Privacy Policy
Alto Markets Data Privacy Policy
Last updated: 27 August 2026
Alto Markets Ltd (“Alto Markets”, “Alto”, “we”, “our” or “us”) is committed to protecting personal data and handling it lawfully, fairly, transparently and securely.
This Privacy Policy explains how we collect, use, process, store, disclose and protect personal information in accordance with the UK General Data Protection Regulation (“UK GDPR”), the Data Protection Act 2018, other applicable data protection legislation, and the standards required by our regulated service partners, including The Currency Cloud Limited (“Currencycloud”) and Ebury Partners.
It also explains how personal data may be processed when users access Alto’s websites, digital applications, calculation tools, APIs, Model Context Protocol (“MCP”) tools and integrations with third-party artificial-intelligence platforms.
1. About Alto Markets
Alto Markets Ltd is a company registered in England and Wales under company number 16760974.
Registered office:
3rd Floor, 86–90 Paul Street, London, EC2A 4NE, United Kingdom
For the purposes of UK data protection law, Alto Markets Ltd will generally act as the data controller in respect of the personal data described in this Policy.
Privacy and data protection enquiries may be directed to:
2. Purpose of This Policy
This Policy explains how Alto collects, processes, uses, retains, discloses and protects personal data relating to:
- clients and prospective clients;
- users of Alto websites and Digital Services;
- registered Alto account holders;
- business contacts;
- suppliers and service providers;
- employees and contractors;
- representatives of corporate clients;
- website visitors;
- users accessing Alto through third-party platforms;
- and other individuals whose personal data Alto lawfully processes.
It applies both to information obtained directly by Alto and information received through authorised third parties or integrations.
3. Scope
This Policy applies to all employees, contractors and partners of Alto Markets who process personal data.
It applies to all systems, services and tools used to collect, store or process personal data, including:
- cloud platforms;
- email systems;
- CRM systems;
- onboarding tools;
- internal databases;
- Alto’s websites;
- the Alto Markets dashboard;
- alto-fx.com;
- Alto calculation and analysis tools;
- uploaded files and spreadsheets;
- authentication systems;
- APIs;
- MCP servers and tools;
- OAuth connections;
- AI-platform integrations;
- support and communications systems;
- and other technology used by Alto from time to time.
References in this Policy to “Digital Services” include Alto’s websites, applications, dashboards, calculation tools, APIs, MCP tools, connectors and integrations with third-party technology platforms.
4. Data Protection Principles
Alto Markets adheres to the following data protection principles.
Lawfulness, fairness and transparency
We process personal data lawfully, fairly and transparently and explain how and why it is used.
Purpose limitation
We collect personal data only for specified, explicit and legitimate purposes and do not use it for incompatible purposes unless permitted by law.
Data minimisation
We seek to collect and process only the personal data that is reasonably necessary for the relevant purpose.
Accuracy
We take reasonable steps to ensure personal data is accurate and, where necessary, kept up to date.
Storage limitation
We retain personal data only for as long as required for the relevant purpose or by applicable legal, regulatory or contractual requirements.
Where financial crime, anti-money-laundering or other financial regulatory requirements apply, relevant data will normally be retained for a minimum of five years.
Integrity and confidentiality
We use appropriate technical and organisational safeguards to protect personal data against unauthorised or unlawful access, alteration, disclosure, loss or destruction.
Accountability
We maintain appropriate policies, procedures and records to demonstrate compliance with applicable data protection requirements.
5. Roles and Responsibilities
Data Protection Officer
The CEO acts as Alto Markets’ Data Protection Officer (“DPO”) and has responsibility for overseeing implementation of this Policy, monitoring compliance and responding to data protection and privacy enquiries.
The DPO may be contacted at:
Employees and contractors
All employees and contractors who handle personal data must comply with this Policy and Alto’s applicable information-security and data-handling procedures.
Any suspected or actual loss, misuse, unauthorised disclosure or other personal data breach must be reported immediately.
Third-party processors
Where a third party processes personal data on Alto’s behalf as a data processor, Alto requires appropriate contractual arrangements, including data-processing provisions or agreements where required, and expects the processor to comply with applicable UK GDPR requirements.
Certain organisations with which Alto shares information, including regulated financial-service providers, may instead act as independent data controllers and process information under their own privacy policies and legal obligations.
6. Personal Data We May Collect
The personal data Alto collects depends upon how an individual interacts with us.
Identity and contact information
This may include:
- name;
- business email address;
- telephone number;
- business address;
- employer or organisation;
- job title or professional role;
- professional contact information.
Alto account information
Where an individual registers for an Alto account, we may process:
- name;
- email address;
- company name;
- account identifier;
- authentication and security information;
- account status;
- login and connection records.
Business and professional information
This may include information relating to:
- an individual’s employer;
- role or responsibilities;
- business requirements;
- communications with Alto;
- professional interests relevant to Alto’s services.
Website and technical information
When an individual accesses a website or Digital Service, Alto or its service providers may process:
- IP address;
- browser information;
- device information;
- login activity;
- timestamps;
- security events;
- session information;
- pages or features accessed;
- technical error information;
- usage and diagnostic information.
Financial and FX calculation information
Where an Alto calculation or analysis tool is used, information submitted may include:
- currencies;
- transaction amounts;
- executed rates;
- contract rates;
- transaction dates;
- transaction times;
- time zones;
- value dates;
- forward-contract information;
- FX exposures;
- projected requirements;
- payment or transaction information;
- other data necessary to perform the requested calculation.
Much of this information relates to organisations rather than identifiable individuals and therefore may not constitute personal data. We nevertheless treat commercially sensitive information appropriately.
Uploaded files and spreadsheets
Where Digital Services permit documents, spreadsheets or other files to be submitted, Alto may process the information contained within them for the purpose of providing the requested service.
Users should avoid including personal data that is not necessary for the relevant analysis.
Client onboarding and compliance information
Where an organisation proceeds separately to client onboarding for FX, payment or related services, Alto and/or its regulated service providers may process additional information including:
- identity information;
- proof of identity;
- directors and beneficial owners;
- corporate records;
- ownership structures;
- KYC information;
- source-of-funds or source-of-wealth information where required;
- sanctions and screening information;
- transaction information;
- other information required by applicable law or regulated service providers.
7. How We Collect Personal Data
We may obtain personal information:
- directly from an individual;
- when an Alto account is registered;
- when an Alto Digital Service is used;
- through correspondence or enquiries;
- through documents or spreadsheets submitted to Alto;
- through authenticated APIs, MCP tools or OAuth connections;
- from an individual’s employer or organisation;
- from regulated service providers;
- from professional advisers;
- from publicly available business or professional information;
- from professional networking platforms;
- from legitimate business-information providers;
- from other third parties where lawful.
Where personal information is obtained indirectly, Alto will process it in accordance with applicable data protection law.
8. How We Use Personal Data
Alto may process personal information for legitimate business purposes including:
- verifying identity;
- conducting Know Your Customer (“KYC”) and other compliance checks;
- setting up accounts;
- onboarding clients;
- supporting FX transactions and payments provided under separate arrangements with regulated service providers;
- complying with legal, regulatory and audit obligations;
- delivering customer service;
- communicating with clients and prospective clients;
- preventing financial crime, fraud and money laundering;
- operating Alto websites and Digital Services;
- creating and administering Alto user accounts;
- authenticating users;
- providing FX calculation and market-data services;
- processing API and MCP requests;
- enabling OAuth and other authorised connections;
- operating AI-platform integrations;
- responding to support requests;
- maintaining service reliability;
- diagnosing technical issues;
- monitoring system security;
- preventing unauthorised use;
- managing business relationships;
- maintaining appropriate records;
- developing and improving Alto’s technology and services;
- establishing, exercising or defending legal rights.
We will not process personal data for an incompatible purpose unless permitted by applicable law.
9. Lawful Bases for Processing
Alto relies upon one or more lawful bases under UK GDPR depending upon the purpose and circumstances of the processing.
Performance of a contract
We may process information where necessary to provide a service requested by an individual, administer an Alto account, fulfil contractual obligations or take steps at an individual’s request before entering into a contract.
Legal obligation
We may process information where necessary to comply with applicable legal or regulatory requirements.
This may include requirements relating to:
- financial crime;
- anti-money laundering;
- sanctions;
- taxation;
- accounting;
- record keeping;
- regulatory requirements;
- lawful requests from public authorities.
Legitimate interests
We may process personal information where necessary for Alto’s legitimate business interests, provided those interests are not overridden by an individual’s fundamental rights and freedoms.
Such interests may include:
- operating Alto’s business;
- operating and improving Digital Services;
- protecting systems and accounts;
- preventing fraud and misuse;
- maintaining appropriate audit and security logs;
- developing products and services;
- managing commercial relationships;
- providing customer support;
- communicating with relevant business contacts;
- conducting proportionate business-to-business marketing;
- establishing or defending legal claims.
Consent
Where applicable law requires consent, we will seek it.
Where processing is based upon consent, consent may be withdrawn at any time. Withdrawal does not affect the lawfulness of processing undertaken before withdrawal.
10. Business-to-Business Marketing
Alto may use professional contact information for proportionate business-development and business-to-business marketing purposes where permitted by law.
We may contact individuals in their professional capacity where Alto reasonably considers that its services may be relevant to their organisation or professional responsibilities.
Professional contact information may be obtained directly, from an individual’s organisation, from publicly available business information, professional networking platforms or legitimate business-information providers.
Alto does not sell personal data or disclose personal data to third parties for those third parties’ own marketing purposes.
Where required, Alto complies with applicable requirements of the Privacy and Electronic Communications Regulations and other relevant direct-marketing legislation.
Individuals may object to direct marketing at any time.
Where an individual opts out, Alto may retain limited suppression information so that the preference can continue to be respected.
11. Regulated Service Providers
Where clients use FX, payment or related services through Alto, information may be shared securely with regulated service partners including Currencycloud and Ebury, payment providers, banking partners, compliance providers or other parties involved in providing the relevant service.
These providers may require information for purposes including:
- client onboarding;
- KYC and AML checks;
- sanctions screening;
- regulatory compliance;
- payment processing;
- FX transaction execution;
- fraud prevention;
- record keeping.
A regulated service provider may act as a separate data controller and may have its own privacy notice and legal obligations.
The provision of regulated FX and payment services is governed separately from Alto’s Digital Services.
12. Alto Digital Services
Alto operates Digital Services including websites, dashboards, FX calculation tools, historical and live market-rate functionality, trade analysis, forward mark-to-market calculations, APIs, MCP tools and related functionality.
When these services are used, Alto may process information necessary to:
- authenticate the user;
- receive the calculation request;
- obtain relevant market data;
- perform the calculation;
- return the requested output;
- maintain security;
- diagnose errors;
- monitor service performance;
- prevent fraud or misuse;
- provide user support;
- maintain appropriate operational records.
Not every data item used in a calculation constitutes personal data. Business transaction information may nevertheless be confidential or commercially sensitive and is treated accordingly.
13. MCP, API and OAuth Connections
Alto may permit authorised third-party applications to access Digital Services through APIs, MCP or similar technologies.
Where an individual authorises such a connection, Alto may process information including:
- the Alto account associated with the connection;
- authentication or authorisation information;
- OAuth tokens or related identifiers;
- permissions granted;
- the Alto tool requested;
- calculation inputs;
- timestamps;
- calculation type;
- success or failure status;
- technical and security metadata.
Alto seeks to limit the information processed through these connections to that reasonably required to authenticate the request, provide the requested functionality and operate the service securely.
OAuth is designed to allow a third-party application to obtain authorised access without the user providing their Alto password directly to that third-party application.
Authorisation may be revoked in accordance with the functionality made available by Alto or the relevant third-party platform.
14. ChatGPT, Claude and Other Artificial-Intelligence Platforms
Alto may make certain Digital Services available through third-party artificial-intelligence platforms, including platforms operated by OpenAI, Anthropic and other technology providers.
These platforms are independent from Alto.
When an individual chooses to use an Alto connector or tool from within a third-party AI platform, that platform may send information to Alto in order to perform the requested calculation.
Alto may receive:
- calculation inputs selected or structured by the AI platform;
- relevant account or authorisation information;
- tool-request metadata;
- other information required to process the authorised request.
Alto does not require access to the user’s entire AI conversation merely because an Alto tool is used. The information Alto receives will depend upon what the third-party platform submits through the relevant tool request.
The AI provider may separately process or retain information including:
- prompts;
- conversations;
- files uploaded to the AI platform;
- responses;
- account information;
- other data supplied directly to that provider.
Such processing is controlled by the third-party provider and is governed by its own terms and privacy policies.
Alto does not control how a third-party AI platform processes information independently of Alto.
Users should review the relevant platform’s privacy arrangements before submitting confidential, commercially sensitive or personal information.
15. AI Interpretation of Alto Outputs
Where an AI platform uses an Alto calculation tool, Alto may return a calculation or market-data result to the platform.
The AI platform may then independently:
- interpret that result;
- aggregate calculations;
- perform additional arithmetic;
- combine it with other information;
- analyse a spreadsheet or document;
- summarise information;
- draw conclusions;
- generate commentary.
These subsequent activities may be performed by the third-party AI provider rather than Alto.
From a data-protection perspective, information processed independently by the AI platform remains subject to the third party’s own privacy arrangements.
16. Uploaded Files and Spreadsheet Processing
Where a user submits a file or spreadsheet to Alto or where information extracted from a file is submitted to an Alto tool through an authorised third-party platform, Alto may process the data necessary to provide the requested calculation or analysis.
Users are responsible for ensuring they have authority to submit such information.
Where possible, users should avoid submitting:
- unnecessary personal information;
- special-category personal data;
- confidential information unrelated to the calculation;
- information relating to third parties where they do not have authority to disclose it.
Where a third-party AI platform reads or structures a file before making a request to Alto, that platform’s handling of the original file is governed separately by the third party.
17. Digital Service Logging and Monitoring
Alto may maintain technical and operational logs relating to use of its Digital Services.
These may include information such as:
- user or account identifier;
- tool or feature used;
- request time;
- calculation type;
- request status;
- security information;
- diagnostic information.
Logs may be used for:
- system security;
- fraud prevention;
- technical troubleshooting;
- service reliability;
- auditability;
- customer support;
- investigating misuse.
Alto seeks to minimise the financial or commercially sensitive information retained in operational logs where it is not required for these purposes.
18. Sharing Personal Data
Alto may share personal information where reasonably necessary with trusted organisations including:
- Currencycloud;
- Ebury;
- other regulated payment or financial-service providers;
- banks and payment providers;
- identity-verification and compliance providers;
- cloud-hosting providers;
- information-technology providers;
- authentication providers;
- CRM providers;
- email and communication providers;
- market-data providers;
- security providers;
- accountants;
- auditors;
- legal advisers;
- insurers;
- other professional advisers;
- public authorities;
- courts;
- regulators;
- law-enforcement bodies where required or permitted by law.
Where a third party processes information solely on Alto’s behalf, appropriate data-processing terms will be used as required by UK GDPR.
Where a recipient determines its own purposes and means of processing, it may act as a separate data controller.
Alto does not sell personal data or provide personal data to third parties for those third parties’ own marketing purposes.
19. Data Retention and Storage
Alto stores personal and transactional information securely and retains it only for as long as required for legitimate business, contractual, regulatory or legal purposes.
Regulatory and client information
Where financial crime, anti-money-laundering or financial-services record-keeping requirements apply, relevant personal and transactional data will be retained for a minimum of five years following the end of the customer relationship, in accordance with applicable AML and financial regulations and relevant service-provider requirements.
Information may be retained for longer where required by law, regulation, litigation, regulatory investigation or another legitimate legal requirement.
Digital Services information
Information relating only to Digital Services, website usage, tool requests or technical logs may be subject to different retention periods depending upon:
- the purpose for which it was collected;
- whether an account remains active;
- security requirements;
- troubleshooting requirements;
- contractual requirements;
- legal limitation periods;
- whether a dispute exists;
- whether information can instead be anonymised.
Alto seeks not to retain personal data for longer than is reasonably necessary.
Where data is no longer required, it will be securely deleted, destroyed or anonymised as appropriate.
Data is stored using appropriately secured systems and access is restricted to authorised personnel on a need-to-know basis.
20. International Data Transfers
Some technology, data or service providers used by Alto may process information outside the United Kingdom.
Third-party AI platforms may also process information internationally.
Where Alto is responsible for transferring personal data to a country outside the United Kingdom, we will use an appropriate transfer mechanism as required by UK data protection law.
This may include:
- a UK adequacy regulation;
- the International Data Transfer Agreement;
- the UK Addendum to approved Standard Contractual Clauses;
- or another transfer mechanism permitted by applicable law.
Where appropriate, Alto will assess whether additional contractual, technical or organisational safeguards are required.
21. Security Measures
Alto Markets maintains appropriate information-security controls designed to protect personal and confidential information.
These include, where appropriate:
- encrypted systems;
- password-protected systems;
- multi-factor authentication;
- access controls;
- access logging and monitoring;
- regular backups;
- security reviews;
- appropriate restrictions on staff access;
- secure deletion or destruction of information when no longer required.
Access to personal information is restricted to authorised individuals who require access for legitimate business purposes.
Although Alto takes appropriate security precautions, no internet-connected technology can be guaranteed to be completely secure.
22. Cookies and Similar Technologies
Alto websites may use cookies and similar technologies for purposes including:
- essential website operation;
- authentication;
- security;
- remembering preferences;
- analytics;
- understanding website use;
- marketing where applicable and lawfully permitted.
Where consent is required for a cookie or similar technology, Alto will seek the required consent.
Further information is available in Alto Markets’ Cookie Policy.
23. Your Data Protection Rights
Subject to applicable law and any relevant exemptions, individuals may have rights including:
- the right to access personal data;
- the right to request correction of inaccurate or incomplete data;
- the right to request deletion where legally permissible;
- the right to restrict processing;
- the right to object to processing;
- the right to object to direct marketing;
- the right to data portability where applicable;
- the right to withdraw consent where processing is based upon consent;
- rights relating to certain forms of automated decision-making.
Not every right applies in every circumstance.
We may need to verify an individual’s identity before responding to a request.
Requests should be submitted to:
Alto aims to acknowledge requests within one business day and complete them within 30 calendar days, unless legally restricted or an extension is permitted under applicable data protection law due to the complexity or number of requests.
24. Direct Marketing Rights
Individuals have the right to object to the processing of their personal data for direct-marketing purposes.
An individual may exercise this right at any time by using an unsubscribe facility where available or by contacting:
Where an individual opts out of marketing, Alto may retain limited suppression information in order to ensure that the preference continues to be respected.
25. Automated Processing and Decision-Making
Alto’s Digital Services may use automated technology to perform mathematical calculations, obtain market data, structure information or return analytical results.
These Digital Services are not intended to make solely automated decisions concerning individuals that produce legal or similarly significant effects.
Regulated service providers may separately conduct automated:
- identity verification;
- sanctions screening;
- fraud monitoring;
- compliance assessment;
- other regulatory checks.
Where such processing is performed by a regulated provider acting independently, that provider’s privacy information will apply.
26. Special Category Personal Data
Alto’s ordinary Digital Services are not designed to require special-category personal data.
Users should not submit unnecessary information concerning matters such as:
- racial or ethnic origin;
- political opinions;
- religious or philosophical beliefs;
- trade-union membership;
- genetic data;
- biometric data;
- health information;
- sex life or sexual orientation.
Where such information must lawfully be processed for a particular purpose, Alto will ensure an appropriate legal basis and additional condition for processing exists.
27. Data Breach Procedure
All suspected or actual personal data breaches must be reported immediately to the CEO/DPO.
Alto will assess each incident promptly and take appropriate steps to:
- contain the breach;
- investigate what occurred;
- assess affected information and individuals;
- mitigate potential harm;
- preserve relevant evidence;
- take remedial action.
Where a personal data breach is required to be reported to the Information Commissioner’s Office (“ICO”), Alto will make the notification without undue delay and, where feasible, within 72 hours of becoming aware of the breach, in accordance with UK GDPR.
Where applicable law requires affected individuals to be informed, Alto will do so without undue delay.
A data breach log is maintained for all suspected and confirmed incidents, including relevant decisions and remedial action.
28. Staff Training
All employees receive annual data protection and anti-money-laundering training.
Additional training or guidance will be provided where appropriate following:
- regulatory changes;
- changes to internal procedures;
- introduction of new systems;
- introduction of new Digital Services;
- changes to third-party service-provider requirements;
- material changes to information-security risks.
Employees and contractors are expected to understand and comply with their responsibilities when handling personal information.
29. Auditing and Review
Alto Markets conducts internal data privacy audits at least annually.
The purpose of these reviews includes assessing:
- compliance with this Policy;
- information-security controls;
- data retention;
- third-party arrangements;
- staff compliance;
- Digital Services;
- new processing activities;
- regulatory developments.
This Policy is reviewed at least annually, or earlier where required because of:
- changes to applicable law;
- regulatory developments;
- changes to Alto’s services;
- introduction of new technology;
- security developments;
- or guidance or requirements from regulated service partners, including Currencycloud or Ebury.
30. Complaints
If you have concerns about the way Alto processes personal data, please contact us in the first instance at:
Individuals also have the right to complain to the UK’s data protection supervisory authority:
Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
United Kingdom
Telephone: 0303 123 1113
31. Children
Alto’s services are intended for businesses, organisations and professional users.
They are not directed at children and Alto does not knowingly seek to collect personal data from children through its Digital Services.
32. Third-Party Websites and Platforms
Alto websites and Digital Services may contain links to, or integrate with, websites and services operated by third parties.
Alto is not responsible for the privacy practices of independent third parties.
Users should review the relevant third party’s privacy policy before providing it with personal information.
This applies particularly where users access Alto through an AI platform or another external application.
33. Access to This Policy
This Privacy Policy is available to all Alto staff and is provided to new employees as part of onboarding.
A public version is maintained on the Alto Markets website.
A full copy may also be provided to clients upon request.
Relevant employees, contractors and partners are expected to familiarise themselves with this Policy and comply with its requirements.
34. Changes to This Policy
Alto may update this Privacy Policy to reflect:
- changes to applicable law or regulation;
- changes to Alto’s business;
- changes to regulated service-provider requirements;
- new Digital Services;
- new AI or technology integrations;
- changes to how personal information is processed;
- changes to information-security requirements.
The current version will be published on the Alto Markets website together with the date of the latest update.
Where a material change significantly affects registered users, Alto may provide additional notification where appropriate.
35. Contact
For privacy enquiries, data protection requests or questions regarding this Policy, please contact:
Data Protection Officer
Alto Markets Ltd
3rd Floor
86–90 Paul Street
London
EC2A 4NE
United Kingdom
Email: support@altomarkets.co.uk
