Privacy Policy
Data protection practices, privacy rights, and personal information handling procedures
Download PDFIntroduction and Data Controller Information
1.1 Pure M Global LTD ("Company") is committed to protecting client privacy and handling personal data responsibly. This Privacy Policy explains how the Company collects, uses, discloses, and safeguards personal information.
1.2 Data Controller: Pure M Global LTD is the data controller for all personal information collected through the Pure Portal website and trading platform. The Company determines what personal data to collect, how it is processed, and for what purposes.
1.3 Data Protection: The Company maintains comprehensive data protection practices in accordance with best practices and applicable data protection regulations. Data protection is a core organizational value.
1.4 Policy Scope: This Privacy Policy applies to all personal data collected through the Pure Portal website, mobile applications, trading platform, and all Company communications.
1.5 Policy Updates: The Company may update this Privacy Policy periodically to reflect changes in data practices or legal requirements. Updated policies are posted on the website. Continued use of the platform after updates constitutes acceptance of revised terms.
1.6 Contact Information: Clients with privacy questions or concerns may contact the Company at privacy@puremarketbroker.com or the Company's Data Protection Officer.
1.7 Legal Basis for Processing: Personal data collection and processing is based on contractual necessity (for account management and trading), legal obligations (regulatory compliance), and legitimate business interests (fraud prevention, service improvement).
1.8 Data Subject Rights: Clients have rights to access, correct, delete, restrict, and port personal data. Rights are exercised through written requests to the Data Protection Officer.
Personal Data Collection and Sources
2.1 Registration Data: During account opening, clients provide: (a) Full name and email address; (b) Telephone number and physical residential address; (c) Date of birth and nationality; (d) Government-issued identification document details; (e) Employment information and occupation.
2.2 Financial Information: The Company collects: (a) Bank account details and routing numbers; (b) Credit/debit card information (encrypted and tokenized); (c) Payment method details; (d) Income and asset information; (e) Source of funds documentation.
2.3 Trading Data: All trading activity recorded including: (a) Orders placed and their execution details; (b) Positions opened and closed with timestamps; (c) Trading frequency and volume information; (d) Account balance changes and equity calculations; (e) Profit and loss information for each trade.
2.4 Communication Data: The Company records: (a) Email communications with customer service; (b) Live chat conversation transcripts; (c) Support ticket submissions and responses; (d) Phone call recordings (when applicable); (e) Complaint submissions and resolution communications.
2.5 Device and Technical Data: Automatically collected: (a) IP addresses of accessing devices; (b) Browser type, version, and settings; (c) Operating system information; (d) Device identifiers and characteristics; (e) Mobile app usage data and session information.
2.6 Behavioral and Usage Data: The Company collects: (a) Website navigation patterns and page visits; (b) Time spent on specific pages and features; (c) Features used and frequency of use; (d) Click-through rates and interaction patterns; (e) Trading patterns and strategy information.
2.7 Third-Party Information: Data obtained from: (a) Credit reporting agencies for larger accounts; (b) Sanctions and compliance screening services; (c) Identity verification service providers; (d) Banking institutions for fund verification; (e) Public records and government databases.
2.8 Cookies and Tracking: Website uses cookies for: (a) Session management and authentication; (b) User preference retention; (c) Analytics and usage tracking; (d) Marketing and advertising purposes; (e) Security and fraud detection.
Purposes of Data Processing
3.1 Account Management and Service Provision: Personal data used for: (a) Creating and maintaining trading accounts; (b) Providing platform access and technical support; (c) Processing deposits and withdrawals; (d) Account administration and customer service; (e) Resolving account-related issues.
3.2 Regulatory Compliance: Data processing required for: (a) Know Your Customer (KYC) verification and identity confirmation; (b) Anti-Money Laundering (AML) screening and sanctions checking; (c) Source of funds verification; (d) Regulatory reporting to financial authorities; (e) Compliance with legal and regulatory obligations.
3.3 Risk Management and Security: Data processed to: (a) Detect and prevent fraudulent activities; (b) Monitor account security and prevent unauthorized access; (c) Identify suspicious trading patterns; (d) Protect against financial crime; (e) Conduct security audits and assessments.
3.4 Customer Service and Support: Data used for: (a) Responding to client inquiries and support requests; (b) Resolving complaints and disputes; (c) Providing account information and statements; (d) Technical troubleshooting and support; (e) Improving customer service quality.
3.5 Marketing Communications: With client consent, data used for: (a) Sending promotional offers and campaign information; (b) Marketing special promotions and new products; (c) Product update announcements; (d) Market research surveys; (e) Referral program communications.
3.6 Analytics and Service Improvement: Data processed for: (a) Understanding user behavior patterns; (b) Improving platform features and functionality; (c) Performance analytics and optimization; (d) User experience enhancement; (e) Statistical and trend analysis.
3.7 Legal and Compliance Purposes: Data used for: (a) Enforcing legal rights and obligations; (b) Responding to legal requests and subpoenas; (c) Defending against legal claims; (d) Regulatory investigations and audits; (e) Tax and financial reporting.
3.8 Security and Fraud Prevention: Data processed to: (a) Detect unauthorized account access; (b) Prevent fraudulent transactions; (c) Identify and report suspicious activity; (d) Conduct fraud investigations; (e) Maintain comprehensive security monitoring.
Data Sharing and Disclosure
4.1 Service Providers and Processors: The Company shares data with third parties providing services including: (a) Payment processors and financial institutions; (b) Cloud hosting and infrastructure providers; (c) Identity verification and compliance service providers; (d) Data analytics and reporting services; (e) Customer support and communication platforms.
4.2 Regulatory Authorities: Data disclosed to: (a) Financial Services Commission of Vanuatu; (b) Tax authorities and revenue agencies; (c) Office of Foreign Assets Control (OFAC); (d) International law enforcement agencies; (e) Other regulatory bodies as required by law.
4.3 Law Enforcement Disclosure: Data provided to law enforcement when: (a) Required by subpoena or court order; (b) Necessary to comply with legal process; (c) Required in connection with criminal investigations; (d) Needed for national security purposes; (e) Authorized by valid legal requests.
4.4 Business Partners and Affiliates: Limited data sharing with: (a) Affiliate organizations and business partners; (b) IB (Introducing Broker) partners; (c) Strategic business partners; (d) Joint venture partners; (e) Other entities with contractual relationships.
4.5 Data Processors: Third-party processors authorized to process data on Company's behalf include: (a) Cloud hosting providers; (b) Analytics and reporting services; (c) Email communication services; (d) Customer relationship management (CRM) systems; (e) Backup and disaster recovery providers.
4.6 No Marketing Information Selling: The Company does not sell or share client personal data with external marketing companies without explicit written consent. Client information is never sold to third parties.
4.7 Aggregate and Anonymized Data: Anonymized and aggregate data (from which personal identification removed) may be shared for: (a) Industry analytics and trends; (b) Academic research; (c) Market research; (d) Statistical analysis; (e) Business intelligence.
4.8 Consent-Based Additional Sharing: Data sharing beyond normal business purposes requires: (a) Explicit written consent from the data subject; (b) Clear description of intended use; (c) Identification of recipient parties; (d) Opt-in requirement for each use; (e) Easy opt-out mechanisms.
Data Retention and Deletion
5.1 Retention Period for Account Data: Personal data retained for: (a) 5 years after account closure to fulfill legal obligations; (b) Indefinitely while account is active; (c) Extended periods if legal proceedings initiated; (d) As required by regulatory authorities; (e) Longer periods if necessary for compliance.
5.2 Trading Records Retention: Trading and transaction records retained for: (a) Minimum 5 years as required by regulations; (b) Full audit trail maintained; (c) Accessible through account portal; (d) Available for regulatory review; (e) Longer retention if required by law.
5.3 Legal Hold Procedures: When legal proceedings initiated, data subject to legal hold meaning: (a) Data retained regardless of normal retention schedule; (b) Retention maintained throughout legal proceedings; (c) Data not deleted until legal proceedings conclude; (d) Extended retention if appeals filed; (e) Company obligation to preserve data.
5.4 Client Deletion Requests: Clients may request data deletion after account closure by: (a) Submitting written request to privacy@puremarketbroker.com; (b) Specifying which data to delete; (c) Providing account identification information; (d) Confirming no pending disputes; (e) Waiting for processing (normally 30 days).
5.5 Regulatory Exception to Deletion: Data not deleted if: (a) Required by law to retain; (b) Needed for regulatory compliance; (c) Subject to legal hold; (d) Required for tax purposes; (e) Necessary for dispute resolution.
5.6 Marketing Data Deletion: Marketing and promotional data deleted immediately upon: (a) Client opt-out request; (b) Email unsubscribe; (c) Preference center update; (d) Written request; (e) Client removed from all marketing communications.
5.7 Data Backup Procedures: Deleted data may remain in: (a) Backup systems for limited period; (b) Archive systems during transition; (c) Disaster recovery copies; (d) Tape backups being phased out; (e) Backups eventually securely destroyed.
5.8 Secure Destruction: When data deletion finalized: (a) Data securely erased using cryptographic methods; (b) Multiple overwrites employed; (c) Hardware destroyed if necessary; (d) Certificates of destruction obtained; (e) Audit trail maintained.
Data Subject Rights and Access
6.1 Right to Access Data: Clients may request copy of personal data held by: (a) Submitting written request to Data Protection Officer; (b) Providing identification information; (c) Specifying requested data; (d) Receiving response within 30 days; (e) Obtaining data in electronic format.
6.2 Right to Data Correction: Inaccurate personal data corrected promptly by: (a) Client request for amendment; (b) Company verification of correction; (c) Update to all systems; (d) Notification to third parties if shared; (e) Confirmation of correction to client.
6.3 Right to Data Deletion: Clients may request deletion by: (a) Submitting deletion request in writing; (b) Providing account information; (c) Confirming deletion rationale; (d) Company processing within 30 days; (e) Regulatory exceptions may limit deletion.
6.4 Right to Restrict Processing: Clients may request restriction meaning: (a) Data retained but not actively processed; (b) Data not used for normal purposes; (c) Storage-only basis; (d) Processing resumes on client request; (e) Restriction noted in records.
6.5 Right to Data Portability: Clients may request data in portable format: (a) Machine-readable format (CSV, JSON); (b) Structured and commonly used format; (c) Transmitted directly to other service provider; (d) Data includes all personal information; (e) Provided within 30 days.
6.6 Right to Object to Processing: Clients may object to: (a) Marketing and promotional communications; (b) Analytics and profiling; (c) Third-party sharing for non-essential purposes; (d) Automated decision-making; (e) Objections honored promptly.
6.7 Right to Lodge Complaint: If concerned about data handling, clients may: (a) File complaint with data protection authorities; (b) Contact Financial Services Commission; (c) Initiate regulatory investigation; (d) Seek regulatory remedies; (e) Maintain complaint records.
6.8 Exercise of Rights Process: Rights exercised by: (a) Submitting written request to privacy@puremarketbroker.com; (b) Providing clear request description; (c) Furnishing necessary identification; (d) Company responding within 30 days; (e) Right to appeal Company decision.
Data Security and Protection Measures
7.1 Encryption Standards: All sensitive data protected by: (a) AES-256 encryption for data at rest; (b) TLS 1.3 encryption for data in transit; (c) End-to-end encryption for communications; (d) Secure key management; (e) Regular encryption audits.
7.2 Secure Data Transmission: Data transmitted securely through: (a) HTTPS protocol on all website pages; (b) TLS secure connections for API communications; (c) VPN for sensitive transmissions; (d) No unencrypted data transmission; (e) Man-in-the-middle attack prevention.
7.3 Access Control Measures: Access to personal data restricted by: (a) Role-based access controls (RBAC); (b) Need-to-know principle; (c) User authentication and authorization; (d) Audit logs of all data access; (e) Immediate access revocation upon employment termination.
7.4 Authentication and Authorization: User authentication includes: (a) Strong password requirements; (b) Multi-factor authentication (MFA) available; (c) Biometric authentication for mobile; (d) Session timeouts; (e) Login activity monitoring.
7.5 Monitoring and Detection: Continuous security monitoring includes: (a) Automated intrusion detection systems; (b) Unauthorized access attempt detection; (c) Suspicious activity alerts; (d) Real-time security monitoring; (e) Incident response capabilities.
7.6 Data Breach Procedures: If breach occurs: (a) Immediate investigation initiated; (b) Affected clients notified within 72 hours if required; (c) Regulatory authorities notified; (d) Breach details documented; (e) Remediation measures implemented.
7.7 Staff Training and Awareness: All staff trained on: (a) Data protection requirements; (b) Privacy best practices; (c) Confidentiality obligations; (d) Breach reporting procedures; (e) Annual refresher training.
7.8 Physical Security: Data center security includes: (a) Restricted physical access; (b) Badge and biometric access controls; (c) Video surveillance and monitoring; (d) Climate control and fire prevention; (e) Disaster recovery facilities.
Cookies, Tracking, and Third-Party Services
8.1 Cookie Usage and Purpose: The Company uses cookies for: (a) Session management and user authentication; (b) Storing user preferences and settings; (c) Remembering login information; (d) Analytics and usage tracking; (e) Marketing and advertising optimization.
8.2 Cookie Categories: Cookies used include: (a) Functional cookies essential for platform operation; (b) Analytics cookies for understanding user behavior; (c) Marketing cookies for targeted advertising; (d) Security cookies for fraud detection; (e) Third-party cookies from partners.
8.3 Consent and Cookie Banner: Non-essential cookies require: (a) User consent via cookie banner; (b) Clear opt-in for marketing cookies; (c) Easy cookie preference management; (d) Consent recorded and documented; (e) Withdrawal of consent available.
8.4 Cookie Control and Management: Users control cookies through: (a) Browser settings to disable cookies; (b) Cookie preference center on website; (c) Selective cookie acceptance; (d) Opt-out of tracking; (e) Cookie deletion capabilities.
8.5 Third-Party Tracking Services: Third parties used for tracking include: (a) Google Analytics for website analytics; (b) Facebook Pixel for marketing; (c) Advertising networks for retargeting; (d) These services have separate privacy policies; (e) Users may opt-out of third-party tracking.
8.6 Do Not Track Respect: The Company respects Do Not Track (DNT) signals by: (a) Minimizing tracking for DNT-enabled browsers; (b) Reducing behavioral targeting; (c) Limited data collection; (d) Respecting user privacy preferences; (e) DNT honored across website.
8.7 Pixel Tags and Beacons: Tracking pixels used for: (a) Analytics and page visit tracking; (b) Marketing campaign effectiveness; (c) User behavior analysis; (d) Conversion tracking; (e) Retargeting purposes.
8.8 Cookie Retention Policies: Cookies retained based on: (a) Functional cookies - for session duration; (b) Analytics cookies - typically 2 years; (c) Marketing cookies - cleared on opt-out; (d) Security cookies - for account protection; (e) Regular cookie audits conducted.