FX24Privacy Policy

Privacy Policy

How FX24 Market collects, processes, stores, protects, and manages personal data when you use our website, services, or partnership programs.

Last updated June 2026FX24 Market

Personal data

We collect data needed to provide services, meet legal duties, verify users, and protect the platform.

Security controls

Technical and organizational safeguards protect data against unauthorized access, disclosure, loss, or misuse.

Your rights

You may request access, correction, deletion, restriction, portability, objection, or withdrawal of consent where applicable.

SECTION 01

Introduction

This Privacy Policy governs the privacy of clients, visitors, partners, representatives, beneficial owners of legal-entity clients, and partner legal entities using https://www.fx24.market.

FX24 Market is operated by Bigray Financial Group, including Bigray Financial Group registration No. 1406246501 in Azerbaijan and Bigray Financial Group registration No. 4044 in Saint Vincent and the Grenadines.

This Policy explains what Personal Data is collected and how it is used, processed, stored, and managed when you visit the Website, use the Services, or enter into a Partnership Agreement.

By using the Website or Services, or by executing a Partnership Agreement, you acknowledge that you have read this Privacy Policy and consent to the processing of your Personal Data as described here.

If you do not agree with this Privacy Policy or any later update, you should stop using the Website and Services and, where applicable, terminate the Partnership Agreement.

SECTION 02

General Provisions

The Company is responsible for Personal Data in its possession or custody, including information transferred to a third party for processing.

The Company confirms compliance with GDPR, applicable data protection regulations in its countries of incorporation, and other applicable data protection laws and regulations.

Personal Data is used only for the purposes outlined in this Policy and is transferred to other parties only where necessary.

The Website or Services may contain third-party links, plug-ins, or apps. We do not control those third-party sites and are not responsible for their privacy statements or policies.

Providing necessary Personal Data is mandatory when you use the Website, use Services, or enter into a Partnership Agreement. If required data is not provided, we may refuse to enter into contractual relations.

SECTION 03

Personal Data That Could Be Collected By Us

Depending on how you use the Website, Services, or Partnership Agreement, we may collect, use, store, and transfer different categories of Personal Data.

Identity Data may include email address, name, username, date of birth, gender, residential address, postal address, citizenship, phone number, account details, source of funds, source of wealth, identity documents, proof of address, occupation, employment industry, and financial standing.

For legal entities, Identity Data may include information confirming a person's role as director, board member, employee, representative, owner, ultimate beneficial owner, or information about ownership and control structure.

Biometrics may include photo, video, audio, and other biometric identifiers or biometric information.

Partnership Information may include partner structure, partner IDs, referral links, group clients, commission calculations, payment history, and related records.

Social identity and Preference Data may include referrals, close connections, preferences, interests, favorites, risk assessment, compliance evaluation, work address, groups, marketing preferences, survey replies, and related connections.

Verification Data may include Personal Data collected for due diligence, AML/CTF checks, photos, and direct video transmission recordings.

Background Data may include Personal Data available from open sources.

Transactions and operations data may include trading and non-trading operations, transaction activity logs, billing, settlement details, orders, instructions, transfers, history, partner commission accruals, and payment records.

Technical Data may include domain, host, operator and carrier data, IP address, device type, browser type, operating system, device IDs, time zone, location, language, diagnostics, crash logs, and similar technical data.

Profile Data may include username, password, login data, identification number, service requests, partnership requests, and communications between you and us.

Marketing and Communication Data may include marketing preferences, communications, survey responses, and voice records.

Sensitive data receives additional safeguards and is processed only where a legal basis and a required extra condition apply.

SECTION 04

Personal Data Processing Purposes

We securely retain data submitted by you or otherwise received by us where required by applicable law.

Contractual purposes include Website registration, agreement performance, Partnership Agreement performance, delivery of Services, execution and management of trading and non-trading instructions, payment processing, fee collection, and recovery of amounts owed.

Analytical purposes include Website statistics, service communications, client support, records management, analytics, and improvements to Website and Service experience.

Marketing and advertising purposes include welcome emails, service updates, partnership updates, surveys, offers, advertisements, and analysis of advertising effectiveness where permitted.

Compliance purposes include record accuracy, KYC checks, AML/CTF compliance, prevention of criminal activity, risk assessment, background checks, fraud prevention, reporting, and protection of legal interests.

Communication purposes include administrative contact, client support, technical or legal notices, and updates about Services or partnerships.

We may process Personal Data for more than one lawful ground depending on the specific purpose, and may process data in connection with merger, financing, acquisition, business transfer, assignment, bankruptcy, dissolution, or similar transactions.

SECTION 05

Source of Obtaining Your Personal Data

We may obtain Personal Data directly from you when you provide it for identification, verification, KYC, service use, partnership relations, agreements, requests, complaints, or emails.

We may obtain Personal Data from financial institutions, registers, identification and verification vendors, partners, and other sources.

Direct collection may occur when you fill forms, upload images, email us, request Services, visit the Website, enter into a Partnership Agreement, provide feedback, respond to advertisements, participate in polls, or request support.

Automated technologies may collect Personal Data through cookies, server logs, and similar methods when you connect through the Website.

We may also obtain information from third parties, publicly available sources, or indirect sources, including IP addresses.

SECTION 07

Security Measures

Data security is extremely important to us. We organize and implement relevant procedures and technology to safeguard and secure Personal Data collected by us.

Security measures are designed to protect Personal Data from involuntary or unauthorized processing, disclosure, destruction, loss, theft, copying, use, modification, or unauthorized access.

Depending on the risks, safeguards may include organizational measures such as training, policy development, security clearances, and need-to-know access limits.

Safeguards may also include technical security measures such as physical protection, encryption, passwords, backups, and measures to secure availability, integrity, and accessibility.

Access to Personal Data is restricted to personnel, contractors, advisors, and auditors who need it for their work or service tasks.

You are responsible for keeping your password confidential and secure. Internet transmission is not completely secure, and transmission of data to the Website is at your own risk where outside our reasonable control.

SECTION 08

Personal Data Subject Rights

Your rights depend on the reason we process your Personal Data.

Right to Access allows you to request confirmation of whether we process your Personal Data and to request a copy of the Personal Data we process, subject to legal limits.

Right to Rectification allows you to ask us to correct incorrect, misleading, excessive, incomplete, or irrelevant Personal Data.

Right to Erasure allows you to ask us to erase Personal Data unless continued processing is required by law, agreement, or another lawful ground.

Right to Restriction allows you to ask us to restrict processing where data is incorrect, incomplete, or unlawfully processed.

Information Availability and Data Portability rights may allow you to receive Personal Data in a structured, commonly used, machine-readable format or request transfer to a third party where technically feasible.

Right to Object allows you to object to processing where you believe we lack lawful grounds and your specific situation affects your fundamental rights and freedoms.

Right to Withdraw Consent allows you to withdraw consent at any time, without affecting processing lawfully carried out before withdrawal.

Right to File a Complaint allows you to submit complaints regarding your Personal Data and lodge a complaint with the relevant supervisory body.

SECTION 09

Transfer of Personal Data to Third Parties

We may transfer Personal Data to regulatory authorities, law enforcement agencies, fraud prevention entities, identity verification providers, payment processors, credit reference bodies, banks, financial institutions, and courts where required or appropriate.

We may transfer Personal Data to related entities, personnel, officers, agents, contractors, designated representatives, service providers, and other third parties where needed for the purposes for which information was collected.

We may transfer Personal Data to analytics providers, verification service providers, software providers, professional advisers, server hosts, communication providers, banking and financial providers, debt recovery agencies, and other providers necessary for Website and Services operation.

We may transfer Personal Data in connection with a sale of all or a substantial part of our assets or business, merger, acquisition, or similar transaction.

Third parties processing Personal Data are expected to maintain appropriate technological and organizational safeguards and preserve confidentiality and security.

Where Personal Data is transferred outside the EEA, appropriate safeguards such as standard contractual clauses and data processing agreements may be used where required.

External links on the Website are not controlled by us. This Privacy Policy applies only to this Website.

SECTION 10

Personal Data Use in Communication and Marketing

We may contact you by phone, email, SMS, or push notification about current and new Services or partnership conditions that may interest you.

Marketing emails will include an unsubscribe option where required by applicable law. You may also opt out of marketing communications by using the contact information in this Policy.

You may request removal from our marketing list, and we will make reasonable efforts to remove your information within a reasonable time frame.

Some required or necessary communications about important Website, Service, or operational changes may still be sent and may not be subject to opt-out.

Where Personal Data is held only for direct marketing, we will stop processing it for direct marketing or erase it within the period required by applicable law after receiving a valid request.

SECTION 11

How Long Do We Store Personal Data

We store Personal Data for the term of its processing by us or third parties engaged by us for providing Services.

We may additionally store Personal Data for 5 years, or 7 years in some cases, after termination of a business relationship with a client or partner unless a longer period is required by applicable law.

SECTION 12

Complaints and Requests

If you have questions about this Privacy Policy, wish to access or correct Personal Data we hold about you, or wish to make a complaint, contact us at info@fx24.market.

We aim to resolve complaints as soon as possible. If we cannot resolve a complaint within that period, we will notify you of the reason for delay and the expected resolution time.

To respond to an access request, we may require information to verify your identity. Applicable legislation may prescribe exceptions affecting your access rights.

If you believe there has been a breach of applicable legislation, please contact us as soon as possible.

If we become aware of a security breach, we may notify you electronically and may make a notice on the Website. Where a Personal Data breach is anticipated to result in high risk to clients' rights and freedoms, we will inform you.

If you are not satisfied with our complaint handling or outcome, you have the right to lodge a complaint with an appropriate authority.

SECTION 13

Cookies

Our Website uses Cookies, small text files saved to your computer or device, to customize and improve your experience while visiting and using the Website.

We may use Cookies for statistics, to understand Website use and user interests, and to improve the delivery of Services on the Website.

The Website may allow you to accept, enable, refuse, or disable the use and saving of Cookies on your computer or device.

You can read more about Cookies by visiting our Cookies Policy.

SECTION 14

Changes to Privacy Policy

Our Privacy Policy is reviewed and updated regularly to reflect new obligations, technologies, business operations, practices, and regulatory changes.

Any Personal Data we store will be subject to our most recent Privacy Policy.

If we update this Privacy Policy, we will post those changes here and in other places we deem necessary.

SECTION 15

Definitions

Data Controller of your Personal Data means a legal entity that determines the purposes, conditions, and manner of any processing activities it carries out.

Direct Marketing means a communication, by whatever means, of advertising or marketing material directed to a particular individual.

GDPR means Regulation (EU) 2016/679 on the protection of natural persons with regard to the processing of Personal Data and on the free movement of such data, as amended, replaced, or superseded from time to time.

Personal Data means any information relating to an identified or identifiable natural person, including identifiers such as name, identification number, location data, online identifier, or factors specific to physical, physiological, genetic, mental, economic, cultural, or social identity. It does not include anonymous data.

Services encompass the services that the Company identifies as being covered by the Company via the Website.