Privacy Policy
This policy explains what we collect about you, why we are permitted to process it, how long we keep it and what you can require us to do with it. It covers the public website, the client portal and the trading platforms we provision on your behalf.
Scope and who is responsible
Connect Funded, operating from the Dubai International Financial Centre, Dubai, United Arab Emirates, is the controller of the personal data described in this policy. The controller is the party that decides why and how your data is processed, and is therefore the party you can hold to account for it.
This policy applies to the connectfunded.com website, the client portal, the accounts we provision for you on MetaTrader 5, cTrader and the Web Terminal, and to correspondence with our support, sales and hiring desks. It does not apply to third-party websites we link to.
Categories of personal data we collect
We collect only what the programme requires. Categories are grouped below by the reason they exist rather than by the system that holds them.
- Identity data: full legal name, date of birth, nationality, country of residence, and the identity document and proof of address submitted at verification
- Contact data: email address, telephone number and postal address
- Account data: profile credentials in hashed form, account tier, evaluation phase, platform logins and the audit trail of actions taken in the portal
- Trading data: orders, executions, positions, equity, balance and drawdown history on every account you hold
- Financial data: payment method type, the masked instrument identifier, payment and payout amounts, and the settlement references produced by our processors
- Compliance data: sanctions and politically exposed person screening results, and any source-of-funds evidence requested
- Technical data: IP address, device and browser characteristics, session timestamps and security event logs
- Communications data: support tickets, emails, contact form submissions and the notes our teams record against them
How we collect it
Most of what we hold you give us directly: at registration, at checkout, at verification, and whenever you contact a desk. Trading data is generated automatically as you use the platforms. Technical data is collected by our servers and by the limited analytics described below.
A small amount of data comes from third parties: payment processors confirm the outcome of a transaction, and screening providers return the result of a sanctions or politically exposed person check. We do not buy personal data from data brokers and we do not enrich your profile with data purchased elsewhere.
Purposes and lawful basis
We process personal data on four bases. Where processing is necessary to perform our contract with you, that includes provisioning accounts, enforcing risk limits, calculating and paying out profit, and providing support. Where processing is necessary to comply with a legal obligation, that includes identity verification, sanctions screening, suspicious activity reporting and the retention of records.
Where processing rests on our legitimate interests, those interests are operating a secure platform, preventing fraud and abuse of the programme, improving the service, and defending legal claims. We balance those interests against your rights each time, and you may object to processing on this basis.
Where processing rests on consent, that covers marketing email, non-essential cookies, and the publication of a testimonial with your name attached. Consent can be withdrawn at any time without affecting processing already carried out.
Cookies and similar technologies
Strictly necessary cookies keep you signed in, maintain your session, remember your theme preference and protect forms against cross-site request forgery. They cannot be switched off without breaking the service and they are set on the legitimate interest basis rather than on consent.
Analytics cookies, where used, measure aggregate page performance and navigation patterns. They are set only with your consent, and that consent can be withdrawn through the same control that granted it.
We do not operate advertising cookies, cross-site tracking pixels or data-sharing arrangements with advertising networks on this site.
Marketing communications
Operational email is sent on the contractual basis and cannot be unsubscribed while you hold an account: verification outcomes, payout confirmations, breach notices, security alerts and material changes to the rulebook.
Marketing email, including the weekly desk note and product announcements, is sent only where you have opted in. Every marketing message carries a one-click unsubscribe, and unsubscribing takes effect immediately across all marketing lists.
Sharing with processors and third parties
We share personal data with service providers who process it on our instructions and under a written data processing agreement. Those categories are payment and payout processors, identity verification and sanctions screening providers, trading platform and liquidity providers, cloud hosting and database providers, email delivery providers, and error monitoring services.
We disclose data to a regulator, law enforcement agency or court where we are legally required to do so, and to professional advisers where necessary to obtain legal or accounting advice. Suspicious activity reports are made confidentially and, as set out in the AML and KYC Policy, cannot be disclosed to you.
We do not sell personal data, and we do not share it with third parties for their own marketing purposes.
International transfers
Our processors operate in several jurisdictions, including the United Arab Emirates, the European Economic Area and the United States. Where personal data leaves the jurisdiction in which it was collected, we rely on an adequacy decision where one applies, and otherwise on standard contractual clauses supplemented by technical measures such as encryption in transit and at rest.
You may request a summary of the safeguards applied to a specific transfer by writing to the data protection contact below.
Data retention
We keep personal data only as long as the purpose requires, and then delete or irreversibly anonymise it. Where a legal retention period applies it overrides a shorter operational one.
- Identity and verification records: six years after the end of the business relationship, as required by anti-money-laundering record-keeping obligations
- Transaction, payout and accounting records: six years after the transaction
- Trading and account history: six years after account closure, retained for dispute resolution and audit
- Support correspondence: three years after the ticket is closed
- Marketing consent records: for the duration of the consent and three years after it is withdrawn, as evidence that it was validly obtained
- Unsuccessful job applications: twelve months, unless you ask us to keep them longer
- Technical and security logs: twelve months, in a form separated from account identifiers wherever practicable
Your rights
Subject to the exemptions in applicable law, you may request access to the personal data we hold about you, correction of anything inaccurate, deletion where we no longer have a basis to keep it, restriction of processing while a dispute over accuracy is resolved, a portable copy of the data you provided to us, and objection to processing carried out on the legitimate interest basis.
Requests are answered within thirty days. There is no charge unless a request is manifestly unfounded or repetitive. We may need to verify your identity before acting, which is itself a protection for you.
Deletion cannot override a legal retention obligation. Where we must keep verification or transaction records for the periods set out above, we will restrict processing to that purpose rather than delete them early, and we will tell you which category applies.
Automated decision-making
Two processes on the platform are automated. Risk-limit enforcement evaluates account equity against the published daily and overall drawdown limits and closes an account that breaches them. Sanctions screening compares your details against published lists and holds an account where a potential match is returned.
Both have a consequential effect, and both are reviewable by a human being. Where an automated decision has been applied to your account you may raise a ticket asking for it to be reviewed by the risk or compliance desk, and you are entitled to an explanation of the record the decision was based on.
Security
Personal data is encrypted in transit using current TLS, and at rest in our databases and backups. Credentials are stored as salted hashes and are never recoverable in plain text, including by us.
Access is granted on a least-privilege basis, is tied to a named individual, requires multi-factor authentication, and is logged in an audit trail. Verification documents are stored separately from trading data with a shorter access list.
Where a personal data breach is likely to result in a risk to your rights, we will notify the relevant supervisory authority and, where the risk is high, notify you directly with a description of what happened and what you should do.
Children
The service is not offered to anyone under 18 and we do not knowingly collect data about children. Where we learn that an account has been opened by a minor, it is closed and the associated data is deleted except where a legal obligation requires it to be retained.
Complaints and contact
Data protection enquiries and rights requests should be addressed to support@connectfunded.com with the subject line marked for the attention of the data protection contact, or raised as a ticket in the client portal.
If you are not satisfied with our response you may complain to the supervisory authority in the jurisdiction in which you live or in which the processing took place. Telling us first is usually faster, and it does not affect your right to complain afterwards.
Changes to this policy
We will update this policy when our processing changes. Material changes are notified through the client portal and by email at least fourteen days before they take effect, and the revision date at the top of the document is updated each time.
Questions about this policy?
If any part of the privacy documentation is unclear, or you believe a provision has been applied incorrectly to your account, write to the desk and ask before you act on it. Compliance and risk questions are answered by the desk that owns the decision, not by a support script.
Written enquiries reach us at support@connectfunded.com, or through a timestamped ticket in the client portal.