Website Privacy Policy

broktrading.com · Broktrading Ltd

Version 2.2026 · Last updated 15 August 2026

How Broktrading Ltd handles personal data collected through this website, what we do with it, who else sees it, and what you can require of us.

1. Who we are and what this policy covers

Broktrading Ltd (“Broktrading”, “we”, “us”) is a private limited liability company incorporated in the Republic of Cyprus under registration number HE 342927, with registered office at Orfeos Street 2B, Office 201, 1070 Nicosia, Cyprus. Our VAT number is CY10342927L.

We are the controller of the personal data described below, within the meaning of Article 4(7) of Regulation (EU) 2016/679 (the “GDPR”). In Cyprus the GDPR is supplemented by the Processing of Personal Data (Protection of Natural Persons) Law of 2018 (Law 125(I)/2018).

This policy covers personal data collected through this website. It does not cover data we process under a signed engagement, licence or service agreement with a client, which is governed by that agreement and by the data-processing terms attached to it.

We have not appointed a Data Protection Officer, and are not required to. Article 37 GDPR requires one where the controller's core activities consist of regular and systematic monitoring of data subjects on a large scale, or of large-scale processing of special category data. Neither describes this website or our business. Questions about this policy go to info@broktrading.com, or to the registered office above.

2. The personal data we collect

Three categories, and no others.

Category What it consists of Where it comes from
Enquiry dataYour name, your surname, your email address and the content of your message, all of which the contact form requires; your company name and your telephone number, which it does not. Nothing else is asked for and no other field exists.You, when you submit the contact form or write to us directly
Technical dataYour IP address, the date and time of the request, the page requested, the referring page if there is one, and your browser's user-agent string.Recorded automatically in the server logs of our hosting provider when your browser requests a page
Anti-abuse dataA one-way cryptographic hash of the IP address the enquiry was sent from, and your browser's user-agent string, stored with the enquiry itself. The hash is computed with a secret key held on our server. Your IP address is not stored with the enquiry, is not sent to the database, and cannot be recovered from the hash.Derived from your request at the moment you submit the contact form

We do not use technical data to build a profile of you, and we do not combine it with enquiry data. Anti-abuse data is by necessity stored next to the enquiry it belongs to, but it is used for the single purpose named in the next section, it is not compared against anything outside this website, and it tells us only that two submissions came from the same place, never where that place is. We do not collect special category data within the meaning of Article 9 GDPR, we do not ask for it anywhere on this site, and we do not knowingly collect personal data from children. Please do not send us sensitive personal data through the contact form.

3. Cookies and tracking

This website sets no cookies. It runs no analytics, no advertising or social-media pixels, and no embedded third-party content. Typefaces are served from our own domain rather than from a third-party font service, so loading a page sends nothing to anyone but our own hosting provider.

Our Cookie Policy records that position in full, explains why no consent banner is shown, and states what we will do if the position changes.

4. Why we process it, and on what lawful basis

Purpose Data used Lawful basis
Reading your enquiry, answering it, and carrying on the correspondence that followsEnquiry dataArticle 6(1)(b) GDPR, steps taken at your request before entering into a contract, where your enquiry concerns our services. Where it does not, Article 6(1)(f), our legitimate interest in replying to people who write to us.
Keeping a record of enquiries received and what was said in replyEnquiry dataArticle 6(1)(f) GDPR, our legitimate interest in keeping an accurate record of our commercial correspondence.
Serving the website, keeping it available, and identifying abuse of itTechnical dataArticle 6(1)(f) GDPR, our legitimate interest in operating the site securely.
Recognising automated submissions to the contact form, and limiting how many enquiries can be sent from the same place in quick successionAnti-abuse dataArticle 6(1)(f) GDPR, our legitimate interest in keeping the form open to the people it is for. Without it the form can be submitted in bulk by a script, which is what closes such forms.
Meeting a legal or regulatory obligation, or establishing, exercising or defending a legal claimEither category, as relevantArticle 6(1)(c) GDPR where the obligation binds us, and Article 6(1)(f) where the interest is in defending a claim.

Where we rely on legitimate interests we have weighed that interest against your interests, rights and freedoms. We consider it is not overridden, because the data involved is limited, you supplied it deliberately, we use it only for the purpose you supplied it for, and none of it is used to profile or to target you. You can object at any time, and we explain how below.

5. Who else sees it

We do not sell personal data, we do not share it with anyone for their own marketing, and we do not disclose it except as set out here.

Recipient What it does with the data Established in
Vercel Inc.Hosts this website and generates the server logs described aboveUnited States, with edge infrastructure in several regions
Supabase, Inc.Stores your contact-form message, together with the anti-abuse data recorded with it, and passes the message to our mailboxUnited States, with data stored in a European Union region
ResendDelivers the notification email that carries your enquiry from our website to our mailboxUnited States, with the sending region set to the European Union
Microsoft (Microsoft 365)Holds the enquiry from the moment it reaches our mailbox, as it holds any other correspondenceEuropean Union, within the Microsoft EU Data Boundary
Our professional advisers, and public authoritiesReceive personal data only where an adviser needs it to advise us, or where we are legally obliged to disclose itCyprus, principally

Each provider named above acts as our processor, on our instructions, under the data-processing terms it publishes for that purpose, which are drafted to meet Article 28 GDPR.

6. Transfers outside the European Economic Area

Two of the providers named above are established in the United States. Where personal data reaches them, the transfer relies on the standard contractual clauses adopted by the European Commission under Article 46(2)(c) GDPR and, where the provider is certified under the EU-US Data Privacy Framework, on the Commission's adequacy decision of 10 July 2023 under Article 45 GDPR.

You can ask us for a copy of the safeguards that apply to a particular transfer by writing to info@broktrading.com.

7. How long we keep it

  • Enquiry data: twenty-four (24) months from our last exchange with you. If the enquiry becomes a client relationship, the correspondence is kept for the life of that relationship and afterwards for as long as Cypriot company and tax law requires records of the engagement to be kept.
  • Technical data: the retention period applied by our hosting provider to its server logs, which is measured in days rather than months.
  • Anti-abuse data: kept with the enquiry it was recorded against, and deleted at the same time as that enquiry. It has no separate life and is never moved anywhere else.
  • Anything we are asked to erase: deleted on request, unless we are required to keep it or need it to establish, exercise or defend a legal claim, in which case we tell you which of the two applies.

8. Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you, and receive a copy of it (Article 15);
  • have it corrected if it is inaccurate or incomplete (Article 16);
  • have it erased (Article 17);
  • restrict how we process it while a dispute about accuracy or lawfulness is resolved (Article 18);
  • receive it in a portable form, where the processing rests on contract and is carried out by automated means (Article 20);
  • object to processing based on our legitimate interests, on grounds relating to your particular situation (Article 21). If you object, we stop unless we can show compelling legitimate grounds that override your interests.

To exercise any of these, write to info@broktrading.com. We answer within one (1) month of receiving the request, as Article 12(3) GDPR requires. If the request is complex we may extend that by up to two (2) further months, and we will tell you within the first month if we do. There is no charge unless the request is manifestly unfounded or excessive.

If you are not satisfied with how we have handled your personal data, you can complain to the Cypriot supervisory authority. You also have the right to an effective judicial remedy under Article 79 GDPR.

  • Office of the Commissioner for Personal Data Protection
  • 1 Iasonos Street, 1082 Nicosia, Cyprus
  • Telephone +357 22 818 456
  • commissioner@dataprotection.gov.cy
  • www.dataprotection.gov.cy

9. Automated decision-making

We take no decisions about you by automated means, and we do not profile you. The contact form carries a hidden field that automated senders fill in and people do not; a submission that fills it is discarded. That check looks at the submission, not at you, and produces no legal or similarly significant effect, so Article 22 GDPR does not apply to it.

10. Security

The site is served over HTTPS, so what you type into the contact form is encrypted in transit. Access to the mailbox that receives enquiries is limited to the people in the company who need it in order to answer you.

No security measure is perfect. If a personal data breach occurs and it is likely to result in a risk to your rights and freedoms, we notify the Commissioner within seventy-two (72) hours as Article 33 GDPR requires, and we notify you directly where Article 34 requires it.

11. Changes to this policy

The version published on this website is the current one and replaces every earlier version. Each version carries a version number and a date. Where a change materially affects what we do with personal data already collected, we say so on the page rather than leaving you to compare versions.

12. How to contact us

  • Broktrading Ltd
  • Orfeos Street 2B, Office 201, 1070 Nicosia, Cyprus
  • Registration number HE 342927 · VAT number CY10342927L
  • info@broktrading.com · +357 99189640