Privacy Policy
1. Controller Identification
Data Controller: MyGold S.P.A.
Registered as Professional Gold Operator under the supervision of the Bank of Italy.
Registered Office: [Insert official registered address]
Email: [Insert official contact email]
Website: https://www.mygold.world
For any privacy-related matter, you may contact us at the email address indicated above.
2. Data Protection Commitment
MyGold S.P.A. is committed to ensuring the lawful, fair, and transparent processing of personal data in accordance with Regulation (EU) 2016/679 (General Data Protection Regulation – GDPR) and applicable Italian data protection legislation.
We process personal data strictly within the limits necessary to provide our services, comply with legal obligations, and ensure regulatory alignment as a supervised precious metals operator.
3. Categories of Personal Data
Through our website and services, we may collect and process:
-
Identification data (name, surname)
-
Contact data (email address, phone number)
-
Company details (where applicable)
-
Identification documentation required under AML/KYC obligations
-
Technical data (IP address, browser type, device data)
-
Transaction-related data
We do not process special categories of personal data unless legally required.
4. Purpose of Processing
Personal data is processed for the following purposes:
-
Responding to inquiries submitted via contact forms
-
Client onboarding and contractual management
-
Compliance with Anti-Money Laundering (AML) obligations
-
Regulatory reporting requirements
-
Risk assessment and internal control procedures
-
Website analytics and security monitoring
-
Legal compliance and defense of legal claims
Processing is based on contractual necessity, legal obligation, legitimate interest, or explicit consent where required.
5. Legal Basis for Processing
We process personal data on the following legal grounds:
-
Performance of a contract
-
Compliance with legal and regulatory obligations
-
Legitimate interest in operating and securing our services
-
Explicit consent where required
6. Data Retention
Personal data is retained only for the period necessary to fulfill the purpose for which it was collected and to comply with legal and regulatory requirements.
Where processing is based on contractual obligations, data will be retained for the duration of the contractual relationship and for the legally required retention period thereafter.
Where data is collected for inquiries only, it will be retained for a reasonable period unless a contractual relationship is established.
7. Disclosure of Data
Personal data may be disclosed to:
-
Regulatory authorities and supervisory bodies
-
Public administrations, courts, or law enforcement authorities when legally required
-
Service providers acting as data processors under contractual obligations
-
Professional advisors (legal, audit, compliance)
All third-party processors act under strict confidentiality and data protection obligations.
8. International Data Transfers
Personal data is processed within the European Economic Area (EEA).
Where transfers outside the EEA are necessary, appropriate safeguards under GDPR will be implemented.
9. Data Subject Rights
Under GDPR, you have the right to:
-
Access your personal data
-
Rectify inaccurate or incomplete data
-
Request erasure (right to be forgotten)
-
Restrict processing
-
Object to processing
-
Request data portability
-
Withdraw consent where applicable
Requests may be submitted in writing to the contact details provided above.
You also have the right to lodge a complaint with the competent Data Protection Authority.
10. Security Measures
MyGold implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
-
Access control mechanisms
-
Data encryption protocols
-
Firewall and network security systems
-
Internal monitoring and audit procedures
-
Staff confidentiality obligations
While we apply industry-standard safeguards, absolute security cannot be guaranteed.
11. IP Addresses and Technical Data
Our servers may automatically collect technical information such as IP address, browser type, and navigation data for statistical, security, and operational purposes.
This information is processed in anonymized or aggregated form where possible.
12. Minors
Our services are not directed to individuals under the age of 18.
We do not knowingly collect personal data from minors without appropriate legal authorization.
13. Applicable Law
This Privacy Policy is governed by:
-
Regulation (EU) 2016/679 (GDPR)
-
Applicable Italian data protection legislation
-
Relevant European regulatory provisions
