Privacy notice: European Union and United Kingdom
Applies together with the main Privacy Policy. Governing privacy law: GDPR and UK GDPR.
Version 2026-10-08 · Effective 8 October 2026 · IAEX NETWORK (proprietor: Abhishek Tiwari)
This notice supplements Part A for people in the European Economic Area ("EU"), the United Kingdom and Switzerland, under Regulation (EU) 2016/679 ("GDPR"), the UK GDPR and Data Protection Act 2018, and the Swiss Federal Act on Data Protection.
Controller, representatives and contact
The controller is IAEX NETWORK (proprietor: Abhishek Tiwari), Plot No. 26, First Floor, Back Left Side, Block A-1, Mohan Garden, Uttam Nagar, New Delhi 110059, India. Privacy contact and data protection point of contact: connect@iaexnetwork.com, Abhishek Tiwari, connect@iaexnetwork.com. We do not offer live payments to customers in the EU or the UK until we have appointed the representative the law requires for those regions; until then you can contact us at the address above. We have not appointed a Data Protection Officer because the law does not require one for our activities; the contact above handles those duties.
Legal bases
| Purpose | Legal basis (GDPR Article 6) |
|---|---|
| Create and run your account, quote, instruct and record payments, invoices, certificates | Performance of a contract with you, or steps you ask for before a contract (6(1)(b)) |
| Identity verification, sanctions and politically-exposed-person screening, anti-money-laundering records, tax and regulatory reporting | Legal obligation (6(1)(c)); for sensitive data, substantial public interest in preventing money laundering and terrorist financing (Article 9(2)(g)) |
| Fraud prevention, security, abuse prevention, service analytics in aggregated form, defending legal claims | Our legitimate interests (6(1)(f)), which we have balanced against your rights; you may object |
| Product news and marketing emails | Your consent (6(1)(a)), withdrawable at any time |
| Optional face-match checks, if offered for your country | Your explicit consent (Article 9(2)(a)) |
Automated decisions
Risk scoring and sanctions matching are automated and may flag or hold a payment. We do not take a decision with legal or similarly significant effect on you solely by automated means: a trained person reviews every refusal, restriction or closure. You can ask for human review, state your view, and contest a decision, as Article 22 GDPR provides.
Your rights
You have the rights of access (Art. 15), rectification (16), erasure (17), restriction (18), notification of recipients (19), portability (20), objection (21, including absolute objection to direct marketing), and not to be subject to solely automated decisions (22). You can withdraw consent at any time. We respond within one month, extendable by two months for complex requests, with notice. Use the data-request form or email connect@iaexnetwork.com.
International transfers
Our infrastructure and some partners are outside the EU and UK (including India, Singapore, the UAE and the US), and these countries are not all covered by an adequacy decision. We transfer personal data under the European Commission's standard contractual clauses (Decision 2021/914) and, for the UK, the International Data Transfer Addendum, after a transfer risk assessment and with supplementary measures such as encryption. To the US we rely on the EU-US Data Privacy Framework (and its UK extension) where the recipient is certified. You can get a copy of the clauses by writing to us.
Retention
As in Part A, section 6. EU anti-money-laundering rules require us to keep identification and transaction records for 5 years after the relationship ends (up to 10 years where national law extends it).
Complaints
You may complain to us first, and always to a supervisory authority: in the EU, the authority in the country where you live, work or where the issue happened (the list is at edpb.europa.eu); in the UK, the Information Commissioner's Office (ico.org.uk); in Switzerland, the Federal Data Protection and Information Commissioner.
Crypto-asset transfers
Where a stablecoin transfer falls under Regulation (EU) 2023/1113, the originator and beneficiary information required by that regulation travels with the transfer and is shared with the receiving institution and authorities.