How Gold Capital International governs, secures and retains personal and compliance data. Our Privacy Policy explains your rights; this policy explains our internal standards.
Last updated: 6 August 2026Version 1.0Issued by Gold Capital International — ABN 26 700 429 189
1.Purpose and scope
This policy applies to all personal data and compliance records processed by GCI, its personnel and its contractors, in any format, whether held in our systems or exchanged with counterparties.
It supports our obligations under the Australian Privacy Act 1988 and the Australian Privacy Principles, and, where applicable to our processing, the EU and UK GDPR and comparable data protection laws in the jurisdictions where we operate.
2.Data protection principles we apply
Lawfulness, fairness and transparency: we tell people what we collect and why, at the point of collection.
Purpose limitation: compliance data collected for KYC and AML is not repurposed for marketing.
Data minimisation: we request only the documents and fields required for the stage of engagement reached.
Accuracy: we correct records on request and refresh compliance data periodically for active relationships.
Storage limitation: records are deleted at the end of the retention periods set out below.
Integrity and confidentiality: access is restricted, encrypted and logged.
Accountability: the Director is responsible for data protection and reviews this policy annually.
3.Roles and responsibilities
The Director of GCI holds overall accountability for data protection and acts as the contact point for privacy requests and incidents at goldcapitalinternational@gmail.com.
All personnel and contractors handling client data must follow this policy, complete confidentiality undertakings, and report suspected incidents immediately. We have not appointed a statutory Data Protection Officer; whether one is required in a given jurisdiction is a matter for our external legal advisers to confirm as the business grows.
4.Technical and organisational security measures
Transport security: HTTPS enforced site-wide with HTTP Strict Transport Security, a restrictive Content Security Policy, and frame, referrer and permission restrictions.
Encryption at rest: database and document storage encrypted by our infrastructure provider.
Access control: client portal authentication, role-based access separating client and staff permissions, and database row-level security so each client can reach only their own records.
Document storage: private, non-public storage with owner and staff scoped access rules, upload type and size validation, and filename sanitisation.
Least privilege: administrative credentials are server-side only and never exposed to browser code.
Change control: database changes are applied through reviewed migrations and scanned automatically for access-control regressions before release.
5.Processors and service providers
We use third-party providers for hosting, database, authentication, document storage and email delivery. Providers are selected on the basis of their security posture and contractual commitments, and are permitted to process data only on our instructions.
Where the GDPR applies, processing is governed by data processing terms containing the required Article 28 obligations, and international transfers rely on adequacy or Standard Contractual Clauses.
6.Retention schedule
Unsuccessful or dormant enquiries: up to 24 months.
KYC, AML, sanctions screening and due diligence records: at least 7 years from the end of the relationship or completion of the transaction.
Executed agreements and transaction documentation: 7 years from completion, or longer where a dispute or statutory requirement applies.
Client portal accounts and uploaded documents: removed within 12 months of an engagement ending, subject to the retention rules above.
Server and security logs: retained for a limited operational period for security and diagnostics.
7.Data breach response
Suspected incidents must be reported internally without delay. We will contain the incident, assess the risk of harm, preserve evidence, and remediate the cause.
Where an eligible data breach is likely to result in serious harm, we will notify the Office of the Australian Information Commissioner and affected individuals as soon as practicable, consistent with the Notifiable Data Breaches scheme. Where the GDPR applies, we will notify the competent supervisory authority within 72 hours of becoming aware, and affected individuals where the risk to their rights is high.
Incidents, findings and remedial actions are recorded in an internal incident register.
8.Privacy by design
New features that involve personal data are assessed before release for the minimum data required, the access model, retention, and any transfer implications. High-risk processing warrants a documented impact assessment prepared with legal advice.
9.Handling data subject requests
Requests are acknowledged within 5 business days and answered within 30 days. Identity is verified before any disclosure. Where a request conflicts with a statutory record-keeping obligation, we explain the basis for retaining the record and address the remainder of the request.
10.Review
This policy is reviewed at least annually, and additionally after any material change to our systems, service providers or applicable law. Legal review by qualified counsel in each operating jurisdiction is recommended at each review point.
Important legal notice
This document is published for general information about how Gold Capital International conducts business. It is not legal, financial, tax or investment advice, and it does not create a contractual relationship on its own. Laws differ between jurisdictions and change over time.
Before relying on this document, or before signing any agreement with us, you should obtain independent advice from a qualified lawyer admitted in your own jurisdiction and in each jurisdiction relevant to your transaction.
Gold Capital International is a private commercial business. Nothing on this website or in this document implies government affiliation, endorsement, licensing, registration or regulatory approval by any authority, and no guarantee of any commercial outcome is given.