Skip to main content

Legal

Privacy Policy

What personal data GOTAFIMA collects, why, how long it is kept, and the choices and rights you have.

1. Who is responsible

GOTAFIMA Institute of Financial Markets ("GOTAFIMA", "we") is the data controller for personal data processed on the Platform. Contact us through the Contact page for any privacy matter, including exercising your rights.

2. Data we collect

  • Account data: first and last name, email address, and a securely hashed password (we never store your password itself). If you sign in with Google, we receive your name, email and Google account identifier.
  • Verification and security data: email-verification status, sign-in history and security events (with IP address and device information) kept in a protected audit trail used solely for account security and fraud prevention.
  • Usage analytics: pages viewed, scroll depth, time on page, clicks on buttons and calls-to-action, education progress, and campaign parameters (UTM, referral and campaign identifiers). Our analytics deliberately store no IP addresses — only your country and a general device class (browser, operating system, device type).
  • Visitor identifier: a random first-party identifier (the gfm_aid cookie) that links a visit, and any campaign that referred it, to a later registration. It contains no personal details.
  • Communications data: which platform emails were sent to you and their delivery status.
  • Consent choices: the analytics and marketing preferences you set in the consent banner, with the time and policy version.

3. Why we process it (purposes and legal bases)

  • To provide your account and the Platform (performance of our contract with you): registration, sign-in, session security, email verification, password recovery.
  • To secure the Platform (legitimate interest): audit trails, rate limiting, bot protection, fraud and abuse prevention.
  • To understand and improve the Platform and to attribute registrations to the campaigns that produced them (legitimate interest, and consent where required): first-party analytics as described above.
  • To send service communications (contract): verification, welcome, security and account emails. Marketing communications are sent only with your consent and can be withdrawn at any time.
  • To comply with legal obligations, including responding to lawful requests.

4. Cookies and similar technologies

The Cookie Policy lists every cookie and storage key we use, what it does and how long it lasts. Strictly necessary cookies (security and session) are always active; analytics runs according to the choice you make in the consent banner, which you can change at any time from the Cookie Policy page.

5. Who receives your data

  • Independent brokers: if you follow a partner link, you leave the Platform and the broker processes your data under its own privacy policy. We pass a click identifier for attribution — never your name or email.
  • Service providers acting on our instructions: email delivery (Resend), bot protection (Cloudflare Turnstile), sign-in with Google (Google), database hosting (MongoDB Atlas), and website/API hosting. Each processes data only as needed to provide its service.
  • Authorities, where the law requires it.
  • We do not sell personal data.

6. International transfers

Our service providers may process data in other countries. Where data leaves your jurisdiction we rely on the providers’ recognised transfer safeguards and contractual commitments.

7. How long we keep data

  • Account data: for the life of your account, then deleted or anonymised within a reasonable period after closure, except where law requires longer retention.
  • Security audit records: retained per event category on a defined schedule; security-critical records are kept longer to protect you and the Platform.
  • Analytics events: automatically purged after a configured retention period (180 days by default).
  • Consent records: kept as evidence of your choices for as long as required.

8. Your rights

Subject to applicable law, you may request access to, correction of, or deletion of your personal data; object to or restrict processing; withdraw consent at any time (without affecting prior processing); and receive a portable copy of data you provided. Contact us through the Contact page to exercise any right; we may need to verify your identity first. You may also complain to your data-protection authority.

9. Security

We protect personal data with industry-standard measures: passwords hashed with a modern memory-hard algorithm, encrypted connections, hardened session cookies, server-side bot protection, strict access controls and an immutable security audit trail. No system is perfectly secure; we encourage a strong unique password and prompt reporting of anything suspicious.

10. Children

The Platform is not directed at children and may not be used by anyone under 18. We do not knowingly collect data from minors; if you believe a minor has registered, contact us and we will delete the account.

11. Changes to this policy

Each version of this policy carries a version number and effective date. Material changes are announced on the Platform or by email before they take effect; where the law requires renewed consent, the consent banner will ask again.

Privacy Policy · GOTAFIMA Institute of Financial Markets

Open Deriv Account