Last updated: August 2026
1. Who We Are
Top Crest SA ("Top Crest", "we", "us", "our") operates this website and provides institutional trading technology and execution services. We are responsible for personal data collected through this website and in the course of providing our services.
2. Data We Collect
We collect and process the following categories of personal information:
2.1 Information You Provide
Contact and inquiry data — Name, company name, email address, telephone number, job title, and the content of your inquiry submitted via our contact form or by email.
Client onboarding data — For clients proceeding to account opening: identity documentation, proof of address, source of funds documentation, beneficial ownership information, and authorised signatory details. This data is collected under our regulatory obligations.
Employment application data — If you apply for a position at Top Crest: CV, cover letter, professional references, and any other information you choose to provide.
2.2 Information Collected Automatically
Usage data — IP address, browser type and version, operating system, referring URL, pages visited, time spent on pages, and links clicked.
Cookie data — Please see our Cookie Policy for details of cookies we use and how to manage them.
3. Legal Basis for Processing
We process your personal data on the following legal bases:
Contractual Necessity
Processing required to perform a contract with you or take steps at your request prior to entering a contract. Applies to client onboarding, account administration, API integration, and execution services.
Legal Obligation
Processing required to comply with applicable legal obligations including anti-money laundering and know-your-customer requirements in jurisdictions where we operate.
Legitimate Interests
Processing necessary for our legitimate interests including: responding to inquiries, improving our website, preventing fraud, and maintaining the security of our systems. We balance these interests against your rights.
Consent
Where you have given explicit consent, such as subscribing to our market insights or accepting non-essential cookies. You may withdraw consent at any time without affecting processing based on other legal bases.
4. How We Use Your Data
We use your personal data for the following purposes:
- Responding to inquiries and providing information about our services
- Processing account applications and conducting due diligence
- Providing and administering execution and quantitative infrastructure services
- Sending market insights and research to subscribers
- Complying with regulatory reporting obligations
- Detecting, investigating, and preventing fraudulent activity
- Maintaining and improving our website and digital infrastructure
- Processing employment applications and managing recruitment
- Enforcing our legal rights and defending against legal claims
5. Data Sharing and Disclosure
We do not sell your personal data. We may share your data with:
5.1 Service Providers
Third-party service providers who assist us in operating our business, including: cloud infrastructure providers, verification providers, legal and tax advisors, auditors, and IT security providers. All processors are bound by appropriate data protection obligations.
5.2 Regulatory Authorities
We disclose personal data to competent authorities as required by law, including for regulatory reporting, suspicious activity reporting, and responding to lawful requests.
5.3 Counterparties and Liquidity Providers
In the course of executing transactions, limited data may be shared with liquidity providers, trading venues, and settlement counterparties as required to complete transactions. All counterparties are regulated financial institutions.
5.4 Group Companies
Data may be shared with affiliated group companies where necessary to provide services across jurisdictions. All group data transfers are governed by appropriate data transfer agreements.
6. International Transfers
Top Crest operates globally and your data may be transferred to and processed in countries outside your jurisdiction of residence, including Switzerland, UAE, Singapore, and the United Kingdom.
We ensure appropriate safeguards are in place for such transfers, including standard contractual clauses or adequacy decisions where applicable.
7. Data Retention
We retain personal data for as long as necessary to fulfill the purposes for which it was collected, including to satisfy legal, regulatory, accounting, and reporting requirements. Specific retention periods vary by data category:
Client KYC & Transaction Records
Retained for the period required by applicable anti-money laundering and financial regulations in the jurisdictions where we operate.
Contact & Inquiry Data
Retained for a reasonable period following our last contact, or until you request deletion where we are not under a legal obligation to retain.
Newsletter Subscriptions
Until you unsubscribe or withdraw consent, plus a reasonable period for record-keeping of consent.
Website Usage Data
Retained for a limited period in line with applicable guidance on analytics data retention.
Employment Applications
Retained for a reasonable period following the conclusion of the recruitment process.
Legal Claims
Data relevant to actual or potential legal proceedings is retained for the duration of proceedings plus applicable limitation periods.
8. Your Rights
Subject to applicable law, you may have the following rights regarding your personal data:
- Right of access — Request a copy of the personal data we hold about you
- Right to rectification — Request correction of inaccurate or incomplete data
- Right to erasure — Request deletion where we have no legal basis to retain
- Right to restriction — Request we limit processing in certain circumstances
- Right to portability — Receive your data in a structured, machine-readable format
- Right to object — Object to processing based on legitimate interests or for direct marketing
- Right to withdraw consent — Withdraw consent at any time without affecting prior lawful processing
To exercise any of these rights, please contact us. We will respond within a reasonable timeframe. You also have the right to lodge a complaint with your local data protection authority.
9. Data Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, destruction, or alteration. These measures include:
- Encryption for data at rest and in transit
- Multi-factor authentication for systems containing personal data
- Role-based access controls limiting data access to authorised personnel
- Regular security testing by independent specialists
- Information security management aligned with industry standards
- Business continuity and disaster recovery procedures
In the event of a personal data breach, we will notify affected individuals and relevant authorities in accordance with applicable law.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting a notice on our website or, for registered clients, by direct communication. The date of the most recent revision is displayed at the top of this page. Continued use of our services after changes constitutes acceptance of the updated policy.
11. Contact
For questions about this Privacy Policy or our data practices, please contact us.