1. Status and scope
This is a privacy-notice drafting structure, not a statement of actual Wolf Markets data practices. The controller, applicable privacy laws, products, systems, processors, retention schedule, and contact routes are not confirmed.
The final notice must cover website visitors, applicants, prospective and current clients, representatives, beneficial owners, payers, contacts, and other relevant individuals.
2. Who controls personal data
Identify each controller’s legal name, address, company number, privacy contact, data-protection officer where required, and representative where an entity offers services to or monitors people outside its establishment.
Where more than one entity determines purposes, explain their roles and how individuals can exercise rights.
3. Personal data collected
- Identity, date of birth, citizenship, tax and government-identifier data.
- Contact, address, account, preference, and communication records.
- Financial circumstances, experience, objectives, appropriateness, source of wealth and funds.
- Payment, banking, transaction, order, position, device, login, and security data.
- Verification documents, facial or biometric-derived data where lawfully used.
- Website, cookie, analytics, marketing, support, complaint, call, and correspondence data.
- Sanctions, politically exposed person, fraud, adverse media, and compliance screening results.
4. Sources of data
State whether information comes directly from the individual, account representatives, payment providers, identity and screening vendors, public registers, regulators, exchanges, analytics providers, devices, cookies, affiliates, or introducing partners.
Where data is obtained indirectly, the final notice should provide the information and timing required by applicable law.
5. Purposes and lawful bases
Map each real processing purpose to a valid lawful basis rather than listing every possible basis generally.
- Assess eligibility, appropriateness, and open and administer accounts.
- Provide platform, execution, payment, reporting, and support services.
- Meet anti-money-laundering, sanctions, tax, regulatory, recordkeeping, and reporting duties.
- Secure systems, prevent fraud, investigate incidents, and manage legal claims.
- Improve products, measure performance, analyze use, and communicate service changes.
- Send marketing only where lawful and respect withdrawal or objection rights.
- Recruit staff and manage candidate applications.
6. Automated decisions and profiling
Describe any automated eligibility, appropriateness, fraud, security, marketing, or risk decisions; the logic and significance required by law; and available human review or challenge rights.
Do not state that no automated decision-making occurs until actual onboarding and monitoring systems are audited.
8. International transfers
Map where data is accessed and stored. For transfers outside the applicable jurisdiction, identify the legal mechanism, safeguards, risk assessment, and how a copy can be requested.
9. Retention and deletion
Provide category-specific retention periods or understandable criteria tied to financial-services, AML, tax, complaint, litigation, security, and corporate requirements.
Explain secure deletion or anonymization and any lawful hold that prevents deletion. Do not promise immediate deletion where regulatory records must remain.
10. Security and breaches
Describe security at an appropriate level without exposing defensive detail: access controls, encryption where used, monitoring, resilience, vendor review, training, and incident management.
Explain how affected individuals and authorities will be notified when required and how suspected incidents can be reported through a verified route.
11. Individual rights
Depending on applicable law, rights may include access, correction, deletion, restriction, portability, objection, withdrawal of consent, complaint to a supervisory authority, and safeguards around solely automated decisions.
The final notice must explain how to submit and verify a request, expected timing, lawful exceptions, and the relevant authority.
13. Contact, complaints, and changes
Publish verified controller and privacy contact details, any DPO or representative, and the competent data-protection authority. Explain how material notice changes will be communicated and maintain a visible effective date and version history.
Authoritative drafting should be checked against the applicable law. For example, GDPR Article 13 and ICO guidance require controller identity, purposes, lawful bases, recipients, retention, and rights information.