Personal Data & Privacy Notice
Introduction
The purpose of this notice is to provide you with information on our use of your personal data in accordance with the Data Protection Act (as revised) of the Cayman Islands (the “DPA”), formerly the Data Protection Law, 2017 (which took effect on 30 September 2019), and, where applicable, the EU/UK General Data Protection Regulation (“GDPR”). The DPA is based on a set of internationally recognized privacy principles and provides a framework of rights and duties designed to give individuals greater control over their personal data. This notice does not change the manner in which we use, or intend to use, your personal data; it explains it.
In this notice, “we,” “us,” “our” and “LYNK” refer to Lynk Capital Markets Ltd., a company incorporated in the Cayman Islands and registered with CIMA (Cayman Islands Monetary Authority) as a Registered Person. LYNK acts as data controller in respect of the Personal Data it collects and processes for the purposes described in this notice. In certain contexts (for example, where LYNK acts as administrator or service provider to a third-party entity) it may act as a data processor on behalf of that entity as data controller, in which case the relevant controller’s privacy notice will govern the processing of your Personal Data. Service providers, sub-administrators and other delegates engaged by us to assist in delivering its services act as data processors on its behalf and are subject to appropriate data-processing agreements.
The Personal Data We Hold
By virtue of your interactions with us, and by you providing us with information about individuals connected with you (for example directors, trustees, officers, employees, representatives, shareholders, investors, clients, beneficial owners or agents), certain information you provide may constitute personal data within the meaning of the DPA (“Personal Data”). We may also obtain Personal Data from other sources, including publicly available sources and screening and verification providers.
Personal Data we may hold includes, without limitation: name; residential address; contact details (email address, telephone number, and/or cellphone number); corporate contact information; signature; nationality; place and date of birth; tax identification; credit history; correspondence records; passport or other identification number; bank account details; source-of-funds and source-of-wealth details; and details relating to your investment activity. Certain data we process may constitute special-category data under the DPA, such as information relating to criminal convictions or offences arising from AML/CFT and sanctions screening, which we process in order to exercise our legal obligation towards the prevention or detection of unlawful acts, as applicable.
In our use of Personal Data, LYNK acts as the “data controller” for purposes of the DPA. In addition, we and our affiliates and/or delegates (including service providers) may act as “data processors” for the purposes of the DPA.
Who This Affects
If you are a natural person, this notice affects you directly. If you are a corporate investor or other entity that provides us with Personal Data about individuals connected with you in relation to your dealings with us, this notice is relevant to those individuals, and you should transmit this notice to them or otherwise make them aware of its content.
How and Why We Use Your Personal Data
LYNK, as data controller, may collect, store and use Personal Data for lawful purposes, including in particular:
Processing activity | Lawful basis |
|---|---|
Counterparty/client onboarding and administration: where this is necessary for the performance of our rights and obligations under our arrangements with you, including those described in the relevant Program Documents (such as subscription agreements, terms of use and other constitutional and operational documents) | Performance of a contract; legitimate interests |
AML/CFT and sanctions screening: where this is necessary for compliance with a legal or regulatory obligation to which we are subject (such as anti-money laundering, counter-terrorist financing, counter-proliferation-financing, sanctions, tax-reporting and other regulatory requirements) | Compliance with a legal obligation |
Platform security and monitoring: where this is necessary for the purposes of our legitimate interests (such as operating, securing and improving our platform and services, and maintaining records), and such interests are not overridden by your interests, fundamental rights or freedoms | Legitimate interests |
Multi-factor authentication: where you have selected this authentication method to receive one-time passcodes via SMS to your provided phone number | Legitimate interests |
Marketing communications: where you have given your consent, in which case you may withdraw that consent at any time (without affecting the lawfulness of processing carried out before withdrawal). | Consent |
Our Service Providers
Our service providers may use Personal Data, for example to provide their services or to discharge legal or regulatory requirements that apply directly to them, but such use will be compatible with at least one of the purposes for which we process Personal Data. Should we wish to use Personal Data for any other specific purpose (including any purpose that requires your consent), we will contact you.
SMS / Text Messaging
Where you choose SMS as your multi-factor authentication method, we collect and use your cellphone number to send you one-time passcodes. The number of messages you receive depends on your account activity. Message and data rates may apply.
We do not sell your cellphone number or your SMS opt-in consent, and we do not share them with third parties or affiliates for marketing or promotional purposes. We disclose your number only to our SMS delivery provider, acting as our data processor, for the sole purpose of transmitting your passcode.
Consenting to SMS messages is not a condition of using our services. If you prefer not to receive text messages, you can use an authenticator app as an alternative.
We keep your cellphone number for as long as SMS authentication is enabled on your account, and in line with the “How Long We Keep Your Personal Data” section below.
Consent withdrawal
You may withdraw your consent at any time by contacting our Data Protection Officer at [email protected]. With respect to SMS consent specifically, you may withdraw it at any time by replying STOP to any message or by changing your multi-factor authentication method in your account settings. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
Why and How We May Share or Transfer Your Personal Data
In certain circumstances we and/or our authorized affiliates or delegates may be legally obliged to share Personal Data and other information with the applicable regulatory authorities, including CIMA or the Cayman Islands Tax Information Authority. They, in turn, may exchange that information with foreign authorities, including tax authorities.
We may disclose Personal Data to parties who provide services to us and their respective affiliates (which may include entities located outside the Cayman Islands or the European Economic Area), who will process Personal Data on our behalf. Such parties may include, to the extent applicable:
- custodians, administrators and/or sub-administrators, as set forth in the relevant Program Documents;
- investment advisers, accountants, auditors, depositories, financial advisers, lawyers and other outside professional advisers to LYNK; and
- technology, communications and authentication service providers, including our SMS delivery provider.
Where we transfer Personal Data outside the Cayman Islands, we do so only in accordance with the DPA and, where applicable, the GDPR. Our principal transfer destinations, and the safeguards we rely on, are set out below:
Destination (region) | Recipients | Transfer mechanism |
|---|---|---|
United States | LYNK affiliates and/or IT/system and service providers | Adequacy assessment / standard contractual clauses / equivalent contractual safeguards |
European Economic Area | Service providers and/or professional advisers | Adequacy / standard contractual clauses |
United Kingdom | Service providers and/or professional advisers | Adequacy / UK addendum to standard contractual clauses |
Where none of the above applies, we transfer Personal Data only where a recognized derogation applies (for example, your explicit consent, or where the transfer is necessary for the performance of a contract with you). You may obtain further information about these transfers, and a copy of the relevant safeguards, by contacting us at [email protected].
The Data Protection Measures We Take
Any transfer of Personal Data by us or our duly authorized affiliates and/or delegates outside of the Cayman Islands will be carried out in accordance with the requirements of the DPA and, where applicable, the GDPR, including by putting in place appropriate safeguards for such transfers.
We and our duly authorized affiliates and/or delegates apply appropriate technical and organizational information-security measures designed to protect against unauthorized or unlawful processing of Personal Data, and against accidental loss or destruction of, or damage to, Personal Data.
Where a breach is likely to have an adverse effect on the privacy of an affected individual, we notify the Office of the Ombudsman and any affected individual without undue delay, and in any event no later than five (5) days after we become aware, or ought reasonably to have become aware, of the breach. And, where the GDPR is applicable, we notify the competent supervisory authority without undue delay and, where feasible, not later than 72 hours after becoming aware of the breach, unless it is unlikely to result in a risk to individuals’ rights and freedoms; and we notify affected individuals where the breach is likely to result in a high risk to their rights and freedoms.
How Long We Keep Your Personal Data
We retain Personal Data only for as long as is necessary for the purposes for which it was collected, including to satisfy our legal, regulatory, accounting, recordkeeping and reporting obligations (which, for certain records, require retention for a number of years after the end of our relationship), and to establish, exercise or defend legal claims. When Personal Data is no longer required, we will securely delete or anonymize it in accordance with our records-retention policy and Applicable Law.
Your Rights
Subject to the conditions and exemptions in the DPA (and, where applicable, the GDPR), you have rights in respect of your Personal Data, which may include the right to:
- be informed about how your Personal Data is processed (which this notice is designed to address);
- request access to a copy of the Personal Data we hold about you;
- request that inaccurate or incomplete Personal Data be corrected;
- require us to stop processing, or not to begin processing, your Personal Data where it is causing, or is likely to cause, unwarranted substantial damage or distress;
- require us to stop processing your Personal Data for direct-marketing purposes;
- in certain circumstances, require us to erase* your Personal Data, or to restrict or object to its processing;
- require that we do not make a decision that significantly affects you based solely on automated processing of your Personal Data; and
- where GDPR applies, receive your Personal Data in a structured, commonly used and machine-readable format and, where technically feasible, to have it transmitted to another controller (right to data portability); and
- seek compensation for damage suffered as a result of a contravention of the DPA (and, where applicable, GDPR).
To exercise any of these rights, please contact us using the details below. We may need to verify your identity before responding. We will respond to your request within 1 (one) month of receipt, unless the request is complex or we have received a high volume of requests, in which case we may extend this period by a further 2 (two) months and will notify you accordingly. If you are not satisfied with how we have handled your Personal Data or a request, you have the right to complain to the Office of the Ombudsman of the Cayman Islands and, where GDPR applies, to the relevant EU/UK supervisory authority in the jurisdiction where you reside, work, or where the alleged infringement occurred.
* The right to erasure and certain other rights may be limited or excluded where we are required to retain data to comply with our legal and regulatory obligations, including AML/CFT obligations and obligations arising under Securities Investment Business Act.
Automated Decision-Making
We do not generally make decisions producing legal effects concerning you, or similarly significantly affecting you, based solely on automated processing without appropriate safeguards. Where we do, we will inform you and apply the protections required by Applicable Law.
Changes to This Notice
We may update this notice from time to time. We will post the updated notice with a revised effective date and version number and, where the change is material, will use reasonable efforts to bring it to your attention. We maintain prior versions of this notice as part of our records.
Getting In Touch
Should you have any queries, wish to exercise your data protection rights, or wish to discuss this notice, please email LYNK’s Data Protection Officer via email to: [email protected].
You may lodge a complaint with the Cayman Islands Office of the Ombudsman at any time if you consider that our processing of your Personal Data does not comply with the DPA, regardless of whether you have first exercised any other right. The Ombudsman’s contact details are available at ombudsman.ky.
Effective date: August 7, 2026