Last updated: July 2026
This privacy policy (the “Policy”) describes how Copper Markets (US) Inc. (“Copper”, “we”, “us” or “our”) collects, uses, processes, secures and shares the personal information you provide to us, and the personal information we collect in the course of operating our business and our website in the United States, copper.co/en-us (http://copper.co/en-us) (the “Website”). This Policy applies to our U.S. institutional customers, prospective customers, website users, vendors, service providers, third parties, employees, job applicants and other individuals whose personal information we process in connection with our U.S. operations (“you” or “your”).
The information we collect depends on your relationship with us, the products or services you request, and applicable legal and regulatory requirements. Before registering for, or using Copper services, in particular before entering any personal information, you need to be informed about our practices regarding your personal information (as defined below), how we will treat your personal information and the basis on which it could be disclosed to third parties. We process personal information in compliance with the provisions of the U.S. federal and state data protection laws and regulations and, to the extent applicable, with the EU General Data Protection Regulation (“GDPR”) and UK General Data Protection Regulation (“UK GDPR”).
Notice to Residents of California and Other U.S. States
The services operate from the United States. Your rights and choices depend in part on the law where you live. If any local privacy laws apply to you, those laws override any contrary descriptions in this Policy. If you have questions about your rights under data privacy laws other than the State of California or to exercise any rights under any state law, please contact us.
As a regulated financial institution, our collection, use, and sharing of personal information is governed by the Gramm-Leach-Bliley Act (“GLBA”) and its implementing rules, including SEC Regulation S-P, together with applicable U.S. state privacy and data security laws.As a financial institution subject to the GLBA, applicable provisions of Regulation S-P, and other federal privacy and information-security requirements, Copper may be exempt from certain state privacy laws and will rely on an exemption only to the extent permitted by applicable law.At a minimum, applicable state privacy laws apply to workforce information (i.e., information relating to employees and job applicants) that is not covered by GLBA, and may apply to other categories of personal information in the grey areas between GLBA and state law.
General Information
Copper Markets (US) Inc. is a corporation organized under the laws of the State of Delaware and a broker-dealer registered with the U.S. Securities and Exchange Commission (“SEC”), a member of the Financial Industry Regulatory Authority (“FINRA”). Copper may transfer personal information to its affiliated companies outside the United States. Copper warrants adequate protection for personal information if the data is transferred to another country for the purpose of providing any products or services on behalf of Copper or as required by applicable law. Copper Markets (US) Inc. is an affiliate of Copper Markets (Switzerland) AG and other members of the Copper group of companies, which are separately subject to their own privacy notices where applicable. Contact details for privacy inquiries are set out in the Contact Us section below.
As a regulated financial institution, our collection, use, and sharing of personal information is governed by the Gramm-Leach-Bliley Act (“GLBA”) and its implementing rules, including SEC Regulation S-P, together with applicable U.S. state privacy and data security laws. This Policy is intended to satisfy our disclosure obligations under GLBA and state law.
We may revise this Policy at any time by amending this page to reflect changes to our practices or applicable law and the latest version will be available on this page. We recommend that you check this page periodically to stay informed of any changes.
Personal Information We Collect
“Personal information” is information that identifies, relates to, or could reasonably be linked, directly or indirectly, with you as an identified or identifiable natural person, such as a name, email address, government identification number, or online identifier.For the purposes of this Policy, “personal information” refers to information about natural persons (individuals) and does not encompass information about corporate entities as such, although information about a company's representatives, beneficial owners, and control persons will constitute personal information about those individuals. Information about institutional entities is separately protected under GLBA and other applicable financial services law and is processed in accordance with those requirements.
To open an institutional account and provide our services, we generally collect:
- Entity information, such as company name, jurisdiction of formation, business address, tax information, governance and formation documents;
- Identification information for authorized representatives, beneficial owners, and control persons, such as name, date of birth, government-issued identification, country of citizenship, tax identification, residential address, email address, and phone number;
- Financial and account information, such as bank account and wire details, wallet addresses, source of funds, source of wealth, tax identification, investment purpose, eligibility and institutional status, to the extent such information is linked to an identifiable individual;
- Transaction information, such as transaction IDs or timestamps, account balances, trading activity, order activity, deposits, and withdrawals, to the extent linked to an identifiable individual;
- Compliance information to satisfy our KYC, KYB, AML obligations under the Bank Secrecy Act, the USA PATRIOT Act, and applicable customer identification, anti-money laundering, sanctions laws and regulations;and
- Correspondence and communications, including information you provide when you contact us or respond to our communications.
For employment-related purposes, we separately collect the following information about employees, workers, and job applicant’s: name, signature, social security number, address, telephone number, passport number, driver's license or state identification number, education, employment history, marital status, race, gender, sexual orientation, disability status, veteran status, national origin, citizenship, bank account number, or any other financial information.
We limit our collection and processing of personal information to what is necessary for these purposes and in accordance with applicable laws and regulations. Our processing extends not only to customers, but also to prospective customers, website users, vendors, service providers, third parties, employees and job applicants, in each case limited to the minimum necessary for the relevant purpose.
If you need to change or amend your personal information, including your contact details, please notify Copper as soon as possible in writing.Requests may be submitted to dpo@copper.co.
Sources of Personal Information
We collect personal information from the following sources:
- Directly from you or your organization, including when you sign up for our services, open an account, use an account or our products or services, request information, register for or attend a webinar or event, sign up for our newsletter, apply for employment with us, or otherwise contact us;
- Through your use of our Website and platform, including through application programming interfaces (“APIs”) that allow third-party systems to integrate or interact with Copper's platform, and device and usage information collected via cookies and similar technologies; and
- From third parties, including identity verification providers, credit bureaus, sanctions and watchlist screening providers, vendors, custodians, exchanges, correspondent institutions, search engine providers and publicly available sources, in each case as necessary to verify your identity, assess eligibility, and comply with our legal and regulatory obligations.Categories of third parties from whom we collect information include: (i) identity verification and KYC/AML service providers; (ii) credit reference agencies; (iii) sanctions screening and watchlist providers; (iv) publicly available government and regulatory databases; and (v) data aggregation and analytics providers.
How We Use Personal Information
We use personal information for the following purposes:
- To open, administer, and service your account; to provide our products and services; and to perform our contractual and regulatory obligations to you;
- To verify your identity and determine investor status, eligibility, accreditation, and geographic restrictions;
- To detect, investigate, and prevent fraud, unauthorized or unlawful activity, and other security incidents;
- To protect assets, products, services, systems, and resolve any security incidents;
- To communicate with you about your account, our services, and matters we believe may be of interest to you;
- For our business purposes, including marketing our services or engaging in business development activity in relation to our services;
- To satisfy our obligations under the Bank Secrecy Act, USA PATRIOT Act, applicable anti-money laundering and sanctions laws and to conduct due diligence, review of adverse media reports, and transaction monitoring in connection with our compliance program;
- To comply with applicable law, regulation, and requests from regulators, courts, and law enforcement; to provide regulatory disclosures or notifications; to comply with reporting obligations to authorities, including but not limited to anti-money laundering and terrorist financing prevention requirements; to comply with tax, books and records, supervision, examination, and regulatory reporting requirements under the Securities Exchange Act of 1934, related regulations and FINRA rules; to exercise or defend our rights in any legal proceeding;
- To operate, manage, monitor, develop and improve our products and services and business, including risk management, accounting, internal audit, and the enforcement of our rights under any agreement between you and us; and
- To recruit, review and process job applications or for employment purposes.
How We Share Your Personal Information
As a financial institution, Copper is required to disclose how we share nonpublic personal information (“NPI”) about our customers. Subject to applicable law, we may disclose personal information to:
- Vendors, service providers or third parties who perform functions on our behalf or assist us with administering the services, such as identity verification, cloud hosting, cybersecurity, compliance-related services, blockchain records or analytics, records management, and professional services, and who are contractually obligated to handle and protect your information and use it only for the purposes we specify. We assess and oversee our vendors, service providers and third parties in a manner proportionate to the services provided and the sensitivity of information processed, including incident-notification obligations where required.
- Banks, custodians, broker-dealers, transfer agents, issuers, redemption agents, exchanges, digital asset platforms, liquidity providers, market makers, wallet providers, staking providers, settlement networks, and counterparties that are integrated with Copper to provide Copper's products and services that you have elected to receive.
- SEC, FINRA, FinCEN, IRS, state regulators, law enforcement, courts, self-regulatory organizations, and other regulatory authorities or as required by law, regulation, subpoena, or other legal process.
- Our attorneys, accountants, auditors, consultants, investigators, insurers, and parties to an actual or proposed merger, acquisition, financing, reorganization, bankruptcy, or asset sale.
- Affiliates for their everyday business purposes to provide our products and services that you have elected to receive.
- Affiliates to market to you, and you may elect to limit this sharing.
To limit our sharing, submit a request in writing using Contact Us. If you are a new customer, we may begin sharing your information 30 days from the date of account opening unless you instruct us otherwise. Your election will remain in effect until you tell us otherwise, even after your relationship with us ends.
Note for California residents: California law imposes requirements regarding not sharing personal information with third parties that falls outside of GLBA.Please see the Your California and Other State Privacy Rights section below for further information.
Use of Service Providers
We engage third-party service providers (“Service Providers”) who process personal information on our behalf in order to deliver our products and services. Our Service Providers are contractually bound to use personal information only to the extent necessary to perform the services they provide to us, and to maintain appropriate technical and organizational measures to protect personal information against unauthorised access, disclosure, or loss. We conduct risk-based due diligence on our Service Providers, proportionate to the sensitivity of the personal information they process and the nature of the services they provide.
Categories of Service Providers we engage include:
- Identity verification and know-your-customer (KYC) providers;
- Cloud computing and data hosting providers;
- Cybersecurity and fraud prevention providers;
- Compliance, anti-money laundering, and sanctions screening providers;
- Blockchain analytics providers;
- Record management and archival providers; and
- Professional services providers, including legal, accounting, and audit firms.
Where Service Providers are located outside the United States, we will ensure that appropriate data transfer safeguards are in place in accordance with applicable law.
Cookies and Tracking Technologies
Copper uses cookies and similar tracking technologies to operate and maintain the Website, platform, and APIs, provide products and services, maintain sessions and preferences, authenticate users, detect fraud and security threats, track and measure performance and usage, and troubleshoot. These technologies may collect information about your device, browser, interactions with our services, and use of particular features. You can manage cookies through your browser settings; please see our separate Cookie Policy for further details.
Usage Data: When you use our Website, we may automatically collect certain technical information, including your IP address, browser type and version, operating system, referring URLs, pages visited, and time and date of your visit. This information is used to operate and improve our Website and services, and to detect and prevent fraud and security threats.
Do Not Track: Although some browsers currently offer a “Do Not Track ('DNT')” option, no common industry standard for DNT currently exists. We therefore do not currently commit to responding to browsers' DNT signals.Please see our Cookie Policy for further details regarding our use of tracking technologies.
Marketing and Opt-Out Rights
Where we use your personal information for marketing purposes, we will only do so in accordance with applicable law. You may opt out of receiving marketing communications from us at any time by:
- Contacting us at dpo@copper.co; or
- Following the unsubscribe instructions contained in any marketing email we send to you.
Please note that even if you opt out of marketing communications, we may still send you transactional or service-related communications that are necessary in connection with your account or services.
We do not sell your personal information to third parties for their own direct marketing purposes. We do not sell or share personal information with any third party that does not assist in providing our services.
Non-Identifiable Data
We may use, share, and disclose aggregated or de-identified information that cannot reasonably be used to identify you, for any purpose permitted by applicable law, including to analyse trends, improve our services, and fulfil reporting obligations. Such de-identified or aggregated information does not constitute “personal information” for the purposes of this Policy or applicable privacy law. We also retain de-identified or aggregate data derived from information about you to the extent permitted by law.
Children
Our Website and services are directed to adults and institutions and are not intended for use by children under the age of 16. We do not knowingly collect personal information from children under 16 years of age. As of the date of this Policy, we have no knowledge of any use of personal information that we collect from persons under the age of 16 for “sale” or “sharing” purposes.If you believe we have inadvertently collected personal information from a child under 16, please contact us at dpo@copper.co and we will promptly take steps to delete such information.
Third Party Links
Please note that our Website may contain links to third-party services, websites, applications or digital platforms, which are provided for your convenience. You should carefully review the privacy and security policies and procedures of each and every other third party before connecting to or using third-party services.We are not responsible for the content, privacy practices, or security of any third-party websites or services to which we provide links.
Data Security and Incident Response
Copper takes privacy and data protection very seriously and is committed to protecting your personal information and confidentiality. We maintain appropriate administrative, technical, and physical safeguards designed to protect personal information, consistent with our obligations under Regulation S-P's Safeguards Rule and Disposal Rule and other applicable law. These measures include access controls, least privilege, multi-factor authentication, segregation of duties, encryption of data in transit, employee training, and due diligence and oversight of service providers who handle personal information on our behalf.
Consistent with Regulation S-P, we maintain a written incident response program designed to detect, respond to, and recover from unauthorized access to or use of customer information. We will notify affected individuals as soon as practicable, and in any event no later than 30 days after we become aware of an incident involving sensitive customer information, unless a longer period is required to avoid interference with a law enforcement investigation.
In addition to our obligations under GLBA and Regulation S-P, we apply consistent information security best practices to all personal information we process, including personal information that may not be subject to GLBA (such as information relating to employees and job applicants). We will notify affected individuals and applicable regulatory authorities of data incidents in accordance with all applicable law.
Data Retention
We retain personal information for as long as necessary to provide our services, comply with our legal and regulatory recordkeeping obligations, and resolve disputes. When personal information is no longer needed, we take reasonable steps to securely delete or anonymize it. Under applicable financial services regulations and FINRA rules, we are required to maintain certain records for prescribed minimum periods. Retention periods for other categories of personal information vary depending on the applicable legal requirement and the nature of the processing.
State Privacy Law Notice
As a financial institution subject to the GLBA, applicable provisions of Regulation S-P, and other federal privacy and information-security requirements, Copper may be exempt from certain state privacy laws and will rely on an exemption only to the extent permitted by applicable law. Depending on the applicable state law, this exemption may apply to Copper as a regulated financial institution, to nonpublic personal information collected, processed, disclosed, or otherwise maintained pursuant to the GLBA, or to both. To the extent applicable state privacy laws apply and no exemption is available, Copper will process personal information and comply with applicable privacy rights in accordance with applicable state privacy laws.
Important: At a minimum, applicable state privacy laws apply to workforce information (i.e., personal information relating to employees and job applicants) that is not covered by GLBA. Copper will comply with all applicable state privacy laws in respect of such information.
Residents of certain states may have the right to:
- Obtain information about the personal information we collect and process;
- Correct inaccurate personal information;
- Request deletion of personal information, subject to applicable exceptions;
- Obtain a copy of certain personal information in a portable format;
- Opt out of the sale of personal information, targeted advertising, or certain profiling activities, where applicable; and
- Exercise other rights provided under applicable state law.
Requests may be submitted in writing using Contact Us.
California and Other State Privacy Rights
The services operate from the United States. Your rights and choices depend in part on the law where you live. If any local privacy laws apply to you, those laws override any contrary descriptions in this Policy. If you have questions about your rights under data privacy laws other than the State of California or to exercise any rights under any state law, please contact us.
This section applies to you only if you reside in California or another U.S. state where applicable law provides for some or all of these rights or substantially similar rights. Rights of California residents are specifically referred to as “rights under the CCPA” or “CCPA rights.” If you are a resident of a state other than California, these laws may not pertain to you.
Rights under the CCPA
The California Consumer Privacy Act, as amended by the California Privacy Rights Act (“CCPA”), provides California consumers rights regarding their Personal Information (as defined in the CCPA). If you reside in a United States jurisdiction that has enacted a data privacy law, we extend the same rights to you that the CCPA grants to California consumers, except where we specify otherwise.
The categories of Personal Information we collect are generally described in the section above titled Personal Information We Collect. These categories depend on how you use the Website.
Under the CCPA, qualifying California consumers may have the following rights:
1. Right to Know, Access, Correct and Delete
A California consumer has the CCPA right to request that we disclose what Personal Information we collect, use, disclose, share or have disclosed for a business purpose.
We may deny deletion requests, in whole or in part, with respect to information we reasonably need to:
- Comply with a legal obligation;
- Allow you, other consumers, or us to exercise free-speech rights or other legal rights;
- Perform a contract with you; or
- If we use the information solely for internal purposes reasonably aligned with consumer expectations.
2. Rights to Opt-Out of Sharing/Sale and Limit Use of Sensitive Information
You also have the CCPA right to direct us (1) not to share or sell your Personal Information and (2) to limit our disclosure and your use of “sensitive personal information” to that which is necessary to provide the Website to you.
Although California consumers have the right to opt-out of sharing or selling of Personal Information, we do not sell or share Personal Information with any third party that does not assist in providing the services.
We do not collect “sensitive personal information” as defined in the CCPA and we therefore do not provide a mechanism to opt out of the use of such information.
As of the date of this Policy, we have no knowledge of any use of Personal Information that we collect from persons under the age of 16 for “sale” or “sharing” purposes.
3. No Retaliation
The CCPA prohibits us from discriminating against you if you exercise rights under the CCPA. You do not need to exercise this CCPA right. We never retaliate against anyone exercising their rights under the CCPA.
Preference Signals
Because we do not collect sensitive Personal Information or sell or share any Personal Information, the Website is not presently configured to honour any global opt-out preference signal sent from California IP addresses to the Website through browser or device-level settings, provided the signal complies with CCPA's requirements.
Submitting Requests Regarding California Rights
To submit a request to exercise a CCPA right, please contact us at:
Copper Markets (US) Inc. 1250 Broadway, New York, NY 10001 Email: dpo@copper.co
with “Personal Information Request” in the subject line of your email.
Verifying Requests
If we receive any request, a California consumer must provide sufficient information to identify the consumer, such as name, email address, home or work address, or other such information that is on record with us so that we can match such information to the Personal Information that we maintain. Do not provide social security numbers, driver's license numbers, account numbers, credit or debit card numbers, medical information or health information with requests. If requests are unclear or submitted through means other than as outlined above, we will provide the California consumer with specific directions on how to submit the request or remedy any deficiencies.
If we cannot verify the identity of the consumer making the request, we may deny the request in full or in part.
Responding to Requests
We will respond to your request as quickly as we can, taking into account the nature of your request and the volume of pending requests. For California consumers, we will confirm receipt of your CCPA request within 10 days and will substantively respond within 45 days, unless we provide an explanation why an additional 45 days is necessary. California residents may submit rights requests through an authorized agent. We may request proof that the person who is the subject of the request is authorized as an agent to submit a privacy request on their behalf.
The content of our response will vary with the nature of your request, but we will always respond in accordance with any deadlines or requirements specified by the laws that apply to you.
Under certain circumstances, we may be unable to provide responsive Personal Information, such as when disclosure would create a substantial, articulable and unreasonable risk to the security of the information, users' accounts with us, or the security of our systems and networks. We do not disclose account passwords or other non-personal information that enables users to access accounts.
We also will not disclose California consumers' social security numbers, driver's license numbers or other government-issued identification numbers, financial account numbers, any health insurance or medication identification numbers, or account passwords and security questions and answers.
We reserve the right to retain an archive of any information about you to the extent permitted by law. We also retain de-identified or aggregate data derived from information about you.
California Do Not Track Disclosures
Although some browsers currently offer a “Do Not Track ('DNT')” option, no common industry standard for DNT exists. We therefore do not currently commit to responding to browsers' DNT signals.
California Civil Code Section 1798.83
Under certain circumstances, California Civil Code Section 1798.83 states that, upon receipt of a request by a California consumer, a business may be required to provide detailed information regarding how that business has shared that customer's Personal Information with third parties for direct marketing purposes. However, the foregoing does not apply to Copper as we do not disclose Personal Information to third parties for direct marketing purposes without prior approval or give customers a free mechanism to opt out of having their Personal Information disclosed to third parties for their direct marketing purposes.
Notice to Residents of the European Economic Area, the United Kingdom, and Switzerland
If you are a resident of the European Economic Area (“EEA”), the United Kingdom (“UK”), or Switzerland, your personal information may be processed by one or more members of the Copper group of companies that are separately subject to EU, UK, and Swiss data protection legislation, including the EU General Data Protection Regulation (Regulation (EU) 2016/679) (“GDPR”), the UK General Data Protection Regulation and the Data Protection Act 2018 (“UK GDPR”), and the revised Swiss Federal Act on Data Protection (“Swiss FADP”), as applicable.
This Policy applies solely to the U.S. operations of Copper Markets (US) Inc. Copper Markets (US) Inc. is an affiliate of Copper Markets (Switzerland) AG and other members of the Copper group of companies, which are separately subject to their own privacy notices where applicable.
For more comprehensive information about how Copper processes your personal information in connection with its EEA, UK, and/or Swiss operations, please refer to the privacy notice published by the applicable Copper group entity. UK, Swiss and EEA resident users of Copper's services should refer to the privacy notice available at copper.co/en/privacy. For more information, please contact our data protection office at dpo@copper.co;
We encourage all EEA, UK, and Swiss residents to review the applicable European or UK privacy notice for comprehensive information about how their personal information is processed.
Where Copper Markets (US) Inc. processes personal information of EEA, UK, or Swiss residents in connection with its U.S. operations, for example, where you access our Website from outside the United States or where you interact with us in a cross-border context, we will comply with applicable international data transfer requirements. This means that where your personal information is transferred from the EEA, UK, or Switzerland to the United States, we will put in place appropriate safeguards, which may include:
- Standard Contractual Clauses (“SCCs”) as approved by the European Commission (for EEA-to-US transfers) or the UK Addendum to SCCs approved by the Information Commissioner's Office (for UK-to-US transfers);
- Any applicable adequacy decisions; or
- Other transfer mechanisms recognized as appropriate under EU GDPR, UK GDPR, or Swiss FADP.
EEA residents have the right to lodge a complaint with the competent data protection supervisory authority in the EU member state of their habitual residence, place of work, or place of the alleged infringement.
UK residents have the right to lodge a complaint with the UK Information Commissioner's Office (“ICO”) at ico.org.uk.
Swiss residents have the right to lodge a complaint with the Federal Data Protection and Information Commissioner (“FDPIC”) at edoeb.admin.ch.
Contact Us
If you have questions about this Policy or wish to exercise any of your privacy rights, please contact us at:
Copper Markets (US) Inc. 1250 Broadway, New York, NY 10001 Email: dpo@copper.co