Data Protection Policy

Last Updated: October 27, 2024

This Data Protection Policy outlines MT Academy’s (“the Company” or “MTAcademy.io”) approach to safeguarding personal data and ensuring compliance with applicable data protection regulations, including the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. The policy ensures that all personal data is handled responsibly and securely, protecting both the Company and its users from legal liabilities.

1. Purpose and Scope

The purpose of this policy is to establish guidelines for the collection, processing, storage, and protection of personal data. This policy applies to all employees, contractors, affiliates, and business partners who handle personal data on behalf of MT Academy. It governs how personal data is managed to prevent unauthorized access, misuse, and breaches.

2. Data Collection

2.1 Types of Data Collected
MT Academy may collect the following types of personal data:

  • Personal Identification Information: Name, email address, contact details, and identification documents (e.g., passport, driver’s license) for account creation and support.
  • Technical Information: IP addresses, device information, browser type, and browsing patterns for optimizing the platform and improving user experience.
  • Usage Information: Interactions with the platform, trading activity data (non-financial), and support inquiries.

2.2 Data Minimization
MT Academy ensures that only the data necessary for the purpose of service delivery, legal compliance, and platform improvement is collected. The Company does not collect excessive data beyond what is required.

3. Lawful Basis for Processing Data

MT Academy processes personal data based on the following legal grounds:

  • Contractual Necessity: To provide services, such as account creation, verification, and platform access, personal data must be processed.
  • Legal Obligation: To comply with regulatory requirements, including anti-money laundering (AML) laws and other legal standards.
  • Legitimate Interests: For business operations, such as improving services, monitoring platform usage, and securing the platform.
  • Consent: When required for marketing communications or additional services, explicit consent is obtained from users.

4. Data Processing and Use

4.1 Use of Data
Personal data is used for:

  • Facilitating account creation and management.
  • Verifying user identity in compliance with legal obligations.
  • Providing access to MT Academy’s platform and services.
  • Enhancing platform functionality and user experience.
  • Communicating updates, service changes, or promotional offers (only with user consent).

4.2 Automated Decision-Making
MT Academy does not engage in automated decision-making processes that have legal or significant effects on users without their explicit consent.

5. Data Security

5.1 Technical and Organizational Measures
MT Academy implements robust measures to protect personal data, including:

  • Encryption: SSL encryption is used to secure data during transmission.
  • Access Controls: Restricted access based on role requirements, ensuring only authorized personnel access sensitive data.
  • Firewalls and Secure Servers: Protecting data from unauthorized access, breaches, and other malicious threats.
  • Regular Security Audits: Conducting regular audits and vulnerability assessments to identify and address potential risks.

5.2 Data Breach Notification
In the event of a data breach that compromises personal information, MT Academy will notify the affected users promptly and report the breach to the relevant regulatory authorities, as required by the UK GDPR.

6. Data Retention and Deletion

6.1 Retention Period
Personal data is retained only for as long as necessary to fulfill the purposes outlined in this policy or as required by law. Specific retention periods include:

  • Account Data: Retained for the duration of the user’s account and for up to 5 years after closure for legal and compliance purposes.
  • Communication Logs: Retained for support and compliance verification purposes for up to 3 years.
  • Marketing Data: Retained only with user consent and deleted upon withdrawal of consent.

6.2 Right to Erasure
Users have the right to request the deletion of their personal data. MT Academy will review and act upon such requests unless legal or regulatory requirements necessitate data retention.

7. User Rights

Under the UK GDPR, users have the following rights regarding their personal data:

  • Right to Access: Users can request a copy of the personal data held by MT Academy.
  • Right to Rectification: Users can request correction of inaccurate or incomplete data.
  • Right to Erasure: Users can request deletion of their data if it is no longer needed or if they withdraw consent.
  • Right to Restrict Processing: Users can request limited processing of their data in certain circumstances, such as when accuracy is contested.
  • Right to Data Portability: Users can receive their personal data in a structured, commonly used format.
  • Right to Object: Users can object to the processing of their data for direct marketing or other legitimate interests.
  • Right to Withdraw Consent: Users can withdraw their consent for data processing at any time without affecting the lawfulness of processing prior to withdrawal.

Users wishing to exercise these rights should contact MT Academy’s support team at [email protected].

8. Data Transfers and International Processing

MT Academy may transfer personal data outside the United Kingdom. When doing so, the Company ensures that appropriate safeguards (e.g., standard contractual clauses) are in place to protect personal data in compliance with the UK GDPR.

9. Third-Party Data Sharing and Disclosure

9.1 Service Providers
MT Academy may share personal data with third-party service providers for administrative, technical, or legal purposes. These providers are bound by confidentiality agreements and are prohibited from using the data for their own purposes.

9.2 Legal and Regulatory Compliance
MT Academy may disclose personal data when required to comply with legal obligations, such as AML regulations, tax laws, or other legal processes. Any disclosure will be done in accordance with applicable laws and only when necessary.

9.3 Marketing Partners
MT Academy will share personal data with marketing partners only with the explicit consent of users. Users have the right to opt out of such data sharing at any time.

10. Children’s Privacy

MT Academy’s platform is not intended for individuals under the age of 18. MT Academy does not knowingly collect personal data from children. If data from a minor is inadvertently collected, it will be deleted immediately upon discovery.

11. Amendments to This Data Protection Policy

MT Academy reserves the right to amend this policy at any time to reflect legal changes, regulatory updates, or improvements to the Company’s practices. Users will be notified of any significant changes, and continued use of the platform constitutes acceptance of the revised policy.

12. Governing Law and Jurisdiction

This Data Protection Policy is governed by the laws of the United Kingdom. Any disputes related to the handling of personal data will be subject to the exclusive jurisdiction of the courts in London, UK.