Legal

Privacy Notice

1. Who We Are and Who Controls Your Data

Montrock Ltd is the data controller for personal data processed in connection with its website, onboarding, regulated services and corporate operations, except where another entity independently determines the purposes and means of processing.

Privacy enquiries should be sent to privacy@mont-rock.com.

2. Data Protection Framework

The Company processes personal data in accordance with the Mauritius Data Protection Act 2017 and other applicable data-protection obligations. Where cross-border laws apply to a particular person or processing activity, additional rights or safeguards may apply.

3. Personal Data We Collect

We may process:

  • identity data: name, date and place of birth, nationality, citizenship, photographs, signatures and identification-document details;
  • contact data: residential and business address, email, telephone and emergency or authorised contacts;
  • KYC/AML data: PEP and sanctions results, adverse-media information, source of funds, source of wealth, beneficial ownership and transaction-purpose information;
  • financial data: bank-account details, payment details, tax identifiers, income, assets, liabilities, net worth, expected transaction profile and trading information;
  • corporate data: incorporation records, constitutional documents, registers, ownership and control, directors, authorised signatories and licences;
  • appropriateness/suitability data: knowledge, experience, objectives, risk tolerance and capacity for loss where required;
  • communications: emails, chat, support interactions, telephone recordings and complaints;
  • technical data: IP address, device identifiers, browser, operating system, login data, cookie identifiers, geolocation indicators and security logs;
  • transaction and platform data: orders, trades, deposits, withdrawals, account history, timestamps and audit logs.

4. How We Obtain Data

Data may be collected directly from you, from authorised representatives, from public registers, sanctions/PEP databases, fraud-prevention providers, identity-verification providers, banks, PSPs, payment agents, counterparties, professional advisers and competent authorities.

5. Purposes of Processing

We process personal data to:

  • assess and onboard prospective clients;
  • perform KYC, AML/CFT, sanctions, fraud and financial-crime controls;
  • provide and administer accounts and regulated services;
  • execute, settle, reconcile and report transactions;
  • manage margin, credit, liquidity, operational and compliance risk;
  • comply with legal, regulatory, tax, audit and recordkeeping obligations;
  • prevent unauthorised access, cybercrime and misuse;
  • handle complaints, disputes, investigations and legal claims;
  • communicate service, regulatory and security notices;
  • improve systems, services and customer experience;
  • conduct proportionate marketing where permitted and subject to applicable consent/opt-out rights.

6. Legal Bases

Depending on the processing, the Company may rely on performance of a contract, steps taken before entering a contract, compliance with legal obligations, legitimate interests, consent, or another lawful basis recognised by applicable data-protection law.

Consent will not be used where another legal basis is more appropriate, and withdrawing consent does not affect processing already lawfully undertaken.

7. Automated Tools and Profiling

The Company may use automated or semi-automated tools for identity verification, sanctions/PEP screening, fraud detection, device risk, geographic checks, transaction monitoring and risk scoring. Material adverse decisions requiring human review will be handled in accordance with applicable law and internal procedures.

8. Sharing of Personal Data

Personal data may be shared, where necessary and lawful, with:

  • FSC Mauritius, the Financial Intelligence Unit, tax authorities, courts, law-enforcement agencies and other competent authorities;
  • banks, custodians, liquidity providers, execution venues, brokers, clearing or settlement providers;
  • approved payment agents, merchant acquirers and payment service providers;
  • identity-verification, screening, fraud-prevention and compliance technology providers;
  • hosting, cloud, cybersecurity, CRM, communications and support providers;
  • auditors, lawyers, accountants, insurers and other professional advisers;
  • potential successors in connection with a lawful merger, restructuring, financing or sale, subject to appropriate safeguards.

The Company does not sell personal data as a business model.

9. International Transfers

Because the Company operates internationally, personal data may be processed outside Mauritius. Where required, the Company will implement appropriate contractual, organisational or legal safeguards and will assess relevant transfer risks.

10. Retention

Records are retained for as long as required by applicable financial-services, AML/CFT, tax, corporate, limitation and data-protection requirements. As a general compliance baseline, KYC, transaction and client relationship records may be retained for at least seven years after the end of the relationship, or longer where required by law, litigation hold, regulatory direction or legitimate evidential need.

11. Security

The Company uses proportionate technical and organisational measures, including access controls, authentication, encryption where appropriate, logging, monitoring, backup, incident response, staff confidentiality and vendor due diligence. No internet-based system is completely risk free.

12. Your Rights

Subject to applicable law and exemptions, you may have rights to access personal data, request correction, object to or restrict certain processing, request erasure where retention is not legally required, obtain portability where applicable, withdraw consent, and complain to the Mauritius Data Protection Office.

Rights requests may require identity verification and may be limited where the Company must retain information for AML/CFT, regulatory, legal or evidential reasons.

13. Marketing

Marketing communications will be sent only where permitted. You may opt out using the mechanism provided in the communication. Service, security, legal and regulatory notices are not marketing and may continue despite an opt-out.

14. Call and Communication Recording

Where legally permitted or required, communications may be recorded for regulatory, evidential, quality, training, fraud-prevention and dispute-resolution purposes.

15. Children’s Data

The Company’s regulated services are not intended for minors. The Company does not knowingly onboard persons who do not meet the applicable age and legal-capacity requirements.

16. Data Breaches

Suspected personal-data breaches are assessed under the Company’s incident-response process and notified to authorities and affected individuals where required by law.

17. Changes to this Notice

The Company may update this Notice to reflect law, technology, vendors or services. Material changes will be communicated appropriately.

Contact and Regulatory Information

Montrock Ltd is incorporated in Mauritius under Company No. 231276 GBC and is regulated by the Financial Services Commission, Mauritius (FSC) as an Investment Dealer (Full Service Dealer, Excluding Underwriting), FSC Licence No. GB25205688. Registered office: Suite 201, Level 2, The Catalyst, 40 Silicon Avenue, Cybercity, Ebene 72201, Mauritius.

Compliance enquiries: compliance@mont-rock.com

Website: https://mont-rock.com

Risk warning: Transactions in financial instruments, particularly leveraged or derivative instruments where offered, involve significant risk and may result in substantial loss. Nothing on the website constitutes a guarantee of profit or investment performance.

Trading leveraged products carries a high level of risk and may result in losses that exceed your deposit. Consider whether you understand how CFDs work and whether you can afford to take the high risk of losing your money. Read full disclosure.