GreatBless Help Center
Security

What GreatBless Does With Your Personal Data, and How Long We Keep It

Opening a brokerage account means handing over identity documents, payment details, and a record of everything you trade. This article says what that data is used for, how long it stays, and what you can ask us to do with it.

What we use it for

The Privacy Policy groups the purposes:

πŸ”Ή Running your account β€” opening and managing it, processing deposits and withdrawals, executing trades.
πŸ”Ή Compliance β€” KYC, anti-money-laundering checks, fraud prevention and monitoring.
πŸ”Ή Security β€” verifying that a login attempt is really you, reviewing withdrawal requests for signs of fraud or account takeover, preventing identity theft.
πŸ”Ή Communication β€” service messages about your account.

On withdrawals specifically, the Policy is precise about the method:

"Withdrawal requests are reviewed against the identity and payment information you have provided. We do not use biometric data to authorise individual transactions." β€” Privacy Policy V4, section 4.3

How long it is kept

"We retain your personal data: for at least 5 years after account closure." β€” Privacy Policy V4, section 8

That period is not a preference β€” it is the retention obligation that applies to regulated financial records. It is also why closing an account does not erase its history.

For a Swap-Free (Islamic) account, the supporting documents are handled more narrowly: access is restricted to staff who need it for that purpose, they are kept only as long as necessary for eligibility and administration plus any period the law requires, and they are not used for marketing.


What you can ask for

"Depending on applicable laws, you may have the right to:… Request deletion (subject to mandatory retention periods required by Anti-Money Laundering (AML) and financial regulations, where your request to delete may be denied until the 5-year statutory period expires)." β€” Privacy Policy V4, section 10

So a deletion request is a real right, with a real limit. Expect access and correction requests to be straightforward, and deletion of regulated records to wait for the retention period to run out.

To make a request, contact support from the email address registered on your account. We may ask you to verify your identity first β€” that check protects you, since the request would otherwise be a way for someone else to obtain your data.


Keeping your side secure

πŸ”Ή Turn on two-factor authentication β€” see How to Enable 2FA.
πŸ”Ή Review and remove active sessions you do not recognise β€” see View and Delete Sessions.
πŸ”Ή Never send passwords, full card numbers, or seed phrases in a chat or email. No member of our staff will ask for them.


Sources: Privacy Policy V4, sections 4, 8 and 10; AML/KYC Policy V6, section 7 (Record Keeping). Published 9 September 2026, updated 15 September 2026. This article summarises those documents for convenience β€” where it differs from them, the signed documents prevail.

πŸ’¬ Need more help?

Chat with our support team or submit a ticket β€” we reply within 24 hours.

Open support page

Other articles