Legal
How Ellington Ltd collects, uses, protects, and shares your personal information — and the rights you have over it.
In brief
This policy explains what personal data Ellington Ltd collects, why we collect it, who we share it with, how long we keep it, and how we protect it. It also sets out your privacy rights and how to exercise them. We collect only what we need to operate your account, meet our legal and regulatory obligations, and keep our services secure — and we never sell your personal data.
This Privacy Policy applies to Ellington Ltd ("Ellington Ltd", "we", "us", or "our") and to the website at ellingtonltd.com, our trading platform, and any related services (together, the "Services"). It describes how we handle the personal information of clients, prospective clients, and visitors.
For the purposes of data-protection law, the controller of your personal information is Ellington Ltd, a registered International Business Company (IBC) with the St. Vincent and the Grenadines Financial Services Authority (SVGFSA) under IBC registration number 12785, also registered as a Virtual Asset Service Provider (VASP) under the Virtual Assets Business Act 2022 (VABA), VASP registration number VABA-2026-0042. Our registered correspondence address is 275 Slater St. #900, Ottawa, ON K1P 5H9, Canada.
Depending on where you live, your personal information may be protected by laws such as the EU and UK General Data Protection Regulation (GDPR), the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), and Canada's Personal Information Protection and Electronic Documents Act (PIPEDA). Where a section below applies only to residents of a particular region, we say so.
Please read this policy alongside our Terms and Conditions and Cookie Policy, which it forms part of.
We collect personal information that you provide to us, that is generated as you use the Services, and that we receive from third parties. As a regulated financial and virtual-asset business, some of this information we are legally required to collect. The main categories are:
Some of this information, such as identity documents and financial data, is treated as particularly sensitive, and we apply additional safeguards to it.
We collect personal information in three main ways:
We use your personal information only where we have a valid legal basis to do so. The table below summarises our main purposes and the legal bases we rely on under the GDPR; equivalent bases apply under other laws.
| Purpose | What it involves | Legal basis (GDPR) |
|---|---|---|
| Opening & operating your account | Registration, account management, and providing the trading platform | Performance of a contract |
| Identity verification & AML/KYC | Verifying who you are, sanctions and PEP screening, and preventing money laundering and fraud | Compliance with a legal obligation |
| Processing transactions | Deposits, withdrawals, trades, and keeping accurate records | Contract; legal obligation |
| Security & fraud prevention | Monitoring activity and protecting accounts, funds, and systems | Legitimate interests; legal obligation |
| Customer support | Responding to your queries and resolving disputes | Contract; legitimate interests |
| Improving our Services | Understanding how the Services are used and improving them | Legitimate interests (consent for non-essential cookies) |
| Marketing | Sending you offers, updates, and information about our Services | Consent (or legitimate interests where permitted) |
| Legal & regulatory compliance | Meeting reporting duties and responding to lawful requests from authorities | Compliance with a legal obligation |
Where we rely on legitimate interests, we have balanced those interests against your rights and freedoms. Where we rely on consent, you may withdraw it at any time (see Sections 5 and 11). We will not use your information for a new, incompatible purpose without telling you first and, where required, obtaining your consent.
Where required by law, we will only send you marketing communications if you have opted in to receive them. We do not bundle marketing consent with the acceptance of our Terms and Conditions — it is a separate, optional choice.
You can opt out of marketing at any time, free of charge, by using the unsubscribe link in any marketing email, adjusting your communication preferences in your account, or contacting us using the details in Section 18. Opting out of marketing will not affect service messages we must send you about your account, transactions, or legal and regulatory matters.
We use cookies and similar technologies to operate the website, remember your preferences, keep your account secure, and understand how the Services are used. Cookies fall into a few broad groups:
Where required, we ask for your consent before setting non-essential cookies, and you can change your choices at any time through our cookie banner, cookie preferences mechanism, or your browser settings or your browser settings. For full details of the specific cookies we use, please see our Cookie Policy.
We do not sell your personal information. We share it only where necessary for the purposes described in this policy, and only with recipients who are bound to protect it. These may include:
We require all processors to keep your information secure, to use it only for the purposes we specify, and to comply with applicable data-protection law.
Because we operate internationally, your personal information may be transferred to, stored in, or accessed from countries other than your own, including countries that may not provide the same level of protection as your home jurisdiction.
Where we transfer personal data internationally, we put appropriate safeguards in place as required by law — such as transferring to countries recognised as providing adequate protection, or using standard contractual clauses or equivalent mechanisms. You may request a copy of the relevant safeguards by contacting us.
We keep your personal information only for as long as necessary for the purposes set out in this policy, and then securely delete or anonymise it.
As a financial and virtual-asset business, we are legally required to retain certain records — including identity, transaction, and AML records — for a minimum period after our relationship with you ends, typically at least seven (7) years, and longer where required or permitted for legal, regulatory, tax, accounting, dispute-resolution, law-enforcement, or legitimate business purposes. These legal retention obligations may mean we cannot delete some of your information immediately on request, even where you ask us to (see Section 11).
When determining retention periods, we consider the amount and sensitivity of the data, the purposes for which we use it, and applicable legal, regulatory, accounting, and reporting requirements.
We implement appropriate technical and organisational measures designed to protect your personal information against unauthorised access, loss, misuse, or alteration. These measures may include encryption of data in transit and at rest where appropriate, access controls and authentication, network and system monitoring, secure backups, staff confidentiality obligations and training, and regular review of our security practices.
While we work hard to safeguard your information, no method of transmission over the internet or method of electronic storage is completely secure, and we cannot guarantee absolute security. You also play an important role: please keep your login credentials confidential, use a strong and unique password, and contact us immediately if you suspect any unauthorised use of your account.
If a personal-data breach is likely to result in a risk to your rights, we will notify the relevant supervisory authority and, where required, affected individuals, in line with applicable law.
Depending on where you live and the laws that apply to you, you may have some or all of the following rights over your personal information:
To exercise any of these rights, please contact us using the details in Section 18. We will respond within the timeframe required by law (generally one month under the GDPR). We may need to verify your identity before acting on a request, and in limited cases we may be unable to fulfil a request where the law requires or permits us to retain the information.
If you are a California resident, you have specific rights under the CCPA, as amended by the CPRA, including the right to:
You may exercise these rights using the contact details in Section 18, and you may use an authorised agent to make a request on your behalf.
For individuals in Canada, we handle personal information in accordance with PIPEDA and its ten fair-information principles: accountability, identifying purposes, consent, limiting collection, limiting use, disclosure and retention, accuracy, safeguards, openness, individual access, and challenging compliance.
You have the right to access the personal information we hold about you and to challenge its accuracy, and you may withdraw consent subject to legal and contractual limits. If you have a concern we have not resolved, you may contact the Office of the Privacy Commissioner of Canada.
We use automated tools as part of our fraud-detection, security, and AML processes, and we may use profiling to help assess risk and the suitability of our Services. Where a decision producing legal or similarly significant effects about you is based solely on automated processing, you have the right — where the law provides it — to obtain human intervention, to express your point of view, and to contest the decision. Contact us using the details in Section 18 to do so.
Our Services are intended only for individuals who are at least 18 years old (or the age of majority in their jurisdiction, if higher). We do not knowingly collect personal information from anyone under that age. If we become aware that we have collected information from a minor, we will delete it. If you believe a minor has provided us with personal information, please contact us.
Our website and platform may contain links to third-party websites, products, or services that we do not control. This policy does not apply to those third parties, and we are not responsible for their privacy practices. We encourage you to read the privacy notice of any third-party service you use.
We may update this policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will update the "last updated" date above and, where appropriate, notify you by email or through the Services. We encourage you to review this policy periodically. Your continued use of the Services after an update means you accept the revised policy.
If you have questions about this policy, wish to exercise your rights, or want to make a complaint about how we handle your personal information, please contact us:
Data protection / privacy enquiries: support@ellington-ltd.com
Data Protection Officer: support@ellington-ltd.com
Post: 275 Slater St. #900, Ottawa, ON K1P 5H9, Canada
If you are in the EU/UK and are not satisfied with our response, you may lodge a complaint with your local data-protection supervisory authority. If you are in Canada, you may contact the Office of the Privacy Commissioner of Canada.
This Privacy Policy is provided for transparency about how your personal information is handled. Figures and legal references reflect commonly applicable standards as of June 2026 and may vary by jurisdiction.