Edenex

Privacy Policy

EDENEX - FZCO

Last updated on:

1. Scope

This policy explains how personal data is processed in connection with:

  • edenex.com — our website, in each of its language versions; and
  • app.edenex.com — the Edenex application, available to registered users.

We refer to these together as the Platform.

It applies to visitors to the Platform, to registered users, to the representatives of corporate users, and to individuals identified in the course of a transaction, including beneficial owners and authorised signatories.

This policy replaces the Privacy Policy previously published for the Platform as a PDF dated December 1, 2025. From the date shown above, it is the only privacy policy that applies, and no earlier version may be relied upon.

1.1 Applicable law

Edenex is established in the United Arab Emirates, and its processing is governed by the law of the United Arab Emirates.

European data protection law applies in addition to part of our processing, because the Platform is accessible to visitors in the European Economic Area and their use of the website is measured by the analytics described in section 3. References in this policy to the GDPR concern that part of our processing.

Residents of the European Economic Area may browse the Platform, access general information and register an expression of interest. They may not at present commit capital or use crypto-asset services. Identity verification and screening are used where a person uses a service that requires them; they are not withheld solely because the person is in the EEA, and they are not used to onboard EEA residents as investors or as clients of a crypto-asset service. Should that change, this policy will be updated and the additional safeguards required by European law will be established before any such onboarding begins.

2. Who is responsible for your personal data

2.1 The operator

The Platform is operated by EDENEX - FZCO, a free zone company holding trade licence 27573 issued by the Dubai Integrated Economic Zones Authority, with its registered office at Premises No. DSO-IFZA, IFZA Properties, Dubai Silicon Oasis, Dubai, United Arab Emirates ("Edenex", "we", "us").

Edenex is the controller of the personal data identified as its responsibility in section 2.2.

2.2 Which entity controls which data

The Platform brings together several independent legal entities. Each determines the purposes and means of its own processing and is an independent controller of it. They are not joint controllers, and none controls the processing carried out by the others.

Category of dataController
Account and profile data, use of the Platform, support correspondence, marketing preferencesEDENEX - FZCO, United Arab Emirates
Identity verification files and screening results relating to an investment in a deal or poolSEGLORIA SPC, Cayman Islands — the obligation to verify investors rests on the issuer rather than the operator
Identity verification and transaction data relating to crypto-asset services in the European Economic AreaEDENEX EX s.r.o., Slovakia. No disclosure is made to this company at present, because it is not authorised and provides no services. This row will apply only if it becomes authorised, and we will tell you before any disclosure begins
Payer and payee data relating to a cross-border paymentThe payment provider selected for that payment, which contracts with you directly and executes the payment under its own licence

Where a controller other than Edenex is responsible, that controller's own privacy notice governs its processing. We identify the relevant entity before the processing begins.

2.3 Contact

PurposeContact
Privacy enquiries and requests to exercise your rights[email protected]
Representative in the European Union under Article 27 GDPREDENEX EX s.r.o., Company ID (IČO) 55 262 864, Magurská 37, 974 11 Banská Bystrica, Slovak Republic. Contact: [email protected]

3. Personal data we process

3.1 Data you provide

  • Registration data — name, email address, telephone number, password credentials, country of residence.
  • Verification data — identity document images and their contents, date of birth, nationality, residential address, a facial image and a short video or image sequence used to confirm that the document belongs to you, tax identification information and, for corporate users, incorporation documents, ownership structure, and the identity of beneficial owners and authorised signatories.
  • Financial and source-of-funds data — bank or wallet details, evidence of the origin of funds, and information about the purpose and intended nature of the relationship.
  • Transaction data — instructions you give, commitments you make, documents you upload, and correspondence with counterparties conducted through the Platform.
  • Correspondence — support requests, complaints and other communications with us.

3.2 Data generated by your use of the Platform

  • Technical data — IP address, device and browser characteristics, operating system and language settings.
  • Usage data — pages viewed, features used, session timing and actions taken within the Platform.
  • Security data — authentication events, access attempts, and records used to detect fraud and unauthorised access.

On the website, and only with your consent, we additionally measure how the site is used and how visitors reach it, using the analytics service named in section 7. If you do not consent, it does not operate. You may give, refuse or withdraw that consent at any time, and withdrawing it is as easy as giving it. The technologies involved, what each stores on your device and for how long, and the choices available to you are set out in the Cookie Policy.

The application contains no analytics. When a shipment map is displayed, your browser requests map tiles from the provider named in section 7, which therefore receives your IP address and the map area shown.

We do not record your session. We use no screen-recording, session-replay or keystroke-capture technology anywhere on the Platform.

3.3 Data from other sources

  • Verification and screening providers — results of identity checks and of sanctions, politically exposed person and adverse media screening.
  • Public and commercial registers — corporate registry data and beneficial ownership records.
  • Counterparties and partners — where a partner must share data with us to complete a transaction you have initiated.
  • Blockchain networks — publicly available transaction data associated with wallet addresses you use.

3.4 Special categories and criminal-offence data

Two forms of processing require particular mention. Both are carried out by our verification provider, Sum and Substance Ltd ("Sumsub"), acting on our instructions and on those of the relevant controller identified in section 2.2.

Biometric data. Verification compares a facial image you provide against the photograph in your identity document. Because that comparison is performed by automated means in order to confirm that you are the person shown in the document, we treat the data involved as biometric data and apply corresponding safeguards: it is used only to complete verification, it is accessible only to the compliance function, and it is retained for the period stated in section 9 and no longer. Your explicit consent is requested before verification begins, and you may refuse. If you refuse, we cannot verify you, and the services that depend on verification are unavailable.

Data relating to criminal offences. Sanctions, politically exposed person and adverse media screening may reveal information about alleged or actual criminal offences. This processing is necessary to meet anti-money-laundering and sanctions obligations applying to us and to our regulated partners, and to prevent the Platform being used for financial crime. Results are accessible only to the compliance function and are used for no purpose beyond those described in section 4.

These forms of processing are used when a person completes verification for a service that requires it. They are not used to onboard residents of the European Economic Area as investors or as clients of a crypto-asset service, for the reason given in section 1.1.

PurposeData usedLegal basis
Creating and administering your account and providing the PlatformRegistration, technical, usagePerformance of a contract — Article 6(1)(b)
Verifying your identity and that of any entity you representVerification, financialLegal obligation — Article 6(1)(c); and our legitimate interest in preventing financial crime and meeting the requirements of our regulated partners — Article 6(1)(f)
Screening against sanctions, politically exposed person and adverse media data, and monitoring for financial crimeVerification, transaction, screening resultsArticles 6(1)(c) and 6(1)(f), together with the bases stated in section 3.4
Enabling and recording transactions and generating the associated documentationTransaction, verificationArticle 6(1)(b)
Checking whether a transaction presented for finance has already been financed elsewhereTransaction, and information drawn from the documents presentedOur legitimate interest, and that of the users funding a transaction, in preventing the same transaction being financed twice — Article 6(1)(f)
Determining whether you are eligible to see or to commit to a given productRegistration, verification, jurisdictionArticles 6(1)(b) and 6(1)(c)
Securing the Platform, detecting fraud, investigating incidents and enforcing the Terms of ServiceTechnical, security, usageOur legitimate interest in protecting the Platform, its users and ourselves — Article 6(1)(f)
Responding to support requests and handling complaintsCorrespondence, accountArticles 6(1)(b) and 6(1)(f)
Measuring use of the website through analyticsTechnical, usageYour consent — Article 6(1)(a)
Sending marketing communicationsContact details, preferencesYour consent — Article 6(1)(a)
Establishing, exercising or defending legal claims, and responding to lawful requests from authoritiesAny of the above, as relevantArticles 6(1)(c) and 6(1)(f)

Where we rely on legitimate interests, we have weighed that interest against your rights and freedoms. You may request a summary of that assessment at [email protected], and you have the right to object as described in section 10.

Where we rely on consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out beforehand.

5. Whether you must provide personal data

Registration data is necessary to open an account. Verification data is necessary before you can deposit, withdraw or commit funds, and is required of us and of our regulated partners by anti-money-laundering law.

If you do not provide it, we cannot open or maintain an account for you, and services that depend on verification are unavailable. Analytics and marketing data is optional, and declining it has no effect on your access to the Platform.

6. Automated decision-making

Certain decisions are taken by automated means.

DecisionWhat it doesPossible effect
Verification and screening outcomeCompares your data against identity, sanctions, politically exposed person and adverse media sources and assigns a risk outcomeMay prevent onboarding, suspend your account, or block a transaction
Jurisdictional and eligibility gatingCompares your country of residence and verification level against the rules in the Investor Eligibility documentMay prevent access to a product or to the Platform

Where such a decision produces legal effects concerning you or similarly significantly affects you, you have the right to obtain human intervention, to express your point of view and to contest the decision. Write to [email protected] and the decision will be reviewed by a person, not by the system that produced it.

We do not use personal data to build advertising profiles. We do not sell personal data and do not make it available to data brokers.

7. Who receives personal data

We name the recipients that matter most to you — those that receive your identity documents, those that hold assets, and those that host or deliver the Platform — and describe the remainder by category.

7.1 Named recipients

RecipientRoleLocation
Sum and Substance Ltd ("Sumsub")Identity verification, sanctions and politically exposed person screening, and Travel Rule messagingUnited Kingdom
STELLARIA, S.A.Holds and administers crypto-assets recorded in your Platform walletPanama
Liminal Custody Pte. Ltd.Custody technology used by the crypto partnerSingapore
Cloudflare, Inc.Delivers the website and filters hostile traffic. It receives the IP address of each request. We do not use Cloudflare to measure visits or to build profilesUnited States and Cloudflare's global network
Google Ireland Limited, with Google LLCAnalytics on the website, subject to your consentEuropean Union and United States
MapTiler AGMap imagery in the application. Your browser requests tiles from MapTiler; the cartographic data is OpenStreetMap. MapTiler receives your IP address and the map area displayedSwitzerland

7.2 Categories of other recipients

  • Cloud hosting and infrastructure providers — operation of the Platform and storage of its data, in jurisdictions in which those providers operate, including outside the European Economic Area.
  • Payment providers and financial counterparties — where you instruct a payment or enter into a transaction, limited to what is necessary to execute and evidence it.
  • Issuers of investment products — where you commit to a deal or pool.
  • Duplicate-finance checking services — where a transaction is presented for finance, limited to what is necessary to establish whether it has already been financed elsewhere.
  • Communications and support providers — email delivery and support tooling.
  • Professional advisers — lawyers, auditors and accountants, bound by professional confidentiality.
  • Competent authorities — regulators, tax authorities, law enforcement and courts, where disclosure is legally required or is necessary to establish, exercise or defend legal claims.
  • A successor — where our business or part of it is transferred, subject to this policy continuing to apply.

Processors act only on documented instructions and under a contract meeting the requirements of Article 28 GDPR.

8. International transfers

Certain recipients are located in countries the European Commission has recognised as providing an adequate level of protection, and no further safeguard is required for them:

RecipientBasis
Google LLC, Cloudflare, Inc. — United StatesEU–US Data Privacy Framework
Sum and Substance Ltd — United KingdomAdequacy decision
MapTiler AG — SwitzerlandAdequacy decision

The partner controllers named in section 2.2 are established in the Cayman Islands and in Panama, and neither country has an adequacy decision. At present we make no transfer of personal data to them for the purpose of onboarding a person in the European Economic Area as an investor or as a client of a crypto-asset service, because those products are not offered there. Should that change, transfers will be made under the European Commission's Standard Contractual Clauses, supplemented where necessary by additional technical and organisational measures following an assessment of the law and practice of the destination country, and those safeguards will be in place before any such transfer begins.

You may request a copy of the safeguards applying to a specific transfer by writing to [email protected].

9. Retention

CategoryRetention periodReason
Identity verification files, supporting documents and screening results5 years after the end of the relationshipAnti-money-laundering record-keeping
Transaction and settlement records5 years after the transactionAnti-money-laundering and accounting record-keeping
Correspondence relating to disputes and complaints6 years after the matter is closedThe general limitation period for bringing claims
Marketing consents and withdrawalsUntil withdrawn, and 2 years thereafterEvidence that processing was lawful under Article 7(1)
Account, profile and session logsDuration of the relationship plus 12 monthsSecurity and incident investigation
Data from an incomplete registration90 daysNo basis to retain it longer

Where a longer period is required by law, by a lawful order, or in order to establish, exercise or defend a legal claim, we retain the data for that longer period and for that purpose alone. At the end of the applicable period, data is deleted or irreversibly anonymised.

10. Your rights

Subject to the conditions and exceptions in applicable law, you have the right to:

  1. be informed about how your data is processed, which is the purpose of this policy;
  2. access the personal data we hold about you and obtain a copy;
  3. rectify inaccurate data and complete incomplete data;
  4. erase your data where no overriding basis exists for us to keep it. Anti-money-laundering records cannot be erased before the end of the statutory retention period;
  5. restrict processing while a dispute about accuracy or lawfulness is resolved;
  6. object to processing based on legitimate interests, and at any time and without giving reasons to processing for direct marketing;
  7. receive your data in a portable form where processing is based on consent or on a contract and is carried out by automated means;
  8. withdraw consent at any time, without affecting processing carried out beforehand;
  9. not be subject to a decision based solely on automated processing that produces legal effects concerning you or similarly significantly affects you, as described in section 6.

To exercise any of these rights, including erasure of your account and the data associated with it, write to [email protected]. We respond within one month, and may extend that period by two further months where a request is complex, in which case we will tell you within the first month. We may ask you to confirm your identity before acting.

You also have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work, or the place of the alleged infringement. That right does not depend on contacting us first, although we would welcome the opportunity to resolve the matter.

11. Security

We apply technical and organisational measures appropriate to the risk, as Article 32 GDPR requires. These include encryption of data in transit, access control on a need-to-know basis, restriction of access to verification files to the compliance function, and logging of administrative access. We do not describe our security measures in more detail here, because doing so would itself weaken them.

No system can be guaranteed secure. If a breach occurs that is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay, and we will notify the competent supervisory authority as required.

12. Children

The Platform is available only to individuals aged 18 or over. We do not knowingly process the personal data of children, and will delete any such data if we learn that we have.

13. Changes

We update this policy when our processing changes. The last-updated date changes with it, and we notify you of material changes by email or by prominent notice on the Platform before they take effect.

This policy is published in English only. Any translation is provided for convenience, and the English text prevails.

14. Contact

Privacy enquiries and requests to exercise your rights: [email protected].

Our representative in the European Union under Article 27 GDPR is identified in section 2.3.

EDENEX - FZCO Premises No. DSO-IFZA, IFZA Properties Dubai Silicon Oasis, Dubai, United Arab Emirates