limited to the purposes described in this policy.

4
Data Security

4.1 Security Measures

We implement security measures to protect your information:

  • Encryption: Data transmissions are encrypted using TLS 1.3
  • Data Storage: Personal data is encrypted at rest
  • Access Controls: Limited employee access to personal data
  • Authentication: Multi-factor authentication for account access
  • Monitoring: Security monitoring and intrusion detection

4.2 Employee Training

Employees with access to personal data undergo privacy and security training. Access is limited to those who need it for legitimate business purposes.

4.3 Incident Response

In the event of a data breach, we have procedures to:

  • Contain and assess the breach promptly
  • Notify affected users where required
  • Report to relevant authorities as required
  • Implement additional safeguards to prevent future incidents

5
Cookies and Tracking Technologies

5.1 Types of Cookies We Use

  • Essential Cookies: Required for basic platform functionality
  • Performance Cookies: Help us understand how users interact with our platform
  • Functional Cookies: Remember your preferences and settings

5.2 Managing Cookie Preferences

You can control cookie settings through your browser or our cookie preference center. Note that disabling certain cookies may affect platform functionality.

6
Your Rights and Choices

6.1 Data Subject Rights

You have the following rights regarding your personal data:

  • Access: Request a copy of the personal data we hold about you
  • Rectification: Correct inaccurate or incomplete personal data
  • Erasure: Request deletion of your personal data (subject to legal obligations)
  • Portability: Receive your data in a structured format
  • Withdraw Consent: Withdraw consent where processing is based on consent

6.2 Exercising Your Rights

To exercise any of these rights, please contact us using the information provided at the end of this policy. We will respond to your request within 30 days and may require verification of your identity.

6.3 Complaints

If you believe we have not handled your personal data in accordance with this policy, you have the right to lodge a complaint with your local data protection authority.

7
Data Retention

7.1 Retention Periods

We retain your personal data for different periods depending on the purpose:

  • Account Data: For the duration of your account plus 5 years for regulatory compliance
  • Trading Records: 5 years from the transaction date as required by financial regulations
  • Communication Records: 2 years from the date of communication
  • Website Analytics: 1 year from collection

7.2 Secure Deletion

When retention periods expire, we securely delete or anonymize your personal data using industry-standard methods to ensure it cannot be recovered.

8
Policy Updates

8.1 Notification of Changes

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will:

  • Notify you by email at least 30 days before the changes take effect
  • Display a prominent notice on our platform
  • Update the "Last Updated" date at the top of this policy

8.2 Continued Use

Your continued use of our services after the effective date of any changes constitutes acceptance of the updated Privacy Policy.

privacy@mitheralfx.com
+1 (503) 224-7328
789 SW Oak St, Portland, OR 97205, USA
Response Time

We will respond to privacy-related inquiries within 30 days. For urgent matters related to data breaches or security concerns, contact us immediately at security@mitheralfx.com.