Royce

Client Policy · Incorporated into the Client Agreement

Privacy
Policy

Royce Capitals Ltd. · Royce Global Markets Limited

Royce Capitals Ltd. — licensed by the Labuan Financial Services Authority, Money-Broking Business Licence No. MB/23/0113
Royce Global Markets Limited — licensed and regulated by the Financial Services Commission, Mauritius, Investment Dealer Licence No. GB25205368
The applicable entity is the one identified in the Client Agreement accepted by the Client.

VersionVersion 1.0 — 29 July 2026
Client issue version
Applies toBoth licensed entities, as identified in the Client Agreement accepted by the Client
RoyceLabuan FSA · FSC Mauritius

Entities Covered and Applicable Licences

Royce Capitals Ltd. Royce Global Markets Limited
ControllerRoyce Capitals Ltd.Royce Global Markets Limited
Financial regulatorLabuan Financial Services Authority — Licence No. MB/23/0113Financial Services Commission, Mauritius — Licence No. GB25205368
Data-protection lawThe personal data protection law of Malaysia, as applicable to the Company’s processing.The Data Protection Act 2017 of Mauritius.
Supervisory authorityThe personal data protection authority of Malaysia.The Data Protection Office of Mauritius.
Rights availableAs conferred by the applicable Malaysian law, which principally provides for access, correction, withdrawal of consent and objection to direct marketing.As conferred by the Data Protection Act 2017, which provides for access, rectification, erasure, restriction, objection, portability and rights in relation to automated decisions.
Governing law of the AgreementFederal Territory of Labuan, MalaysiaMauritius

Key Points for Clients

In summary

The controller of personal data is the Royce entity named in the Client Agreement accepted by the Client. Because the two entities are subject to different data-protection regimes, the applicable law, the supervisory authority and the rights available differ between them, as set out in the table above.

Personal data is processed to open and operate an Account, to provide the Services, to meet legal and regulatory obligations, to prevent financial crime and to keep systems secure. Telephone, video, chat, email and platform communications are recorded.

An individual may ask for access to their personal data and may exercise the other rights described in section 17, subject to the exemptions in that section. Requests may be made through the privacy contact channel published on the Website, through the Client Portal, or to client support.

Contents

Contents1PURPOSE AND STATUS OF THIS POLICY

1.1This Privacy Policy forms part of the Agreement between the Client and the Company and is incorporated into it by reference. It explains what personal data the Company collects, why and on what basis it processes that data, with whom it is shared, how long it is kept, and what rights the individual has.

1.2The Policy is issued in satisfaction of the Client Agreement, which provides that further information on lawful bases, retention, rights and complaints appears in the Privacy Policy.

1.3This Policy does not create, extend or limit any contractual right. Where this Policy and the Client Agreement address the same matter, the Client Agreement prevails in accordance with the order of precedence stated in it.

1.4Nothing in this Policy removes or reduces a right conferred by applicable data-protection law that cannot lawfully be excluded.

1.5Terms defined in the Client Agreement have the same meaning in this Policy. References to personal data, processing, controller and processor have the meanings given by the applicable data-protection law.

Contents2WHO IS RESPONSIBLE FOR YOUR PERSONAL DATA

2.1The controller of personal data is the Royce entity identified in the Client Agreement that the Client has accepted. Each entity determines the purposes and means of processing in relation to its own clients.

2.2Each entity is separately incorporated, separately licensed and subject to a different data-protection regime. The applicable law, supervisory authority and set of rights depend on the contracting entity and are summarised in the entity variation table above.

2.3Where the entities process personal data jointly, or where one processes on behalf of the other, the arrangement is documented and the individual's rights may be exercised against either entity.

2.4Enquiries about this Policy, and requests to exercise rights, may be sent through the privacy contact channel published on the Website, through the Client Portal, or to the Company's client support address. The Company will direct a request to the correct entity where necessary.

Contents3WHOSE PERSONAL DATA THIS POLICY COVERS

3.1This Policy covers personal data relating to Clients and prospective Clients; their authorised representatives, directors, signatories, partners, trustees and beneficial owners; individuals connected with a corporate Client; visitors to the Website and users of the Client Portal and Trading Platform; and individuals who contact the Company.

3.2Where a Client provides the Company with personal data about another individual, the Client confirms that it is entitled to do so and that the individual has been given the information in this Policy.

3.3This Policy does not apply to processing carried out by an independent third party under its own arrangements, including a bank, card scheme, payment provider or external website reached through a link. Those parties process personal data under their own terms.

Contents4CATEGORIES OF PERSONAL DATA

4.1Identity and status data, including name, date of birth, nationality, country of residence, government identification and its reference numbers, photographs contained in identification documents, tax residence and taxpayer identification.

4.2Contact data, including address, email address and telephone numbers.

4.3Verification and due-diligence data, including proof of identity and address, source of funds and source of wealth information, screening results, beneficial ownership information and politically exposed person status where applicable.

4.4Financial and account data, including Account identifiers, balances, payment instrument details, deposits, withdrawals, Margin, Positions, Orders, Transactions, statements and confirmations.

4.5Suitability and classification data, including knowledge, experience, investment objectives, financial circumstances and the outcome of any appropriateness assessment.

4.6Communications data, including correspondence, support tickets, chat transcripts and recordings of telephone, video and platform communications.

4.7Technical and usage data, including internet protocol address, device and browser information, operating system, login records, session data, platform and Website activity, and cookie identifiers.

4.8Compliance and conduct data, including screening and monitoring alerts, records of investigations, complaints, disputes and any regulatory correspondence relating to the individual.

Contents5HOW PERSONAL DATA IS COLLECTED

5.1Directly from the individual, through an application, the Client Portal, the Trading Platform, correspondence, a telephone call or a support interaction.

5.2Automatically, through use of the Website, the Client Portal and the Trading Platform, including through cookies and similar technologies.

5.3From the individual's activity, including Orders, Transactions, payments and platform behaviour generated in the ordinary course of the relationship.

5.4From third parties, including identity-verification providers, sanctions and adverse-media screening services, credit and fraud-prevention databases, public registers, banks and payment providers, introducing brokers and affiliates, regulators and authorities, and group companies.

5.5Where the Company obtains personal data from a third party, the third party may retain a record of the enquiry, and that record may be visible to other users of the same service.

Contents6PURPOSES AND LAWFUL BASES

6.1The Company processes personal data only where it has a lawful basis to do so under the applicable data-protection law. The bases relied on are performance of a contract, compliance with a legal obligation, the legitimate interests of the Company or a third party, consent, and, where the applicable law requires it, another basis provided by that law.

6.2To assess an application, verify identity, and open, maintain, administer and close an Account. Basis: performance of a contract and compliance with a legal obligation.

6.3To provide the Services, execute and record Transactions, calculate Margin and charges, produce statements and confirmations, and process deposits and withdrawals. Basis: performance of a contract.

6.4To meet anti-money-laundering, counter-terrorist-financing, sanctions, tax-reporting, record-keeping, transaction-reporting and other regulatory obligations, and to respond to a regulator, authority or court. Basis: compliance with a legal obligation.

6.5To classify the Client, assess appropriateness, and apply product-governance and risk controls. Basis: compliance with a legal obligation and legitimate interests.

6.6To detect, investigate and prevent fraud, market abuse, prohibited trading conduct, unauthorised access and misuse of the Services, and to protect the security and integrity of systems. Basis: legitimate interests and compliance with a legal obligation.

6.7To verify instructions, monitor quality and conduct, and resolve disputes and complaints, including by reference to recorded communications. Basis: performance of a contract, legitimate interests and compliance with a legal obligation.

6.8To manage credit, counterparty and operational risk, and to establish, exercise or defend legal claims. Basis: legitimate interests.

6.9To analyse and improve the Services, including aggregated and statistical analysis. Basis: legitimate interests. Where analysis can be carried out on data that does not identify an individual, the Company uses that data instead.

6.10To communicate with the individual about the Account, the Services and changes to the Agreement. Basis: performance of a contract and compliance with a legal obligation.

6.11To send marketing communications, where permitted. Basis: consent, or legitimate interests where the applicable law allows and the individual has not objected.

6.12Where the Company relies on legitimate interests, it has considered the effect on the individual and processes only to the extent that its interest is not overridden by the individual's interests, rights and freedoms. Further information about that assessment is available on request.

6.13Where the Company relies on consent, consent may be withdrawn at any time. Withdrawal does not affect processing carried out before withdrawal, and does not affect processing for which the Company has another lawful basis, including its regulatory obligations.

6.14Where personal data is required in order to enter into or perform the Agreement, or to meet a legal obligation, and the individual does not provide it, the Company may be unable to open or maintain the Account or to provide the Services.

Contents7RECORDING OF COMMUNICATIONS

7.1The Company may record telephone, video, chat, email and platform communications, and does so as a matter of course on channels used for instructions and support.

7.2Recordings are used to verify instructions, monitor quality and conduct, resolve disputes, prevent fraud and meet legal and regulatory obligations.

7.3Recordings remain the Company's records, subject to any access right the individual has under applicable data-protection law.

7.4An individual who does not wish to be recorded should not use a recorded channel. Certain instructions may only be accepted through a recorded channel.

7.5Recordings are retained for the period required by Applicable Law and by the Company's retention arrangements, and are accessible only to those who need them for a purpose described in this Policy.

Contents8AUTOMATED CHECKS AND MONITORING

8.1The Company uses automated tools for sanctions and adverse-media screening, fraud and payment-risk detection, transaction and trade monitoring, and platform security.

8.2An alert generated by an automated tool is reviewed by a person before a decision is taken that produces a legal effect for the individual or similarly significantly affects them, except where the applicable law permits otherwise and appropriate safeguards are in place.

8.3Where a decision is taken by automated means and the applicable law confers a right to obtain human intervention, to express a point of view or to contest the decision, the Company will give effect to that right.

8.4The Company does not use personal data to make automated trading decisions on the Client's behalf, and does not provide personal recommendations.

Contents9MARKETING

9.1Marketing communications are sent only where permitted by the applicable law and by the individual's preferences.

9.2An individual may object to marketing at any time, through the preference settings in the Client Portal, by using the unsubscribe facility in a communication, or by contacting the Company. The objection is given effect without charge.

9.3An objection to marketing does not stop communications the Company is required or entitled to send about the Account, the Services or the Agreement.

9.4The Company does not sell personal data. It does not share personal data with an unaffiliated third party for that party's own marketing purposes without consent.

9.5Where an introducing broker or affiliate introduced the Client, that party may hold its own records and may market to the individual under its own arrangements, for which it is responsible as controller.

Contents10COOKIES AND SIMILAR TECHNOLOGIES

10.1The Website and Client Portal use cookies and similar technologies that are strictly necessary for the service to function, together with technologies used for security, preference storage, performance measurement and, where permitted, analytics and marketing.

10.2Non-essential technologies are used only where the applicable law permits, and where consent is required it is obtained and may be withdrawn.

10.3Browser controls may be used to restrict cookies. Restricting strictly necessary cookies may prevent the Client Portal or Trading Platform from operating correctly.

10.4Further detail about the categories in use is published in the cookie information on the Website.

Contents11DISCLOSURE AND RECIPIENTS

11.1Personal data may be shared with regulators, authorities, courts and law-enforcement bodies where lawful and necessary, including in response to an order, a request or a reporting obligation.

11.2Personal data may be shared with affiliates and group companies for onboarding, compliance, risk management, technology and administrative support.

11.3Personal data may be shared with banks, custodians, payment providers, card schemes, liquidity providers, principal brokers, execution venues and counterparties, to the extent necessary to process payments, safeguard funds and execute or settle Transactions.

11.4Personal data may be shared with identity-verification, screening, credit and fraud-prevention providers; technology, hosting, communications and data-storage providers; and record-keeping and archiving providers.

11.5Personal data may be shared with professional advisers, auditors, insurers and, where relevant, a proposed assignee or successor, in each case where reasonably necessary and lawful and subject to appropriate confidentiality or legal safeguards.

11.6Personal data may be shared with an introducing broker or affiliate in relation to the Client it introduced, limited to what is necessary to administer that relationship and to calculate remuneration.

11.7The Company does not disclose personal data beyond what this Policy describes, except where required or permitted by Applicable Law or where the individual has consented.

11.8In some circumstances the Company is prohibited by law from telling an individual that a disclosure has been made, in particular where disclosure relates to a financial-crime report.

Contents12PROCESSORS AND SERVICE PROVIDERS

12.1Where a third party processes personal data on the Company's behalf, it acts as a processor under a written contract that requires it to act only on the Company's instructions, to apply appropriate security measures, to keep the data confidential, and to assist the Company in meeting its obligations.

12.2Processors are assessed before appointment and are reviewed thereafter, including in relation to their security arrangements and their own use of sub-processors.

12.3Outsourcing does not transfer the Company's responsibility as controller.

Contents13INTERNATIONAL TRANSFERS

13.1The Company operates internationally and uses providers located in more than one country. Personal data may therefore be transferred to, stored in, or accessed from a country other than the individual's own.

13.2A transfer is made only where necessary for the Services, for compliance or for administration, and only using the safeguards required by the applicable data-protection law. Those safeguards may include a determination of adequacy by the relevant authority, approved contractual clauses, an authorisation from the supervisory authority, or another mechanism the applicable law permits.

13.3Where a transfer is made in reliance on a contractual safeguard, a copy of the relevant terms may be requested through the privacy contact channel, subject to the redaction of commercially confidential information.

13.4The legal protection available in a receiving country may be less extensive than in the individual's own country. The Company applies its own security and confidentiality standards to the data regardless of where it is held.

Contents14RETENTION

14.1Personal data is retained for as long as necessary for the purposes described in this Policy, and thereafter for the period required by Applicable Law, by the Company's regulatory record-keeping obligations and by its retention arrangements.

14.2Retention periods differ by category. Applications, communications, recordings, Orders, Transactions and due-diligence records are retained for the period required by Applicable Law applicable to the contracting entity.

14.3Data may be retained beyond an ordinary period where it is relevant to an unresolved complaint, dispute, investigation, legal claim, regulatory enquiry or legal hold, until that matter is concluded.

14.4Where a period expires, personal data is deleted or anonymised. Anonymised data that no longer identifies an individual may be retained and used for statistical purposes.

14.5Where an individual ends the relationship, personal data is retained for the applicable period rather than deleted on request, to the extent retention is required by law.

Contents15SECURITY

15.1The Company applies technical and organisational measures appropriate to the risk, including access controls based on role, encryption in transit and at rest where appropriate, network and endpoint protection, logging and monitoring, segregation of environments, and staff confidentiality obligations and training.

15.2Access to personal data is restricted to those who need it for a purpose described in this Policy.

15.3No system is entirely secure. The Company cannot guarantee that transmission over the internet, or use of a device or network outside its control, is free from risk.

15.4The individual is responsible for keeping credentials and authentication factors secure, for using supported software and secure networks, and for notifying the Company immediately of any suspected compromise.

15.5The Company will never request a password or a full authentication code through an unofficial channel. Unusual requests should be verified using the published contact details before being acted on.

Contents16PERSONAL DATA BREACHES

16.1The Company maintains procedures for identifying, containing, investigating and recording personal data breaches.

16.2Where a breach meets the threshold set by the applicable data-protection law, the Company notifies the relevant supervisory authority within the period that law requires.

16.3Where a breach is likely to result in a high risk to the rights and freedoms of an individual, and the applicable law requires it, the Company notifies the affected individual without undue delay and describes the likely consequences and the measures taken.

16.4A record of each breach is retained, including the facts, the effects and the remedial action taken.

Contents17RIGHTS OF INDIVIDUALS

17.1The rights available to an individual depend on the applicable data-protection law and therefore on the contracting entity, as summarised in the entity variation table above.

17.2Subject to that law, an individual may have the right to be informed about processing; to obtain access to their personal data and information about how it is processed; to have inaccurate data corrected; to have data erased in certain circumstances; to restrict processing in certain circumstances; to object to processing carried out on the basis of legitimate interests, and to object to direct marketing at any time; to receive certain data in a portable form; to withdraw consent where processing is based on consent; and not to be subject to certain decisions taken solely by automated means.

17.3A right may be limited or unavailable where the applicable law provides an exemption, including where the Company must retain data to meet a regulatory or record-keeping obligation, where a request would prejudice the prevention or detection of financial crime, where it would infringe the rights of another person, or where it would disclose information subject to legal privilege or a confidentiality duty owed to a third party.

17.4An individual who withdraws consent, or objects to processing necessary for the Company to meet a legal obligation, may find that the Company can no longer provide the Services or maintain the Account.

Contents18HOW TO EXERCISE A RIGHT

18.1A request may be made through the privacy contact channel published on the Website, through the Client Portal, or to the Company's client support address.

18.2The Company may ask for information reasonably needed to verify the identity of the person making the request, and will not disclose personal data until it is satisfied as to identity.

18.3The Company responds within the period required by the applicable data-protection law. Where a request is complex or numerous, that period may be extended to the extent the law permits, and the individual will be told of the extension and the reason.

18.4Requests are handled without charge, except where the applicable law permits a fee for a manifestly unfounded or excessive request, or for further copies.

18.5Where the Company declines a request in whole or in part, it will explain why, so far as it is lawful to do so, and will tell the individual how to complain.

Contents19COMPLAINTS AND SUPERVISORY AUTHORITIES

19.1An individual who is dissatisfied with how the Company has handled their personal data may complain to the Company under the Complaints Handling Policy.

19.2An individual also has the right to complain to the data-protection supervisory authority applicable to the contracting entity, as identified in the entity variation table above, and to pursue a remedy through a competent court.

19.3The Company does not require an individual to complain to it first before approaching a supervisory authority.

Contents20PERSONAL DATA OF OTHER INDIVIDUALS AND OF MINORS

20.1The Services are not offered to, and are not intended for, individuals below the age at which they may lawfully enter into the Agreement in their country of residence. The Company does not knowingly collect personal data from such individuals.

20.2Where the Company becomes aware that it holds personal data of an individual who is not eligible to hold an Account, it will delete that data unless it is required to retain it by Applicable Law, and will close or refuse the Account.

20.3Where a Client provides personal data about a director, signatory, beneficial owner or other individual, the Client must ensure it is entitled to do so and must make this Policy available to that individual.

Contents21CHANGES, LANGUAGE AND VERSIONS

21.1This Policy may be amended in accordance with the amendment provisions of the Client Agreement, and will be updated where processing, legal obligations or arrangements change.

21.2Material amendments will be notified in advance through an Approved Medium, except where immediate effect is required by law, a regulator, security or market conditions. Continued use of the Services after the effective date does not by itself constitute consent where consent is legally required.

21.3The current version is made available through an Approved Medium. The Company maintains version control and records the effective date of each version.

21.4The governing language of this Policy is English. A translation is provided for convenience only and, in the event of conflict, the English version prevails to the extent permitted by Applicable Law.

End of Policy
Royce Capitals Ltd.Licensed by the Labuan Financial Services Authority
Money-Broking Business Licence No. MB/23/0113
Company No. LL18275
Royce Global Markets Ltd.Licensed and regulated by the Financial Services Commission, Mauritius
Investment Dealer (Full Service Dealer, excluding Underwriting)
Licence No. GB25205368 · Code SEC-2.1B
Client Support roycecapitals.com
support@roycecapitals.com
+60 87 584 859

This Policy is incorporated into the Client Agreement of the contracting entity identified in that Agreement. It does not vary the Client Agreement and does not remove a protection conferred by Applicable Law.
Version 1.0 — 29 July 2026 · Client issue version · Governing language: English.