HomeProductNewsContact Us

ABEX Privacy Notice

Last updated: 24 September 2026

ABEX is committed to protecting your personal data. This notice explains what personal data we collect, why we collect it, who we share it with, how long we keep it, and what rights you have. It applies across the ABEX group.

Please read it carefully. If you have any questions, contact us at info@abex.capital.

1. Who we are

“ABEX” means ABEX Capital Limited and its subsidiaries. The entity that is your data controller depends on how you deal with us:

ABEX entities and the personal data each controls
EntityRegistrationController for
Entity
ABEX Capital Limited
Registration
England and Wales, company number 14607492.
Controller for
Visitors to abex.capital, enquiries and prospective business relationships, suppliers and service providers, recruitment, and group functions.
Entity
ABEX UK Derivatives Limited
Registration
England and Wales, company number 16138627. Authorised and regulated by the Financial Conduct Authority, FRN 1033792.
Controller for
Clients and counterparties of its regulated business, and the individuals who represent them.
Entity
ABEX Capital UK Limited
Registration
England and Wales, company number 12328188. Registered with the Financial Conduct Authority, FRN 933825, as a cryptoasset business under the Money Laundering Regulations 2017.
Controller for
Clients and counterparties of its cryptoasset business, and the individuals who represent them.
Entity
ABEX HK Limited
Registration
Hong Kong, company number 78615279, at 3504-06, 35/F, One Taikoo Place, 979 King’s Road, Quarry Bay, Hong Kong. Provides technology and quantitative solutions only; carries on no regulated activity.
Controller for
Its own suppliers and personnel. It also receives personal data from the UK entities — see section 8.

The registered office of each UK entity is Mutual House, 4th Floor, 70 Conduit Street, London W1S 2GF.

Each entity is an independent controller for the personal data it collects for its own purposes. Where more than one entity is involved — for example where an enquiry becomes a client relationship — the receiving entity becomes controller of that data in its own right from that point.

We have not appointed a Data Protection Officer, as we are not required to. Responsibility for data protection sits with our Compliance function.

2. Who this notice is for

This notice applies if you:

  • visit our website at abex.capital, including our API documentation;

  • use the ABEX client platform, API or GUI;

  • contact us, make an enquiry, or discuss a possible business relationship with us;

  • are a client or counterparty, or represent one, including a director, beneficial owner or authorised signatory;

  • supply goods or services to us, or represent an organisation that does;

  • meet us at an event, or visit our office; or

  • apply for a role with us.

ABEX provides services only to professional clients and eligible counterparties. We do not provide services to retail clients or consumers.

3. What we collect, why, and our lawful basis

Processing purposes, the personal data used, and our lawful basis
PurposePersonal data usedLawful basis
Purpose
Responding to your enquiry and corresponding with you
Personal data used
Name, work email, telephone, employer, role, country, contents of your message
Lawful basis
Legitimate interests in responding to enquiries addressed to us (Article 6(1)(f))
Purpose
Assessing and progressing a possible business relationship
Personal data used
As above, plus notes of our discussions
Lawful basis
Legitimate interests in developing business relationships; steps prior to entering a contract at your request (Article 6(1)(b))
Purpose
Operating and securing our client platform
Personal data used
Server log information, including IP address, the pages requested and the time of the request; sign-in records, including IP address, browser, and the time and outcome of each sign-in
Lawful basis
Legitimate interests in running a secure and functioning platform
Purpose
Onboarding a client or counterparty, and carrying out customer due diligence
Personal data used
Name, date of birth, nationality, address, identification documents, proof of address, role, ownership and control information, source of funds and wealth, politically exposed person status
Lawful basis
Legal obligation under the Money Laundering Regulations 2017 (Article 6(1)(c)); performance of a contract or steps prior to it (Article 6(1)(b))
Purpose
Screening against sanctions, politically exposed person and adverse media sources, and ongoing monitoring
Personal data used
As above, plus screening results and risk ratings
Lawful basis
Legal obligation (Article 6(1)(c)); and, so far as the processing is necessary for the detection, investigation or prevention of crime, the recognised legitimate interest at Article 6(1)(ea) and Annex 1. Where this involves criminal offence data, we rely on the conditions in Schedule 1 of the Data Protection Act 2018, including preventing or detecting unlawful acts
Purpose
Providing our services, including arranging, transmitting and executing orders, and managing the relationship
Personal data used
Contact details, account and instruction records, transaction and order records, correspondence
Lawful basis
Performance of a contract (Article 6(1)(b))
Purpose
Recording telephone and electronic communications relating to orders
Personal data used
Recordings, message content, metadata
Lawful basis
Legal obligation under the FCA Handbook (Article 6(1)(c)). Where recording is not required, legitimate interests in maintaining accurate records
Purpose
Regulatory reporting, record-keeping and responding to regulators and law enforcement
Personal data used
Any of the above
Lawful basis
Legal obligation (Article 6(1)(c))
Purpose
Managing suppliers and service providers, including due diligence and outsourcing oversight
Personal data used
Business contact details, role, records of dealings
Lawful basis
Performance of a contract; legal obligation; legitimate interests in managing our supply chain
Purpose
Attending or hosting events, and managing visitors to our office
Personal data used
Name, business contact details, employer, role, visitor records
Lawful basis
Legitimate interests in business development and premises security
Purpose
Recruitment
Personal data used
Name, contact details, CV, education and employment history, references, and where lawful and proportionate to the role, background screening including right to work, credit and criminal records
Lawful basis
Steps prior to entering a contract at your request (Article 6(1)(b)); legal obligation, including fit and proper assessments under the Senior Managers and Certification Regime (Article 6(1)(c)); legitimate interests in running a fair recruitment process
Purpose
Handling complaints, including data protection complaints
Personal data used
Contact details, complaint records, related correspondence and transaction records
Lawful basis
Legal obligation (Article 6(1)(c)); legitimate interests in resolving complaints
Purpose
Establishing, exercising or defending legal claims, and protecting our business and systems
Personal data used
Any of the above
Lawful basis
Legitimate interests in protecting our legal position and our infrastructure
Purpose
A sale, merger or restructuring of our business
Personal data used
Any of the above
Lawful basis
Legitimate interests in enabling the business to continue

Where we rely on legitimate interests, we have assessed whether those interests are overridden by your interests, rights and freedoms, and concluded that they are not. You can ask us for that assessment. Recognised legitimate interests under Article 6(1)(ea) do not require that assessment, but all other data protection principles still apply to them.

Where we rely on consent, you can withdraw it at any time. Withdrawal does not affect the lawfulness of anything done before it.

We do not collect special category personal data through our website, and you should not send it to us by email or through any form on our site.

4. Where we get your information

Most personal data comes directly from you. We also receive it from:

  • publicly available sources, including public registers and business contact databases;

  • identity verification, sanctions screening and adverse media providers;

  • your employer, and other individuals at your organisation;

  • introducers, event organisers, banks, payment providers and trading venues; and

  • recruitment and background screening providers.

Where we obtain personal data from a source other than you, we provide the information required by Article 14 UK GDPR within the period that article requires.

5. Cookies and similar technologies

Our website does not use cookies, analytics, advertising or tracking technologies. We do not track or profile visitors, and we do not build a picture of who you are or what you do across the internet.

We do store a small amount of information in your browser, and our client platform uses cookies where they are strictly necessary. This section explains all of it.

What our website stores in your browser

What our website stores in your browser
WhatWhereWhyBasisHow long
What
Your scroll position
Where
Session storage on your device
Why
So that returning to a page you have already viewed takes you back to where you were, rather than to the top
Basis
Strictly necessary to provide the page navigation you asked for
How long
Deleted when you close the tab
What
A reload marker
Where
Session storage on your device
Why
So that, if we publish an update while you have a page open, the page reloads once to fetch it rather than repeatedly
Basis
Strictly necessary to provide the page you asked for
How long
Deleted on the next page load

Neither is sent to us as a record of your activity, neither is used to identify or track you, and neither requires your consent, because storage that is strictly necessary to provide a service you have asked for falls outside the consent requirement in Regulation 6 of PECR.

Cookies on our client platform

Our client platform uses cookies and similar storage and access technologies. A cookie is a small file placed on your device that lets a website recognise it.

Regulation 6 of PECR prohibits storing information, or gaining access to information stored, on your device unless one of the exceptions in Schedule A1 applies or you consent. Here is what we use and the basis for each:

Cookies and browser storage used by our client platform
WhatWhereWhyBasisHow long
What
Your sign-in session
Where
Cookies and local storage, on the client platform and its sign-in page
Why
To keep you signed in and to authenticate you between requests
Basis
Strictly necessary to provide the service you asked for
How long
Until you sign out
What
Protecting your sign-in
Where
Cookies on the client platform’s sign-in page
Why
To recognise your device and protect your account against automated attacks
Basis
Strictly necessary to keep the service you asked for secure
How long
12 months
What
Server routing
Where
Cookies on the client platform
Why
So that your requests keep reaching the same server while you view your orders
Basis
Strictly necessary to provide the service you asked for
How long
7 days
What
Your settings
Where
Local storage, on the client platform only
Why
So the platform stays as you set it up: filters, sorting and views; table columns and page sizes; panel, sidebar and dashboard layout; light or dark mode; and your recent order-form selections
Basis
Strictly necessary — recording a selection you have made
How long
Until you clear it from your browser
What
Technical information
Where
Local and session storage, on the client platform only
Why
To coordinate the platform across your open tabs, keep your permissions up to date, and prevent repeated redirects while you sign in
Basis
Strictly necessary to provide the service you asked for
How long
Until you close the tab or clear it from your browser

Strictly necessary technologies are set without your consent because the platform cannot provide what you have asked for without them. Each of the above is used for the single purpose shown and for nothing else, and none is used for analytics, advertising or tracking. You can also block or delete cookies through your browser, but the platform may then not keep you signed in or remember your settings.

Content loaded from other websites

No page on our website loads content from any other company. Typefaces, scripts and all other assets are served from our own infrastructure, so your browser does not connect to any third party when you use our site.

Server logs

Our website does not keep logs of visitors’ requests. Our client platform keeps standard server logs, which record the internet protocol address of the device requesting a page, which page was requested, and when. We use these only to keep the platform available and secure. They are not used to identify or track individual users. Our sign-in provider also keeps a record of each sign-in to the client platform — your IP address, your browser, and when and whether you signed in — for 30 days, to protect your account.

If we introduce cookies, analytics or any similar technology that is not strictly necessary, we will update this notice and put a consent mechanism in place before doing so.

6. Marketing

We will only send you marketing communications where you have asked to receive them, or where you are a corporate contact and we are entitled to do so on the basis of legitimate interests. Every message contains an unsubscribe link, and you can opt out at any time by contacting info@abex.capital. You have an absolute right to object to direct marketing under Article 21(2) UK GDPR.

Service communications — notices about changes to our services, our terms, or applicable law — are not marketing and cannot be opted out of while a relationship is in place.

7. Who we share it with

We do not sell your personal data and we do not share it for third-party marketing.

We share it with:

  • other ABEX entities, where necessary for the purposes in this notice;

  • service providers acting on our behalf, including hosting and infrastructure, email security and archiving, customer relationship management, identity verification and screening, and recruitment providers, each under written terms compliant with Article 28 UK GDPR;

  • trading venues, brokers, custodians, banks and payment providers, where necessary to provide our services;

  • professional advisers, including lawyers, auditors, insurers and compliance consultants;

  • regulators, law enforcement and other authorities, where required or permitted by law, including reports of suspicious activity; and

  • a buyer or prospective buyer of our business, and its advisers.

8. Where we store it, and transfers outside the UK

We store personal data on Microsoft Azure and Amazon Web Services infrastructure in the United Kingdom. Our trading system is deployed on Amazon Web Services infrastructure in Ireland. Email is secured and archived through Mimecast.

Where we transfer personal data outside the United Kingdom, we do so under Chapter V of the UK GDPR, relying on:

  • UK adequacy regulations, where the destination country has been recognised as offering an adequate level of protection. This covers the European Economic Area, and so covers our Irish deployment;

  • the International Data Transfer Agreement issued by the Information Commissioner, or the UK Addendum to the EU Standard Contractual Clauses; or

  • where appropriate, a derogation under Article 49 UK GDPR.

Hong Kong is not covered by UK adequacy regulations. Where personal data is transferred to, or accessible from, ABEX HK Limited, that transfer is made under an intra-group agreement incorporating the International Data Transfer Agreement, supported by a transfer risk assessment.

Where a transfer is to a country without UK adequacy, we assess whether the standard of protection for the individual is materially lower than under UK law, in line with ICO guidance. You can ask us for a copy of the safeguards in place.

9. How long we keep it

How long we keep each category of personal data
DataRetention
Data
Enquiries and correspondence where no relationship follows
Retention
24 months from last contact
Data
Client and counterparty due diligence records, and records of transactions
Retention
5 years from the end of the business relationship, as required by the Money Laundering Regulations 2017, extended only where permitted or required
Data
Recorded communications relating to orders
Retention
5 years, or 7 years where the FCA requires it
Data
Client platform sign-in records
Retention
30 days. Your account keeps only the time and IP address of your most recent sign-in, until the account is closed
Data
Client platform server logs
Retention
120 days. Logs are searchable for up to 90 days, then held in archive until deleted
Data
Marketing contacts
Retention
Until you unsubscribe, or we identify you as inactive
Data
Supplier, event and visitor records
Retention
Duration of the relationship, plus 24 months
Data
Unsuccessful job applications
Retention
12 months from the end of the recruitment process

We keep personal data for longer where the law requires it, or where we need it to establish, exercise or defend a legal claim. We may anonymise data so it can no longer be associated with you, and use it indefinitely in that form.

10. How we protect it

We maintain technical and organisational measures appropriate to the risk, including access controls, encryption in transit, role-based access, and supplier due diligence. ABEX has completed a SOC 2 Type II examination covering its operational controls.

Transmission over the internet is never entirely secure. Where we have given you a password or credentials, you are responsible for keeping them confidential.

11. Your rights

You have the right to:

  • access the personal data we hold about you and receive a copy;

  • rectify inaccurate or incomplete data;

  • erase your data in certain circumstances;

  • restrict our processing in certain circumstances;

  • portability — receive data you provided in a structured, commonly used, machine-readable format, and have it sent to another controller where technically feasible;

  • object to processing based on our legitimate interests, and an absolute right to object to direct marketing; and

  • withdraw consent where we rely on it.

Some rights are limited where we process your data to meet our legal obligations. In particular, we cannot erase records we are required to keep under the Money Laundering Regulations or the FCA Handbook; the right to object does not apply to processing we are legally required to carry out; and we may be unable to disclose information where doing so would prejudice the prevention or detection of financial crime. Where a right is not available to you, we will explain why.

To exercise a right, contact info@abex.capital. We respond within the period the law allows, normally one month from the point at which we have the information we need to identify you and deal with your request. We will tell you if a complex request requires longer.

Automated decisions

We do not make significant decisions about you — decisions producing legal effects or similarly significant effects — based solely on automated processing without meaningful human involvement. Our execution algorithms make decisions about orders, not about people.

If that position changes, we will tell you, and you will have the safeguards in Article 22C UK GDPR: information about the decision, the opportunity to make representations, human intervention on your request, and the ability to contest the decision.

Complaints

If you are unhappy with how we have handled your personal data, please tell us first, at info@abex.capital. We will acknowledge your complaint within 30 days, make reasonable enquiries, keep you informed of progress, and tell you the outcome in plain language.

You can also complain to the Information Commissioner’s Office, the UK supervisory authority, at ico.org.uk or on 0303 123 1113. Complaining to us does not affect that right.

12. Children

Our services are not directed at anyone under 18 and we do not knowingly collect their personal data. If we learn that we have, we will delete it.

13. Changes

We review this notice regularly and will post any updated version here. Where a change is material, we will take reasonable steps to bring it to your attention.

14. Contact

ABEX Capital Limited
For the attention of the Compliance function
Mutual House, 4th Floor, 70 Conduit Street, London W1S 2GF
info@abex.capital

HomeProductPrivacy NoticeTerms of Use
2026 ABEX. All rights reserved.
This document shall remain the property of ABEX. ABEX reserves the right to require the return of this document (together with any copies or extracts thereof) at any time. The document and its contents are confidential and should not be distributed or passed on, directly or indirectly, by recipients to any other person. It is being supplied to you solely for your information and may not be reproduced, forwarded to any other person or published, in whole or in part, for any purpose.
No reliance may be placed for any purpose whatsoever on the information contained in this document or on its completeness, accuracy or fairness. No undertaking, representation, warranty or other assurance, express or implied, is given by ABEX, its directors, employees or professional advisers as to the accuracy, fairness, sufficiency or completeness of the information, opinions or beliefs contained in this document. Save in the case of fraud, no liability is accepted for any loss, cost or damage suffered or incurred as a result of the reliance on such information, opinions or beliefs. Nothing in this document constitutes legal, tax, investment, or other advice. As a recipient of this document, you should conduct your own investigation, evaluation and analysis of the business, data and information described and seek independent financial, legal and tax advice.
ABEX Capital Limited is a company registered in England and Wales (company registration number: 14607492). ABEX Capital UK Limited is a company registered in England and Wales (company registration number: 12328188), and is registered with the Financial Conduct Authority (firm reference number: 933825) as a cryptoasset business (which exclusively provides a cryptoasset exchange and custodian wallet service), under the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017, as amended. The Financial Ombudsman Service or the Financial Services Compensation Scheme do not apply to the cryptoasset business carried on by ABEX Capital UK Limited. ABEX HK Limited, is a private company incorporated in Hong Kong, operating solely as a provider of technology, software and quantitative solutions (including the development and supply of algorithms, and, technical and technological components) to institutional clients, and does not intend to nor undertake any regulated activities and does not offer financial services or products under the laws of Hong Kong.
All investments, including cryptoassets, carry a high degree of risk (including but not limited to potential volatility, regulatory uncertainty, cybersecurity threats, technology failures, liquidity constraints, fraud risk, operational disruptions, smart contract or blockchain changes, third party banking/ safekeeping/ payment provider failures), such that the value of your investments and assets may fall significantly and/or lead to total loss.