Last updated: 4 October 2026 · Template — to be reviewed by qualified legal counsel before publication.
1. Who We Are
The controller of your personal data is OCTO FINANCIAL LTD, 178 Merton High Street, London, England, SW19 1AY (“OctoHex”, “we”). We have appointed a Data Protection Officer, who can be contacted at privacy@octohex.com. Where required, our representative in the European Union is not yet appointed; until an appointment is published in this Policy, EU residents can contact our Data Protection Officer at privacy@octohex.com.
This Policy applies to personal data processed when you visit our website, register an account, complete identity verification, use the client area, participate in the partner program or otherwise interact with us. It is designed to comply with the EU General Data Protection Regulation (GDPR) and other applicable data protection laws.
2. Personal Data We Collect
Identity and contact data: name, date of birth, nationality, address, email address, phone number, country of residence.
Verification (KYC) data: images and details of identity documents, selfie images and liveness video, facial biometric templates used to compare your selfie with your document, proof of address, and the results of sanctions, PEP and adverse media screening.
Financial and transaction data: deposit and withdrawal records, wallet addresses, blockchain transaction hashes, wallet risk-screening results, Package details, daily credits and withdrawal-window releases, trading results, fees, and source of funds or wealth information.
Account and usage data: login credentials (stored in hashed form), security settings, records of accepted documents with version and timestamp, communications with us, preferences such as language and Stop-Loss Protection settings.
Technical data: IP address, device and browser information, approximate location derived from IP, log data and cookie identifiers (see our Cookie Policy).
Partner data: partner applications and approval records, referral links and codes, referred client relationships, team member relationships, volume tiers, commission, cashback and introducer bonus calculations, and payout records.
3. Biometric Data
Facial images and biometric templates constitute special category data under the GDPR. They are processed by our verification provider Didit, acting as our processor, solely to verify your identity and prevent fraud. We process this data on the basis of your explicit consent given during verification and, where applicable, on the basis of substantial public interest in the prevention of money laundering and fraud as permitted by law. Biometric templates are retained only for as long as necessary for the verification and in accordance with the retention periods required by AML law. You may withdraw consent, but we will then be unable to verify your identity by this method and may be unable to provide the Services.
4. Purposes and Legal Bases
To create and manage your account and provide the Services, including execution of strategies, calculation of fees and distributions and processing of deposits and withdrawals — performance of a contract.
To verify your identity, screen against sanctions and PEP lists, monitor transactions, apply the Travel Rule, report suspicious activity and keep records — compliance with legal obligations.
To prevent fraud, secure the Platform, enforce our Terms and defend legal claims — our legitimate interests.
To administer the partner program and attribute referrals — performance of a contract with the partner and our legitimate interests.
To send service communications and important notices — performance of a contract and legal obligations.
To send marketing communications and use optional analytics cookies — your consent, which you may withdraw at any time.
To improve the Platform and our strategies using aggregated or pseudonymised data — our legitimate interests.
5. Recipients and Processors
We share personal data only where necessary, with the following categories of recipients:
Identity verification provider (Didit) for document, liveness, biometric and screening checks;
Crypto payment processor for processing deposits and withdrawals;
Blockchain analytics and wallet-screening providers;
Liquidity providers and prime brokers, to the extent required for execution and their own compliance obligations;
Cloud hosting, database, email and customer support providers;
Analytics providers, only where you have consented to analytics cookies;
Professional advisers, auditors and insurers;
Competent authorities, financial intelligence units, courts and law enforcement where required by law.
Our processors act on our documented instructions under data processing agreements. A current list of processors is available on request from privacy@octohex.com. We do not sell your personal data.
6. International Transfers
Some recipients may be located outside the European Economic Area or your country of residence. Where personal data is transferred to a country that does not provide an adequate level of protection, we use appropriate safeguards such as the European Commission’s Standard Contractual Clauses together with supplementary measures where needed. You may request a copy of the relevant safeguards from privacy@octohex.com.
7. Retention
We retain KYC records, transaction records and related correspondence for at least five (5) years after the end of the business relationship or the date of the relevant transaction, or longer where required by applicable AML law or a competent authority (currently five years under the UK Money Laundering Regulations 2017). Other account data is kept for the duration of the relationship and thereafter for as long as necessary to comply with legal obligations and to establish or defend legal claims. Marketing data is retained until you withdraw consent. Where data is no longer required, we delete or anonymise it securely.
8. Your Rights
Subject to applicable law, you have the right to access your personal data, to rectify inaccurate data, to erasure, to restrict processing, to data portability, to object to processing based on legitimate interests, and to withdraw consent at any time without affecting the lawfulness of prior processing. Certain rights are limited where we must retain data under AML or other legal obligations.
To exercise your rights, contact privacy@octohex.com. We may need to verify your identity before responding. We will respond within one month, which may be extended where permitted by law. You also have the right to lodge a complaint with a supervisory authority, in particular in your country of residence or the Information Commissioner's Office (ICO).
9. Automated Decision-Making
Identity verification and screening involve automated processing, which may result in a decision to approve, refer or decline verification. Where a decision produces legal or similarly significant effects, you may request human review, express your point of view and contest the decision by contacting support@octohex.com. The execution of trading strategies is automated but does not involve profiling of you as an individual.
10. Cookies
We use essential cookies to operate the Platform and, with your consent, optional analytics cookies. Details are set out in our Cookie Policy.
11. Security
We implement appropriate technical and organisational measures to protect personal data, including encryption in transit and at rest, access controls on a need-to-know basis, password hashing, logging and monitoring, and vendor due diligence. No system is completely secure; if a personal data breach occurs that is likely to result in a high risk to you, we will notify you and the competent authority as required by law.
12. Children
The Services are not directed at persons under 18 years of age, and we do not knowingly collect their personal data. If we learn that we have collected data from a minor, we will close the account and delete the data, subject to legal retention obligations.
13. Changes and Contact
We may update this Policy from time to time. The current version and its effective date are published on this page, and we will notify you of material changes. For questions about this Policy, contact our Data Protection Officer at privacy@octohex.com or write to OCTO FINANCIAL LTD, 178 Merton High Street, London, England, SW19 1AY.
