Privacy Policy
SCOSDesk institutional platform
Introduction
SHAKSETTLE Capital Ltd. ("SHAKSETTLE Capital", "we", "us", or "our") respects the privacy of the individuals whose personal data we process in connection with SCOSDesk (the "Platform"). This Privacy Policy explains what personal data we collect, why we collect it, how we use and protect it, and the rights available to data subjects.
Data Controller
SHAKSETTLE Capital Ltd. acts as the data controller for personal data processed through the Platform. Where an affiliated entity independently determines the purposes and means of processing, that entity acts as controller for the relevant activities.
Categories of Personal Data
We process identity and contact data (name, job title, work email); access and authentication data (user IDs, hashed credentials, MFA metadata, session tokens, API key identifiers); technical and device data (IP address, device identifiers, browser and OS information, country-level geolocation); activity and audit data (login events, actions performed, trades initiated, configuration changes, approvals, timestamps); compliance data (KYC, sanctions screening, AML, conflict-of-interest declarations); and communications data (support requests, incident reports, internal messages).
Purposes and Legal Bases
We process personal data to provision and administer Platform access (contract, legitimate interests); authenticate users and monitor security (legitimate interests, legal obligation); execute and record proprietary trading activity (legitimate interests, legal obligation); meet compliance, KYC, sanctions, AML, and audit obligations (legal obligation, legitimate interests); conduct governance and risk management (legitimate interests); respond to incidents and disputes (legitimate interests, legal obligation); and communicate with authorized users (contract, legitimate interests).
Sources of Data
We collect personal data directly from authorized users, and also receive data from affiliated entities, HR and identity-management systems, corporate counterparties, service providers, sanctions and screening databases, and public registries used for compliance purposes.
Automated Processing
The Platform uses automated processes for security controls, risk limits, alerting, and trade execution. These may flag activity for review, restrict access, or trigger approval workflows. Decisions with material consequences are subject to human oversight under our governance framework. We do not use personal data for automated decisions producing legal effects on the general public.
Sharing of Personal Data
We share personal data only where necessary and subject to appropriate safeguards, with: affiliated entities of SHAKSETTLE Capital; service providers and processors (cloud hosting, security, monitoring, identity, audit) under written agreements; auditors and legal advisors bound by confidentiality; regulators, supervisory authorities, courts, and law-enforcement agencies where required by law; and counterparties, exchanges, custodians, and infrastructure providers to the limited extent needed to execute or settle proprietary trading activity. We do not sell personal data and do not share it for third-party advertising.
International Transfers
Personal data may be transferred to and processed in jurisdictions other than the one in which it was collected. Where transfers involve jurisdictions with different data-protection regimes, we rely on appropriate safeguards, such as standard contractual clauses, intra-group data-transfer agreements, and technical and organizational measures.
Retention
We retain personal data for as long as necessary to fulfil the purposes described in this Policy and thereafter as required to meet legal, regulatory, audit, tax, and dispute-resolution obligations. Trading, compliance, and audit records are retained in accordance with applicable regulatory retention periods.
Security
We maintain technical and organizational measures designed to protect personal data against unauthorized access, disclosure, alteration, loss, and destruction, including encryption in transit and at rest where appropriate, strong authentication, role-based access control, network segmentation, activity logging, monitoring, vulnerability management, and incident-response procedures.
Data-Subject Rights
Subject to applicable law, data subjects may have the right to request access, correction, erasure, restriction, or portability of their personal data; to object to processing based on legitimate interests; and, where processing is based on consent, to withdraw consent. Requests may be submitted through the SHAKSETTLE Capital privacy contact designated below.
Complaints
Data subjects who believe their personal data has been processed in breach of applicable data-protection law have the right to lodge a complaint with the competent supervisory authority in their jurisdiction. We encourage data subjects to contact us first so we can address concerns directly.
Changes to This Policy
We may update this Policy from time to time to reflect changes in law, the Platform, our operations, or our practices. Material changes will be communicated to authorized users through appropriate internal channels.
Contact
For questions about this Policy, requests relating to personal data, or to report a privacy concern, contact the SHAKSETTLE Capital privacy function through the designated internal channel. External inquiries should be directed to the official SHAKSETTLE Capital point of contact and will be handled subject to confidentiality, verification, and applicable law.
