How we handle data on your behalf.
This is a plain-English summary of the Data Processing Agreement that applies when TradeFloor processes personal data on your behalf (for example, for a desk or fund). The full binding DPA is available on request and governs in case of conflict.
Roles & obligations
You are the Controller; TradeFloor is the Processor. We process personal data only on your documented instructions, and we:
- Ensure everyone authorised to process personal data is under confidentiality obligations.
- Maintain the technical and organisational security measures summarised in Annex A.
- Assist you in responding to data-subject requests and meeting Articles 32–36 GDPR.
- Return or delete all personal data at the end of the contract, at your choice.
- Make available the information needed to demonstrate compliance, and allow audits.
Sub-processors
You grant general authorisation to engage sub-processors subject to equivalent safeguards. We notify you of any intended change to the sub-processor list by email at least 30 days in advance, during which you may object.
International transfers
Where personal data leaves the EEA, we rely on the Standard Contractual Clauses (Commission Decision 2021/914) as the transfer mechanism.
Data-subject rights & deletion
We provide in-product tooling for data export, rectification and erasure. On termination, within 30 days we return or delete all personal data at your option, save for records we must retain for legal integrity.
Breach notification
We notify you without undue delay after becoming aware of a personal-data breach, with the information you need to meet your own obligations.
Audit & security
We maintain an up-to-date security overview at /security. Annex A summarises the technical and organisational measures in force.
// full DPA on request · [email protected]