Privacy Policy
Version 1.0 — June 2026
1. Introduction
1.1. This Privacy Policy (the "Policy") explains how ST Global Markets (Mauritius) Limited (the "Company", "we", "us" or "our") collects, uses, discloses, transfers and protects your personal data, and the rights you have in relation to it.
1.2. The Company is the data controller in respect of the personal data it processes about you. The Company processes personal data in accordance with the Data Protection Act 2017 (the "DPA") and applicable Mauritius law.
1.3. This Policy forms part of, and should be read together with, the Company's Terms of Business. Capitalised terms used but not defined in this Policy have the meaning given to them in the Terms of Business.
1.4. By accepting this Policy and the Terms of Business, you acknowledge that you have read and understood how the Company processes your personal data as described here.
2. Personal Data We Collect
2.1. We collect and process the following categories of personal data:
Identity data — name, date of birth, nationality, gender, and government-issued identification (such as passport or national identity card);
Contact data — residential address, email address and telephone number;
Financial and transactional data — bank account and cryptocurrency wallet details, deposits and withdrawals, trading activity, balances and account history;
Verification and compliance data — proof of address, source of funds and source of wealth information, tax residence and self-certification, politically-exposed-person status, and sanctions and adverse-media screening results;
Technical and usage data — IP address, device and browser information, login data and platform usage;
Communications data — correspondence with us, and recordings of telephone calls and electronic communications.
2.2. We do not generally seek to collect special categories of personal data (as defined in the DPA). Where any such data is unavoidably processed in the course of identity verification, it is processed only to the extent permitted by the DPA.
3. How We Collect Personal Data
3.1. We collect personal data:
Directly from you, when you complete the Application Form, use the Trading Platform, deposit or withdraw funds, or communicate with us;
Automatically, through your use of our website, client portal and Trading Platform; and
From third parties, including introducing brokers and affiliates, payment service providers, banks, identity-verification, credit-reference, fraud-prevention and sanctions-screening providers, and publicly available sources.
4. Purposes and Lawful Bases for Processing
4.1. We process your personal data on the following lawful bases under the DPA, for the purposes indicated:
Performance of a contract — to open and administer your Trading Account, execute and settle your Transactions, process deposits and withdrawals, and provide customer support;
Compliance with a legal obligation — to carry out customer due diligence, ongoing monitoring and reporting under the Financial Intelligence and Anti-Money Laundering Act 2002 and the FSC's AML/CFT framework; to comply with tax-reporting obligations (including FATCA and the Common Reporting Standard); and to comply with the requirements of the FSC and other competent authorities;
Legitimate interests — to prevent fraud and financial crime, ensure the security and integrity of our systems, manage risk, and operate and improve our business, provided these interests are not overridden by your interests and rights; and
Consent — for direct marketing (where required) and for certain cookies and similar technologies. Where we rely on consent, you may withdraw it at any time.
5. Marketing
5.1. Where required by law, we will send you marketing communications only with your consent. You may opt out of marketing at any time, without affecting the provision of the Services, by using the unsubscribe mechanism in our communications or by contacting us using the details in section 13.
6. Disclosure of Personal Data
6.1. We may disclose your personal data to:
Our liquidity provider(s), banks and payment service providers, to the extent necessary to execute Transactions and process payments;
Introducing brokers and affiliates connected with your account;
Service providers and processors who act on our behalf under written agreements, including our customer-relationship-management and back-office providers, identity-verification, screening and IT providers;
Regulators and authorities, including the FSC, the Financial Intelligence Unit, the Mauritius Revenue Authority and any other competent authority, where required or permitted by law;
Our professional advisers (such as auditors and lawyers) under a duty of confidentiality; and
A successor or assignee of our business, in connection with a reorganisation, transfer or sale.
6.2. Where we engage a processor, we require, by written agreement, that the processor acts only on our instructions and applies appropriate security and organisational measures.
7. International Transfers
7.1. Some of the recipients described in section 6 are located outside Mauritius. Where we transfer personal data outside Mauritius, we do so in accordance with the DPA, on the basis of an appropriate legal ground — which may include your consent, the necessity of the transfer for the performance of your contract, or the existence of appropriate safeguards ensuring an adequate level of protection.
7.2. By accepting this Policy, you acknowledge that the provision of the Services necessarily involves the transfer of your personal data to recipients outside Mauritius for the purposes described in this Policy.
8. Data Retention
8.1. We retain your personal data for as long as necessary to provide the Services and to comply with our legal and regulatory obligations.
8.2. In particular, we retain records relating to you, your Transactions and your account-opening documentation for at least seven (7) years after the termination of your relationship with us, or such longer period as Applicable Law requires. When personal data is no longer required, we securely delete or anonymise it.
9. Security of Processing
9.1. We implement appropriate technical and organisational measures to protect personal data against unauthorised or unlawful processing, accidental loss, destruction or damage, in accordance with the DPA. These measures include access controls, encryption where appropriate, staff confidentiality obligations, and ongoing monitoring of our systems.
10. Personal Data Breaches
10.1. Where a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the Data Protection Office, and, where the breach is likely to result in a high risk to you, we will communicate it to you, in each case as and to the extent required by the DPA.
11. Your Rights
11.1. Subject to the conditions and exceptions in the DPA, you have the right to:
Access the personal data we hold about you;
Request rectification of inaccurate or incomplete personal data;
Request erasure of your personal data;
Object to, or request restriction of, the processing of your personal data; and
Withdraw consent where processing is based on consent.
11.2. We may be unable to give full effect to a request where we are required by law (including AML/CFT and tax-reporting obligations) to retain or continue processing your personal data. We will respond to your request within the period required by the DPA.
11.3. To exercise any of these rights, please contact us using the details in section 13.
12. Cookies
12.1. Our website and client portal use cookies and similar technologies to operate the site, remember your preferences, and analyse usage. You can manage non-essential cookies through your browser settings or any cookie-management tool we provide. Further information is set out in our Cookie Policy, where available.
13. Data Protection Officer and Contact Details
13.1. The Company has designated a Data Protection Officer as the point of contact for data-protection matters and for the exercise of your rights.
13.2. You may contact us, or our Data Protection Officer, in relation to this Policy or your personal data at: support.bs@stgmarkets.com, or in writing to the Company at its registered office.
14. Complaints
14.1. If you have a concern about how we process your personal data, we encourage you to contact us first using the details in section 13. You also have the right to lodge a complaint with the Data Protection Office of Mauritius.
15. Changes to this Policy
15.1. We may update this Policy from time to time. The current version is published on the Website, and material changes will be notified to you in accordance with the Terms of Business.
NOTE: Capitalised terms used in this Policy have the meaning given to them in the Company's Terms of Business. In the event of any conflict between this Policy and the Terms of Business, the Terms of Business prevail.