ATAS Markets

Legal

Privacy Policy

ATAS Markets Limited, operator of ATAS Markets — Live Order Flow Terminal.

Effective date
15 September 2026
Version
1.0

1. Who we are

This Privacy Policy explains how ATAS Markets Limited ("ATAS Markets", "we", "us") collects, uses, discloses, retains, and protects personal data when you visit atasmarkets.com and its subdomains (the "Website"), create an account, download or use the ATAS Markets desktop software, buy a subscription, or contact us (together, the "Services").

We are a company incorporated in the Hong Kong Special Administrative Region (Business Registration No. 81129918), with our registered office at 7/F, MW Tower, 111 Bonham Strand, Sheung Wan, Hong Kong. For the purposes of the Personal Data (Privacy) Ordinance (Cap. 486) of Hong Kong (the "PDPO"), we are the data user responsible for your personal data.

This Policy also serves as our Personal Information Collection Statement ("PICS") under Data Protection Principle 1 of the PDPO.

ATAS Markets is market-analysis software. We are not a broker, exchange, investment adviser, or licensed corporation under the Securities and Futures Ordinance (Cap. 571), and we do not hold client funds or execute trades on your behalf.

Contact for privacy matters

Data Protection Officer, ATAS Markets Limited
Email: privacy@atasmarkets.com
Post: 7/F, MW Tower, 111 Bonham Strand, Sheung Wan, Hong Kong

2. Scope

This Policy applies to personal data relating to Website visitors, registered users, trial and paid subscribers, partners and affiliates (in their individual capacity), and anyone who contacts our support or sales teams.

It does not apply to third-party websites, exchanges, brokers, data-feed providers, or payment services that you connect to or access through ATAS Markets. Their own privacy policies govern how they handle your data.

3. Personal data we collect

3.1 Data you give us

CategoryExamplesWhen it is collected
Account dataEmail address, password (stored only as a salted hash), display name, preferred languageWhen you register
Billing and invoicing dataFull name, billing address, country, company name, tax or VAT identification number (where applicable), purchase history, subscription plan, amounts paidWhen you buy a subscription or request an invoice
CommunicationsContent of support tickets, chat messages, emails, feedback, survey answers, attached screenshots or log filesWhen you contact us or report an issue
Partner and affiliate dataName, company, payout details, referral code, tax informationWhen you apply to our partner or referral programme
Marketing preferencesYour consent or refusal to receive direct marketing, and channel preferencesWhen you sign up for newsletters or change settings

We do not receive or store your full payment card numbers. Payments are handled by independent payment service providers (see Section 6), which receive the card or wallet data you enter directly on their forms.

3.2 Data collected automatically

CategoryExamples
Device and connection dataIP address, approximate location derived from IP (country/city), browser type, operating system, device identifiers, time zone
Website usage dataPages viewed, referring URL, campaign parameters (UTM), clicks, session duration, collected through cookies and similar technologies
Software licence and diagnostic dataLicence key, hardware fingerprint used for licence activation, software version, crash reports, performance and error logs, feature usage statistics
Security dataLogin timestamps, failed login attempts, fraud-prevention and anti-bot signals

3.3 Data we do not intend to collect

We do not ask for, and ask you not to send us: identity card or passport numbers, brokerage or exchange passwords, exchange API secret keys, or information about health, religion, political opinions, or similar sensitive matters. If such data reaches us by mistake (for example, in a screenshot), we will delete it once we become aware of it, unless we must keep it by law.

3.4 Whether supplying data is obligatory

Data marked as required in our registration and checkout forms is obligatory. Without it we cannot create your account, activate your licence, process your payment, or issue invoices. All other data is voluntary. If you choose not to provide voluntary data, your use of the Services is unaffected, although some optional features may not be available.

4. Purposes of use

We collect and use personal data for the following purposes, and for directly related purposes:

  1. Providing the Services: creating and managing your account, activating and validating software licences, delivering updates, and providing features you request.
  2. Payments and administration: processing subscriptions, renewals, and refunds; issuing invoices and receipts; and managing partner commissions.
  3. Customer support: answering questions, troubleshooting, and handling complaints and requests.
  4. Security and fraud prevention: detecting abuse, licence sharing, payment fraud, and unauthorised access, and protecting our systems and users.
  5. Improving the Services: analysing aggregated usage and diagnostic data to fix bugs, improve performance, and design new features.
  6. Service communications: sending essential messages about your account, billing, security, and material changes to our terms or this Policy. These are not direct marketing.
  7. Direct marketing (with your consent only): see Section 5.
  8. Legal and compliance: meeting accounting, tax, and record-keeping obligations; complying with sanctions and export-control laws; responding to lawful requests from courts, regulators, and law-enforcement authorities; and establishing, exercising, or defending legal claims.
  9. Business transactions: in connection with a merger, acquisition, restructuring, or sale of all or part of our business, subject to confidentiality protections.

We will obtain your prescribed consent (express, voluntary, and not withdrawn in writing) before using your personal data for any new purpose that is not the original purpose or a directly related one, as required by Data Protection Principle 3.

5. Direct marketing

We intend to use your personal data for direct marketing, but we will not do so unless we have your consent, in accordance with Part 6A of the PDPO.

Opting out: you can withdraw consent at any time, free of charge, by clicking "unsubscribe" in any marketing email, changing preferences in your account settings, or emailing privacy@atasmarkets.com. We will stop using your data for direct marketing without delay.

6. Disclosure of personal data

We keep your personal data confidential. We may disclose it only to the following classes of recipients, and only as needed for the purposes in Section 4:

RecipientPurposeTypical location
Cloud hosting and infrastructure providersHosting the Website, account system, and licence serversUSA, Singapore, EU
Payment service providers, acting as independent data usersProcessing payments and preventing payment fraudUSA / Ireland
Email, customer-support, and CRM toolsSending service and marketing emails, and managing support ticketsUSA, EU
Analytics and advertising providers (only with your cookie consent where required)Measuring Website performance and advertising effectivenessUSA, EU
Professional advisersLegal, accounting, audit, and tax servicesHong Kong and other jurisdictions
Partners and affiliatesConfirming a referral and calculating commission. Partners receive only minimal data, such as a masked email and purchase status.Various
Courts, regulators, law enforcement, and government authoritiesWhere required or permitted by lawHong Kong and other jurisdictions
A purchaser or successor entityIn a business transaction described in Section 4(9)Various

We require our service providers (data processors) to protect personal data under written contracts, to use it only on our instructions, and to delete or return it when the service ends, as required by Data Protection Principles 2(3) and 4(2).

7. Transfers outside Hong Kong

Our Services are used internationally, and our service providers may store or process personal data outside Hong Kong, including in the United States, Singapore, the European Union, and other countries.

Where we transfer personal data outside Hong Kong, we take reasonable steps to ensure it receives protection substantially similar to that under the PDPO. These steps include using contractual terms based on the Recommended Model Contractual Clauses published by the Office of the Privacy Commissioner for Personal Data (PCPD), carrying out due diligence on recipients, and applying security measures such as encryption.

Where you are located in a jurisdiction with specific cross-border transfer rules, the additional safeguards described in Section 13 apply.

8. Retention

We keep personal data for no longer than is necessary for the purposes for which it is used, in line with Data Protection Principle 2(2) and section 26 of the PDPO. Indicative periods are:

DataRetention period
Account dataFor the life of the account, plus 24 months after closure or last login, then deleted or anonymised
Billing, invoices, and transaction records7 years from the transaction, to meet Hong Kong record-keeping requirements under the Inland Revenue Ordinance and Companies Ordinance
Support communications3 years after the ticket is closed
Marketing consent recordsFor as long as consent is active, plus 3 years as proof of consent or withdrawal
Licence and diagnostic logs12 months, unless needed to investigate a security incident
Website analytics dataAs set out in the Cookie Policy, usually no more than 26 months
Data needed for legal claims or investigationsUntil the matter is finally resolved

When retention periods end, we securely delete personal data or irreversibly anonymise it.

9. Security

We take all practicable steps to protect personal data against unauthorised or accidental access, processing, erasure, loss, or use, as required by Data Protection Principle 4. Our measures include encryption in transit (TLS) and at rest, hashed passwords, role-based access control and the principle of least privilege, multi-factor authentication for staff systems, logging and monitoring, vendor security assessments, and confidentiality obligations for staff and contractors.

No system is completely secure. You are responsible for keeping your password and licence key confidential.

Data breaches: if a data breach is likely to create a real risk of harm to you, we will notify you and the PCPD as soon as practicable, following the PCPD's Guidance on Data Breach Handling and Data Breach Notifications, and will take steps to contain the breach and limit its impact.

10. Your rights

Under the PDPO you have the right to:

How to make a request: email privacy@atasmarkets.com with the subject line "Data Access Request" or "Data Correction Request". You may use the PCPD's specified Data Access Request Form (OPS003). To protect your data, we may need to verify your identity before responding.

Timing and fees: we will respond within 40 days of receiving a request. We may charge a fee for complying with a data access request. Any fee will not be excessive and will be limited to our directly related and necessary costs. We will tell you the fee before processing the request. Correction requests are free of charge.

In some cases the PDPO permits or requires us to refuse a request, for example where we cannot verify your identity or where providing the data would disclose personal data of another person. If we refuse, we will give you written reasons.

Many details (email, name, language, marketing preferences) can also be viewed and updated directly in your account settings.

11. Children

The Services are intended for adults and are not directed at persons under 18 years of age. We do not knowingly collect personal data from minors. If you believe a minor has provided us with personal data, contact us and we will delete it.

12. Cookies and similar technologies

We use cookies, local storage, pixels, and SDKs on the Website and in our emails. Details, including the categories used, providers, durations, and how to manage your choices, are set out in our Cookie Policy.

13. Additional information for users outside Hong Kong

The PDPO applies to our handling of personal data. Where you are located in a jurisdiction whose data protection laws apply to us, you may have additional rights, which we will honour. Contact privacy@atasmarkets.com to exercise them.

13.1 European Economic Area, United Kingdom, and Switzerland

Where the GDPR or UK GDPR applies:

13.2 United States

Where applicable US state privacy laws (such as California's CCPA/CPRA) apply, you may have the right to know, delete, and correct personal information, and to opt out of "sale" or "sharing" for cross-context behavioural advertising. We do not sell personal information. Where our use of advertising cookies may count as "sharing", you can opt out through the "Your Privacy Choices" link in the Website footer. We honour Global Privacy Control (GPC) signals, and we will not discriminate against you for exercising your rights.

13.3 Latin America

13.4 Asia-Pacific

13.5 Middle East

United Arab Emirates (Federal PDPL), Saudi Arabia (PDPL), Qatar, Bahrain, and others: you may exercise the access, correction, deletion, and objection rights available under your local law. Where local law restricts transfers outside the country, we will rely on the permitted transfer mechanisms.

14. Changes to this Policy

We may update this Policy from time to time. We will publish the updated version on this page with a new effective date. If the changes are material, we will notify you by email or through a notice in your account or the software before the changes take effect. Where your consent is legally required, we will ask for it again.

15. Contact and complaints

For any questions, requests, or complaints about this Policy or our handling of your personal data, contact:

Data Protection Officer

ATAS Markets Limited
7/F, MW Tower, 111 Bonham Strand, Sheung Wan, Hong Kong
Email: privacy@atasmarkets.com

We will try to resolve your concern promptly. If you are not satisfied, you may complain to:

Office of the Privacy Commissioner for Personal Data, Hong Kong

12/F, Sunlight Tower, 248 Queen's Road East, Wan Chai, Hong Kong
Tel: +852 2827 2827
Website: www.pcpd.org.hk

16. Governing law and language

This Policy is governed by the laws of the Hong Kong Special Administrative Region. We may provide translations of this Policy for convenience. If there is any inconsistency, the English version prevails, except where local law requires otherwise.