TOKENSDESK

Privacy Policy

What we collect, why, who sees it, and what you can ask us to do
Document version: 3.0  ·  Effective: 18 August 2026  ·  Applies to: tokensdesk.com and the TOKENSDESK platform
This policy describes what we actually do, not what a template says. Where we send data to someone else, that party is named in section 6. Where we hold something for a long time, the reason is given in section 8.

1. Who is responsible for your data

The data controller is PRIMARYMARKETS PTY LTD, ACN 136 368 244, ABN 24 136 368 244, registered office Sydney NSW 2000, Australia, trading as TOKENSDESK.

For any privacy question, or to exercise any right in section 9, write to [email protected]. A privacy request is handled by our compliance function, and we will respond within 30 calendar days.

We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. Where the General Data Protection Regulation applies to you because you are in the European Economic Area or the United Kingdom, we also comply with it and section 9 sets out the additional rights it gives you.

2. What we collect

CategoryWhat it isWhere it comes from
Identity Full name, date of birth, nationality, residential address, country of residence You, at sign-up and at verification
Contact Email address, telephone number You
Verification documents Passport, national ID, driving licence or residence permit; a bank statement or utility bill; and, if you apply for leverage above 1:20, evidence of your source of funds You, uploaded to the verification page
Financial Account balance, deposits, withdrawals, blockchain wallet addresses you deposit from or withdraw to, transaction hashes You, and the public blockchain
Trading Orders, positions, trade history, leverage settings, profit and loss Generated by your use of the Platform
Account security Password (stored only as a cryptographic hash — we never see it), two-factor authentication status, session tokens, IP address and approximate location, browser and device type You, and automatically on sign-in
Communications Emails and support messages you send us, and our replies You
Preferences Theme, account currency, watchlist, chart settings, tutorial progress Stored on your own device, and in your profile where it must follow you between devices

We do not collect biometric data, health data, political or religious information, or any other sensitive category, and we do not ask for it. We do not buy personal data from data brokers, and we do not track you across other websites.

3. Why we use it

PurposeLawful basis
Opening and operating your account; executing your orders; settling your moneyPerformance of our contract with you
Verifying your identity, address and source of funds; sanctions and watch-list screening; monitoring for financial crime; reporting suspicious mattersLegal obligation — the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) and the AML/CTF Rules
Confirming you are not in a restricted jurisdictionLegal obligation and our legitimate interest in operating lawfully
Keeping the Platform secure; detecting fraud, market abuse and unauthorised accessLegitimate interests — protecting clients and the broker
Sending service messages you cannot opt out of: deposit credited, withdrawal paid, verification approved, security alerts, changes to these termsPerformance of our contract
Sending marketing about our own servicesConsent, which you may withdraw at any time using the unsubscribe link in any such message
Keeping records of trades, communications and decisionsLegal obligation
Improving the Platform and diagnosing faultsLegitimate interests

We do not make decisions producing legal or similarly significant effects about you by automated means alone. Verification decisions, withdrawal approvals and account closures are made by a person.

4. What we do not do with it

5. Cookies and local storage

We use only what the Platform needs to work. There is no advertising cookie and no analytics cookie, so there is no consent banner to click through.

WhatPurposeLasts
Session tokenKeeps you signed in and authenticates each requestUntil you sign out or it expires
Local storageTheme, watchlist, chart layout, leverage preference, tutorial progressUntil you clear your browser data

Preferences kept in local storage stay on your device. Clearing your browser data removes them and nothing else is lost.

6. Who we share it with

We share personal information only with the parties below, only for the purpose stated, and only to the extent needed. Each acts as our processor under contract, except where noted.

RecipientWhat they receiveWhy
Supabase Inc. (United States, on Amazon Web Services infrastructure) Account records, verification documents, trading and funding records Our database, authentication and encrypted document storage
Resend, Inc. Your email address and the content of the message we send you Delivering transactional email
Twilio Inc. Your telephone number, where SMS is used Delivering security codes and alerts
Custodian banks Your name and the details needed to hold and move client funds Holding client money in segregated accounts
Regulators, law enforcement, AUSTRAC Whatever the law requires Legal obligation. Where we report a suspicious matter, the law prohibits us from telling you
Professional advisers (lawyers, auditors) Only what a specific matter requires Legal and accounting advice, under professional confidentiality
A purchaser, if the business is sold Client records, under equivalent protection Business transfer. We would tell you before your data moved

Market data and blockchain services — including Binance, CoinGecko, TwelveData, Frankfurter, TronGrid and Solana public nodes — receive no personal information from us. We request public prices and, when verifying a deposit, we look up a transaction that is already public on the blockchain.

A note on the public blockchain. A deposit or withdrawal is a public transaction. The wallet address, amount and time are visible to anyone, permanently, and neither we nor you can remove them. That is a property of the networks, not of our platform, and it is worth understanding before you send funds.

7. Where your data is held

Our infrastructure providers are based in the United States and process data there and in other countries where they operate. Sending your information outside Australia is therefore necessary for us to provide the service.

Before disclosing personal information overseas we take reasonable steps to ensure the recipient handles it consistently with the Australian Privacy Principles, through contractual data-processing terms, and — where the recipient is in a country without an equivalent privacy regime and GDPR applies — through Standard Contractual Clauses.

8. How long we keep it

RecordKept forWhy
Identity and verification documents7 years after the account closesRequired by the AML/CTF Act 2006 (Cth)
Transaction, trade and funding records7 years after the transactionRequired by the AML/CTF Act and the Corporations Act
Communications with you7 yearsComplaint handling and regulatory evidence
Marketing consent and withdrawal of itUntil withdrawn, then 3 years as evidence that we stoppedDemonstrating compliance
Security logs, IP addresses12 monthsFraud and intrusion investigation

These periods are legal minimums we must observe, and they are why we cannot delete everything on request while the obligation runs. When a period ends, records are deleted or irreversibly anonymised.

9. Your rights

You may ask us to:

Write to [email protected]. We will ask you to verify your identity first — the alternative is handing your data to whoever asks for it. We do not charge for a request.

10. If you are unhappy with how we handled your data

Tell us first at [email protected]. We acknowledge within 5 business days and respond within 30 calendar days.

If you are not satisfied, you may complain to the Office of the Australian Information Commissioner at oaic.gov.au. If you are in the European Economic Area or the United Kingdom, you may complain to your local data protection authority instead.

11. How we protect it

No system is perfectly secure. If a data breach occurs that is likely to result in serious harm to you, we will notify you and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme.

12. Children

The Platform is for adults. We do not knowingly collect information about anyone under 18, and an account cannot lawfully be opened by one. If we learn that we hold a minor's data, we delete it and close the account.

13. Changes to this policy

We may update this policy. The version and effective date are at the top. For a change that materially affects your rights, we will notify you by email at least 14 days before it takes effect.


Related documents: Terms & Conditions  ·  AML & KYC Policy