Proprietary capital only, no client accounts, no third-party assets

Privacy Policy

SCOSDesk institutional platform

v1.0
SCOSDesk is an internal proprietary trading system. It does not process personal data of the general public in ordinary operations. This Policy primarily applies to authorized personnel, contractors, counterparties, and auditors who interact with the Platform.
Effective 4 July 2026
1

Introduction

SHAKSETTLE Capital Ltd. ("SHAKSETTLE Capital", "we", "us", or "our") respects the privacy of the individuals whose personal data we process in connection with SCOSDesk (the "Platform"). This Privacy Policy explains what personal data we collect, why we collect it, how we use and protect it, and the rights available to data subjects.

2

Data Controller

SHAKSETTLE Capital Ltd. acts as the data controller for personal data processed through the Platform. Where an affiliated entity independently determines the purposes and means of processing, that entity acts as controller for the relevant activities.

3

Categories of Personal Data

We process identity and contact data (name, job title, work email); access and authentication data (user IDs, hashed credentials, MFA metadata, session tokens, API key identifiers); technical and device data (IP address, device identifiers, browser and OS information, country-level geolocation); activity and audit data (login events, actions performed, trades initiated, configuration changes, approvals, timestamps); compliance data (KYC, sanctions screening, AML, conflict-of-interest declarations); and communications data (support requests, incident reports, internal messages).

4

Purposes and Legal Bases

We process personal data to provision and administer Platform access (contract, legitimate interests); authenticate users and monitor security (legitimate interests, legal obligation); execute and record proprietary trading activity (legitimate interests, legal obligation); meet compliance, KYC, sanctions, AML, and audit obligations (legal obligation, legitimate interests); conduct governance and risk management (legitimate interests); respond to incidents and disputes (legitimate interests, legal obligation); and communicate with authorized users (contract, legitimate interests).

5

Sources of Data

We collect personal data directly from authorized users, and also receive data from affiliated entities, HR and identity-management systems, corporate counterparties, service providers, sanctions and screening databases, and public registries used for compliance purposes.

6

Automated Processing

The Platform uses automated processes for security controls, risk limits, alerting, and trade execution. These may flag activity for review, restrict access, or trigger approval workflows. Decisions with material consequences are subject to human oversight under our governance framework. We do not use personal data for automated decisions producing legal effects on the general public.

7

Sharing of Personal Data

We share personal data only where necessary and subject to appropriate safeguards, with: affiliated entities of SHAKSETTLE Capital; service providers and processors (cloud hosting, security, monitoring, identity, audit) under written agreements; auditors and legal advisors bound by confidentiality; regulators, supervisory authorities, courts, and law-enforcement agencies where required by law; and counterparties, exchanges, custodians, and infrastructure providers to the limited extent needed to execute or settle proprietary trading activity. We do not sell personal data and do not share it for third-party advertising.

8

International Transfers

Personal data may be transferred to and processed in jurisdictions other than the one in which it was collected. Where transfers involve jurisdictions with different data-protection regimes, we rely on appropriate safeguards, such as standard contractual clauses, intra-group data-transfer agreements, and technical and organizational measures.

9

Retention

We retain personal data for as long as necessary to fulfil the purposes described in this Policy and thereafter as required to meet legal, regulatory, audit, tax, and dispute-resolution obligations. Trading, compliance, and audit records are retained in accordance with applicable regulatory retention periods.

10

Security

We maintain technical and organizational measures designed to protect personal data against unauthorized access, disclosure, alteration, loss, and destruction, including encryption in transit and at rest where appropriate, strong authentication, role-based access control, network segmentation, activity logging, monitoring, vulnerability management, and incident-response procedures.

11

Data-Subject Rights

Subject to applicable law, data subjects may have the right to request access, correction, erasure, restriction, or portability of their personal data; to object to processing based on legitimate interests; and, where processing is based on consent, to withdraw consent. Requests may be submitted through the SHAKSETTLE Capital privacy contact designated below.

12

Complaints

Data subjects who believe their personal data has been processed in breach of applicable data-protection law have the right to lodge a complaint with the competent supervisory authority in their jurisdiction. We encourage data subjects to contact us first so we can address concerns directly.

13

Changes to This Policy

We may update this Policy from time to time to reflect changes in law, the Platform, our operations, or our practices. Material changes will be communicated to authorized users through appropriate internal channels.

14

Contact

For questions about this Policy, requests relating to personal data, or to report a privacy concern, contact the SHAKSETTLE Capital privacy function through the designated internal channel. External inquiries should be directed to the official SHAKSETTLE Capital point of contact and will be handled subject to confidentiality, verification, and applicable law.

Related