ABEX Privacy Notice
Last updated: 24 September 2026
ABEX is committed to protecting your personal data. This notice explains what personal data we collect, why we collect it, who we share it with, how long we keep it, and what rights you have. It applies across the ABEX group.
Please read it carefully. If you have any questions, contact us at info@abex.capital.
1. Who we are
“ABEX” means ABEX Capital Limited and its subsidiaries. The entity that is your data controller depends on how you deal with us:
| Entity | Registration | Controller for |
|---|---|---|
Entity ABEX Capital Limited | Registration England and Wales, company number 14607492. | Controller for Visitors to abex.capital, enquiries and prospective business relationships, suppliers and service providers, recruitment, and group functions. |
Entity ABEX UK Derivatives Limited | Registration England and Wales, company number 16138627. Authorised and regulated by the Financial Conduct Authority, FRN 1033792. | Controller for Clients and counterparties of its regulated business, and the individuals who represent them. |
Entity ABEX Capital UK Limited | Registration England and Wales, company number 12328188. Registered with the Financial Conduct Authority, FRN 933825, as a cryptoasset business under the Money Laundering Regulations 2017. | Controller for Clients and counterparties of its cryptoasset business, and the individuals who represent them. |
Entity ABEX HK Limited | Registration Hong Kong, company number 78615279, at 3504-06, 35/F, One Taikoo Place, 979 King’s Road, Quarry Bay, Hong Kong. Provides technology and quantitative solutions only; carries on no regulated activity. | Controller for Its own suppliers and personnel. It also receives personal data from the UK entities — see section 8. |
The registered office of each UK entity is Mutual House, 4th Floor, 70 Conduit Street, London W1S 2GF.
Each entity is an independent controller for the personal data it collects for its own purposes. Where more than one entity is involved — for example where an enquiry becomes a client relationship — the receiving entity becomes controller of that data in its own right from that point.
We have not appointed a Data Protection Officer, as we are not required to. Responsibility for data protection sits with our Compliance function.
2. Who this notice is for
This notice applies if you:
visit our website at abex.capital, including our API documentation;
use the ABEX client platform, API or GUI;
contact us, make an enquiry, or discuss a possible business relationship with us;
are a client or counterparty, or represent one, including a director, beneficial owner or authorised signatory;
supply goods or services to us, or represent an organisation that does;
meet us at an event, or visit our office; or
apply for a role with us.
ABEX provides services only to professional clients and eligible counterparties. We do not provide services to retail clients or consumers.
3. What we collect, why, and our lawful basis
| Purpose | Personal data used | Lawful basis |
|---|---|---|
Purpose Responding to your enquiry and corresponding with you | Personal data used Name, work email, telephone, employer, role, country, contents of your message | Lawful basis Legitimate interests in responding to enquiries addressed to us (Article 6(1)(f)) |
Purpose Assessing and progressing a possible business relationship | Personal data used As above, plus notes of our discussions | Lawful basis Legitimate interests in developing business relationships; steps prior to entering a contract at your request (Article 6(1)(b)) |
Purpose Operating and securing our client platform | Personal data used Server log information, including IP address, the pages requested and the time of the request; sign-in records, including IP address, browser, and the time and outcome of each sign-in | Lawful basis Legitimate interests in running a secure and functioning platform |
Purpose Onboarding a client or counterparty, and carrying out customer due diligence | Personal data used Name, date of birth, nationality, address, identification documents, proof of address, role, ownership and control information, source of funds and wealth, politically exposed person status | Lawful basis Legal obligation under the Money Laundering Regulations 2017 (Article 6(1)(c)); performance of a contract or steps prior to it (Article 6(1)(b)) |
Purpose Screening against sanctions, politically exposed person and adverse media sources, and ongoing monitoring | Personal data used As above, plus screening results and risk ratings | Lawful basis Legal obligation (Article 6(1)(c)); and, so far as the processing is necessary for the detection, investigation or prevention of crime, the recognised legitimate interest at Article 6(1)(ea) and Annex 1. Where this involves criminal offence data, we rely on the conditions in Schedule 1 of the Data Protection Act 2018, including preventing or detecting unlawful acts |
Purpose Providing our services, including arranging, transmitting and executing orders, and managing the relationship | Personal data used Contact details, account and instruction records, transaction and order records, correspondence | Lawful basis Performance of a contract (Article 6(1)(b)) |
Purpose Recording telephone and electronic communications relating to orders | Personal data used Recordings, message content, metadata | Lawful basis Legal obligation under the FCA Handbook (Article 6(1)(c)). Where recording is not required, legitimate interests in maintaining accurate records |
Purpose Regulatory reporting, record-keeping and responding to regulators and law enforcement | Personal data used Any of the above | Lawful basis Legal obligation (Article 6(1)(c)) |
Purpose Managing suppliers and service providers, including due diligence and outsourcing oversight | Personal data used Business contact details, role, records of dealings | Lawful basis Performance of a contract; legal obligation; legitimate interests in managing our supply chain |
Purpose Attending or hosting events, and managing visitors to our office | Personal data used Name, business contact details, employer, role, visitor records | Lawful basis Legitimate interests in business development and premises security |
Purpose Recruitment | Personal data used Name, contact details, CV, education and employment history, references, and where lawful and proportionate to the role, background screening including right to work, credit and criminal records | Lawful basis Steps prior to entering a contract at your request (Article 6(1)(b)); legal obligation, including fit and proper assessments under the Senior Managers and Certification Regime (Article 6(1)(c)); legitimate interests in running a fair recruitment process |
Purpose Handling complaints, including data protection complaints | Personal data used Contact details, complaint records, related correspondence and transaction records | Lawful basis Legal obligation (Article 6(1)(c)); legitimate interests in resolving complaints |
Purpose Establishing, exercising or defending legal claims, and protecting our business and systems | Personal data used Any of the above | Lawful basis Legitimate interests in protecting our legal position and our infrastructure |
Purpose A sale, merger or restructuring of our business | Personal data used Any of the above | Lawful basis Legitimate interests in enabling the business to continue |
Where we rely on legitimate interests, we have assessed whether those interests are overridden by your interests, rights and freedoms, and concluded that they are not. You can ask us for that assessment. Recognised legitimate interests under Article 6(1)(ea) do not require that assessment, but all other data protection principles still apply to them.
Where we rely on consent, you can withdraw it at any time. Withdrawal does not affect the lawfulness of anything done before it.
We do not collect special category personal data through our website, and you should not send it to us by email or through any form on our site.
4. Where we get your information
Most personal data comes directly from you. We also receive it from:
publicly available sources, including public registers and business contact databases;
identity verification, sanctions screening and adverse media providers;
your employer, and other individuals at your organisation;
introducers, event organisers, banks, payment providers and trading venues; and
recruitment and background screening providers.
Where we obtain personal data from a source other than you, we provide the information required by Article 14 UK GDPR within the period that article requires.
5. Cookies and similar technologies
Our website does not use cookies, analytics, advertising or tracking technologies. We do not track or profile visitors, and we do not build a picture of who you are or what you do across the internet.
We do store a small amount of information in your browser, and our client platform uses cookies where they are strictly necessary. This section explains all of it.
What our website stores in your browser
| What | Where | Why | Basis | How long |
|---|---|---|---|---|
What Your scroll position | Where Session storage on your device | Why So that returning to a page you have already viewed takes you back to where you were, rather than to the top | Basis Strictly necessary to provide the page navigation you asked for | How long Deleted when you close the tab |
What A reload marker | Where Session storage on your device | Why So that, if we publish an update while you have a page open, the page reloads once to fetch it rather than repeatedly | Basis Strictly necessary to provide the page you asked for | How long Deleted on the next page load |
Neither is sent to us as a record of your activity, neither is used to identify or track you, and neither requires your consent, because storage that is strictly necessary to provide a service you have asked for falls outside the consent requirement in Regulation 6 of PECR.
Cookies on our client platform
Our client platform uses cookies and similar storage and access technologies. A cookie is a small file placed on your device that lets a website recognise it.
Regulation 6 of PECR prohibits storing information, or gaining access to information stored, on your device unless one of the exceptions in Schedule A1 applies or you consent. Here is what we use and the basis for each:
| What | Where | Why | Basis | How long |
|---|---|---|---|---|
What Your sign-in session | Where Cookies and local storage, on the client platform and its sign-in page | Why To keep you signed in and to authenticate you between requests | Basis Strictly necessary to provide the service you asked for | How long Until you sign out |
What Protecting your sign-in | Where Cookies on the client platform’s sign-in page | Why To recognise your device and protect your account against automated attacks | Basis Strictly necessary to keep the service you asked for secure | How long 12 months |
What Server routing | Where Cookies on the client platform | Why So that your requests keep reaching the same server while you view your orders | Basis Strictly necessary to provide the service you asked for | How long 7 days |
What Your settings | Where Local storage, on the client platform only | Why So the platform stays as you set it up: filters, sorting and views; table columns and page sizes; panel, sidebar and dashboard layout; light or dark mode; and your recent order-form selections | Basis Strictly necessary — recording a selection you have made | How long Until you clear it from your browser |
What Technical information | Where Local and session storage, on the client platform only | Why To coordinate the platform across your open tabs, keep your permissions up to date, and prevent repeated redirects while you sign in | Basis Strictly necessary to provide the service you asked for | How long Until you close the tab or clear it from your browser |
Strictly necessary technologies are set without your consent because the platform cannot provide what you have asked for without them. Each of the above is used for the single purpose shown and for nothing else, and none is used for analytics, advertising or tracking. You can also block or delete cookies through your browser, but the platform may then not keep you signed in or remember your settings.
Content loaded from other websites
No page on our website loads content from any other company. Typefaces, scripts and all other assets are served from our own infrastructure, so your browser does not connect to any third party when you use our site.
Server logs
Our website does not keep logs of visitors’ requests. Our client platform keeps standard server logs, which record the internet protocol address of the device requesting a page, which page was requested, and when. We use these only to keep the platform available and secure. They are not used to identify or track individual users. Our sign-in provider also keeps a record of each sign-in to the client platform — your IP address, your browser, and when and whether you signed in — for 30 days, to protect your account.
Changes
If we introduce cookies, analytics or any similar technology that is not strictly necessary, we will update this notice and put a consent mechanism in place before doing so.
6. Marketing
We will only send you marketing communications where you have asked to receive them, or where you are a corporate contact and we are entitled to do so on the basis of legitimate interests. Every message contains an unsubscribe link, and you can opt out at any time by contacting info@abex.capital. You have an absolute right to object to direct marketing under Article 21(2) UK GDPR.
Service communications — notices about changes to our services, our terms, or applicable law — are not marketing and cannot be opted out of while a relationship is in place.
7. Who we share it with
We do not sell your personal data and we do not share it for third-party marketing.
We share it with:
other ABEX entities, where necessary for the purposes in this notice;
service providers acting on our behalf, including hosting and infrastructure, email security and archiving, customer relationship management, identity verification and screening, and recruitment providers, each under written terms compliant with Article 28 UK GDPR;
trading venues, brokers, custodians, banks and payment providers, where necessary to provide our services;
professional advisers, including lawyers, auditors, insurers and compliance consultants;
regulators, law enforcement and other authorities, where required or permitted by law, including reports of suspicious activity; and
a buyer or prospective buyer of our business, and its advisers.
8. Where we store it, and transfers outside the UK
We store personal data on Microsoft Azure and Amazon Web Services infrastructure in the United Kingdom. Our trading system is deployed on Amazon Web Services infrastructure in Ireland. Email is secured and archived through Mimecast.
Where we transfer personal data outside the United Kingdom, we do so under Chapter V of the UK GDPR, relying on:
UK adequacy regulations, where the destination country has been recognised as offering an adequate level of protection. This covers the European Economic Area, and so covers our Irish deployment;
the International Data Transfer Agreement issued by the Information Commissioner, or the UK Addendum to the EU Standard Contractual Clauses; or
where appropriate, a derogation under Article 49 UK GDPR.
Hong Kong is not covered by UK adequacy regulations. Where personal data is transferred to, or accessible from, ABEX HK Limited, that transfer is made under an intra-group agreement incorporating the International Data Transfer Agreement, supported by a transfer risk assessment.
Where a transfer is to a country without UK adequacy, we assess whether the standard of protection for the individual is materially lower than under UK law, in line with ICO guidance. You can ask us for a copy of the safeguards in place.
9. How long we keep it
| Data | Retention |
|---|---|
Data Enquiries and correspondence where no relationship follows | Retention 24 months from last contact |
Data Client and counterparty due diligence records, and records of transactions | Retention 5 years from the end of the business relationship, as required by the Money Laundering Regulations 2017, extended only where permitted or required |
Data Recorded communications relating to orders | Retention 5 years, or 7 years where the FCA requires it |
Data Client platform sign-in records | Retention 30 days. Your account keeps only the time and IP address of your most recent sign-in, until the account is closed |
Data Client platform server logs | Retention 120 days. Logs are searchable for up to 90 days, then held in archive until deleted |
Data Marketing contacts | Retention Until you unsubscribe, or we identify you as inactive |
Data Supplier, event and visitor records | Retention Duration of the relationship, plus 24 months |
Data Unsuccessful job applications | Retention 12 months from the end of the recruitment process |
We keep personal data for longer where the law requires it, or where we need it to establish, exercise or defend a legal claim. We may anonymise data so it can no longer be associated with you, and use it indefinitely in that form.
10. How we protect it
We maintain technical and organisational measures appropriate to the risk, including access controls, encryption in transit, role-based access, and supplier due diligence. ABEX has completed a SOC 2 Type II examination covering its operational controls.
Transmission over the internet is never entirely secure. Where we have given you a password or credentials, you are responsible for keeping them confidential.
11. Your rights
You have the right to:
access the personal data we hold about you and receive a copy;
rectify inaccurate or incomplete data;
erase your data in certain circumstances;
restrict our processing in certain circumstances;
portability — receive data you provided in a structured, commonly used, machine-readable format, and have it sent to another controller where technically feasible;
object to processing based on our legitimate interests, and an absolute right to object to direct marketing; and
withdraw consent where we rely on it.
Some rights are limited where we process your data to meet our legal obligations. In particular, we cannot erase records we are required to keep under the Money Laundering Regulations or the FCA Handbook; the right to object does not apply to processing we are legally required to carry out; and we may be unable to disclose information where doing so would prejudice the prevention or detection of financial crime. Where a right is not available to you, we will explain why.
To exercise a right, contact info@abex.capital. We respond within the period the law allows, normally one month from the point at which we have the information we need to identify you and deal with your request. We will tell you if a complex request requires longer.
Automated decisions
We do not make significant decisions about you — decisions producing legal effects or similarly significant effects — based solely on automated processing without meaningful human involvement. Our execution algorithms make decisions about orders, not about people.
If that position changes, we will tell you, and you will have the safeguards in Article 22C UK GDPR: information about the decision, the opportunity to make representations, human intervention on your request, and the ability to contest the decision.
Complaints
If you are unhappy with how we have handled your personal data, please tell us first, at info@abex.capital. We will acknowledge your complaint within 30 days, make reasonable enquiries, keep you informed of progress, and tell you the outcome in plain language.
You can also complain to the Information Commissioner’s Office, the UK supervisory authority, at ico.org.uk or on 0303 123 1113. Complaining to us does not affect that right.
12. Children
Our services are not directed at anyone under 18 and we do not knowingly collect their personal data. If we learn that we have, we will delete it.
13. Changes
We review this notice regularly and will post any updated version here. Where a change is material, we will take reasonable steps to bring it to your attention.
14. Contact
ABEX Capital Limited
For the attention of the Compliance function
Mutual House, 4th Floor, 70 Conduit Street, London W1S 2GF
info@abex.capital