Full text
Privacy notice
The notice explaining how personal information is handled.
1. Responsibility and scope
Trade-win Meridian Services Ltd is responsible for the personal information described in this Notice. Contact privacy@trade-win.example with privacy questions or requests. This Notice covers the Trade-win website, account services, verification, financial operations and support to the extent those services are actually provided to you. Separate providers may be responsible for their own processing; their role and notice must be identified when their services are used.
2. Information and sources
Depending on your interaction with Trade-win, the relevant information includes:
- Contact and profile details, such as name, email, telephone number and address.
- Account and security information, such as authentication identifiers, session events, device information and records of security or recovery actions.
- Verification information, such as identity documents, verification outcomes, face images and associated checks described in the Verification Notice in Appendix A.
- Financial records, such as orders, positions, fills, balances, fees, transfers, payment references and information necessary to investigate discrepancies.
- Communications, such as support messages, complaint evidence and optional explanation requests and responses.
- Website and preference information described in the Storage Notice in Appendix A.
Information may come from you, your use of the service and the providers listed in the Provider Register in Appendix A. Where Google sign-in is enabled, the sign-in interface and processing register must identify the account information received. Trade-win does not need your Google password. Public browsing and a completed account application do not involve identical data collection.
3. Purposes and lawful grounds
We use information to provide requested account services, verify eligibility, process and reconcile transactions, secure the service, respond to requests and maintain required records. the Processing Register in Appendix A must specify the actual data, purpose and lawful ground for each activity under the applicable jurisdiction. Contract necessity, legal obligations, legitimate interests and consent must not be treated as interchangeable justifications.
Optional marketing and non-essential tracking require the choices applicable in your jurisdiction. Refusing an optional purpose will not by itself prevent use of an unrelated essential service. If consent is the ground, you may withdraw it for future processing; this does not automatically erase records processed on another valid ground. We will explain any materially different purpose before using your information for it and obtain consent where required.
4. Identity and face verification
Before collecting verification material, the Verification Notice in Appendix A must explain what is collected, which provider processes it, whether a biometric template is created, the purpose, legal grounds and applicable retention period. A photograph is not automatically equivalent to a biometric identification template.
Access to verification material must be limited to authorized roles with a documented need. Do not send identity documents through public comments or ordinary support attachments when a secure verification channel is provided. If a verification outcome prevents access, the notice must describe available review or alternative verification routes and their limits.
5. Recipients and international processing
Relevant recipients may include contracted hosting, identity, payment, execution, custody and communications providers, but only where they are actually used and listed in the Provider Register in Appendix A. Their roles, purposes and locations must be stated. Disclosure to authorities or advisers must have an applicable legal basis and be limited to information necessary for that purpose.
Where information is transferred across borders, the Transfer Statement in Appendix A describes the applicable mechanism and how further information can be obtained. A provider's global presence is not itself a safeguard. This Notice does not authorize unspecified future providers to use personal information for unrelated purposes.
6. Automated processing and explanations
Where automated checks affect verification, fraud review or eligibility, the Processing Register in Appendix A must describe their role and any significant decisions, consequences and review rights. Human review must not be promised unless an operational process is available.
If you use optional AI explanations, the interface must explain which input is processed, any external recipient and retention before information is sent. Do not enter passwords, recovery phrases or unnecessary identity documents. Financial actions remain separate from explanation requests. Any use of these interactions for model training requires an explicit, accurate disclosure and an appropriate legal basis; it is not authorized by a generic service-purpose clause.
7. Retention and deletion
the Retention Schedule in Appendix A specifies periods or objective criteria separately for profile data, security logs, verification material, financial records, support and complaints. Information will not be retained merely because storage is available. Documented legal holds may require specific records to be kept longer.
Account closure or withdrawal of a sign-in permission does not automatically delete transaction history or legally required evidence. When deletion cannot be completed, we will explain the applicable restriction and limit continued use. Data already recorded on a public blockchain cannot be erased by deleting a Trade-win account; do not put unnecessary personal information into public transaction fields.
8. Choices, rights and security
Depending on applicable law, you may request access, correction, deletion, restriction, portability or objection, and withdraw consent where relevant. Use privacy@trade-win.example. We may request proportionate verification to protect your information. We will explain the outcome, applicable response period and any lawful limitation. You may contact the competent data-protection authority for your place of residence where eligible; this Notice does not remove any right to complain directly to an authority.
Security measures must match the sensitivity of the information and the actual service. No internet service can promise absolute security. Report a suspected account compromise through security@trade-win.example. Material notice changes will identify their effective date and the changed processing; a notice update does not substitute for consent where consent is required.
Appendix A — Data schedules
Processing Register. The document pages display informational content and do not collect identity documents, payment details or complaint submissions. Any voluntary presentation feedback should use synthetic information. Account, KYC and financial processing require a separate verified register before activation.
Provider Register. No identity-verification, payment, custody or execution provider is appointed by this presentation. No external AI processing is authorized by this Notice. Hosting arrangements must be documented for an external release.
Transfer Statement. No production cross-border transfer arrangement is established by this presentation. A provider-specific assessment and lawful transfer mechanism are required before production processing.
Verification Notice. No identity or face-verification submission is available on these document pages. Do not submit actual identification material during a presentation.
Storage Notice. The document text itself introduces no tracking scripts, advertising cookies or submission forms. This statement does not certify storage behavior of other pages; a site-wide inventory is required before publication.
Retention Schedule. Use synthetic records for presentation. Proposed production periods are 30 days for general diagnostic logs, 90 days for unresolved application records, and 5 years after relationship or case closure for financial and complaint records. Verification originals should be removed 30 days after a final verification outcome unless a specific legal requirement requires retention. These operational choices require validation against the actual jurisdiction before collection.