Privacy Policy
Your data, our responsibility.
1. Who We Are & Scope
ForexBrokerRatings.com (“FBR,” “we,” “our,” “us”) is an independent publisher that analyses and reviews retail foreign-exchange (“forex”) brokers. We operate the website https://forexbrokeratings.com (the “Site”). We do not provide brokerage services or personalised investment advice. This Privacy Policy governs all personal data processed via the Site, APIs, email, and any future mobile applications.
2. Legal Frameworks
We designed this Policy to comply with—or provide equivalent protection to—the world’s leading privacy regimes:
Law / Region | Key Rights Reflected |
---|---|
GDPR (EEA/UK) | Art. 6 lawful bases, Art. 15-22 data-subject rights, SCCs for transfers |
CCPA / CPRA (California) | Notice at collection, “sale/share” opt-out, enhanced consumer rights |
LGPD (Brazil) | Legitimate interest basis, data portability, DPO contact |
PIPEDA (Canada) | 10 Fair Information Principles |
POPIA (South Africa) | Processing limitation, openness, security safeguards |
Australia Privacy Act | APP 1-13, cross-border disclosure protections |
Where local law affords stronger protections than this Policy, we will honour them.
3. Information We Collect
Category | Examples | Collection Method |
---|---|---|
Identifiers | email, IP, cookie ID, device fingerprint | web forms, analytics scripts |
Usage Data | pages viewed, clicks on broker links, session duration | first-party cookies, log files |
Commercial Data | broker promotions clicked, affiliate IDs | redirect URLs |
Marketing Preferences | newsletter opt-in status, email opens | ESP reports |
User-generated Content | comments, feedback, survey results | voluntary submission |
We do not knowingly collect special-category data (e.g., health, biometrics) or data from children < 13 yrs. If notified, we will delete such data within 30 days.
4. Purposes & Legal Bases
Purpose | GDPR Basis | CCPA Category |
---|---|---|
Operate & secure Site | Legitimate interests | “Security” |
Send newsletters | Consent | “Marketing” |
Track affiliate referrals | Legitimate interests | “Commercial information” |
Respond to enquiries | Contract | “Customer records” |
Comply with law / tax | Legal obligation | “Legal compliance” |
6. Global Data Transfers
Our servers are hosted in [select cloud region]. If your data is transferred cross-border, we rely on:
- Standard Contractual Clauses (SCCs) for EEA/UK transfers
- UK Addendum to SCCs (where applicable)
- Implementing adequacy decisions, Binding Corporate Rules, or other recognised safeguards
8. Data Retention
We retain data only as long as necessary for each purpose, plus any statutory retention period (e.g., 5 yrs for tax). Afterward, data is anonymised or securely erased using NIST SP-800-88 methods.
9. Security Measures
- HTTPS/TLS 1.3 encryption in transit
- At-rest encryption (AES-256) on production databases
- WAF & DDoS filtration, rate limiting
- Role-based access controls, MFA for admin accounts
- Quarterly vulnerability scans & annual penetration tests
- Incident-response plan aligned with ISO 27001 Annex A
No Internet transmission is 100 % secure; use the Site at your own risk.
10. Your Rights
Region | Rights & How to Exercise |
---|---|
GDPR / UK-GDPR | Access, rectify, erase, restrict, object, data portability, lodge complaint with supervisory authority. |
CCPA / CPRA | Know, delete, correct, opt-out of sale/share, limit use of sensitive data. |
LGPD | Confirm processing, anonymise, data portability, revoke consent. |
Others | Equivalent rights under PIPEDA, POPIA, etc. |
Submit requests via privacy@forexbrokeratings.com. We must verify identity (K-ID request token) before actioning. Response window: 30 days (extendable +60 days for complex cases).
11. Automated Decision-Making
We do not use profiling or automated decisions that produce legal or similarly significant effects (GDPR Art. 22).
12. Third-Party Links
Outbound links to brokers & resources have independent privacy practices. Review their policies before providing personal data. We disclaim liability for third-party content or data handling.
13. Children’s Privacy
The Site is not directed to children under 13. If you are a parent/guardian and believe your child provided data, contact us and we will delete it.
14 Changes to This Policy
We may revise this Policy due to legal, technical, or business changes. Updates appear here with a new “Last updated” date; material changes may be emailed to subscribers. Continued use after an update equals acceptance.