CFDs are complex instruments and come with a high risk of losing money rapidly due to leverage. 57% of retail investor accounts lose money when trading CFDs with this provider. You should consider whether you understand how CFDs work and whether you can afford to take the high risk of losing your money.
In

Legal

Privacy Policy

How Ellington Ltd collects, uses, protects, and shares your personal information — and the rights you have over it.

Last updated: 10 June 2026  ·  Effective: 10 June 2026


In brief

This policy explains what personal data Ellington Ltd collects, why we collect it, who we share it with, how long we keep it, and how we protect it. It also sets out your privacy rights and how to exercise them. We collect only what we need to operate your account, meet our legal and regulatory obligations, and keep our services secure — and we never sell your personal data.

1. Who we are and what this policy covers

This Privacy Policy applies to Ellington Ltd ("Ellington Ltd", "we", "us", or "our") and to the website at ellingtonltd.com, our trading platform, and any related services (together, the "Services"). It describes how we handle the personal information of clients, prospective clients, and visitors.

For the purposes of data-protection law, the controller of your personal information is Ellington Ltd, a registered International Business Company (IBC) with the St. Vincent and the Grenadines Financial Services Authority (SVGFSA) under IBC registration number 12785, also registered as a Virtual Asset Service Provider (VASP) under the Virtual Assets Business Act 2022 (VABA), VASP registration number VABA-2026-0042. Our registered correspondence address is 275 Slater St. #900, Ottawa, ON K1P 5H9, Canada.

Depending on where you live, your personal information may be protected by laws such as the EU and UK General Data Protection Regulation (GDPR), the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), and Canada's Personal Information Protection and Electronic Documents Act (PIPEDA). Where a section below applies only to residents of a particular region, we say so.

Please read this policy alongside our Terms and Conditions and Cookie Policy, which it forms part of.


2. The information we collect

We collect personal information that you provide to us, that is generated as you use the Services, and that we receive from third parties. As a regulated financial and virtual-asset business, some of this information we are legally required to collect. The main categories are:

  • Identity and contact details — your name, date of birth, nationality, residential address, email address, and telephone number.
  • Verification and "know-your-customer" (KYC) data — government-issued identification, proof of address, photographs or identity selfies, tax identifiers, and information about your source of funds and source of wealth. We collect this to meet anti-money-laundering (AML) and counter-terrorist-financing obligations.
  • Financial and transactional data — bank account or payment-card details, deposits, withdrawals, account balances, positions, and your full trading and transaction history.
  • Suitability and profile data — information about your trading experience, knowledge, financial situation, and objectives, where we are required to assess the appropriateness of our Services for you.
  • Account and support data — your login credentials, account settings and preferences, and records of your communications with us, including support tickets and chat messages.
  • Communications — emails, messages, and telephone calls, which may be recorded or logged for security, training, and regulatory record-keeping purposes.
  • Technical and usage data — your IP address, device and browser type, operating system, approximate location, and information about how you interact with our website and platform, including through cookies.
  • Marketing preferences — your choices about receiving communications from us.

Some of this information, such as identity documents and financial data, is treated as particularly sensitive, and we apply additional safeguards to it.


3. How we collect your information

We collect personal information in three main ways:

  • Directly from you — when you register for an account, complete verification, deposit funds, trade, contact our support team, or otherwise use the Services.
  • Automatically — as you browse our website and use our platform, through cookies, server logs, and similar technologies (see Section 6).
  • From third parties — including identity-verification and AML-screening providers, payment processors, fraud-prevention services, sanctions and politically-exposed-person (PEP) databases, and publicly available sources, to the extent permitted by law.

4. How and why we use your information

We use your personal information only where we have a valid legal basis to do so. The table below summarises our main purposes and the legal bases we rely on under the GDPR; equivalent bases apply under other laws.

PurposeWhat it involvesLegal basis (GDPR)
Opening & operating your accountRegistration, account management, and providing the trading platformPerformance of a contract
Identity verification & AML/KYCVerifying who you are, sanctions and PEP screening, and preventing money laundering and fraudCompliance with a legal obligation
Processing transactionsDeposits, withdrawals, trades, and keeping accurate recordsContract; legal obligation
Security & fraud preventionMonitoring activity and protecting accounts, funds, and systemsLegitimate interests; legal obligation
Customer supportResponding to your queries and resolving disputesContract; legitimate interests
Improving our ServicesUnderstanding how the Services are used and improving themLegitimate interests (consent for non-essential cookies)
MarketingSending you offers, updates, and information about our ServicesConsent (or legitimate interests where permitted)
Legal & regulatory complianceMeeting reporting duties and responding to lawful requests from authoritiesCompliance with a legal obligation

Where we rely on legitimate interests, we have balanced those interests against your rights and freedoms. Where we rely on consent, you may withdraw it at any time (see Sections 5 and 11). We will not use your information for a new, incompatible purpose without telling you first and, where required, obtaining your consent.


5. Marketing communications

Where required by law, we will only send you marketing communications if you have opted in to receive them. We do not bundle marketing consent with the acceptance of our Terms and Conditions — it is a separate, optional choice.

You can opt out of marketing at any time, free of charge, by using the unsubscribe link in any marketing email, adjusting your communication preferences in your account, or contacting us using the details in Section 18. Opting out of marketing will not affect service messages we must send you about your account, transactions, or legal and regulatory matters.


6. Cookies and similar technologies

We use cookies and similar technologies to operate the website, remember your preferences, keep your account secure, and understand how the Services are used. Cookies fall into a few broad groups:

  • Strictly necessary cookies — required for the site and platform to function and to keep your session secure. These cannot be switched off.
  • Functional cookies — remember your settings and preferences.
  • Analytics cookies — help us understand how visitors use the site so we can improve it.
  • Marketing cookies — used to measure and tailor our advertising.

Where required, we ask for your consent before setting non-essential cookies, and you can change your choices at any time through our cookie banner, cookie preferences mechanism, or your browser settings or your browser settings. For full details of the specific cookies we use, please see our Cookie Policy.


7. How we share your information

We do not sell your personal information. We share it only where necessary for the purposes described in this policy, and only with recipients who are bound to protect it. These may include:

  • Service providers (processors) — companies that process data on our behalf and under our instructions, such as payment service providers, banks, card networks, acquiring banks, e-wallet providers, cryptocurrency payment processors, and other payment infrastructure providers, identity-verification providers, AML screening providers, sanctions-screening providers, fraud-prevention providers, politically-exposed-person database providers, and document-verification providers, cloud hosting providers, data-storage providers, cybersecurity providers, backup providers, infrastructure providers, and other technical service providers, and analytics providers, website-performance tools, customer-support tools, email and messaging providers, CRM systems, call-recording providers, marketing-communication tools, and other communications or service-management providers.
  • Group companies and partners — affiliates, group companies, introducing brokers, business partners, or service partners, where this is necessary to provide the Services, manage client relationships, operate the platform, meet legal or regulatory obligations, or support our business operations.
  • Financial institutions — banks and payment networks involved in processing your deposits and withdrawals.
  • Regulators and authorities — courts, law-enforcement, tax authorities, and financial regulators, where we are legally required or permitted to disclose information.
  • Professional advisers — auditors, lawyers, and consultants, under duties of confidentiality.
  • Business transfers — a buyer or successor in the event of a merger, acquisition, or reorganisation, subject to this policy.

We require all processors to keep your information secure, to use it only for the purposes we specify, and to comply with applicable data-protection law.


8. International data transfers

Because we operate internationally, your personal information may be transferred to, stored in, or accessed from countries other than your own, including countries that may not provide the same level of protection as your home jurisdiction.

Where we transfer personal data internationally, we put appropriate safeguards in place as required by law — such as transferring to countries recognised as providing adequate protection, or using standard contractual clauses or equivalent mechanisms. You may request a copy of the relevant safeguards by contacting us.


9. How long we keep your information

We keep your personal information only for as long as necessary for the purposes set out in this policy, and then securely delete or anonymise it.

As a financial and virtual-asset business, we are legally required to retain certain records — including identity, transaction, and AML records — for a minimum period after our relationship with you ends, typically at least seven (7) years, and longer where required or permitted for legal, regulatory, tax, accounting, dispute-resolution, law-enforcement, or legitimate business purposes. These legal retention obligations may mean we cannot delete some of your information immediately on request, even where you ask us to (see Section 11).

When determining retention periods, we consider the amount and sensitivity of the data, the purposes for which we use it, and applicable legal, regulatory, accounting, and reporting requirements.


10. How we protect your information

We implement appropriate technical and organisational measures designed to protect your personal information against unauthorised access, loss, misuse, or alteration. These measures may include encryption of data in transit and at rest where appropriate, access controls and authentication, network and system monitoring, secure backups, staff confidentiality obligations and training, and regular review of our security practices.

While we work hard to safeguard your information, no method of transmission over the internet or method of electronic storage is completely secure, and we cannot guarantee absolute security. You also play an important role: please keep your login credentials confidential, use a strong and unique password, and contact us immediately if you suspect any unauthorised use of your account.

If a personal-data breach is likely to result in a risk to your rights, we will notify the relevant supervisory authority and, where required, affected individuals, in line with applicable law.


11. Your privacy rights

Depending on where you live and the laws that apply to you, you may have some or all of the following rights over your personal information:

  • Access — to be told whether we hold your data and to request a copy of it.
  • Rectification — to have inaccurate or incomplete data corrected.
  • Erasure — to ask us to delete your data, subject to our legal retention obligations (see Section 9).
  • Restriction — to ask us to limit how we use your data in certain circumstances.
  • Portability — to receive certain data in a structured, commonly used, machine-readable format, or to have it transferred to another provider.
  • Objection — to object to processing based on our legitimate interests, and to object to direct marketing at any time.
  • Withdraw consent — to withdraw any consent you have given, without affecting processing carried out before withdrawal.
  • Complain — to lodge a complaint with your local data-protection or supervisory authority.

To exercise any of these rights, please contact us using the details in Section 18. We will respond within the timeframe required by law (generally one month under the GDPR). We may need to verify your identity before acting on a request, and in limited cases we may be unable to fulfil a request where the law requires or permits us to retain the information.


12. California residents (CCPA/CPRA)

If you are a California resident, you have specific rights under the CCPA, as amended by the CPRA, including the right to:

  • Know and access the categories and specific pieces of personal information we have collected, the sources, the purposes, and the categories of recipients.
  • Delete personal information we have collected, subject to legal exceptions.
  • Correct inaccurate personal information.
  • Opt out of the "sale" or "sharing" of personal information. We do not sell or share your personal information as those terms are defined under California law.
  • Limit the use and disclosure of sensitive personal information.
  • Non-discrimination — we will not discriminate against you for exercising your rights.

You may exercise these rights using the contact details in Section 18, and you may use an authorised agent to make a request on your behalf.


13. Canadian residents (PIPEDA)

For individuals in Canada, we handle personal information in accordance with PIPEDA and its ten fair-information principles: accountability, identifying purposes, consent, limiting collection, limiting use, disclosure and retention, accuracy, safeguards, openness, individual access, and challenging compliance.

You have the right to access the personal information we hold about you and to challenge its accuracy, and you may withdraw consent subject to legal and contractual limits. If you have a concern we have not resolved, you may contact the Office of the Privacy Commissioner of Canada.


14. Automated decisions and profiling

We use automated tools as part of our fraud-detection, security, and AML processes, and we may use profiling to help assess risk and the suitability of our Services. Where a decision producing legal or similarly significant effects about you is based solely on automated processing, you have the right — where the law provides it — to obtain human intervention, to express your point of view, and to contest the decision. Contact us using the details in Section 18 to do so.


15. Children and age requirements

Our Services are intended only for individuals who are at least 18 years old (or the age of majority in their jurisdiction, if higher). We do not knowingly collect personal information from anyone under that age. If we become aware that we have collected information from a minor, we will delete it. If you believe a minor has provided us with personal information, please contact us.


16. Third-party links and services

Our website and platform may contain links to third-party websites, products, or services that we do not control. This policy does not apply to those third parties, and we are not responsible for their privacy practices. We encourage you to read the privacy notice of any third-party service you use.


17. Changes to this policy

We may update this policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will update the "last updated" date above and, where appropriate, notify you by email or through the Services. We encourage you to review this policy periodically. Your continued use of the Services after an update means you accept the revised policy.


18. How to contact us

If you have questions about this policy, wish to exercise your rights, or want to make a complaint about how we handle your personal information, please contact us:

Ellington Ltd

Data protection / privacy enquiries: support@ellington-ltd.com

Data Protection Officer: support@ellington-ltd.com

Post: 275 Slater St. #900, Ottawa, ON K1P 5H9, Canada

If you are in the EU/UK and are not satisfied with our response, you may lodge a complaint with your local data-protection supervisory authority. If you are in Canada, you may contact the Office of the Privacy Commissioner of Canada.

↑ Back to top

This Privacy Policy is provided for transparency about how your personal information is handled. Figures and legal references reflect commonly applicable standards as of June 2026 and may vary by jurisdiction.