Privacy Policy
Effective date: [EFFECTIVE DATE]
This Privacy Policy explains how [LEGAL ENTITY NAME], trading as "FundedIQ" ("FundedIQ", "we", "us", or "our"), collects, uses, shares, and protects your personal data when you visit [WEBSITE URL], create an account, purchase and take part in our paid evaluation challenges, use our simulated trading accounts, or otherwise interact with our services (together, the "Services"). FundedIQ operates evaluation challenges in which a customer pays a one-time fee for a simulated (demo) trading account governed by rules such as a profit target, a daily-loss limit, and a maximum drawdown. No real client money is traded, and accounts are simulated. FundedIQ is not a broker, bank, investment adviser, or money manager; it does not hold client trading capital and does not provide financial or investment advice. This Policy describes what personal data we handle, why we handle it, the legal bases we rely on, who we share it with, how long we keep it, and the rights you have. Please read it together with our Terms and Conditions. By using the Services, you acknowledge the practices described here. If you do not agree with this Policy, please do not use the Services.
1. Who We Are and Who Controls Your Data
The data controller responsible for your personal data is [LEGAL ENTITY NAME], a company incorporated in [COUNTRY OF INCORPORATION] with its registered address at [REGISTERED ADDRESS]. Where this Policy refers to us being the "controller", it means we determine the purposes and means of processing your personal data.
For certain activities, some third parties act as independent controllers of their own (for example, our identity-verification and payment providers, who are separately responsible for the data you submit directly to them). Where that is the case, their own privacy notices also apply, and we identify them below.
If you have any questions about this Policy or about how we handle your personal data, you can contact us using the details in the "Contact Us and Data Protection Officer" section.
2. Scope of This Policy
This Policy applies to personal data we process about: visitors to our website; registered account holders; customers who purchase and take part in evaluation challenges; holders of funded simulated accounts eligible for performance-based rewards; and individuals who contact our support team or otherwise communicate with us.
Our Services are offered to customers internationally, but certain jurisdictions and persons are restricted. This Policy does not change any eligibility or access restrictions set out in our Terms and Conditions.
Our Services may contain links to third-party websites, tools, or services that we do not control. This Policy does not apply to those third parties, and we encourage you to review their own privacy notices.
3. Personal Data We Collect
We collect personal data that you provide directly to us, data that is generated automatically when you use the Services, and data we receive from third parties such as our identity-verification and payment providers. The categories of personal data we collect include the following.
- Account and contact data: your name, username, email address, telephone number, country of residence, postal or billing address, date of birth, login credentials, and account preferences.
- Identity verification (KYC) data: government-issued identity documents such as passport, national ID card, or driver's licence; a selfie or live photograph used for biometric face matching; proof of address; date of birth; nationality; and other information required to verify your identity and confirm your eligibility. This may include information treated as sensitive under applicable law (for example, biometric identifiers used for verification).
- Payment, crypto, and transaction data: the payment method you use, billing details, cryptocurrency wallet addresses, blockchain transaction identifiers, the type and amount of cryptocurrency (such as USDT) or other funds used, purchase history, refund records, and reward or payout records. We do not store full card numbers; card and crypto payment details are handled by our payment processor.
- Trading, usage, and performance data: your simulated trading activity, orders, positions, execution and latency data, profit and loss, drawdown, adherence to challenge rules, challenge results, progress toward profit targets, and related performance metrics generated by your use of the simulated accounts.
- Communications and support data: the content of messages, tickets, emails, chat, and other communications you exchange with us, including any information you choose to include.
- Device, log, and cookie data: your IP address, device and browser type, operating system, device identifiers, language settings, referring and exit pages, timestamps, access logs, and information collected through cookies and similar technologies (see "Cookies and Tracking Technologies").
- Marketing and preference data: your marketing preferences, consents, and interactions with our communications, where applicable.
4. How and Why We Use Your Personal Data
We use your personal data only for specified, legitimate purposes, including the following.
- To provide and operate the Services: create and manage your account, deliver evaluation challenges and simulated trading accounts, apply challenge rules, track performance, and provide access to funded simulated accounts.
- To verify your identity and comply with legal obligations: carry out identity verification (KYC), anti-money-laundering (AML), counter-terrorist-financing, sanctions-screening, and eligibility checks, particularly before processing any reward or payout.
- To prevent fraud, abuse, and risk: detect and prevent multi-accounting, cheating, market or latency abuse, collusion, prohibited conduct, unauthorized access, and other activity that breaches our Terms and Conditions or applicable law.
- To process payments, rewards, and payouts: handle challenge fees, process cryptocurrency and other payments, administer performance-based rewards and profit splits (which are discretionary and subject to rules and successful identity verification), and manage refunds where applicable.
- To provide customer support: respond to your enquiries, resolve disputes, and communicate with you about your account and the Services.
- To send marketing communications: where you have consented or where otherwise permitted by law, send you information about products, offers, and updates. You can withdraw consent or opt out at any time.
- To maintain, secure, and improve the Services: monitor performance and reliability, secure our systems, conduct analytics, debug, and develop new features.
- To comply with law and enforce our rights: satisfy legal, regulatory, tax, and record-keeping obligations, respond to lawful requests from authorities, and establish, exercise, or defend legal claims.
5. Legal Bases for Processing
Where data protection laws such as the EU/UK GDPR apply, we rely on one or more of the following legal bases to process your personal data. The applicable basis depends on the specific purpose for which we use the data.
- Performance of a contract: to create and operate your account, deliver the evaluation challenges and simulated accounts, and provide the Services you request.
- Compliance with a legal obligation: to carry out KYC/AML checks, sanctions and eligibility screening, tax and record-keeping, and to respond to lawful requests from authorities.
- Legitimate interests: to prevent fraud and abuse, secure and improve the Services, enforce our Terms and Conditions, and conduct limited direct marketing, provided our interests are not overridden by your rights and freedoms.
- Consent: for certain marketing communications, non-essential cookies and tracking, and any processing of biometric or other sensitive data used for identity verification, where consent is required. You may withdraw consent at any time without affecting processing carried out before withdrawal.
6. Sharing Your Personal Data with Third Parties
We do not sell your personal data. We share personal data only where necessary for the purposes described in this Policy, and only with recipients who are subject to appropriate confidentiality and data-protection obligations. The categories of recipients include the following.
- Identity-verification (KYC) provider: [KYC PROVIDER NAME], our third-party provider, processes your identity documents, selfies, and related data to verify your identity and support AML and fraud-prevention checks.
- Payment processor: Match2Pay, our third-party cryptocurrency payment processor, and any card or other payment providers we use, process your payment, wallet, and transaction data to complete purchases, rewards, and payouts.
- Hosting and infrastructure providers: cloud hosting, storage, database, security, communications, and analytics providers that support the operation of the Services, including [HOSTING PROVIDER].
- Professional advisers and service partners: legal, accounting, audit, compliance, and support providers acting on our behalf.
- Authorities and regulators: courts, law-enforcement, tax, and regulatory bodies where we are required or permitted by law to disclose personal data, or to protect our rights, users, or the public.
- Business transfers: parties involved in a merger, acquisition, reorganization, financing, or sale of assets, subject to appropriate safeguards.
7. International Data Transfers
FundedIQ operates internationally, and your personal data may be transferred to, stored in, or processed in countries other than the one in which you reside, including countries whose data-protection laws may differ from those of your home jurisdiction.
Where we transfer personal data across borders, we take steps to ensure it receives an adequate level of protection. Where required, we rely on recognized transfer mechanisms, such as adequacy decisions or standard contractual clauses (or equivalent safeguards), together with appropriate technical and organizational measures.
You may request more information about the safeguards we apply to international transfers by contacting us using the details in the "Contact Us and Data Protection Officer" section.
8. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including to provide the Services, comply with our legal and regulatory obligations, resolve disputes, and enforce our agreements.
Because we are subject to anti-money-laundering and related obligations, KYC and identity-verification records (including identity documents and related verification data) are retained to meet those obligations for [DATA RETENTION PERIOD], and may be kept longer where a longer period is required by law or is necessary for the establishment, exercise, or defense of legal claims.
When personal data is no longer required, we will securely delete, anonymize, or otherwise render it inaccessible in accordance with our retention practices and applicable law. Note that blockchain transaction data recorded on public networks is outside our control and cannot be altered or erased by us.
9. How We Protect Your Personal Data
We implement appropriate technical and organizational measures designed to protect personal data against unauthorized access, loss, misuse, alteration, and disclosure. These measures may include encryption in transit, access controls, authentication requirements, network and application security controls, logging and monitoring, and staff confidentiality obligations.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your login credentials confidential and for notifying us promptly if you suspect any unauthorized use of your account.
In the event of a personal data breach that is likely to result in a risk to your rights, we will notify the relevant supervisory authority and, where required, affected individuals, in accordance with applicable law.
10. Your Rights
Depending on your location and applicable law (such as the EU/UK GDPR or similar frameworks like the CCPA/CPRA), you may have some or all of the following rights in relation to your personal data.
- Access: to request confirmation of whether we process your personal data and to obtain a copy of it.
- Correction: to request that inaccurate or incomplete personal data be corrected or updated.
- Deletion: to request that we delete your personal data, subject to legal and regulatory retention obligations (for example, AML record-keeping).
- Restriction: to request that we limit the processing of your personal data in certain circumstances.
- Portability: to receive certain personal data you provided to us in a structured, commonly used, machine-readable format, and to have it transmitted to another controller where technically feasible.
- Objection: to object to processing based on our legitimate interests, and to object to direct marketing at any time.
- Withdraw consent: to withdraw consent at any time where we rely on consent, without affecting the lawfulness of processing before withdrawal.
- Non-discrimination and opt-out (where applicable): where laws such as the CCPA/CPRA apply, to exercise your rights without receiving discriminatory treatment, and to opt out of any "sale" or "sharing" of personal data as those terms are defined (note that we do not sell your personal data).
- Complain to a supervisory authority: to lodge a complaint with your local data-protection or privacy regulator, such as [SUPERVISORY AUTHORITY].
11. Exercising Your Rights
To exercise any of your rights, please contact us using the details in the "Contact Us and Data Protection Officer" section. We may need to verify your identity before responding, which may involve confirming information we already hold about you.
We will respond to your request within the timeframe required by applicable law. In some cases, we may be unable to fully comply with a request, for example where doing so would conflict with our legal obligations (such as AML retention requirements) or the rights of others. Where that is the case, we will explain the reason to the extent permitted by law.
You may use an authorized agent to submit a request where permitted by law, subject to appropriate verification.
12. Cookies and Tracking Technologies
We use cookies and similar technologies (such as pixels, local storage, and device identifiers) to operate the Services, remember your preferences, keep your session secure, measure usage, and, where permitted, support analytics and marketing.
Some cookies are strictly necessary for the Services to function and cannot be switched off. Non-essential cookies (such as analytics and marketing cookies) are used only with your consent where required by law.
You can manage your cookie preferences through our cookie settings at [COOKIE SETTINGS / PREFERENCES LINK] and through your browser settings. Disabling certain cookies may affect the availability or functionality of parts of the Services.
13. Marketing Communications
Where you have consented or where otherwise permitted by law, we may send you marketing communications about our products, offers, and updates.
You can opt out of marketing communications at any time by using the unsubscribe link in our emails, adjusting your account preferences, or contacting us. Opting out of marketing does not stop service-related or transactional communications that are necessary to operate your account and the Services.
14. Children's Privacy
The Services are intended solely for individuals who are 18 years of age or older. The Services are not directed to, and we do not knowingly collect personal data from, anyone under the age of 18.
If we become aware that we have collected personal data from a person under 18, we will take steps to delete that data and close any associated account. If you believe a minor has provided us with personal data, please contact us using the details below.
15. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or the Services. When we make material changes, we will update the "Effective date" above and, where appropriate, provide additional notice (for example, by email or through the Services).
We encourage you to review this Policy periodically. Your continued use of the Services after an updated Policy takes effect constitutes your acknowledgement of the changes, to the extent permitted by law.
16. Contact Us and Data Protection Officer
If you have questions, concerns, or requests regarding this Privacy Policy or our handling of your personal data, you can contact us as follows.
Data controller: [LEGAL ENTITY NAME], [REGISTERED ADDRESS], [COUNTRY OF INCORPORATION].
General support: [SUPPORT EMAIL]. Privacy and data-protection enquiries, including rights requests: [PRIVACY / DPO EMAIL].
Data Protection Officer (or privacy contact), where appointed: [DATA PROTECTION OFFICER CONTACT]. You also have the right to contact your local supervisory authority, such as [SUPERVISORY AUTHORITY].