1. Who is responsible
Jadenex is the controller of the personal data described in this policy. The legal name, registered office and contact details of the controller are published on the company page.
Questions about this policy, and requests to exercise a right described in it, should be sent to the data protection team at the address published on the contact page.
2. Personal data collected
Jadenex collects the following categories of personal data.
| Category | Examples | Source |
|---|---|---|
| Identity data | Full legal name, date of birth, nationality, identity document number and image, photograph taken during verification | You and the verification provider |
| Contact data | Email address, telephone number, residential address | You |
| Financial data | Bank account details, payment card details, digital asset addresses, balances and transaction history | You and payment providers |
| Transaction data | Orders, trades, deposits, withdrawals, staking subscriptions and card transactions | Your use of the service |
| Screening data | Sanctions, politically exposed person and adverse media screening results, blockchain analytics results | Screening providers |
| Technical data | Internet protocol address, device identifiers, browser type, operating system, session and login records | Your device |
| Usage data | Pages viewed, features used, time and duration of use | Your device, subject to cookie consent |
| Communications data | Messages to support, complaint records, call recordings where calls are recorded | You |
3. Purposes and legal bases
Personal data is processed for the purposes set out below. Each purpose is matched with the legal basis relied on.
| Purpose | Legal basis |
|---|---|
| Opening and operating your account and providing the exchange service | Performance of a contract with you |
| Verifying your identity and screening you against sanctions and politically exposed person lists | Compliance with a legal obligation |
| Monitoring transactions and market activity for financial crime and market abuse | Compliance with a legal obligation |
| Reporting suspicious activity to the competent authority | Compliance with a legal obligation |
| Retaining records for the periods required by law | Compliance with a legal obligation |
| Securing the service, preventing fraud and investigating incidents | Legitimate interests in protecting the service and its users |
| Responding to your enquiries and handling complaints | Performance of a contract with you and legitimate interests |
| Measuring how the website is used | Your consent, given through the cookie banner |
| Sending service messages about your account | Performance of a contract with you |
| Sending marketing about Jadenex products | Your consent, which you may withdraw at any time |
| Establishing, exercising or defending legal claims | Legitimate interests in protecting our legal position |
Where processing relies on legitimate interests, a balancing assessment has been carried out and is available on request.
4. Biometric and special category data
Identity verification may involve a facial image compared against the image on your identity document. Where this comparison constitutes processing of biometric data for the purpose of unique identification, it is carried out on the basis of substantial public interest in the prevention and detection of financial crime, and where required your explicit consent is obtained before the check is performed.
No other special category data is collected deliberately. If you provide such data in a message it is not used for any purpose other than responding to you.
5. Who personal data is shared with
Personal data is shared only where there is a lawful basis to do so, and with the following categories of recipient.
- Identity verification and screening providers engaged to perform checks required by law.
- Payment providers, banking partners, card issuers and card scheme operators, to the extent needed to process a payment or to operate the card.
- Custody and blockchain analytics providers engaged to secure client assets and to screen transfers.
- Cloud hosting, communications and support providers acting under contract as processors.
- Competent authorities, law enforcement agencies, regulators and tax authorities where disclosure is required by law or by a valid request.
- Professional advisers such as auditors and lawyers acting under a duty of confidence.
- An acquirer or successor in the event of a corporate transaction, subject to the same protections.
Personal data is not sold and is not shared for another party to use for its own marketing.
6. International transfers
Personal data may be transferred to a country other than the country in which it was collected. Where a transfer is made to a country that has not been recognised as providing an adequate level of protection, the transfer is made under standard contractual clauses or another lawful transfer mechanism, supported by a transfer risk assessment. A copy of the mechanism relied on is available on request.
7. Retention
Personal data is kept only as long as necessary for the purpose for which it was collected, subject to the minimum periods set by law.
| Record | Retention period |
|---|---|
| Identification and verification records | At least five years after the end of the business relationship |
| Transaction records including orders, trades and funding | At least five years after the transaction |
| Suspicious activity reports and supporting records | At least five years after the report |
| Communications with support and complaint records | Six years after the matter is closed |
| Technical and security logs | Twelve months, unless retained for an investigation |
| Marketing consent records | Until consent is withdrawn and for two years thereafter |
Where a longer period is required by a legal obligation, a regulatory request or an ongoing claim, records are retained until that requirement ends.
8. Your rights
Subject to the conditions set by applicable law, you have the following rights.
- The right to be informed about how your personal data is processed, which this policy provides.
- The right of access to a copy of the personal data held about you.
- The right to have inaccurate personal data corrected.
- The right to erasure where the data is no longer necessary and no legal obligation requires it to be kept.
- The right to restrict processing while an objection or a correction is considered.
- The right to data portability for data you provided which is processed by automated means on the basis of consent or contract.
- The right to object to processing carried out on the basis of legitimate interests.
- The right to withdraw consent at any time where processing relies on consent, without affecting processing carried out before withdrawal.
- The right not to be subject to a decision based solely on automated processing which produces a legal or similarly significant effect, other than where that decision is permitted by law.
- The right to complain to a supervisory authority.
A request is answered within one month of receipt. Where a request is complex or where several requests are made, that period may be extended by two further months and you are told of the extension and the reason for it within the first month. No fee is charged unless a request is manifestly unfounded or excessive.
9. Automated decision making
Automated screening is used in identity verification, sanctions screening and transaction monitoring. An alert generated by an automated process does not by itself determine an outcome. A decision to refuse an application, to block a transaction or to close an account is reviewed by a member of the compliance team before it takes effect, except where an immediate block is required by law.
Where a decision affects you, you may ask for the decision to be reviewed and may express your point of view. Some information cannot be disclosed where disclosure would prejudice the prevention or detection of financial crime.
10. Security of personal data
Technical and organisational measures are applied to protect personal data, including encryption in transit and at rest, access control on the principle of least privilege, segregation of production environments, logging and monitoring, and staff training.
Where a personal data breach is likely to result in a risk to the rights and freedoms of individuals, it is notified to the supervisory authority without undue delay and, where the risk is high, to the individuals affected.
11. Cookies
Cookies and similar technologies are described in the cookie policy. Only strictly necessary cookies are set without your consent.
12. Changes to this policy
This policy may be updated. The version number and the date of the last update are shown at the top of this page. Where a change is material, notice is given before it takes effect.