Regulated EntitySegregated Client FundsSecure & Transparent
Legal

Data Protection Notice

Last updated: September 2026

1. Introduction

Monolith Market is the online and mobile trading platform operated by Monolith Private Wealth Limited (“MPW”, the “Company”, “we”, “us”, or “our”), a company incorporated in the Republic of Mauritius and licensed by the Financial Services Commission of Mauritius (“FSC”) under the Securities Act 2005.

MPW takes the protection of your personal data seriously. This notice (the “Notice”) explains, in clear language, what personal data we collect about you, why we collect it, the lawful reasons for using it, how long we keep it, who we share it with, how we transfer it outside Mauritius, what safeguards we apply, how we protect it, what rights you have under the Data Protection Act 2017 of Mauritius, and how you can contact our Data Protection Officer.

MPW is the data controller for personal data collected through the Monolith Market platform.

2. Legal Framework

This Notice is adopted in compliance with, and shall be read in conjunction with, the following principal instruments:

Instrument Relevance
Data Protection Act 2017 (Mauritius) (“DPA 2017”) This is the main data protection law in Mauritius. It has been in force since 15 January 2018 and is broadly aligned with internationally recognised data protection standard.
Constitution of Mauritius This protects the fundamental right to privacy.
Financial Intelligence and Anti-Money Laundering Act 2002 (FIAMLA) This requires MPW to keep records, monitor activity for AML purposes, and make reports where required. These obligations affect how we process and retain personal data.
Securities Act 2005 and Securities (Licensing) Rules 2007 These set conduct of business obligations for investment dealers and investment advisers.
FSC Code of Business Conduct This sets conduct standards for FSC licensees, including standards on the protection of client information.
Income Tax Act 1995 and the FATCA / CRS frameworks These create tax-information reporting obligations to the Mauritius Revenue Authority and, through it, to foreign tax authorities.

3. Key Definitions

For the purposes of this Notice, the following terms have the meanings ascribed to them in the DPA 2017 (or as defined below):

Term Definition
Personal Data Any information that relates to a person who can be identified, directly or indirectly. This may include a name, identification number, location data, online identifier, or other information specific to that person.
Data Subject The person whose personal data is being collected, used or otherwise processed.
Special Category Personal Data More sensitive personal data, such as information about racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, genetic or biometric data, health, sex life or sexual orientation.
Processing Anything done with personal data, whether manually or automatically. This includes collecting, storing, using, sharing, restricting, deleting or destroying it.
Controller The person or organisation that decides why and how personal data is processed. MPW is the controller for personal data processed through Monolith Market.
Processor A person or organisation that processes personal data for a controller and only on that controller’s instructions.
DPO The Data Protection Officer appointed by MPW to oversee compliance with the DPA 2017 and to act as a contact point for data subjects and the Data Protection Commissioner.
Third-Party Service Provider An external provider used by MPW whose services involve processing personal data. This may include cloud-hosting, payment-processing, electronic identity verification, screening, custody, IT or similar providers.
Personal Data Breach A security breach that causes personal data to be accidentally or unlawfully destroyed, lost, changed, disclosed without authorisation, or accessed without authorisation.

4. Personal Data We Collect

We collect personal data when you apply to open an account, when you use the Monolith Market platform, and during our ongoing relationship with you. We may also receive personal data about you from third parties, such as electronic identity verification providers, screening agencies, custodians and other regulated counterparties.

4.1 Categories of Personal Data

We may collect and use the following types of personal data:

Category Examples
Identity Data Your full name, date and place of birth, nationality, gender, passport or national ID details, signature, photograph, or liveness image.
Contact Data Your residential address, mailing address, email address and telephone numbers.
Tax and Regulatory Data Your country or countries of tax residence, Tax Identification Number, FATCA/CRS self-certification responses, and whether you are a U.S. Person.
Employment and Financial Data Your occupation, source of income, source of funds, source of wealth, net-worth band, and expected trading volume.
Suitability and Knowledge Data Your responses to the Client Investment Profile questionnaire, including your investment objectives, risk tolerance, financial situation, knowledge and experience, and assigned suitability profile.
Account and Transaction Data Your account number, balances, holdings, deposits and withdrawals, securities transactions, order history, and margin or leverage usage.
Authentication Data Your login credentials, stored in hashed form, multi-factor authentication tokens, and device-binding identifiers.
Technical and Device Data Your IP address, device type, operating system, browser, time zone, language settings, device fingerprint, mobile-app version, and push-notification tokens.
Usage Data Information about how you use the platform, such as login frequency, screens viewed, features used, session duration, support interactions and in-app messages.
Communications Data Emails, chats, telephone calls where recorded, and in-app messages exchanged with our team.
AML/CFT/CPF Data Sanctions and politically exposed person screening results, adverse-media findings, money-laundering risk rating, and suspicious transaction report records, where applicable and subject to statutory confidentiality.
Marketing Preferences Your subscriptions, communication preferences and opt-outs.
Special Category Data (limited) Limited biometric data captured through liveness checks for identity verification, where strictly required by our regulatory obligations.

4.2 Sources of Personal Data

We collect personal data from the following sources:

  • Directly from you. This includes information you provide during onboarding, while using the platform, when contacting support, during KYC refreshes, and in other communications with us.

  • Automatically through the platform. This includes technical, usage and authentication data collected when you use the platform.

  • From third parties. This may include electronic identity verification providers, screening agencies such as LSEG World-Check One, credit bureaux where applicable, tax authorities, regulators, custodians, banks and other regulated financial institutions.

  • From public sources. This may include corporate registries, sanctions and PEP databases, and publicly available adverse-media sources.

5. Purposes of Processing and Lawful Bases

In accordance with the DPA 2017, all processing by MPW is based on one or more lawful bases. The principal purposes and corresponding bases are set out below:

Purpose Lawful Basis Special Category Basis (if applicable)
Onboarding, identity verification, account opening Performance of contract / pre-contractual measures Substantial public interest (AML/CFT); explicit consent for biometric data
Providing the platform, executing transactions, and handling communications Performance of contract Not applicable
Customer due diligence, AML monitoring, and STR filing Legal obligation (FIAMLA; FIAMLR 2018; FSC AML/CFT Handbook) Substantial public interest
Tax reporting under FATCA and CRS Legal obligation (Income Tax Act 1995; Mauritius-U.S. IGA; CRS regulations) Not applicable
Suitability and appropriateness assessment Legal obligation (FSC Code of Business Conduct; Securities Act 2005); performance of contract Not applicable
Sanctions screening Legal obligation (UN Sanctions Act 2019) Not applicable
Risk management, fraud prevention, security monitoring Legitimate interests of MPW and clients Not applicable
Internal record-keeping and audit Legal obligation; legitimate interests Not applicable
Service communications and platform updates Performance of contract; legitimate interests Not applicable
Defending or pursuing legal claims Legitimate interests; legal obligation Not applicable
Responding to lawful requests from regulators or law-enforcement Legal obligation Not applicable

Note on consent: Most processing carried out by MPW is necessary for the performance of the Client Agreement, compliance with legal obligations (FIAMLA, the FSC Code of Business Conduct, and tax-information reporting), or MPW's legitimate interests as a regulated financial services provider. Where consent is relied upon as a lawful basis — specifically in relation to biometric data captured through liveness checks during identity verification — you have the right to withdraw that consent at any time, without affecting the lawfulness of processing carried out prior to withdrawal. Withdrawal of consent in respect of biometric data may prevent MPW from completing or maintaining the identity verification required to open or operate your account.

6. Third-Party Service Providers and Data Processors

MPW uses external service providers to help operate the Monolith Market platform. Some of these providers process personal data on MPW’s behalf. They do so only on MPW’s instructions and under a written Data Processing Agreements that meet the requirements of DPA 2017.

6.1 Categories of Third-Party Service Providers

Category Function
Cloud Infrastructure and Hosting Providers hosting the Monolith Market platform, databases, and back-up infrastructure.
Identity Verification (eIDV) and Liveness Providers performing document authentication, biometric liveness checks, and identity-verification searches at onboarding and refresh.
Sanctions, PEP and Adverse-Media Screening Providers such as LSEG World-Check One that screen clients, beneficial owners, and counterparties.
Payment and Banking Services Banks and payment service providers that hold client money in segregated accounts and process deposits, withdrawals, and money movements.
Custody, Clearing and Execution Custodians, clearing brokers, and executing brokers that hold securities, execute transactions, or settle trades.
Communication and Notification Email service providers, SMS gateways, push-notification providers, and in-app chat platforms.
Customer Support and CRM CRM platforms, ticketing systems, and outsourced customer-support providers.
Analytics and Performance Web and mobile analytics providers used to monitor platform performance, security, and user experience.
IT and Cybersecurity Endpoint protection, security-operations, vulnerability-scanning, and incident-response providers.
Legal, Audit and Tax Advisers Professional advisers engaged in connection with MPW's business (in many cases acting as independent controllers).
Document Storage and Archiving Providers storing back-ups, archives, and disaster-recovery copies of data.

MPW maintains internal records of its key third-party service providers, their processing functions, and the jurisdictions in which personal data may be processed. These records are maintained for governance, audit, and regulatory purposes. Disclosure of specific provider identity, system architecture, or data-flow information is subject to MPW's information security obligations and any applicable confidentiality arrangements. Where required by the DPA 2017 or by order of a competent authority, relevant information will be provided to the extent permitted by law.

6.2 Mandatory Data Processing Agreement

Before sharing your personal data with any external provider, MPW puts a written contract in place that sets out exactly what that provider may do with your data, requires them to keep it secure and confidential, and obliges them to delete or return it when their engagement ends. MPW retains the right to audit compliance with those obligations.

6.3 Ongoing Oversight

After onboarding, MPW will continue to monitor its third-party service providers. This includes reviewing security certifications and audit reports from time to time, monitoring incidents, reassessing providers annually, reviewing any material changes to how they process data, and planning for termination or migration, including the secure return or deletion of personal data.

7. Cross-Border Transfers of Personal Data

When operating the Monolith Market platform, MPW may transfer personal data outside the Republic of Mauritius. This may include transfers to cloud-hosting providers, screening providers, custodians or clearing brokers, or transfers required for FATCA/CRS tax-reporting purposes.

7.1 Conditions for Cross-Border Transfer

In accordance with the DPA 2017, MPW will not transfer your personal data outside Mauritius unless at least one of the following conditions is met:

  1. the Data Protection Commissioner has determined that the recipient country provides an adequate level of protection;

  2. you have consented to the transfer after being informed of the risks involved;

  3. the transfer is necessary to open or operate your Account or to carry out a transaction you have requested;

  4. the transfer is necessary for a contract concluded in your interest;

  5. the transfer is required by law, including international tax-reporting obligations such as FATCA and CRS;

  6. the transfer is necessary for the establishment, exercise, or defence of legal claims;

  7. appropriate safeguards have been put in place by the recipient; or

  8. the transfer has been specifically authorised by the Data Protection Commissioner.

7.2 Safeguards

When MPW transfers personal data outside Mauritius, it will apply appropriate safeguards. These may include a written contract with data-processing and cross-border transfer protections, confirmation that the recipient is subject to substantially equivalent data-protection laws or otherwise provides adequate protection, encryption of personal data in transit and at rest, and limiting the data transferred to what is strictly necessary for the relevant purpose.

7.3 Disclosures for Tax-Information Reporting

MPW transfers personal data to the Mauritius Revenue Authority (“MRA”), where required under FATCA and CRS. Through the MRA, personal data may also be shared with the U.S. Internal Revenue Service and with the relevant tax authorities in CRS Reportable Jurisdictions where a client is tax-resident. These transfers are required by law and are made on a regular, periodic basis.

8. How Long We Keep Your Personal Data

In line with the DPA 2017, MPW keeps personal data only for as long as it is needed for the purpose for which it was collected, or as required by applicable legal, regulatory or contractual obligations. Once the relevant retention period has expired, the data is securely deleted or anonymised.

Category of Data Retention Period
AML/CFT records (CDD, transaction records, communications) Minimum 7 years from the relevant transaction or termination of the business relationship (FIAMLA; FIAMLR 2018; FSC AML/CFT Handbook).
Records relating to suitability or appropriateness Minimum 7 years from the date of the recommendation, transaction, or termination of the relationship.
Order and execution records Minimum 7 years from the date of order or execution.
FATCA and CRS records Minimum 7 years from the relevant reporting year.
Complaints records Minimum 7 years from the date of the final response.
Marketing data (consent-based) Until consent is withdrawn or the data subject objects.
Technical and log data Usually 12 to 24 months, depending on log type and any security-incident considerations.
Dormant account records Minimum 7 years from account closure; longer where required under any applicable unclaimed-property regime.
Records related to investigations Until the matter is concluded and any limitation period for related claims has expired.

9. Security of Personal Data

In accordance with the DPA 2017, MPW implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk of the processing.

9.1 Technical Measures

MPW uses a range of technical measures to keep personal data safe. Personal Data is encrypted when it is sent and when it is stored. Clients and internal users must use multi-factor authentication when accessing accounts or sensitive systems. Access to Personal Data is limited to people who need it for their role. MPW also uses network security tools, including firewalls, network segmentation and intrusion-detection systems, to help protect its systems from unauthorised access.

Devices that connect to MPW systems are protected with endpoint-security tools. MPW also monitors its systems on an ongoing basis, carries out vulnerability checks, applies security patches, and performs penetration testing from time to time. When developing or updating its platform, MPW follows secure software-development practices, including code review. MPW also maintains back-ups, replication and disaster-recovery measures to support business continuity and data recovery.

9.2 Organisational Measures

MPW also supports these technical measures with clear internal rules and procedures. These include this Notice, the internal Information Security Policy, and related procedures that explain how Personal Data must be handled.

All employees receive mandatory data-protection and security training each year. Personnel who have access to Personal Data may also be subject to background checks, and employees and contractors are required to keep Personal Data confidential. MPW has a documented incident-response plan and tests it from time to time, so that security incidents can be managed quickly and properly. MPW also carries out internal audits and may obtain external assurance reviews to check that its controls remain effective. Where third-party processors are used, MPW applies vendor risk-management procedures, as described in Section 6.

10. Personal Data Breaches

MPW operates a personal-data-breach management programme designed to detect, contain, and respond to incidents promptly and to comply with notification obligations under the DPA 2017.

10.1 Notification to the Data Protection Commissioner

If MPW confirms that a personal data breach has occurred, it will notify the Office of the Data Protection Commissioner as quickly as possible. The notification will explain what happened, who to contact at MPW, what the likely impact is, and what steps MPW is taking to fix the problem and limit any harm.

10.2 Communication to Data Subjects

If a personal data breach is likely to create a high risk for the people affected, MPW will inform those people without undue delay.

10.3 Processor Breaches

If a personal data breach happens at a third-party processor, the processor must inform MPW without undue delay, as required under its Data Processing Agreement with MPW.

MPW remains responsible for notifying the Data Protection Commissioner and the affected individuals, where those notifications are required under the DPA 2017.

11. Your Rights as a Data Subject

Under the DPA 2017, you have certain rights over your personal data. MPW will respond to your requests within the time limits set by the DPA 2017. In most cases, this means within one month of receiving your request, although this period may be extended where the request is complex.

Right What It Means
Right of Access You can ask MPW to confirm whether it processes your personal data. Where it does, you can ask for a copy of that data and for information about how it is used.
Right of Rectification You can ask MPW to correct personal data that is inaccurate or to complete personal data that is incomplete.
Right of Erasure You can ask MPW to delete your personal data in certain circumstances. This right may be limited where MPW is required to keep the data by law, for example under FIAMLA record-keeping requirements or FATCA/CRS tax-reporting rules.
Right to Restriction of Processing You can ask MPW to restrict how your personal data is used in certain circumstances, for example where you dispute the accuracy of the data. Depending on the data concerned and the restriction requested, this may limit the services MPW can provide to you. In some cases, it may mean that MPW is unable to continue providing certain services until the restriction is lifted or the issue is resolved.
Right to Object You can object to processing based on legitimate interests.
Right to Data Portability Where processing is based on your consent or on a contract, and is carried out by automated means, you can ask for a machine-readable copy of your data. Where technically possible, you can also ask for it to be sent to another controller.
Right Not to be Subject to Automated Decisions You can ask not to be subject to decisions that are based only on automated processing and that produce legal or similarly significant effects. MPW applies human oversight to this type of decision-making.
Right to Lodge a Complaint You can complain to the Office of the Data Protection Commissioner of Mauritius if you believe that MPW has processed your personal data in breach of the DPA 2017.
Right to Withdraw Consent Where MPW relies on your consent to process personal data, you can withdraw that consent at any time. This will not affect any processing that was lawfully carried out before your consent was withdrawn. If the withdrawn consent relates to data that MPW needs to provide a service, MPW may no longer be able to provide that service to you. In some cases, this may result in the suspension or termination of the relevant service.

Important Limitations on Rights. Some of your rights may be limited where MPW has legal or regulatory obligations. For example, MPW cannot delete personal data that it is required to keep by law. This includes records that must be retained for AML purposes under FIAMLA, generally for 7 years, and records required for FATCA/CRS tax-reporting purposes. The right to object also does not apply where MPW is required by law to process the data. In addition, where MPW is carrying out an AML investigation or has filed a Suspicious Transaction Report, FIAMLA tipping-off rules may limit what MPW can say in response to certain data-subject requests. In those cases, MPW may not be able to provide full details if doing so would breach its legal obligations.

11.1 How to Exercise Your Rights

You can exercise any of these rights by contacting MPW’s Data Protection Officer using the details in Section 14. Before responding, MPW may need to verify your identity. This is to help protect your personal data and make sure it is not disclosed to the wrong person.

12. Cookies and Similar Technologies

The Monolith Market website, available at www.monolithmarket.com, and the Monolith Market mobile app use cookies and similar technologies. These may include local storage, mobile-app identifiers and push-notification tokens. They help us provide the service, keep the platform secure, remember your preferences and, where you have given consent, support analytics and marketing. More details are available in the Cookie Policy on the Monolith Market website.

13. Age Restriction

The Monolith Market platform is not directed at individuals under the age of 18, and MPW does not knowingly collect personal data from such individuals. Account-opening eligibility requires each applicant to be at least 18 years old.

If MPW becomes aware that it has inadvertently collected personal data relating to a person under the age of 18, it will take appropriate steps to delete that data promptly, unless retention is required by applicable law.

14. Contact - Our Data Protection Officer

MPW has appointed a Data Protection Officer to oversee its compliance with the DPA 2017 and to act as the primary point of contact for data-protection matters. If you wish to exercise your rights, ask a question, or raise a concern regarding the processing of your personal data, please contact us at:

Organisation: Monolith Private Wealth Limited (operator of the Monolith Market platform)

Address: The Gardens, Ground Floor, Bagatelle Office Park, Moka 80832, Mauritius

Email: dpo@monolithmarket.com

Website: www.monolithmarket.com

If you are not satisfied with MPW's response, you have the right to lodge a complaint with the supervisory authority in Mauritius:

Organization: Office of the Data Protection Commissioner of Mauritius

Website: dataprotection.govmu.org

15. Governance, Review, and Updates

This Notice is owned by the Data Protection Officer and the Compliance Department and is approved by the Board of Directors. It shall be reviewed at least annually and, where appropriate, earlier upon the occurrence of any of the following:

  • any material changes to the DPA 2017, the FSC framework, FIAMLA, or any other applicable Mauritian law or regulation affecting the processing of personal data;

  • the issuance of any relevant guidance, directive, or decision by the Office of the Data Protection Commissioner;

  • any material changes to MPW’s processing activities, technology stack, or third-party service providers;

  • any material findings arising from an internal audit, compliance review, regulatory review, or supervisory engagement; or

  • any material personal data breach or near-miss incident.

Material amendments to this Notice shall be approved by the Board of Directors. Where an amendment materially affects clients, MPW shall communicate the amendment through the Monolith Market platform with reasonable advance notice.

16. Legal Disclaimer

Disclaimer: This Notice has been prepared to support MPW’s compliance with the Data Protection Act 2017 of Mauritius and related legal and regulatory obligations. It is intended for general information and internal compliance purposes only and does not constitute legal advice or an exhaustive statement of all obligations applicable to MPW.

Where any conflict arises between this Notice and applicable Mauritian law or regulation, including the DPA 2017, FIAMLA, FSC requirements, or applicable tax law, the relevant law or regulation shall prevail. MPW reserves all rights available to it under applicable law, regulation, and the Brokerage Terms and Conditions.

This Data Protection Notice should be read together with the Cookie Policy, the AML/CFT/CPF Policy Statement, the FATCA and CRS Notice, the KYC and Onboarding Requirements Notice, the Brokerage Terms and Conditions, and the Complaints Handling Procedure.

The current version of this Notice is published on the Monolith Market website at www.monolithmarket.com and within the mobile application.

Clients are deemed to have accepted this Notice as part of the Brokerage Terms and Conditions, subject to the limitations on certain data-subject rights described in Section 11.

← All legal documents© Monolith Market

Risk NoticeTrading Forex and CFDs involves significant risk and may not be suitable for all clients. Leverage can amplify losses. Please ensure you understand the risks before trading.