My Maa Markets Ltd
Effective Date: 25 August 2026
My Maa Markets Ltd (“My Maa Markets”, “we”, “us” or “our”) respects your privacy and is committed to protecting your personal data.
This Privacy Policy explains how we collect, use, process, disclose, store and protect personal data when you:
This Privacy Policy is intended to provide clear information about how we handle personal data in accordance with applicable data protection laws and regulatory requirements.
This Privacy Policy should be read together with our applicable Terms and Conditions, Risk Disclosure, Cookie Policy and other legal and regulatory documents.
My Maa Markets Ltd is incorporated in Saint Lucia as an International Business Company (No. 2026-00114) under the International Business Companies Act, Cap 12.14. The Client is onboarded by, and enters into a contractual relationship with, this entity.
Certain operational functions supporting our services, including payment processing and liquidity provision, are provided by My Maa Markets Ltd (Mauritius), Company No. 210279 GBC, which holds Global Business Licence No. GB24203320 issued by the Financial Services Commission of Mauritius. This affiliate provides payment and liquidity services and is not the entity with which the Client contracts for the provision of trading services.
For purposes of applicable data protection legislation, My Maa Markets acts as a Data Controller in relation to personal data processed for our business purposes. Where we engage third parties to process personal data on our behalf, those parties may act as data processors or independent controllers depending on the nature of the service and applicable law.
“Personal Data” means information relating to an identified or identifiable individual. This may include information that directly identifies you or information that can reasonably be associated with you.
Depending on the services you use and your relationship with us, we may collect and process the following categories of personal data.
Where permitted or required by applicable law or regulation, telephone calls and electronic communications may be recorded or monitored for compliance, security, training, quality assurance and dispute-resolution purposes.
We may collect personal data:
You are responsible for ensuring that information you provide to us is accurate and up to date.
We may process your personal data for the following purposes:
Where permitted by applicable law, we may use your contact information to provide service-related communications, account notifications, product updates, educational material, market information and marketing communications. Where consent is required, we will obtain the appropriate consent. You may opt out of marketing communications at any time. Opting out of marketing will not prevent us from sending essential service, security, transactional or regulatory communications.
Depending on the circumstances, we may process personal data based on one or more of the following:
Where processing is necessary to enter into or perform a contract with you, including providing our services and managing your account.
Where processing is necessary to comply with applicable laws, regulations, AML/CFT requirements or lawful requests from competent authorities.
Where processing is necessary for our legitimate business interests, including security, fraud prevention, risk management, service improvement, business administration and defending legal claims, provided that such interests do not override applicable data protection rights.
Where applicable law requires consent, we will obtain your consent before processing your personal data for the relevant purpose. Where processing is based on consent, you may withdraw your consent at any time. Withdrawal does not affect the lawfulness of processing carried out before consent was withdrawn.
We may use automated systems and analytical tools to assist with fraud detection, security monitoring, AML/CFT and sanctions screening, risk management, account security, service optimisation and regulatory compliance. Where applicable law provides rights concerning automated decision-making or profiling, you may exercise those rights in accordance with this Privacy Policy.
We may disclose personal data where necessary and lawful to regulatory and government authorities (including competent financial services regulators, financial intelligence units, law enforcement authorities, courts and tribunals, and tax authorities); service providers (including KYC and identity verification, AML/CFT screening, payment processing, banking services, technology and hosting, cloud infrastructure, trading platforms, CRM systems, cybersecurity, customer support, communications, analytics, auditing and professional services); and professional advisers (lawyers, auditors, accountants, consultants and compliance advisers). We may also disclose information where you have authorised it, where required by law, or where necessary to protect our rights, prevent fraud or financial crime, or protect the safety of our clients, employees or systems. We do not sell your personal data to third parties.
Some of our service providers, technology providers, financial institutions or other recipients may be located in other jurisdictions. Where personal data is transferred internationally, we will take appropriate measures and implement safeguards required by applicable data protection legislation. These safeguards may include contractual protections, security measures and other mechanisms permitted by applicable law.
We implement appropriate technical and organisational measures designed to protect personal data against unauthorised access, unlawful processing, accidental loss, destruction, alteration, unauthorised disclosure and other forms of misuse. Security measures may include access controls, authentication mechanisms, encryption, network security, monitoring, logging, secure hosting, backups, staff access restrictions and incident-response procedures. However, no electronic transmission or storage system can be guaranteed to be completely secure. You are responsible for maintaining the confidentiality of your login credentials and should notify us immediately if you suspect unauthorised access to your account.
Our website and applications may use cookies, software development kits (SDKs), pixels, logs and similar technologies for authentication, security, maintaining sessions, remembering preferences, website functionality, performance monitoring, analytics, improving user experience and marketing where permitted. You may be able to control certain cookies through your browser or device settings. Further information is available in our Cookie Policy.
We retain personal data only for as long as reasonably necessary for the purposes for which it was collected, unless a longer period is required or permitted by applicable law. As a financial services business, we may be legally required to retain certain information after your account has been closed or after you request deletion of your profile, including KYC and identification records, account files, business correspondence, transaction records, financial records, AML/CFT records, regulatory records, audit records, and records required to establish, exercise or defend legal claims. Where a legal or regulatory retention obligation applies, your right to request deletion may be limited to the extent permitted by applicable law. When information is no longer required to be retained, we will take appropriate steps to securely delete, destroy or anonymise it.
You may request closure of your account and deletion or erasure of your personal data, subject to applicable legal and regulatory requirements. Submitting a deletion request does not necessarily mean that all information will be immediately or permanently deleted. Where we are legally required to retain information, that information will continue to be securely retained for the applicable retention period and processed only for legitimate purposes, including legal, regulatory, compliance, audit or dispute-resolution purposes. To request account closure or deletion of your personal data, please contact [email protected]. You may also use any account deletion functionality made available through our Client Portal or mobile application.
Subject to applicable law and any relevant exceptions or restrictions, you may have the right to request access to personal data we hold about you; request correction of inaccurate or incomplete personal data; request deletion or erasure of personal data where applicable; request restriction of processing in circumstances permitted by law; object to certain processing of your personal data; withdraw consent where processing is based on consent; opt out of direct marketing communications; and exercise applicable rights concerning automated decision-making or profiling where provided by law. These rights are not absolute and may be subject to legal, regulatory, contractual or other applicable restrictions. For example, we may be unable to delete information that we are legally required to retain.
To exercise your data protection rights, please contact us at [email protected] with the subject “Data Protection Request”. To protect your account and personal information, we may need to verify your identity before processing certain requests, and may request additional information where reasonably necessary. We will handle requests within the applicable statutory timeframe. Where we are unable to comply fully with a request, we will explain the reason to the extent permitted by applicable law.
Our financial services are intended for individuals who are legally permitted to enter into financial services agreements under applicable law. We do not knowingly collect personal data from individuals who are not eligible to use our services. If you believe that a minor has provided personal data to us, please contact us so that we can take appropriate action.
We maintain procedures designed to identify, assess and respond to personal data breaches and security incidents. Where applicable law requires notification to a regulator or affected individuals, we will make such notification in accordance with applicable legal requirements.
Our website, applications or communications may contain links to third-party websites or services. We are not responsible for the privacy practices, security or content of third-party websites. You should review the privacy policies of third parties before providing them with personal information.
We may update this Privacy Policy from time to time to reflect changes in our services, changes in technology, changes in our data-processing practices, changes in applicable laws or regulations, or regulatory guidance. Where appropriate, we may notify you of material changes through our website, application, Client Portal or other communication channels. The latest version of this Privacy Policy will be made available on our website.
If you have concerns about how we process your personal data, we encourage you to contact us first so that we can investigate and attempt to resolve your concern. You may also have the right to lodge a complaint with a competent data protection or supervisory authority, subject to applicable law.
For questions regarding this Privacy Policy, your personal data, account deletion or your data protection rights, please contact us using the details in the sidebar.
We are committed to protecting your personal data and being transparent about how we use it. If you have any questions about this Privacy Policy, please contact us using the details provided.