1.1. Finco Group (the "Company", "we", "us", "our") is the data controller responsible for personal data processed in connection with the Viriora brand and Website(s) viriora.com (the "Website") and the trading platform (together, the "Services"). We are licensed and regulated by KUNAISA (Licence No. FX0042026), registered office Central Street, Kunaisa Bldg., Nurr-Wala-Morti, Kuna de Wargandi Territory, Republic of Panama.
1.2. Privacy contact. For any question about this Policy or how we handle personal data, contact:
Privacy Contact: [NAME / ROLE, e.g. Data Protection Officer]
Email: privacy@viriora.com
Postal address: [registered office address above / alternative correspondence address]
1.3. [If a Data Protection Officer or EU/UK representative is required under applicable law, confirm the appointed person/entity and insert details here, including any local representative appointed under Art. 27 GDPR.]
2.1. This Policy applies to personal data we process about: (a) prospective, current, and former Clients; (b) authorised representatives, beneficial owners, and directors of corporate Clients; and (c) visitors to the Website. It should be read alongside the Client Agreement, the Cookie Notice, and any product-specific notices provided at the point of data collection.
2.2. This Policy does not apply to data processed by third-party websites or services we do not control, even where linked from our Website.
3.1. Identity and contact data: name, date and place of birth, nationality, gender, residential address, email, phone number, and national identifier or passport/ID details.
3.2. Verification (KYC) data: copies of identity documents, proof of address, photographs/selfies, and, where relevant, source-of-funds and source-of-wealth information.
3.3. Financial and transactional data: income and net-worth information, employment status, trading activity, account balances, deposits and withdrawals, and payment-method details (in reduced/tokenised form for cards — see clause 9).
3.4. Technical and usage data: IP address, device identifiers, browser type, operating system, login records, timestamps, and interactions with the Website and platform.
3.5. Communications: correspondence, support tickets, chat logs, and recordings of calls (where the Client is notified of recording).
3.6. Special category / sensitive data: we do not seek to collect special category data (e.g. health, biometric-for-identification, or similarly sensitive data) except where strictly necessary for identity verification via biometric matching of a selfie to an ID document, and only with an appropriate lawful basis and, where required, explicit consent.
4.1. We only process personal data where we have a valid lawful basis. The table below sets out our main purposes and the corresponding lawful basis relied on:
Purpose
Lawful basis
Open and administer accounts and provide the Services
Performance of the Client Agreement (contract)
Verify identity and comply with AML/CFT, sanctions screening, and KUNAISA regulatory obligations
Compliance with a legal obligation
Process transactions, deposits, and withdrawals
Performance of contract
Detect and prevent fraud, market abuse, and money laundering; manage credit and operational risk
Legitimate interests (fraud/risk prevention) and legal obligation
Provide client support and send service messages (e.g. account notices, security alerts)
Performance of contract; legitimate interests
Send marketing about our products and services
Consent, where required by applicable law; the Client may withdraw consent at any time (see clause 10)
Improve, secure, and maintain our systems; meet record-keeping and audit duties
Legitimate interests; legal obligation
Respond to regulatory, tax, or law-enforcement requests
Compliance with a legal obligation
Establish, exercise, or defend legal claims
Legitimate interests
4.2. Where we rely on legitimate interests, we have considered that this interest is not overridden by the Client's rights and freedoms. Details of this balancing assessment are available on request from the Privacy Contact in clause 1.2.
4.3. Automated decision-making. We may use automated tools to support fraud detection, AML risk-scoring, and eligibility checks. Any decision that produces a legal or similarly significant effect on a Client (e.g. account restriction) based solely on automated processing will, where required by applicable law, be subject to a right to obtain human review — see clause 10.
5.1. We may share personal data with:
Service providers and processors engaged to support our operations — including identity-verification providers, cloud hosting, IT and security providers, analytics providers, communications tools, and payment providers — each bound by a data-processing agreement and confidentiality obligations, and instructed to process data only as we direct;
Banks, payment institutions, and liquidity providers, as needed to process transactions;
Auditors, professional advisers (legal, accounting, compliance), and our registered agent;
KUNAISA, law-enforcement, tax, or other competent authorities, where legally required or to comply with a valid legal request;
A successor entity, in the event of a merger, acquisition, restructuring, or sale of assets, subject to appropriate protections;
Credit reference or fraud-prevention agencies, where relevant to risk assessment.
5.2. A current list of our key sub-processors is available on request from the Privacy Contact.
5.3. We do not sell personal data, and we do not share personal data with third parties for their own independent marketing purposes without consent.
6.1. Because we operate internationally, personal data may be transferred to and processed in countries other than the Client's own, including countries that may not have data protection laws equivalent to those in the Client's home jurisdiction.
6.2. Where we transfer personal data originating from the EU/UK (or another jurisdiction with transfer restrictions) to a country not deemed to offer an adequate level of protection, we put in place an appropriate safeguard, which may include: (a) the European Commission's or UK's Standard Contractual Clauses (SCCs/IDTA); (b) an applicable adequacy decision; or (c) another mechanism recognised under applicable law. [CONFIRM safeguard mechanism actually used for EU/UK data, and confirm whether a Transfer Impact Assessment has been carried out.]
6.3. A copy of the relevant safeguard can be requested from the Privacy Contact.
7.1. We retain personal data only for as long as necessary for the purposes set out in this Policy, and to meet our legal and regulatory obligations. Indicative retention periods:
Data category
Retention period
KYC/identity verification records
At least [5 / 7] years after the end of the business relationship, as required by applicable AML law [CONFIRM]
Transaction records
At least [5 / 7] years from the date of the transaction [CONFIRM]
Communications and support records
[e.g. 3 years] from the last interaction [CONFIRM]
Marketing consent records
Until consent is withdrawn, plus a limited period to evidence compliance
Website/technical/usage data
[e.g. 12–24 months], or as set out in the Cookie Notice [CONFIRM]
7.2. Where retention periods are not fixed by law, we determine retention by reference to the purpose of processing, applicable limitation periods for legal claims, and regulatory guidance.
7.3. When no longer required, personal data is securely deleted or irreversibly anonymised.
8.1. We implement appropriate technical and organisational measures designed to protect personal data against unauthorised access, loss, misuse, or alteration, including: encryption in transit and, where appropriate, at rest; access controls and role-based permissions; staff confidentiality obligations and training; and regular review and testing of our security measures.
8.2. No system is completely secure. We maintain incident-response procedures to detect, contain, and respond to any suspected breach — see clause 12.
9.1. Card payments are processed through PCI-DSS-compliant payment providers. Full card numbers are not stored by the Company; card data is transmitted in a reduced/tokenised form over encrypted connections. We apply industry-standard technical and organisational measures, including up-to-date encryption in transit, access controls, and staff confidentiality obligations.
10.1. Subject to applicable law, the Client may have the right to:
access a copy of their personal data;
request correction of inaccurate or incomplete data;
request erasure of personal data, in certain circumstances;
restrict or object to certain processing, including processing based on legitimate interests;
request portability of data provided to us, in a structured, commonly used, machine-readable format;
withdraw consent to marketing or other consent-based processing at any time, without affecting the lawfulness of processing before withdrawal;
obtain human review of a decision based solely on automated processing that produces a legal or similarly significant effect (see clause 4.3).
10.2. Requests can be made to privacy@viriora.com. We may need to verify identity before actioning a request. We will respond within the period required by applicable law (typically within one month, extendable in complex cases).
10.3. Some rights are limited where we must retain or process data to meet a legal or regulatory obligation.
NOTE FOR LEGAL REVIEW: the source draft stops here, mid-list, at clause 10.3. Clause 8.2 refers forward to a clause 12 (breach/incident notification) that has not been drafted yet, and clauses 11 onward (e.g. children's data, changes to this Policy, complaints/governing law, contact/complaints authority) are still missing. These will need to be drafted and the cross-references checked before this Policy is finalised.