← Back to MaxBrokVenture
1. Data Controller
MaxBrokVenture Ltd ("we," "us," or "our"), registered in England and Wales, is the data controller for personal data collected through the maxbrokventure.com platform. We are committed to protecting your personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
2. Information We Collect
Information You Provide Directly
- Account registration: username, email address, password (stored as a bcrypt hash);
- KYC verification: government-issued identity documents, facial photographs (where applicable);
- Deposit & withdrawal requests: cryptocurrency wallet addresses, transaction hashes, deposit amounts;
- Communications: messages sent via live chat or email support.
Information Collected Automatically
- Usage data: pages visited, features used, session duration;
- Device & technical data: IP address, browser type, operating system, device identifiers;
- Cookies: session cookies required for platform operation (see Section 8).
| Category | Examples | Purpose |
| Identity | Username, full name (KYC) | Account management, AML compliance |
| Contact | Email address | Notifications, support, security alerts |
| Financial | Deposit amounts, wallet addresses | Transaction processing |
| Technical | IP address, browser, device | Security, fraud prevention |
| Usage | Pages visited, click events | Platform improvement |
3. How We Use Your Information
We use your personal data for the following purposes:
- To create and manage your account;
- To process deposits, investment plans, daily returns, and withdrawal requests;
- To verify your identity and comply with our Anti-Money Laundering (AML) and Know Your Customer (KYC) obligations;
- To detect, prevent, and investigate fraud, security incidents, and violations of our Terms of Service;
- To send you transactional emails (deposit confirmations, withdrawal approvals, security alerts);
- To improve platform functionality, user experience, and security;
- To comply with legal and regulatory obligations.
We do not use your personal data for unsolicited marketing communications unless you have explicitly consented to receive them.
4. Legal Basis for Processing
Under UK GDPR, we process your personal data on the following legal bases:
- Contract performance: Processing necessary to deliver our investment services and process your transactions;
- Legal obligation: Processing required for compliance with UK AML regulations, tax law, and FCA guidelines;
- Legitimate interests: Fraud prevention, security monitoring, and platform improvement;
- Consent: Where you have given explicit consent (e.g., optional marketing communications).
5. Sharing Your Information
We do not sell your personal data. We may share your data with:
- Service providers: Third-party tools used to operate the platform (e.g., live chat software, hosting providers) under strict data processing agreements;
- Law enforcement / regulators: Where required by law, court order, or to protect the rights and safety of MaxBrokVenture and its users;
- Professional advisers: Solicitors, accountants, or auditors bound by confidentiality obligations.
All third-party service providers are required to process your data securely and only for the purposes for which it was shared.
6. Data Retention
We retain your personal data for as long as necessary to provide the Service and comply with our legal obligations:
- Account data is retained for the duration of your account and for 6 years after closure (for legal and tax purposes);
- Transaction records are retained for 7 years in accordance with UK AML regulations;
- KYC documents are retained for 5 years after the end of our business relationship;
- Technical logs (IP addresses, session data) are retained for up to 12 months.
After the applicable retention period, your data is securely deleted or anonymised.
7. Your Rights
Under UK GDPR, you have the following rights regarding your personal data:
- Right of access: Request a copy of the personal data we hold about you;
- Right to rectification: Request correction of inaccurate or incomplete data;
- Right to erasure ("right to be forgotten"): Request deletion of your data (subject to legal obligations);
- Right to restriction: Request that we limit the processing of your data in certain circumstances;
- Right to data portability: Receive your data in a structured, machine-readable format;
- Right to object: Object to processing based on legitimate interests;
- Rights related to automated decision-making: We do not make solely automated decisions that significantly affect you.
To exercise any of these rights, contact us at privacy@maxbrokventure.com. We will respond within 30 days. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
8. Cookies
We use only essential session cookies required to operate the platform securely (e.g., to maintain your login session). These cookies are:
- Session cookies: Expire when you close your browser. Required to keep you logged in and protect against cross-site request forgery (CSRF).
We do not use tracking cookies, advertising cookies, or any third-party analytics cookies that process personal data without your consent. You can disable cookies in your browser settings, but this will prevent you from logging in to the platform.
9. Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, disclosure, alteration, or destruction. These include:
- HTTPS encryption for all data in transit;
- Bcrypt hashing for all passwords (never stored in plain text);
- Session security with HTTP-only, Secure, and SameSite cookie attributes;
- Login throttling to prevent brute-force attacks;
- Admin-restricted access to user data and transaction records.
While we take security seriously, no system is completely immune to breaches. In the event of a data breach affecting your rights, we will notify you and the ICO as required by UK GDPR.
10. Children's Privacy
The Service is not directed at individuals under 18 years of age. We do not knowingly collect personal data from children. If we become aware that we have collected personal data from a minor without verified parental consent, we will take steps to delete that data promptly.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will post the updated policy on this page with a revised "last updated" date. For significant changes, we will notify registered users via email or in-platform notification. Your continued use of the Service after any change constitutes acceptance of the updated policy.