The data controller is PRIMARYMARKETS PTY LTD, ACN 136 368 244, ABN 24 136 368 244, registered office Sydney NSW 2000, Australia, trading as TOKENSDESK.
For any privacy question, or to exercise any right in section 9, write to [email protected]. A privacy request is handled by our compliance function, and we will respond within 30 calendar days.
We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. Where the General Data Protection Regulation applies to you because you are in the European Economic Area or the United Kingdom, we also comply with it and section 9 sets out the additional rights it gives you.
| Category | What it is | Where it comes from |
|---|---|---|
| Identity | Full name, date of birth, nationality, residential address, country of residence | You, at sign-up and at verification |
| Contact | Email address, telephone number | You |
| Verification documents | Passport, national ID, driving licence or residence permit; a bank statement or utility bill; and, if you apply for leverage above 1:20, evidence of your source of funds | You, uploaded to the verification page |
| Financial | Account balance, deposits, withdrawals, blockchain wallet addresses you deposit from or withdraw to, transaction hashes | You, and the public blockchain |
| Trading | Orders, positions, trade history, leverage settings, profit and loss | Generated by your use of the Platform |
| Account security | Password (stored only as a cryptographic hash — we never see it), two-factor authentication status, session tokens, IP address and approximate location, browser and device type | You, and automatically on sign-in |
| Communications | Emails and support messages you send us, and our replies | You |
| Preferences | Theme, account currency, watchlist, chart settings, tutorial progress | Stored on your own device, and in your profile where it must follow you between devices |
We do not collect biometric data, health data, political or religious information, or any other sensitive category, and we do not ask for it. We do not buy personal data from data brokers, and we do not track you across other websites.
| Purpose | Lawful basis |
|---|---|
| Opening and operating your account; executing your orders; settling your money | Performance of our contract with you |
| Verifying your identity, address and source of funds; sanctions and watch-list screening; monitoring for financial crime; reporting suspicious matters | Legal obligation — the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) and the AML/CTF Rules |
| Confirming you are not in a restricted jurisdiction | Legal obligation and our legitimate interest in operating lawfully |
| Keeping the Platform secure; detecting fraud, market abuse and unauthorised access | Legitimate interests — protecting clients and the broker |
| Sending service messages you cannot opt out of: deposit credited, withdrawal paid, verification approved, security alerts, changes to these terms | Performance of our contract |
| Sending marketing about our own services | Consent, which you may withdraw at any time using the unsubscribe link in any such message |
| Keeping records of trades, communications and decisions | Legal obligation |
| Improving the Platform and diagnosing faults | Legitimate interests |
We do not make decisions producing legal or similarly significant effects about you by automated means alone. Verification decisions, withdrawal approvals and account closures are made by a person.
We use only what the Platform needs to work. There is no advertising cookie and no analytics cookie, so there is no consent banner to click through.
| What | Purpose | Lasts |
|---|---|---|
| Session token | Keeps you signed in and authenticates each request | Until you sign out or it expires |
| Local storage | Theme, watchlist, chart layout, leverage preference, tutorial progress | Until you clear your browser data |
Preferences kept in local storage stay on your device. Clearing your browser data removes them and nothing else is lost.
We share personal information only with the parties below, only for the purpose stated, and only to the extent needed. Each acts as our processor under contract, except where noted.
| Recipient | What they receive | Why |
|---|---|---|
| Supabase Inc. (United States, on Amazon Web Services infrastructure) | Account records, verification documents, trading and funding records | Our database, authentication and encrypted document storage |
| Resend, Inc. | Your email address and the content of the message we send you | Delivering transactional email |
| Twilio Inc. | Your telephone number, where SMS is used | Delivering security codes and alerts |
| Custodian banks | Your name and the details needed to hold and move client funds | Holding client money in segregated accounts |
| Regulators, law enforcement, AUSTRAC | Whatever the law requires | Legal obligation. Where we report a suspicious matter, the law prohibits us from telling you |
| Professional advisers (lawyers, auditors) | Only what a specific matter requires | Legal and accounting advice, under professional confidentiality |
| A purchaser, if the business is sold | Client records, under equivalent protection | Business transfer. We would tell you before your data moved |
Market data and blockchain services — including Binance, CoinGecko, TwelveData, Frankfurter, TronGrid and Solana public nodes — receive no personal information from us. We request public prices and, when verifying a deposit, we look up a transaction that is already public on the blockchain.
A note on the public blockchain. A deposit or withdrawal is a public transaction. The wallet address, amount and time are visible to anyone, permanently, and neither we nor you can remove them. That is a property of the networks, not of our platform, and it is worth understanding before you send funds.
Our infrastructure providers are based in the United States and process data there and in other countries where they operate. Sending your information outside Australia is therefore necessary for us to provide the service.
Before disclosing personal information overseas we take reasonable steps to ensure the recipient handles it consistently with the Australian Privacy Principles, through contractual data-processing terms, and — where the recipient is in a country without an equivalent privacy regime and GDPR applies — through Standard Contractual Clauses.
| Record | Kept for | Why |
|---|---|---|
| Identity and verification documents | 7 years after the account closes | Required by the AML/CTF Act 2006 (Cth) |
| Transaction, trade and funding records | 7 years after the transaction | Required by the AML/CTF Act and the Corporations Act |
| Communications with you | 7 years | Complaint handling and regulatory evidence |
| Marketing consent and withdrawal of it | Until withdrawn, then 3 years as evidence that we stopped | Demonstrating compliance |
| Security logs, IP addresses | 12 months | Fraud and intrusion investigation |
These periods are legal minimums we must observe, and they are why we cannot delete everything on request while the obligation runs. When a period ends, records are deleted or irreversibly anonymised.
You may ask us to:
Write to [email protected]. We will ask you to verify your identity first — the alternative is handing your data to whoever asks for it. We do not charge for a request.
Tell us first at [email protected]. We acknowledge within 5 business days and respond within 30 calendar days.
If you are not satisfied, you may complain to the Office of the Australian Information Commissioner at oaic.gov.au. If you are in the European Economic Area or the United Kingdom, you may complain to your local data protection authority instead.
No system is perfectly secure. If a data breach occurs that is likely to result in serious harm to you, we will notify you and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme.
The Platform is for adults. We do not knowingly collect information about anyone under 18, and an account cannot lawfully be opened by one. If we learn that we hold a minor's data, we delete it and close the account.
We may update this policy. The version and effective date are at the top. For a change that materially affects your rights, we will notify you by email at least 14 days before it takes effect.
Related documents: Terms & Conditions · AML & KYC Policy