Skip to main content
GCIGold Capital International

Legal

Privacy Policy

This policy explains how Gold Capital International handles personal and corporate information collected through this website, the client portal and during commercial engagement.

Last updated: 6 August 2026Version 1.0Issued by Gold Capital International — ABN 26 700 429 189

1.Who we are and scope of this policy

Gold Capital International (ABN 26 700 429 189) of Parkinson, Queensland 4115, Australia is the controller of the personal information described in this policy. Contact: notifygoldcapitalexchange@gmail.com.

This policy applies to goldcapital.exchange, the GCI client portal, our enquiry and quote request forms, and information exchanged by email, telephone or messaging during an engagement.

We conduct business internationally. Where the EU or UK General Data Protection Regulation applies to our processing of your information, the additional rights described in this policy apply to you.

2.Information we collect

  • Contact and business details: name, role, company name, business email, telephone, WhatsApp number, country and destination market.
  • Enquiry content: counterparty type (buyer or seller), product interest, indicative quantity, timelines and free-text messages.
  • Compliance information: identification documents, corporate registration and ownership records, beneficial ownership details, source of funds and source of goods information, sanctions and PEP screening results.
  • Transaction documents: LOIs, ICPOs, proof of funds references, agreements, certificates, permits and logistics documentation uploaded or sent to us.
  • Account information: client portal email address, authentication data managed by our identity provider, and portal activity records.
  • Technical information: IP address, device and browser type, pages visited and timestamps, collected through server logs and essential cookies.

3.How we collect information

We collect information directly from you when you submit a form, email us, sign an agreement, or upload documents to the client portal.

We also collect information from third parties where necessary for compliance, including company registries, sanctions and PEP screening sources, publicly available adverse media, and referees or introducers who put us in contact with you.

We do not purchase marketing lists and we do not collect special category data unless it appears in an identity document you provide for KYC purposes.

4.Why we use your information and our lawful bases

  • To respond to enquiries and issue quotations — performance of a contract or steps taken at your request; legitimate interests in conducting business.
  • To conduct KYC, AML, sanctions and responsible sourcing due diligence — compliance with legal obligations and legitimate interests in preventing financial crime.
  • To coordinate and document transactions — performance of a contract.
  • To operate, secure and improve the website and client portal — legitimate interests in security and service quality.
  • To keep business, tax and compliance records and to establish or defend legal claims — legal obligation and legitimate interests.
  • To send occasional business updates where you have asked for them — consent, which you can withdraw at any time.

5.We do not sell your information

We do not sell, rent or trade personal information, and we do not use it for third-party advertising or profiling. We do not make decisions producing legal or similarly significant effects about you by automated means alone; compliance decisions involve human review.

6.Who we disclose information to

  • Transaction counterparties and their advisers, only where necessary to progress an engagement you have agreed to and normally after an NDA or NCNDA is in place.
  • Refiners, assayers, inspection agents, freight forwarders, secure logistics providers and insurers involved in an agreed transaction.
  • Professional advisers, including lawyers, accountants and auditors, under duties of confidentiality.
  • Technology service providers that host our website, database, authentication and document storage under contractual confidentiality and security obligations.
  • Government agencies, regulators, customs authorities, law enforcement and financial institutions where disclosure is required or authorised by law.

7.International transfers

Because we coordinate cross-border transactions, your information may be transferred to and accessed from countries other than your own, including Australia, and countries where counterparties, refiners, logistics providers and our service providers operate.

Where information protected by the GDPR is transferred outside the EEA or UK, we rely on an adequacy decision where one applies, or otherwise on Standard Contractual Clauses together with a transfer risk assessment and appropriate technical safeguards.

Where Australian Privacy Principle 8 applies, we take reasonable steps to ensure overseas recipients handle information consistently with the Australian Privacy Principles.

8.Security of your information

The website is served over HTTPS with strict transport security and a content security policy. The client portal requires authentication, and database access is restricted by row-level security so counterparties can only see their own records.

Uploaded documents are stored in a private storage bucket that is not publicly accessible, with type and size validation applied at upload and access restricted to the uploading client and authorised GCI personnel. Data is encrypted in transit and at rest by our infrastructure providers.

Access to compliance files is limited to personnel who need it. Despite these measures, no method of electronic transmission or storage is completely secure, and you send information to us at your own risk.

9.Where your information is stored

Website content, the client portal database, authentication records and uploaded documents are hosted with our infrastructure providers on managed cloud infrastructure. Primary data residency for the application database and private document storage is the provider's nominated region, with encrypted backups held by the same provider.

Email correspondence is processed by our email and transactional mail providers, which may store message content on servers located outside Australia. Because of this, sensitive KYC, identification, proof-of-funds, LOI and ICPO documents must be uploaded through the secure form or portal rather than sent as email attachments.

A current list of the categories of provider used, and the regions in which they store data, is available to counterparties on request at notifygoldcapitalexchange@gmail.com.

10.Deletion and secure destruction

When a retention period ends, records are deleted from the live system and removed from backups on the provider's rolling backup cycle. Private document objects are deleted from storage and the corresponding metadata record is removed.

Where records are subject to statutory retention or an active legal claim, they are isolated and access-restricted rather than deleted, and are destroyed once the obligation ends.

11.Data breach response and notification

We maintain an incident response process covering detection, containment, assessment and remediation. Suspected incidents involving personal information are assessed promptly by the Director.

Where an eligible data breach is likely to result in serious harm, we notify the Office of the Australian Information Commissioner and affected individuals as soon as practicable, consistent with the Notifiable Data Breaches scheme. Where the GDPR applies, we notify the relevant supervisory authority within 72 hours of becoming aware, and affected individuals without undue delay where the risk to their rights and freedoms is high.

Notifications describe what happened, the information involved, the steps taken, and the actions you can take to protect yourself. Incidents and their outcomes are recorded in an internal breach register.

12.How long we keep information

Enquiries that do not progress are retained for up to 24 months so we can respond to follow-up contact, unless you ask us to delete them earlier.

KYC, AML, sanctions screening and transaction records are retained for at least seven years after the end of the business relationship or the completion of the transaction, consistent with anti-money laundering and record-keeping expectations in the jurisdictions in which we operate.

Portal accounts and their documents are removed within 12 months of an engagement ending, except where longer retention is required by law or to defend legal claims.

13.Your privacy rights

  • Request access to the personal information we hold about you and ask for a copy of it.
  • Ask us to correct information that is inaccurate, out of date, incomplete or misleading.
  • Ask us to delete information where we no longer have a lawful basis to keep it. Compliance records subject to statutory retention cannot be deleted on request.
  • Object to, or ask us to restrict, processing based on legitimate interests, and withdraw consent where consent is the basis for processing.
  • Request portability of information you provided to us, in a structured, commonly used, machine-readable format, where the GDPR applies.
  • Lodge a complaint with a supervisory authority — in Australia the Office of the Australian Information Commissioner (oaic.gov.au), or your local data protection authority in the EU or UK.

14.How to exercise your rights or make a complaint

Email notifygoldcapitalexchange@gmail.com with the subject line "Privacy Request". We may need to verify your identity before acting, particularly where compliance records are involved.

We aim to acknowledge requests within 5 business days and to respond substantively within 30 days. If we decline a request, we will explain why and how you can escalate the matter.

15.Cookies and analytics

We use only cookies and local storage that are necessary for the website and client portal to function, including session and authentication storage and your language preference. Our Cookie Policy explains these in detail and how to control them.

16.Children

This website is directed at businesses and professional counterparties. We do not knowingly collect information from anyone under 18. If you believe a minor has provided information to us, contact us and we will delete it.

17.Changes to this policy

We may update this policy to reflect changes in our practices or the law. The current version is always published on this page with its update date and version number. Material changes affecting existing clients will also be notified by email where practicable.

Important legal notice

This document is published for general information about how Gold Capital International conducts business. It is not legal, financial, tax or investment advice, and it does not create a contractual relationship on its own. Laws differ between jurisdictions and change over time.

Before relying on this document, or before signing any agreement with us, you should obtain independent advice from a qualified lawyer admitted in your own jurisdiction and in each jurisdiction relevant to your transaction.

Gold Capital International is a private commercial business. Nothing on this website or in this document implies government affiliation, endorsement, licensing, registration or regulatory approval by any authority, and no guarantee of any commercial outcome is given.

© 2026 Gold Capital International. All rights reserved. "Gold Capital International" and "GCI", together with the GCI logo and site design, are unregistered trade marks used by the business. This document may not be reproduced, redistributed or adapted for commercial purposes without prior written consent.

Questions about this policy? Contact us at notifygoldcapitalexchange@gmail.com or +61 469 763 174. Postal enquiries: Parkinson, QLD 4115, Australia.