IMPORTANT:
Applicability of Privacy Policy and Cookie Policy. The specific Privacy Policy and Cookie Policy governing your contractual relationship are based on the applicable CEX.IO entity, determined by your residency and account type. Click the links below to unfold the Privacy Policy and Cookie Policy for individual entities.
CEX.IO CORP (US)
Privacy Policy
Last update: 23rd of April, 2025
Table of Contents
1. Information We Collect and How We Collect It
Information You Provide
Information We Collect Automatically
Publicly Available Information
Face Data Collection, Usage, and Storage
2. Children
3. How We Use Your Information
4. Disclosure of Information
5. Your Choices
6. Security
7. Retention of Personal Information
8. AI Products in Communication Channels
9. External Links
10. Contact Us
______________________________________
This Privacy Policy outlines how CEX.IO Corp. and its affiliates (collectively, “CEX.IO,” “we,” “us,” or “our”) collect, process and use the information we collect about you through our website, email newsletters, mobile app and other services (collectively, “Services”). Protecting and securing information and the systems that process and maintain CEX.IO’s data is a critical part of our operations. This Privacy Policy, in conjunction with our Terms of Use, governs the use of the information we collect.
You acknowledge and understand that by visiting or accessing our website or using CEX.IO services, you agree to this Privacy Policy. You also agree that our privacy policy and privacy notices are subject to the terms and conditions set forth in the Terms of Use. CEX.IO reserves the right to change, amend or revise this Privacy Policy at any point, under our sole discretion. When we update this Privacy Policy, we will update the “Last Updated” date above and post the policy. If you do not agree with the terms of this Policy, do not access or use our Services, or access our website.
If you are a California resident, you can learn more about how we use your information and your privacy rights by reviewing our California Privacy Notice.
1. Information We Collect and How We Collect It
For purposes of this policy, “Personal Information” refers to any data or information that can be used to identify an individual, either alone or in combination with other data. We require your Personal Information only for the purposes of providing the services requested from CEX.IO, and to satisfy the legal requirements from our regulatory obligations as a licensed financial institution. If you refuse to share your Personal Information, we will not be able to provide our services to you. The types of personal information we collect, and share depend upon the product or service you are using with us. This information can include:
Information You Provide
- Account Information: The information we collect varies depending on several factors, including whether you are an individual or representing a corporate entity, as well as other relevant circumstances and considerations. When you create an account, we may collect information associated with your account such as your username, name, corporate legal name (including d/b/a name), date of birth, contact information, address(es), phone number, biometric identifiers (facial recognition and facial geometry data derived from photographs or videos you submit to us during the onboarding process), photographs, audio recordings, and government-issued identification documents (e.g. drivers license, passport, social security number, employer identification number, and taxpayer identification number), information to corroborate the stated source of your funds and employment details (collectively, “Account Information”) proof of legal existence and beneficial ownership (e.g. state certified articles of incorporation or certificate of formation, unexpired government-issued business license, trust instrument, operating agreement, share registry, capitalization table, schedule K-1, and/or other comparable legal documents as applicable) information concerning all authorized account customers and beneficial owners (including but not limited to, full names, proof of identity, and contact information). Account information includes any additional personal information at the discretion of our Compliance Department.
- Financial Information: Certain services require financial information such as your credit/debit card information, digital asset wallet addresses, information about your income/source of funds, tax information.
- Social Media Information: We have profiles and pages on social media websites (referred to as “Social Media Pages”) like X, LinkedIn, Facebook, Telegram, Instagram, YouTube, Reddit, Pinterest, and TikTok. When you interact with us on Social Media Pages, we will collect personal information that you choose to provide us, such as your contact details. Additionally, any information shared on these platforms is subject to the respective social media platform's privacy policy and terms of service. We do not have control over the information collected by these platforms and are not responsible for their actions. We reserve the right to moderate or remove any content that violates these guidelines or our company policies.
- Communication information: When you contact us, we collect information concerning the contents of your communications, whether by email, chat, social media, telephone or otherwise. These communications may include data in files which are uploaded or emailed or otherwise provided by you. Please note that the obligation to record and retain conversations with customers arises from legal and regulatory requirements, as well as our legal interest in defending against potential claims.
- Other Information You Voluntarily Choose to Provide: We may collect information, including personal information, that you voluntarily provide to us when you:
- Participate in surveys, sweepstakes, promotions, and contests;
- Register for, attend, or participate in conferences, webinars or other events;
- Apply for a job with CEX.IO
Other Personal Information that we should process in accordance with our legal obligations and legal interest.
Information We Collect Automatically
- Location Data: We collect your IP address automatically when you use our Services, from which we or third parties operating on our behalf may be able to determine your approximate location (e.g. country and city). Such information is collected for the limited purposes of: system administration, to report aggregate information for our internal statistics, to ensure that you are in a jurisdiction which we are authorized to operate, and to ensure that your account has not been compromised by detecting irregular or suspicious logins or transactions.
- Device Information: We collect your device information, such as browser type and operating system, to analyze trends, administer the website and gather demographic information.
- Referral URLs and Clickstream Data: We may collect information about the pages you visit on our website, and other actions you take while navigating through our website.
- Tracking Technologies and Cookies: Our websites automatically gather certain information and store it in log files. This information may include your IP address, browser type, referring/exit pages, operating system, date/time stamp and clickstream data. Tracking technologies used are beacons, tags, and scripts to collect and track information and to improve and analyze our site. The technologies we use may include web beacons and cookies. To learn more about how we use cookies, please see our Cookie Policy.
Publicly Available information
- Information from Third Party Sources: We may collect information that is publicly available or obtained from other sources. This includes information that you have knowingly made available to the public such as information posted on public directories, other publicly accessible websites. The collection of publicly available information is done in accordance with applicable laws and regulations.
- Public Blockchains:Transactions in digital assets are not necessarily anonymous. All public blockchains allow anyone to see the balance and transaction history of any public digital asset address. It may be possible to match your public digital asset wallet address to other Personal Information about you, and therefore may be able to identify you from a blockchain transaction. This is a result of Personal Information published on a blockchain (such as your digital asset wallet address and IP address) which may be correlated with Personal Information that CEX.IO and others may have. Additionally, when using data analysis techniques on a given blockchain, it may be possible to identify other Personal Information about you. As part of our security, anti-fraud, identity verification and authentication checks, we may conduct such analysis to collect and process such Personal Information about you.
Face Data Collection, Usage, and Storage
- Purpose of Collecting Face Data
At CEX.IO, we use face data as part of our liveness check during the user verification process. This is essential for:
- Identity Verification: Ensuring that the person verifying their identity is physically present and not using a photo or video, which helps prevent identity fraud.
- Security: Adding an extra layer of security to ensure the authenticity of the user during the verification process.
- Fraud Prevention: Detecting and preventing potential attempts to bypass security measures, ensuring that the verification process remains secure and trustworthy. Verifying that the individual accessing our services is indeed who they claim to be.
- Regulatory Compliance: Meeting legal and regulatory requirements that mandate secure identity verification methods for Anti-Money Laundering (AML) and Know Your Customer (KYC) regulations.
By utilizing face data in the liveness check, we ensure a more secure and reliable verification process for all users.
- Storage and Retention of Face Data
Face data is stored securely in compliance with regulatory requirements that CEX.IO must adhere to. We implement robust security measures to protect this data. We retain face data for a period of five to eight years, depending on local regulatory body requirements. This retention period starts from the date of the user’s last transaction or the end of the tax period in which the last transaction occurred. This duration is necessary to comply with legal and regulatory obligations and to ensure we can respond to any legal or compliance inquiries that may arise during this period.
We are committed to ensuring that face data is handled securely and stored only for as long as necessary and required by legal and regulatory requirements to fulfill the purposes for which it was collected. Our approach to the storage and retention of face data is governed by the following principles:
- Limited Retention Period:
Face data is stored only for the duration needed to complete the verification process or meet the legal requirements related to identity verification. Once the verification is complete, we retain the data for a specific period in accordance with regulatory obligations and internal policies. - Purpose-Specific Retention:
We store face data for the following purposes:- Identity Verification: Retained for a limited period to allow for audits or disputes related to the verification process.
- Fraud Prevention and Security: Retained to detect and prevent potential fraud during and after the verification process.
- Data Deletion Policy:
Once face data is no longer necessary for the purposes it was collected for, or after the retention period has passed, it is securely deleted. We do not retain face data indefinitely. - Compliance with Legal Requirements:
Our retention policy complies with applicable data protection regulations. Face data is retained only for as long as necessary to fulfill the purposes for which it was collected, in accordance with legal, regulatory, and contractual obligations. - User Rights:
Users have the right to request the deletion of their face data at any time, in accordance with applicable privacy laws. We ensure a transparent and easy process for users to exercise this right.
By adhering to these principles, we aim to balance the need for effective user verification and security with the rights and privacy of our users.
- Sharing of Face Data with Third Parties
We prioritize the security and privacy of face data and only share it with third parties when absolutely necessary. Our approach to sharing face data is guided by the following principles:
- Limited Sharing:
We share face data with third parties only when it is essential to provide our services or comply with legal obligations. The main purposes for sharing face data include:- Identity Verification Providers: We may share face data with trusted service providers who assist us in conducting secure user verification and liveness checks.
- Cloud Storage Providers: Face data may be stored securely by third-party cloud service providers who are bound by strict data protection agreements.
- Security and Fraud Prevention Partners: We may share data with specialized security vendors to help detect and prevent fraud during the verification process.
- Banks and Payment Providers: We may share face data with banks and payment providers upon request for investigation related to specific transactions.
- Regulatory Authorities: If required by law or to comply with legal obligations, we may share face data with government or regulatory bodies to meet legal requirements or respond to law enforcement requests.
- Robust Data Protection Agreements:
All third parties we share face data with are required to comply with strict contractual agreements that meet or exceed applicable data protection laws. These agreements ensure that third parties use the data solely for the purposes we have defined and apply stringent security measures to protect the data. - No Unauthorized Use:
We do not permit third parties to use face data for any purpose other than what is explicitly stated in our agreements. Third parties are prohibited from using the data for advertising, analytics, or any other purposes outside of those required for verification or security. - Data Retention by Third Parties:
Some third parties, such as identity verification providers, may retain face data for a limited period to comply with legal or contractual obligations. We ensure that any third-party data retention policies are consistent with our own practices, and they are required to delete or anonymize face data once it is no longer needed. - Transparency and User Rights:
We provide transparency to our users about which third parties may have access to their face data and the reasons for such sharing. Users also have the right to request information about third-party sharing and to request deletion of their face data.
By adhering to these principles, we ensure that face data is shared responsibly and securely, maintaining the privacy and trust of our users.
- Third-Party Data Storage and Practices
When we share face data with third parties, we ensure that their data storage practices align with the highest standards of privacy and security. Below is an outline of how third-party data storage is handled, along with our measures to protect user privacy:
- Data Storage by Third Parties:
Some third parties, such as identity verification providers and cloud storage services, may store face data temporarily to assist us in completing the user verification process. The specific practices include:- Secure Cloud Storage: Third-party providers may store face data on secure servers that use encryption and advanced security measures to protect data from unauthorized access.
- Temporary Retention: In most cases, third parties only store face data for the duration necessary to complete verification, after which the data is either securely deleted or anonymized.
- Privacy Practices of Third Parties:
We carefully vet all third-party providers to ensure their privacy practices are compliant with applicable data protection regulations. Their privacy practices must include:- Limited Data Usage: Third parties are prohibited from using face data for any purpose other than those specified by us, such as verification and fraud prevention.
- Security Measures: They are required to implement strong security protocols, such as encryption and secure access controls, to safeguard face data.
- Compliance with Regulations: Third parties must adhere to relevant data protection regulations, and we regularly review their compliance.
- Data Retention Policies:
If third parties retain face data, they are bound by specific retention policies that comply with the following guidelines:- Purpose-Limited Retention: Face data is only retained for the period necessary to fulfill the specific purpose (e.g., user verification or fraud detection).
- Deletion or Anonymization: Once the data is no longer needed, third parties must either securely delete it or anonymize it to ensure it cannot be linked to individual users.
- Reasons for Third-Party Data Storage:
Third parties may store face data for the following reasons:- Verification Records: To maintain an audit trail of user verification for compliance with legal or contractual requirements.
- Fraud Prevention: To identify and prevent repeated or attempted fraud during the verification process.
By enforcing strict data storage and privacy practices with our third-party partners, we ensure that face data is handled securely and in compliance with all relevant privacy laws.
- User Rights
Users can access, correct, or request the deletion of their face data by contacting our Support Team. However, please note that we may need to retain personal information if required by data protection laws for specific purposes, such as regulatory compliance or defending legal claims. In such cases, we will inform you and provide an explanation if this applies.
- Additional Information
This section specifically addresses face data and complements the other provisions of our privacy policy. For any questions or additional details not covered here, please refer to the full privacy policy for comprehensive information.
2. Children
Minors are not permitted to use CEX.IO. If you are under the age of 18, please do not provide any personal information through the Sites or Services. If you are a parent or guardian and believe that CEX.IO has information of a child under the age of 18 please contact us immediately at dpo@cex.io, so we remove any such information from our database.
3. How We Use Your Information
Please see below for the purposes for which we process your Personal Information:
- To provide and maintain our services, including to allow you to open and operate an account and monitor the usage of services;
- To manage your account: To manage your registration as a Сustomer of the service(s). The Personal Data you provide can give you access to different functionalities of the Service that are available to you as a registered customer, i.e., to enable you to complete transactions on the Platform;
- For the performance of a contract: The development, compliance and undertaking of the purchase contract for the products, items, or services you have purchased or of any other contract with us;
- Contact You: We may contact you by email, telephone, SMS, or other equivalent forms of electronic communication, such as push notifications from our mobile app. We may use these methods to provide you with updates, informative communications related to the functionalities of our products or contracted services, including security updates when necessary or reasonable for their implementation, and to reply to your queries;
- Marketing: To provide you with news, special offers and general information about other goods, services, and events which we offer that are similar to those that you have already purchased or enquired about unless you have opted not to receive such information;
- Requests: To attend to, and manage your requests of us;
- Security: To ensure security of your account (for instance, if you make a request to disable 2-factor authentication on your account we can ask you to provide additional Personal Information to confirm your identity);
- Legal Obligations: To comply with legal obligation purposes such as tax reporting, fraud prevention, our reporting obligations etc.;
- Joint Marketing: To provide you with information about products and promotions that may be of interest to you, from ourselves and third parties, although only if you have specifically agreed to receive such information;
- Market Research: For market research e.g., surveying your needs and opinions on issues, such as performance. Unless consented, your data for this purpose would be anonymised;
- Business Transfers: We may use your Personal information to evaluate or conduct a merger, divestiture, restructuring, reorganization, dissolution, or other sale or transfer of some or all our assets, whether as a going concern or as part of bankruptcy, liquidation, or similar proceeding, in which Personal Data held by us about you is among the assets transferred; and
- Other Purposes: We may use your Personal Information for other purposes, such as data analysis, identifying usage trends, determining the effectiveness of our promotional campaigns and to evaluate and improve our service(s), products, services, marketing, and your experience.
- Your Privacy Rights
You have the right to access the Personal Information we collect about you, the right to correct any inaccuracies in your Personal Information, and, in certain circumstances, the right to limit its sharing. Please note that your privacy rights may vary depending on the specific regulations of your state. Please feel free to reach out to our Help Centre or at dpo@cex.io if you have any questions regarding your privacy rights, or want to exercise them.
4. Disclosure of Information
- Affiliates and Subsidiaries: We disclose your information with our affiliates and subsidiaries, including information regarding your experience using our services.
- Third Party Service Providers: We may share Personal Information with third-party service providers (including those that may be located outside of the United States or your country), who help us operate our platform and systems, and detect fraud and security threats throughout the normal course of our business. Any third party which receives or has access to your Personal Information is required to protect such Personal Information and only to use it for the limited purposes necessary to carry out the services they are explicitly contracted to provide. Such third parties, aside from law enforcement or regulatory authorities, are contractually bound by the same security and confidentiality policies and responsibilities as CEX.IO. We do not sell customer Personal Information to third-parties for the purposes of marketing. We ensure that all third-parties are bound by obligations under the Privacy Policy. CEX.IO represents that we will only enter into contracts with future third parties that are bound by terms no less protective than the obligations of this Privacy Policy and are consistent with all applicable data protection laws.
- Advertising and Third-Party Data Sharing: We may collaborate with third-party advertising partners (e.g., ad networks and advertising service providers) to deliver tailored advertisements and promotional content to you when you visit our website and use our Services. These advertising partners may utilize cookies, pixel tags, and similar technologies to collect information about your activities for the purpose of providing personalized advertisements. Additionally, we may share hashed data, including personal data such as email addresses and phone numbers, with third-party entities for data analytics, profiling, and user acquisition purposes. This shared information helps us monitor the effectiveness of our advertising campaigns and display relevant ads for products and services that align with your interests, based on your visits to our website and other websites. It's important to note that these third-party entities maintain their own privacy policies, which may differ from ours. We encourage you to review their respective privacy policies to understand how they handle your information. Rest assured that we ensure these third parties adhere to data privacy standards that are no less stringent than our own. For marketing and analytics purposes, we may share your Personal Information, including hashed data, along with other general or non-personally identifiable data, with the following entities: Appsflyer, AdRoll (including NextRoll), Customer.i,Gleam.io, Google and its affiliates (including Firebase), Hotjar, Hubspot, Intercom, META and its affiliates, Mixpanel, Pinterest, Prefinery, Quora, Reddit, RudderStack, Snapchat, Trustpilot, X, Typeform, Wheel of Popups, Zapier, and Microsoft Advertising.
- When Required by Law: As a licensed non-bank financial institution and Money Services Business in the United States, CEX.IO must comply with Section 326 of the USA PATRIOT ACT; which requires all financial institutions to obtain, verify, and record Personal Information that identifies each person who opens an account. This federal requirement applies to all customers. This Personal Information is used to assist the United States government in the fight against the funding of terrorism and money-laundering activities. We may disclose your Personal information when required by applicable laws, regulations, legal processes, or government authorities. This may include, but is not limited to, complying with court orders, subpoenas, or other legal obligations. We may also disclose your information to protect our legal rights, respond to legal claims, or defend against legal disputes. In some situations where we believe it is necessary to prevent imminent harm, financial loss, or to report suspected illegal activities, we reserve the right to disclose your Personal Information to relevant law enforcement authorities or other government agencies. Please be aware that, while we take measures to protect your privacy, we may be legally obligated to disclose your information without providing prior notice.
- Change in Ownership: We may share your Personal Information with financial institutions, insurance companies or other companies in an anonymized format to an interested buyer or seller of the business or business assets. In the case of a merger, divestiture, corporate reorganization, or asset sale of the business, we will notify you prior to the non-anonymized transfer of your Personal Information. We encourage you to exercise all of your rights regarding the sharing of your Personal Information.
5. Your Choices
When it comes to your privacy, we are able to offer you certain choices concerning the personal information we collect from you.
- Email Marketing: In order to no longer receive email marketing messages from us, please click “unsubscribe” at the very bottom of the email message. Alternatively, you can contact us at dpo@cex.io and request that we remove you from receiving email marketing messages.
- Push Messaging Marketing: In order to block push notification marketing messages in iOS Settings, go to Settings > Notifications > Select the desired CEX.IO app > Toggle the “allow notifications” to turn off the notifications. For android, go to Apps > Choose an app > Notifications > Turn off all notifications or select specific types to turn off.
- SMS Messaging: At this time, CEX.IO does not send marketing messages over SMS Messaging.
- Do Not Track: Some browsers have incorporated “Do Not Track” (DNT) features that can send a signal to the websites you visit indicating you do not wish to be tracked. Currently, our website does not respond to browser DNT signals.
- Social Media: We may use social media advertising to promote our services and reach a wider audience. Such advertising may involve the use of cookies or similar technologies to collect data about your browsing behavior. If you do not wish to receive targeted advertising from us, you can adjust your social media platform's settings or opt-out of targeted advertising by following the instructions provided by the respective social media platform.
- Analytics
- You can opt-out of having made your activity on the website available to Google Analytics by installing the Google Analytics opt-out browser add-on. The add-on prevents the Google Analytics JavaScript (gtm.js) from sharing information with Google Analytics about visits activity. For more information on the privacy practices of Google, please visit the Google Privacy & Terms web page: https://policies.google.com/privacy.
- If you wish to opt out of various third-party ad networks, including those operated by the Network Advertising Initiative (NAI) and the Digital Advertising Alliance (DAA), you can find more details on interest-based advertising and how to opt out on their respective websites: www.aboutads.info/choices (DAA) and https://optout.networkadvertising.org/?c=1 (NAI). By opting out of one or more NAI or DAA member networks (many of which overlap), you will no longer receive targeted content or ads from those members. However, this does not mean that you will stop receiving all ads on our Sites or other websites. You may still receive advertisements based on the particular website you are currently visiting. Additionally, please note that if your browser settings reject cookies, if you delete your cookies, or if you switch to a different computer or web browser, your NAI or DAA opt-out may no longer remain effective.
- Cookie Preferences
To facilitate easier customization of your cookie preferences and similar technologies, we have implemented a cookie window, the appearance, and settings of which may vary depending on your region.
6. Security
CEX.IO maintains physical, electronic and procedural security measures to guard against unauthorized access to systems and uses safeguards such as firewalls and data encryption.
No security measure is perfect. However, we have implemented technical and organizational security measures to ensure the confidentiality, integrity and accountability of your Personal Information. Through a constant process of reevaluation and testing we pride ourselves on our abilities to protect your Personal Information from loss, misuse, manipulation or destruction. Examples of measures we take to protect your Personal Information include:
- Pseudonymization and TLS 1.3 encryption of personal data
- Access control
- The ability to ensure the ongoing confidentiality, integrity, availability and resilience of our processing systems and services
- The ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident
- Only authorized personnel, who are subject to strict confidentiality agreements, have access to your Personal Information.
Technical and organizational security measures will be reviewed on a rolling basis to consider all legal and technical developments. Additionally, we perform ongoing due diligence on third-party vendors which may have access to your Personal Information.
In the event of a data breach or the failure of our security measures, we will notify you in accordance with applicable laws, regulations, or guidelines. CEX.IO may retain a data protection and breach notification security advisory firm which monitors all applicable reporting requirements for the United States and other jurisdictions which we operate.
7. Retention of Personal Information
CEX.IO will retain your Personal Information for as long as is necessary to complete the purposes for which it was collected, or as may be required by law. However, please note that some data may be retained for a longer period if required or permitted by law, to resolve disputes, enforce our agreements, or for other legitimate business purposes. If you have any questions or concerns regarding our retention practices, please contact us using the information provided in the “Contact Us” section below.
8. AI Products in Communication Channels
We continuously strive to ensure prompt resolution of questions and issues arising from our customers' use of our services. The primary method of communication with our Support Team is via chat available on our website. This tool is provided to us by our third-party provider, Intercom Inc., with whom we have appropriate agreements in place. These agreements include provisions ensuring that Intercom Inc., acting as a Data Processor, cannot provide a lower level of data protection than we do. Furthermore, to streamline the operation of our Support Team, particularly in responding to users' queries promptly, we have implemented the functionality of Intercom Inc.'s AI chatbot, Fin AI Agent, into the chat.
To address any potential concerns that may arise, we provide key information below regarding the measures we have implemented to minimize risks to the protection of individuals' personal data:
- We conducted a thorough assessment of the risks to personal data protection and consulted with relevant stakeholders regarding the implementation of AI Products.
- We have entered into appropriate agreements with Intercom Inc. guaranteeing data protection in using AI. These agreements include:
- OpenAI being contractually restricted from using customer data to train its AI model, with zero data retention enabled by Intercom Inc.
- No sensitive data shared within the chat will be stored or used for self-learning by OpenAI. Sensitive data will only be processed by Strac.io when converted into physical conversations with agents.
- You will have the choice of receiving a quick response via the AI chatbot or proceeding directly to a conversation with our agent.
For additional information about the Fin AI Agent, please refer to the following resource: What is Fin?.
*The term ‘artificial intelligence’ means a machine-based system that can, for a given set of human-defined objectives, make predictions, recommendations or decisions influencing real or virtual environments.
9.External Links
This Privacy Policy applies only to our website. There may be links on our website that will direct you to websites hosted by third-parties. Accessing those third-party websites will require you to leave our website. We do not control third-party websites or any of the content contained therein. You acknowledge that by leaving our website, CEX.IO is not responsible or liable for any of those third-party websites, including, without limitation, their content, policies, failures, promotions, products, services or actions and/or any damages, losses, failures or problems caused by, related to or arising from those websites. We encourage you to review all policies, rules, terms and regulations, including the privacy policies, for each website that you visit.
10. Contact Us
Please let us know how we can improve, or if you have any questions, comments, or concerns regarding our privacy policies and practices, feel free to send us an email at support@cex.io, or contact us through chat available on our website.
Additional resources may be found through our Help Centre. At the Help Centre, you can search for a particular question and read our collection of Frequently Asked Questions (“FAQ”).
CEX.IO Corp.’s registered office is 100 SE 2nd St, Suite 3852 Miami, Florida, 33131, USA.
Privacy Notice for California Residents
Last update: September 6th, 2024
CEX.IO Corp. and its affiliates (hereinafter, "CEX.IO", “CEX US”, "we", "us" or "our") are committed to protecting and respecting your privacy.
This Privacy Notice for California Residents supplements the information contained in our Privacy Policy and it applies solely to all visitors, users, and others who reside in the State of California (hereinafter, "User", “Consumer”, "you" and derived).
Collection of Personal Information
Categories of Personal Information Collected
We collect information that identifies, relates to, describes, references, is capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular Consumer or Device. The following is a list of categories of personal information which we may collect or may have been collected from California residents within the last twelve (12) months.
Please note that the categories and examples provided in the list below are those defined in the California Consumer Privacy Act / California Privacy Rights Act. This does not mean that all examples of that category of personal information were in fact collected by us but reflects our good faith belief to the best of our knowledge that some of that information from the applicable category may be and may have been collected. Please note that only certain categories of personal information would only be collected if you provided such personal information directly to us. Additionally, please be aware that some information is collected automatically.
- Identifiers, such as your real name, user ID, postal address, email address, a copy of your identification (such as your driver’s license or passport), your social security number and/or other government identification or registration data, IP address, domain name, and other similar identifiers.
- Personal Information listed in the California Customer Records statute (Cal. Civ. Code § 1798.80(e)):
- Financial information, such as bank account information, routing number
- Transaction Information, such as public blockchain data
- Credit and Fraud Information, such as credit investigation, credit eligibility, identity or account verification, fraud detection, or as may otherwise be required by applicable law
- Correspondence, such as information that you provide to us in correspondence, including account opening and customer support
- Institutional Information, such as for institutional customers, we may collect additional information, including institution’s legal name, Employer Identification Number (“EIN”) or any comparable identification number issued by a government, and proof of legal existence (which may include articles of incorporation, certificate of formation, business license, trust instrument, or other comparable legal document)
- Device Information, such as hardware, operating system, browser, device model, screen width, screen height
- Telephone number
- Usage Data, such as system activity, internal and external information related to CEX.IO pages that you visit, clickstream information
- Additional Information, as permitted by law or required to comply with legal obligations, which may include criminal records or alleged criminal activity, or information about any person or corporation with whom you have had, currently have, or may have a financial relationship. Personal Information you provide during the registration process may be retained, even if your registration is left incomplete or abandoned. - Commercial information, such as information about your transactions and transaction history, account balances.
- Internet or other Electronic Network Activity Information, such as information related to browsing history, search history, and information regarding a consumer’s interactions with CEX.IO Sites, or advertisement.
- Geolocation data to the extent we need to verify your location for regulatory or anti-fraud purposes depending on the Services provided and your use of them (for example, some laws may require us to identify your location if the use of any Services involves gambling).
- Sensory data: audio, electronic, visual, thermal, olfactory, or similar Information, such as images and videos collected for identity verification, audio recordings left on answering machines.
- Biometric Information, such as scans of your face geometry extracted from identity documents.
- Professional or employment-related information, such as your occupation, source of funds.
- Inferences drawn from the above information, which may include inferences about preferences, characteristics, and behavior.
- Sensitive Personal Information, such as government-issued verification numbers (i.e. Social Security Number or equivalent, driver’s license number, passport number), and biometric information (i.e. scans of your face geometry extracted from identity documents.
We collect this personal information to underwrite and set up your account, as well as to provide and promote our Services to you.
Sources of Personal Information
We obtain the categories of personal information listed above from the following categories of sources:
Directly from you. For example, from the forms you complete on our Platform, preferences you express or provide through our Service, or from your purchases on our Platform.
Indirectly from you. For example, from observing your activity on our Platform.
Automatically from you. For example, through cookies we or our Service Providers set on your Device as you navigate through our Site(s).
From Service Providers. For example, third-party vendors to monitor and analyze the use of our Service, third-party vendors to provide advertising on our Service, third-party vendors to deliver targeted advertising to you, third-party vendors for payment processing, or other third-party vendors that we use to provide the Service(s) to you.
Use of Personal Information
For details on the purposes for which we collect personal information, please see Section 3 of our Privacy Policy.
Disclosure of Personal Information
We may use or disclose and may have used or disclosed in the last twelve (12) months all of the categories of personal information provided in the section Categories of Personal Information Collected for business or commercial purposes.
Use and disclosure of Sensitive Personal Information. We recognize the importance of protecting your sensitive personal information, as defined by applicable California law. If we collect, use, or share sensitive personal information, we limit its use or disclosure to only those business purposes that are permitted by law. These purposes may include processing transactions, fulfilling orders, providing customer service, and conducting internal audits or analysis. We may also disclose sensitive personal information as required by law, to protect our legal rights, or to comply with a court order or legal process.
Share of Personal Information
We may share, and have shared in the last twelve (12) months, your personal information certain identified in the above categories with the following categories of third parties:
- Service Providers, which include IT and cloud hosting companies, auditors, analytics providers, advertising partners, ad networks for business purposes
- Affiliates and subsidiaries of CEX.IO and other companies within CEX.IO group of companies
- Payment providers
- Our business partners
- Third party vendors to whom you or your agents authorize us to disclose your personal information in connection with products or services we provide to you.
California’s “Shine the Light” Law
As a California resident, you have the right to request and receive, once per year and free of charge, information about our sharing of certain categories of Personal Information with third parties for their direct marketing purposes during the previous calendar year. CEX.IO does not share personal information with third parties for their direct marketing purposes without your consent or without providing you with the opportunity to opt out.
Personal Information of Minors Under 16 Years of Age
Minors are not permitted to use CEX.IO. If you are a parent or guardian and believe that CEX.IO has information of a child under the age of 18 please contact us immediately at dpo@cex.io so we remove any such information from our database.
Your CCPA Privacy Rights
You have rights that you can exercise in relation to your personal information. In particular:
- Right to know about the personal information we collect about you and how it is used and shared. You may ask for information about the categories of personal information we have collected about you, the categories of sources from which your personal information has been collected, the business or commercial purpose for collecting or selling your personal information, as well as the categories of third parties with whom we may share or to whom we sell your personal information and the categories of personal information that have been provided to such third parties. You may also ask us for a copy of the specific pieces of personal information we have collected about you in a machine-readable format.
- Right to delete. You have the right to request the deletion of your Personal Information. Please note that we may not be able to fully address your request in certain circumstances, such as when we need to complete a transaction for you, detect and protect against fraudulent or illegal activity, exercise our rights, or comply with a legal obligation. If we are unable to fulfill your request, we will inform you of the reason why.
- Right to opt-out of the Sale of Personal Information. We do not sell the Personal Information of consumers. However, if we begin to sell personal information in the future, you have the right to direct us to not sell your Personal Information at any time.
- Right to correct. You may ask us to correct inaccurate information that we have about you.
- Right to limit. You have the right to request us to only use your sensitive personal information (f. e., your social security number, financial account information, your precise geolocation data, or your genetic data) for limited purposes, such as providing you with the Services.
- Right to nondiscrimination. We will not discriminate against you for exercising any of your consumer’s rights listed above. This means that we will not deny you Services, charge you different fees, or provide you with a lower level of Services if you exercise your privacy rights.
Exercising Your CCPA/CPRA Data Protection Rights
You may exercise any of your privacy rights by contacting us through one of the communication channels provided in the Contact Us section of this Privacy Notice.
Your request to us should:
- Provide sufficient information that allows Us to reasonably verify You are the person about whom we collected personal information or an authorized representative.
- Describe your request with sufficient detail that allows Us to properly understand, evaluate, and respond to it
We cannot respond to your request or provide you with the required information if we cannot:
- Verify your identity or authority to make the request
- And confirm that the personal information relates to you.
We will disclose and deliver the required information free of charge within 45 days of receiving your verifiable request. The period to provide the required information may be extended once by an additional 45 days when reasonably necessary and with prior notice.
Any disclosures we provide will only cover the 12-month period preceding the verifiable request's receipt.
For data portability requests, we will select a format to provide your personal information that is readily usable and should allow you to transmit the information from one entity to another entity without hindrance.
Please note that where we use and disclose personal information for purposes related to security, fraud detection and other similar purposes, some of your rights may be limited. As such, please consider that there might be cases where your request cannot be fulfilled. For example, as permitted by the CCPA, it is possible that we may not comply with a request to delete your personal information if we need that information for the purpose of detecting security incidents, or protecting against malicious, deceptive, fraudulent, or illegal activities, where such information is necessary to record our contractual dealings or your transactions or where required or otherwise permitted by law.
Authorized Agents
If you are a registered agent seeking to submit a request on behalf of a California consumer with a registered CEX.IO account in good standing, you should collaborate with the user to submit an access request directly through their account.
For requests on behalf of individuals without a registered CEX.IO account or for CEX.IO users with suspended accounts, you may submit the request through our official support channel or via email to dpo@cex.io.
To process the request, you must provide Proof of Identity (POI) and Proof of Address (POA) for the consumer on whose behalf you are submitting the request, along with evidence of your authorization to act on their behalf. We will fulfill the request only after verifying both your authorization and the requestor's identity.
Please note that if the information (name, address, or email address) you provide for the consumer does not match our records, we will be unable to process the request.
Contact us
If you want to know more about your rights, or you want to exercise them, or you have any questions or concerns regarding this Privacy Notice you can reach us by live chat on the Site. Alternatively, you can contact us through email support@cex.io or dpo@cex.io. Additional resources may be found through our Help Centre.
Cookie Policy
Last update: September 24, 2026
This Cookie Policy explains how CEX.IO Corp. uses cookies and similar technologies on our website, in our mobile application, and in our emails. Read it together with our US Privacy Policy, our Terms of Use, and, if you are a California resident, our California Privacy Notice.
Table of Contents
1. Which CEX.IO Entity This Policy Applies To
2. What Cookies and Similar Technologies Are
3. Consent Preferences
4. Categories of Cookies and Similar Technologies We Use
5. How US Law Applies to Cookies
6. Your Choices
Consent Preferences
Opt-Out Preference Signals, Including Global Privacy Control
Asking Us Directly
Managing Cookies Through Your Browser or Device
Mobile Application Technologies
Tracking Technologies in Our Emails
7. Do Not Track
8. Third-Party Technologies
9. Session Replay
10. How Long Cookies and Your Choices Last
11. Changes to This Policy and How to Contact Us
1. Which CEX.IO Entity This Policy Applies To
This Cookie Policy applies to you if you are resident in the United States and your CEX.IO account is held with CEX.IO Corp.
2. What Cookies and Similar Technologies Are
Cookies are small text files placed on your browser or device when you visit a website. Similar technologies include local and session storage, software development kits embedded in mobile applications, pixels and web beacons, tags, scripts, advertising identifiers and device identifiers, and other techniques used to store information on, or retrieve information from, a browser, application, or device. In this policy we refer to all of them as "cookies."
Some technologies last only for a session and are deleted when the browser or application closes. Others are persistent and remain until their stated expiration date, until you delete them, or until the relevant identifier is reset. First-party technologies are set by the service you are using. Third-party technologies are set or accessed by another organization whose functionality is built into the service.
3. Consent Preferences
Consent Preferences is our cookie and similar-technology preference interface. It is displayed when you first visit our site, and it remains available at any time through a permanently accessible "Consent Preferences" link or icon on the left-hand side of the site footer.
Through Consent Preferences you can accept all optional cookies, decline all optional cookies, or manage them by category. The option to decline all optional categories is given the same visual prominence, and requires the same number of steps, as the option to accept all. We do not treat closing the banner, ignoring it, scrolling, continuing to browse, or any pre-ticked or bundled action as your agreement to optional cookies.
Declining optional cookies will not prevent you from using your account or from trading, although some optional features may not work as intended. You can change your choices at any time through the same link.
4. Categories of Cookies and Similar Technologies We Use
Category | What It Is Used For | Default | Is This a "Sale" or "Share" Under State Law? |
Necessary | Operating and securing the site and platform; maintaining your session; authenticating you; two-factor authentication; preventing fraud, account takeover, and technical abuse; remembering your Consent Preferences; and providing functionality you have requested, such as completing a transaction. | Always active. These cannot be switched off through Consent Preferences, because the platform cannot operate securely without them. | No. |
Functional | Optional features and personalization, such as remembering selected settings and preferences, collecting feedback, enabling live chat, displaying embedded content, and supporting referral, promotional, and sign-up features. | Active by default. You may decline it at any time through Consent Preferences. | No, unless a specific tool is also used for advertising, in which case it appears in the Advertisement category. |
Analytics | Understanding how visitors reach and use the site and platform; measuring traffic, journeys, and interactions; identifying errors; testing and improving performance, content, and customer experience; and recording sessions so that we can diagnose usability problems. | Active by default. You may decline it at any time through Consent Preferences. | Generally no. Where an analytics provider also operates an advertising business and we permit it to use the information for its own purposes, we treat that as a "share" and it appears in the Advertisement category. |
Advertisement | Measuring advertising campaigns; attributing sign-ups to the campaign that produced them; limiting repeated advertisements; creating and matching audiences; and displaying and measuring CEX.IO advertising on other websites, applications, and services. | Active by default. You may decline it at any time through Consent Preferences, by sending an opt-out preference signal, or by asking us directly. | Yes. We treat this category as a "sale" and a "share" under California law, and as "targeted advertising" under the other state privacy laws. See Section 5. |
A single technology may serve more than one purpose. We review each purpose separately and assign the technology to the category that reflects its most significant purpose.
5. How US Law Applies to Cookies
No United States law requires us to obtain your consent before we set cookies. US law requires disclosure and an effective right to opt out of certain uses. Optional cookies are therefore active by default, and you may decline them at any time.
Under the California Consumer Privacy Act, as amended by the California Privacy Rights Act, and under the privacy laws of other states in which we operate, you have the right to opt out of the "sale" or "sharing" of your personal information and of its use for targeted advertising.
We do not sell your personal information for money. When we allow advertising and social media companies to set cookies on our site, or when we give them identifiers so that they can measure our campaigns or build audiences, that activity meets the definition of a "sale" or a "share" under California law and of "targeted advertising" under other state laws, even though no money changes hands. We treat it as a sale and a share, and we give you the right to opt out.
We do not use cookies to collect sensitive personal information for advertising, to infer characteristics such as health, religion, or sexual orientation, or to knowingly target minors.
6. Your Choices
Consent Preferences
Consent Preferences, described in Section 3, is the primary way to control the technologies we use. It is available at any time through the permanently accessible link or icon on the left-hand side of the site footer, and the choices you make there apply to the browser and device you are using.
You can ask us at any time to stop the sale and sharing of your personal information and its use for targeted advertising. Contact us by live chat on our site or by email at dpo@cex.io. You do not need to give a reason. We will not charge you for the request, and we will not give you a lower level of service because you made it.
Managing Cookies Through Your Browser or Device
Most browsers let you block, delete, or manage cookies through their settings. Browser settings are less specific than Consent Preferences, and they may not reach technologies used in our mobile application or in our emails. If you block Necessary technologies, secure login, session maintenance, transaction flows, and fraud prevention may not work correctly. Changing your choices in Consent Preferences does not delete cookies already stored on your device; to remove those, use your browser or device settings.
Mobile Application Technologies
If you use our mobile application, we may use mobile software development kits and device identifiers, including advertising identifiers where enabled, for security, analytics, functionality, or advertising. If platform rules or applicable law require permission, we request it before we use those identifiers for tracking or advertising. You can also manage these permissions in your device settings, including Apple's App Tracking Transparency and the Android advertising identifier controls. Those controls operate in addition to, and do not replace, the choices you make in Consent Preferences.
Tracking Technologies in Our Emails
Our emails may contain pixels, tagged links, or similar technologies that tell us whether a message was delivered, opened, or clicked, and that help us protect our communications and detect abuse. You can unsubscribe from marketing emails using the link in any marketing message or through your account notification preferences. Service, security, legal, and transaction messages will continue, because we are required to send them.
7. Do Not Track
Browser “Do Not Track” or similar signals are not by themselves a substitute for valid consent unless recognised by applicable law and supported by the relevant technology. We apply such signals where legally required and use Consent Preferences as the primary control for technologies used through CEX.IO.
8. Third-Party Technologies
We use third-party providers for analytics, advertising, social media, customer engagement, consent management, security, and technical services. If a provider acts on our behalf, it may use the information only for the purposes we have agreed to and subject to contractual controls. If a provider acts as a separate business for its own purposes, its own privacy policy governs that use. Consent Preferences holds the current, detailed inventory. The table below summarizes it.
Purpose | Category | How to Decline |
Security, fraud prevention, authentication, and platform operation | Necessary | Not available |
Product analytics and performance measurement | Analytics | Consent Preferences |
Session replay and usability diagnostics | Analytics | Consent Preferences |
Customer support and live chat | Necessary for the chat itself; Functional for the optional elements | Consent Preferences, for the optional elements |
Marketing operations, forms, surveys, referrals, and promotions | Functional | Consent Preferences |
Mobile attribution and campaign measurement | Advertisement | Consent Preferences, an opt-out preference signal, or by asking us |
Advertising delivery, audience matching, and campaign measurement | Advertisement | Consent Preferences, an opt-out preference signal, or by asking us |
If we give an advertising or analytics provider a hashed email address or hashed phone number so that it can match you to its own records, our US Privacy Policy describes that practice, and the choices in Section 6 apply to it.
9. Session Replay
We use session replay technology to record how visitors interact with our pages, including mouse movement, clicks, scrolling, page changes, and text typed into forms. We use these recordings to identify broken pages, confusing screens, and steps where users are unable to complete a task. We configure this technology to mask password fields, payment card details, government identification numbers, and other sensitive inputs so that it does not capture them. Session replay is in the Analytics category, and you can decline it in Consent Preferences.
10. How Long Cookies and Your Choices Last
Each technology has its own duration, and Consent Preferences shows it. Session technologies normally expire when the browser or application session ends. Persistent technologies remain until their stated expiration date, until you delete them, or until the relevant identifier is reset.
Your choices apply separately to each browser, device, application and domain on which Consent Preferences is used. We keep a record of the choices you make so that we can apply them and show that we applied them, and we may keep that record longer than the technology it relates to. We do not ask you to renew your choice on every visit. We do not treat a choice as valid for more than 24 months, and we will ask you again sooner if the technologies, purposes, providers, or applicable legal requirements change materially.
11. Changes to This Policy and How to Contact Us
We may update this policy to reflect changes in law, guidance, technologies, providers, categories, purposes, or durations. When we do, we will update the "Last update" date at the top of this page. If a change is material, we will give additional notice through the site, the platform, or by email. If a configuration change affects the technologies described here, we will update Consent Preferences at the same time.
If you have questions about this policy, or you want to exercise any of the choices described in it, you can reach us by live chat on our site, by email at dpo@cex.io or support@cex.io, or by mail at: CEX.IO Corp., 100 SE 2nd St, Suite 3852, Miami, Florida 33131, USA.
CEX.IO OVRS (ST. KITTS AND NEVIS)
Privacy Policy
Last updated: 24 September 2026
This Privacy Policy explains how CEX OVRS LLC collects, uses, shares, retains and protects personal data in connection with the Services.
Who is responsible for your personal data?
CEX OVRS LLC is the controller where it provides Services to you or otherwise determines why and how your personal data is processed.
The CEX.IO entity responsible for your Account and Services depends on your country of residence, as provided by you, and on the Services made available to you through the Platform. If the entity providing Services to you changes, the applicable entity and legal documents will be presented to you through the Platform, in your Account and/or in relevant email notifications.
This Privacy Policy should be read together with the Terms of Use, the Cookie Policy and any product-specific notice presented when personal data is collected.
Contents
1. Scope and status of this Policy
2. Who we are and how to contact us
3. Personal data we collect
4. How we collect personal data
5. How we use personal data and our lawful bases
6. Special category data and information relating to criminal convictions, offences and related proceedings
7. Automated decision-making and profiling
8. How we share personal data
9. Blockchain and transfer information
10. International transfers
11. Data retention
12. Security
13. Your data protection rights
14. How to exercise your rights
15. Data protection complaints
16. Marketing, advertising and social media
17. Cookies and similar technologies
18. Children
19. Additional information where the GDPR applies
20. Third-party websites and services
21. Changes to this Policy
1. Scope and status of this Policy
1.1 This Privacy Policy applies where CEX OVRS LLC (“CEX.IO”, “we”, “us” or “our”) processes personal data as controller in connection with the Site, Platform, Account and Services provided to Users, including prospective Users, individual Users, representatives and beneficial owners of corporate Users, payers, beneficiaries, recipients, counterparties, website and application visitors, and persons who contact us.
1.2 If another CEX.IO entity provides a Service to you or determines its own purposes and means of processing, that entity’s privacy policy applies to that processing. If another CEX.IO entity processes personal data only on our instructions, it acts as our processor. In some cases, another CEX.IO entity may act with us as a joint controller where we jointly determine the purposes and essential means of a specific processing activity. Where this applies, we will provide the information required by applicable data protection law.
1.3 Capitalised terms not defined in this Privacy Policy have the meanings given to them in the Terms of Use. Terms defined in applicable data protection laws have the meanings given to them in those laws.
1.4 This Privacy Policy is governed by the data protection and privacy standards that apply to the relevant processing. Saint Kitts and Nevis has enacted a Data Protection Act, 2018, which, as at the date of this Policy, has not been brought into force by the ministerial commencement order required under that Act. Pending commencement, general Nevis law, including contract, consumer-protection, electronic-transactions and financial-services legislation – governs the protection of personal data in Nevis. Where the GDPR or another data protection law applies extraterritorially to specific processing (including under Article 3 GDPR), the GDPR-specific legal bases, rights, safeguards, complaint routes and international-transfer requirements described in this Policy apply to that processing. In the absence of a fully operative domestic data-protection supervisory regime in Nevis, we also apply the data-protection principles, safeguards and disclosures in this Policy as a matter of internal policy and recognised international best practice. Other legal and regulatory requirements may also require or permit particular processing, including in relation to AML/CTF, sanctions, tax, crypto-asset services, payment services, customer protection, complaints, legal claims and regulatory supervision. If the Nevis Data Protection Act, 2018 is brought into force, repealed or amended, we will update this Policy accordingly.
1.5 GDPR during the EU/EEA exit period. CEX OVRS LLC no longer onboards new Users resident in the EU/EEA. Where CEX OVRS LLC continues to provide limited Services to persons in the EU/EEA who were onboarded before that change, during an applicable transition, migration, withdrawal-only or orderly-exit period, and the GDPR applies under Article 3, the GDPR-specific legal bases, rights, safeguards, complaint routes and international-transfer requirements described in this Privacy Policy continue to apply to that processing until the applicable retention period for the relevant personal data expires.
2. Who we are and how to contact us
2.1 CEX OVRS LLC is a limited liability company established in St. Kitts and Nevis with company number L 22275 and registered office at Suite 1, A.L. Evelyn LTD Building, Charlestown, Nevis, St. Kitts and Nevis.
2.2 You may contact us or our Data Protection Officer using any of the following official channels:
- Secure online live chat available through the Site, mobile application and Help Centre;
- Data Protection Officer: dpo@cex.io;
- Customer support email: support@cex.io;
- Post: Data Protection Officer, CEX OVRS LLC, Suite 1, A.L. Evelyn LTD Building, Charlestown, Nevis, St. Kitts and Nevis.
2.3 For security, do not send passwords, one-time codes, private keys, recovery phrases or complete payment card details through live chat, email or social media. Where reasonably necessary to protect your personal data and Account, we may ask you to verify your identity or continue an Account-specific discussion through an authenticated channel designated by CEX.IO.
3. Personal data we collect
The personal data we process depends on how you interact with us, the Services you use, your Account type and the legal and risk requirements that apply. We may process the following categories of personal data:
(See the table at the end of this section for the categories of personal data we collect.)
Certain information must be provided because it is necessary for us to enter into or perform our contract with you under the Terms of Use, verify identity, apply required AML/CTF, sanctions, Travel Rule, fraud-prevention and regulatory controls, process Transactions or comply with legal and regulatory requirements. If you do not provide required information, or if we cannot complete required checks using the information and verification methods available in the relevant circumstances, we may be unable to open or maintain an Account, provide a Service, process a Transaction, answer a request or continue the relationship.
If you have accessibility, technical or other legitimate difficulties completing an automated identity-verification or liveness process, you may contact us through the channels in section 2 so that we can assess whether an alternative verification route is available and appropriate in the circumstances.
| Category | Examples |
|---|---|
| Identity and contact data | Full name, previous names, date and place of birth, age, nationality, citizenship, residential and mailing address, email address, telephone number, signature, user ID, customer number and Account identifiers. |
| Identity-verification and due-diligence data | Government-issued identity documents and document details; photographs, selfie images, video, liveness information and verification results; proof of address; tax identification numbers and tax residence; occupation, employer and professional information; source of funds and source of wealth; purpose and intended nature of the relationship; corporate documents, ownership and control information, directors, authorised representatives and beneficial owners; politically exposed person, sanctions and adverse-media screening information; and information requested during onboarding, ongoing monitoring or an Account Review. |
| Financial and payment data | Bank and payment account details, payment card data or tokens, card issuer and payment method information, bank statements, payment references, payer and beneficiary information, balances, fees, charges, refunds, chargebacks, recalls, reversals, settlement information and accounting or tax records. |
| Transaction and Digital Asset data | Orders, trades, conversions, Deposits, Withdrawals, transfers, staking activity, CEX.IO Pay activity, transaction dates and values, Trading Pairs, wallet addresses, destination addresses, transaction hashes, selected networks, memos and tags, originator and beneficiary information, Travel Rule information, counterparties and related instructions or confirmations. |
| Compliance, fraud and risk data | Customer and transaction risk ratings, screening results, blockchain analytics, wallet attribution and exposure information, fraud indicators, device and behavioural risk signals, unusual or suspicious activity indicators, investigations, Account Review records, regulatory reports, law-enforcement requests and decisions concerning access, limits, holds, restrictions or closure. |
| Technical, device and security data | IP address, approximate location derived from IP or device signals, device type and identifiers, browser and operating system, application version, language, time zone, session identifiers, cookies and similar technologies, login and authentication events, 2FA and security-event metadata, connected devices, API identifiers and activity logs, network and diagnostic information, crash and error data, and records of suspected compromise. |
| Usage and interaction data | Pages, screens and features used, clicks, navigation, search and referral data, product and interface preferences, service configuration, activity timestamps, performance and analytics information, and responses to surveys or research. |
| Communications, support and complaint data | Live-chat messages, emails, telephone or video call records where used, support tickets, complaints, requests, correspondence, attachments, screenshots, call or chat recordings where notified, verification responses, investigation notes and associated metadata. |
| Marketing and preference data | Marketing choices, communication preferences, campaign engagement, referral and promotion information, survey responses, advertising identifiers, cookie or pixel identifiers, hashed contact data used for audience matching where permitted, and social-media interactions. |
| Corporate User and representative data | Organisation name, registered and business addresses, company number, constitutional documents, business activity, regulatory status, ownership structure, beneficial ownership, directors, authorised signatories, employee or representative role, authority and permissions, and business contact details. |
| Other data you provide | Any other personal data you choose to provide, or that we reasonably require for the Services, security, compliance, dispute resolution or legal obligations. Please provide only information relevant to your request. |
4. How we collect personal data
We collect personal data from the following sources:
- Directly from you when you register, complete verification, use the Services, submit an instruction, contact support, make a complaint, exercise a right, participate in a survey or communicate with us.
- From your use of the Platform through Account records, Transactions, authentication, cookies, SDKs, APIs, logs, security tools and other technical systems.
- From affiliated CEX.IO entities where necessary for cooperation and operational arrangements relating to the Platform and Services, including customer administration, security, compliance, customer support, technology, internal audit and business administration.
- From service and infrastructure providers including identity and liveness verification providers, sanctions and PEP screening providers, blockchain analytics providers, Travel Rule providers, fraud and device-intelligence providers, cloud and communications providers, customer-support providers, custodians, staking or validator providers, liquidity providers, exchanges and market infrastructure providers.
- From banks, payment and financial institutions including payment service providers, card networks such as Visa and Mastercard, card issuers, acquirers, correspondent banks, e-money institutions and other payment participants.
- From authorised crypto-asset service providers, custodians, wallet providers or other regulated providers where necessary to process a transfer, migration, withdrawal, reallocation, closure, safeguarding measure or other regulatory-transition action.
- From other persons including corporate customers, authorised representatives, beneficial owners, counterparties, originators, beneficiaries, CEX.IO Pay senders or recipients, referral partners and persons who report suspected fraud or unauthorised activity.
- From public and official sources including company registers, sanctions lists, PEP lists, court and insolvency records, professional registers, public websites, public blockchain data, regulators, law-enforcement authorities, tax authorities and other competent bodies.
- From advertising, analytics and social-media partners where you have consented or the processing is otherwise permitted by law.
5. How we use personal data and our lawful bases
We process personal data only where we have a lawful basis. More than one lawful basis may apply to a particular processing activity. Depending on the purpose and circumstances, we may rely on contractual necessity, compliance with a legal obligation, our legitimate interests, consent or another lawful basis available under applicable data protection laws.
Where we rely on legitimate interests, we consider the nature and purpose of the processing, whether the processing is necessary, and its possible impact on your interests, rights and freedoms.
Where we rely on consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before consent was withdrawn or processing we carry out under another lawful basis.
Regulatory changes and service availability. Where the availability of Services changes because of licensing, regulatory or supervisory requirements, guidance or expectations, AML/CTF, sanctions or other legal matters, we may continue to process personal data where necessary to administer your Account, communicate with you, process withdrawals or transfers, support migration or orderly wind-down, safeguard Users and assets, keep records, provide support, maintain security, comply with law and respond to regulatory matters. The relevant lawful basis depends on the activity and may include contractual necessity, compliance with a legal obligation and/or our legitimate interests.
(See the table at the end of section 6 for the purposes for which we use personal data, the categories involved and the applicable lawful basis.)
Purpose | Personal data we use | Lawful basis |
|---|---|---|
Open, administer and maintain Accounts; verify eligibility and authority; establish the Account relationship; provide Account interfaces and functionality; and maintain Account details and preferences. | Identity and contact data; identity-verification data; corporate and representative data; technical, device and security data; usage data; and communications data. | Contract: to take steps at your request before entering into our contract with you and to perform our contract under the Terms of Use. Legitimate interests: where you act for a corporate User, and for secure and efficient Account administration. |
Provide and operate the Services, where available, including Account, wallet and balance functionality; Fiat Currency and Digital Asset deposits and withdrawals; spot trading; purchase, sale, exchange and conversion of supported Digital Assets and Fiat Currency; order placement, execution, matching, routing and settlement; internal transfers; Instant Buy and Instant Sell; CEX.IO Pay; staking; API access; supported payment methods; market information; and related Platform functionality. | Identity and contact data; corporate and representative data; financial and payment data; Account data; Order, Transaction and Digital Asset data; wallet addresses; payment and beneficiary details; internal-transfer and CEX.IO Pay information; staking, validator and unstaking information; API activity; technical, device and security data; usage data; and communications data. | Contract: to provide the Services and perform our contract under the Terms of Use. Legal obligation: where transaction information, controls, records or disclosures are required by law. Legitimate interests: operating the Platform, administering Transactions, reconciling balances, maintaining reliable Services and managing operational risk. |
Apply customer-protection, eligibility and regulatory controls, including customer categorisation, appropriateness or suitability assessments where used, risk warnings, waiting or cooling-off periods, product and jurisdictional restrictions, acknowledgements and other measures required or permitted in connection with the Services. | Identity and contact data; date of birth and age; residence and location data; customer-category information; knowledge and experience information; assessment responses and results; risk-warning acknowledgements; Account and Transaction data; technical data; and compliance and risk data. | Legal obligation: to comply with applicable crypto-asset, payment, customer-protection, consumer-protection, marketing, disclosure and regulatory requirements. Legitimate interests: where appropriate, ensuring that Services and communications are provided only to eligible Users and managing regulatory, product and customer-protection risk. |
Verify identity and conduct customer due diligence, enhanced due diligence, sanctions and politically exposed person screening, source-of-funds and source-of-wealth checks, beneficial-ownership and authority checks, ongoing monitoring, Travel Rule compliance, tax compliance and regulatory reporting. | Identity and contact data; identity-verification data; photographs, video or liveness information where used; corporate and representative data; beneficial-ownership information; financial and payment data; Account, Transaction and Digital Asset data; wallet information; tax information; compliance, fraud and risk data; and supporting documents and declarations. | Legal obligation: including applicable anti-money laundering, counter-terrorist financing, sanctions, proliferation-financing, transfer-of-funds, Travel Rule, tax and regulatory requirements. Legitimate interests: where appropriate, preventing unlawful use of the Services, impersonation and fraud, protecting Users, CEX.IO and the Platform, and maintaining reliable verification and security controls. Where special category data or information relating to criminal convictions, offences or related proceedings is processed, we also rely on an applicable condition or authorisation under the GDPR or other applicable law. |
Prevent, detect and investigate unlawful, fraudulent or prohibited activity, including fraud, money laundering, terrorist financing, proliferation financing, sanctions evasion, market abuse, account takeover, payment abuse, cybersecurity incidents and misuse of the Platform or Services. | Any relevant categories of personal data, particularly identity and verification data; Account, Order, Transaction and Digital Asset data; financial and payment data; wallet and blockchain information; technical, device and security data; compliance, fraud and risk data; and communications data. | Legal obligation: where monitoring, prevention, investigation, reporting or disclosure is required by law. Legitimate interests: preventing loss, crime, fraud and misuse; protecting Users, CEX.IO, affiliated CEX.IO entities and third parties; and maintaining the security and integrity of the Platform. |
Manage Accounts, supported assets and operational or regulatory changes, including Account Reviews, risk scoring, investigations, limits, holds, restrictions, suspension and closure; inactive and deactivated Accounts; reactivation; unsupported assets; product, jurisdictional or regulatory changes; regulatory transition, migration, service-restriction, suspension, wind-down or orderly-exit measures; client communications; withdrawal, transfer, reallocation or closure instructions; residual balances; protocol events; system upgrades; and related transfers or conversions permitted under the Terms of Use or required by applicable law. | Identity and contact data; identity-verification data; Account status; jurisdiction and eligibility information; Account and balance data; supported and unsupported asset information; financial and payment data; Orders, Transactions and Digital Asset data; wallet information; withdrawal, transfer, closure or migration instructions; technical, device and security data; usage data; client communications; regulatory-status information; compliance, AML/CTF, sanctions, fraud and risk data; and records of actions taken to safeguard Users and comply with applicable regulatory requirements. | Contract: to administer the Account, process instructions and apply the Terms of Use. Legal obligation: where restrictions, communications, records, disclosures, migration, wind-down, reporting or other actions are required by applicable licensing, AML/CTF, sanctions, tax, crypto-asset services, payment services, customer-protection or other legal or regulatory requirements. Legitimate interests: maintaining operational continuity and system integrity; managing regulatory transition, unsupported assets, inactive Accounts and residual balances; protecting Users, CEX.IO and affiliated CEX.IO entities; safeguarding assets; and applying proportionate operational, legal and risk controls. |
Authenticate Users and protect Accounts, assets, systems and information, including password and authentication management, two-factor authentication, approved devices, API access, access controls, fraud controls, activity logging, security monitoring, vulnerability management, incident detection and response, operational resilience and security testing. | Identity and contact data; authentication data; technical, device and security data; IP addresses and device identifiers; API keys and activity logs; usage data; Account and Transaction information; compliance and risk data; and communications data. | Legal obligation: to maintain appropriate technical and organisational security measures and meet applicable legal and regulatory requirements. Contract: to provide secure access to the Account and Services. Legitimate interests: protecting systems, Users, assets, personal data and the integrity of the Platform. |
Process payments, corrections and recoveries, including deposits and withdrawals, settlement, fees, refunds, chargebacks, recalls, reversals, clawbacks, set-off, payment disputes, erroneous credits, incorrectly sent Fiat Currency or Digital Assets, reconciliation, recovery of amounts due and cooperation with banks, payment providers and other relevant participants. | Identity and contact data; Account data; financial and payment data; bank-account, payment-card and payment-method information; Order and Transaction data; wallet and beneficiary information; compliance, fraud and risk data; technical and security data; communications data; and supporting evidence. | Contract: to process and administer payments and Transactions under the Terms of Use. Legal obligation: where payment, record-keeping, fraud-prevention, tax or regulatory requirements apply. Legitimate interests: reconciliation, correcting errors, recovering funds and amounts due, resolving payment disputes, preventing fraud and protecting the rights and assets of Users, CEX.IO and relevant third parties. |
Provide customer support and communicate with you, including responding to questions, requests and complaints; investigating Account and Transaction issues; providing service, legal, regulatory, security and incident communications; communicating about legal, regulatory, product or service changes, Account restrictions, migration options, withdrawal or transfer deadlines, wind-down measures, safeguarding arrangements and actions required from you; making reasonable adjustments; and operating live-chat, email and other support channels. | Identity and contact data; Account, Order and Transaction data; financial and payment data; technical and security data; communications data; support history; call or chat records; and any other information relevant to the matter raised. | Contract: to provide support in connection with the Account and Services. Legal obligation: including complaint-handling, accessibility and data-protection obligations. Legitimate interests: providing effective support, maintaining service quality, investigating issues, resolving disputes and keeping appropriate records. |
Respond to and administer data protection rights and complaints, including identifying and locating relevant personal data, verifying identity where reasonably necessary, communicating with the requester, investigating complaints and recording the response and outcome. | Identity and contact data; identity-verification information where necessary; Account data; communications data; complaint and request details; and any personal data relevant to the request or complaint. | Legal obligation: to comply with applicable data protection rights and complaint-handling requirements. Legitimate interests: preventing unauthorised disclosure, maintaining evidence of compliance and resolving requests and complaints fairly and securely. |
Maintain records and evidence, including records of notices, disclosures, instructions, Orders, Transactions, consents, preferences, acknowledgements, communications, Account activity, investigations and decisions; and establish, exercise or defend legal rights and claims. | Communications data; Account, Order and Transaction data; financial and payment data; technical logs; consent and preference records; compliance, fraud and risk data; complaint and support records; and other relevant evidence. | Legal obligation: where records must be retained or produced by law. Contract: to evidence and administer the Account, Services and Transactions. Legitimate interests: maintaining appropriate evidence, resolving disputes, enforcing the Terms of Use and establishing, exercising or defending legal claims. |
Comply with legal and regulatory duties and respond to competent authorities, including court orders, statutory notices, lawful requests and duties involving regulators, law-enforcement agencies, tax authorities, supervisory authorities and other competent bodies, including competent data protection, financial-services, financial-intelligence, sanctions, tax and law-enforcement authorities where applicable. | Any categories of personal data that are necessary and proportionate to the relevant request, duty, investigation or proceeding. | Legal obligation: where disclosure, reporting or cooperation is required by law. Legitimate interests: where cooperation is lawful, proportionate and not legally mandatory, including protecting rights, preventing harm and responding appropriately to competent authorities. |
Analyse, develop, test, maintain and improve the Site, Platform and Services, including monitoring performance, troubleshooting, analysing use, improving interfaces, security and customer experience, and developing, testing and evaluating new, beta, pilot or limited-release products, tools and features. | Account and user identifiers; cookie, device and session identifiers; IP addresses; technical, device and security data; usage and interaction data; communications data; feedback; testing information; and relevant Account and Transaction data, including data that has been pseudonymised where appropriate. | Legitimate interests: product development, testing, service improvement, reliability, operational efficiency, security and resilience. Contract: where processing is necessary to provide a beta, pilot or other feature selected by you. Consent: where applicable law requires consent for cookies, SDKs or similar technologies. |
Send marketing and product communications, including information about products, Services, features, market developments, events and offers; conduct surveys; measure communications and campaigns; and build or use audiences where permitted. | Identity and contact data; marketing preferences; consent and opt-out records; limited Account-relationship data; usage and interaction data; cookie, advertising and device identifiers; survey responses; and campaign information. | Consent: where required by applicable electronic communications, cookie or privacy law. Legitimate interests: for communications that may lawfully be sent to existing customers without consent and for appropriate campaign measurement. Legal obligation: to apply applicable regulatory requirements, restrictions, warnings and controls to communications. You may opt out of direct marketing at any time. |
Administer promotions, referral arrangements, surveys and research, including checking eligibility, managing participation, delivering any applicable benefit, preventing misuse and evaluating outcomes. | Identity and contact data; Account and Transaction data necessary to establish eligibility; referral information; marketing preferences; survey and research responses; communications data; and fraud and risk data. | Contract: where you choose to enter or participate in a promotion or arrangement. Consent: where required. Legitimate interests: administering and evaluating promotions, referrals, surveys and research and preventing misuse. |
Manage our business and relationships with affiliated CEX.IO entities and other organisations, including cooperation and operational arrangements with affiliated CEX.IO entities; governance; audits; insurance; professional advice; financing; restructuring; corporate transactions; business continuity; and internal administration. | Relevant identity and contact data; corporate and representative data; Account and contractual information; financial data; compliance and risk data; technical and security data; and communications data. | Legitimate interests: operating, administering, protecting, financing and reorganising our business and managing relationships with affiliated CEX.IO entities, service providers, advisers and business partners. Legal obligation: where records, audits, disclosures or other actions are required by law. |
Create anonymised or aggregated information that no longer identifies an individual, including for analytics, research, reporting, security, risk management and product development. | Any categories of personal data capable of lawful anonymisation or aggregation. | Legitimate interests: analysing and improving our business, Services, security and risk management. Information that has been effectively anonymised is no longer personal data. |
6. Special category data and information relating to criminal convictions, offences and related proceedings
6.1 Facial images, liveness and biometric-related information. Photographs, video, selfie images, liveness information and verification outputs are personal data. They become special category biometric data only where they are processed through specific technical means for the purpose of uniquely identifying or authenticating an individual.
We may use facial images, document images, video, selfie checks, liveness checks and related verification outputs to verify identity, confirm that the person presenting an identity document corresponds to that document, prevent impersonation and fraud, protect Account security, and comply with AML/CTF, sanctions, Travel Rule and other legal and regulatory requirements.
Where a specific verification process involves special category biometric data, we use it only where the processing is necessary and proportionate for the relevant verification, fraud-prevention, security or regulatory purpose, and where other applicable legal requirements are identified and documented. We do not rely on legitimate interests alone to process special category biometric data.
We do not use special category biometric data for marketing, advertising or unrelated commercial profiling.
We apply safeguards including data minimisation, human review where required or appropriate, access restrictions, vendor controls, security measures, retention limits, DPIA review where required, and controls designed to avoid retaining biometric templates, embeddings or comparison data for longer than necessary.
6.2 Other special category data. We do not seek special category data unless it is necessary. It may be processed if you voluntarily disclose health or disability information when requesting reasonable support, or if information obtained during compliance or legal processes reveals a special category. We process it only where an applicable lawful basis is in place.
6.3 Information relating to criminal convictions, offences and related proceedings. Compliance, fraud, security and dispute records may include information about criminal convictions, offences, investigations, proceedings or related precautionary or security measures. We process such information where necessary for regulatory compliance, the prevention or detection of unlawful acts, fraud prevention, regulatory action or the establishment, exercise or defence of legal claims. We use enhanced access, retention and governance controls.
7. Automated decision-making and profiling
7.1 We use automated systems, rules, models and profiling to support identity verification, document and liveness checks, sanctions and PEP screening, fraud detection, blockchain and transaction monitoring, device and behavioural risk analysis, customer and Transaction risk scoring, eligibility checks, security controls, product functionality, marketing preferences and service improvement.
7.2 The factors considered may include identity-match and document-authenticity results; screening matches; Account history; Transaction patterns and values; wallet and blockchain exposure; source-of-funds information; location, device and network signals; links to other Accounts or payment methods; security events; legal restrictions; and information supplied during an Account Review. We do not disclose detailed detection rules where doing so could undermine security, fraud prevention, financial-crime controls or the rights of others.
7.3 Automated outputs may result in a request for further information, enhanced authentication, a delay or hold, a Transaction being rejected, access to a feature being limited, or an Account application or activity being referred for review. Some decisions may be made without meaningful human involvement where permitted by law.
7.4 Where a decision based solely on automated processing has a legal or similarly significant effect on you, we apply the safeguards required by law. These include giving you information about the decision, enabling you to make representations, request human intervention, and contest the decision, except where a lawful exemption applies. You may request a review through the channels in section 2.
7.5 AI-enabled tools may be used in customer support to classify or summarise requests, retrieve support information, propose answers, or provide an automated first response. You may request a human agent. Support AI is not used to make final decisions about onboarding, Account restrictions, or Transactions. Contractual and technical controls are used to limit provider access and use of support data.
8. How we share personal data
We disclose personal data only where necessary, proportionate and lawful. Recipients may include:
- affiliated CEX.IO entities, where necessary for cooperation and operational arrangements relating to the Platform and Services, including customer administration, security, compliance, customer support, technology, internal audit and business administration. Depending on the relevant processing activity, an affiliated CEX.IO entity may act as our processor, as a separate controller for its own purposes and legal obligations, or, where we jointly determine the purposes and essential means of a specific processing activity, as a joint controller with us.
- identity, compliance and risk providers, including identity-document, selfie, liveness and biometric verification providers; sanctions, PEP and adverse-media screening providers; blockchain analytics and wallet intelligence providers; Travel Rule providers; fraud, device-intelligence and cybersecurity providers.
- banks and payment participants, including payment service providers, e-money institutions, card networks such as Visa and Mastercard, issuers, acquirers, banking partners, correspondent banks and settlement providers. Some act as independent controllers and provide their own privacy information.
- Digital Asset and market infrastructure providers, including custodians, wallet and node infrastructure providers, validators and staking providers, liquidity providers, exchanges, market makers, market-data providers, blockchain networks and protocol participants.
- authorised crypto-asset service providers, payment institutions, custodians, wallet providers or other regulated providers where necessary to process a transfer, migration, withdrawal, reallocation, closure, safeguarding measure or other action requested by you, required by law or implemented as part of an orderly regulatory transition or wind-down process.
- technology and business service providers, including cloud hosting, data storage, software, analytics, communications, email and SMS delivery, live-chat and customer support, document management, consent management, auditing, accountancy, legal, insurance and professional-advisory providers.
- other Users and counterparties where necessary to provide a requested transaction or feature, including the limited CEX.IO Pay information described in section 9.2.
- regulators and public authorities, including the competent data protection, financial-services, financial-intelligence, sanctions, tax and law-enforcement authorities, tax authorities, sanctions authorities, courts, law-enforcement bodies, financial-intelligence units and other competent authorities, where required or permitted by law.
- persons involved in disputes or legal proceedings, including counterparties, their representatives, courts, tribunals, mediators, insurers and professional advisers.
- corporate transaction recipients, including prospective buyers, investors, lenders and advisers in connection with a merger, acquisition, financing, reorganisation or transfer of business or assets, subject to appropriate confidentiality and data-protection measures.
- advertising, analytics and social-media providers only where the required consent or other lawful basis exists and subject to your choices in Consent Preferences and your marketing choices.
Service providers acting on our behalf are authorised to process personal data only for agreed purposes and are subject to contractual confidentiality, security, assistance, and deletion or return obligations. Where a recipient acts as an independent controller, its own privacy notice and legal obligations apply.
9. Blockchain and transfer information
9.1 Platform records and public blockchain records
Where you deposit Digital Assets from an external wallet, withdraw Digital Assets to an external wallet or otherwise initiate a transfer that is transmitted to or recorded on a public blockchain, information relating to the relevant transfer may become publicly accessible on a decentralised and potentially immutable network. This may include wallet addresses, transaction hashes, amounts, timestamps and other network information.
Public blockchain information may be viewed by anyone and may be analysed or combined with other information in a manner that could identify or relate to an individual. CEX.IO cannot delete, correct or restrict information recorded on a public blockchain. However, where we hold related information in our own systems, we may be able to provide access to that information, correct inaccurate internal records, restrict or stop certain internal uses, delete or block off-chain records when retention is no longer required, or explain why a legal exemption or retention requirement applies.
9.2 CEX.IO Pay and other internal transfers
Where CEX.IO Pay or another internal transfer functionality is available, transfers between eligible CEX.IO Accounts are generally processed within CEX.IO systems and are not necessarily recorded as individual transfers on a public blockchain.
When you send Digital Assets using CEX.IO Pay, the recipient may see your registered first name, the first letter of your last name and your unique CEX.IO user identification number. This limited disclosure is used to identify the transaction counterparty and provide the relevant functionality.
We do not authorise recipients to use that information for unrelated purposes. However, recipients are independently responsible for any further use of information they receive.
9.3 Travel Rule and payment information
For certain Digital Asset or Fiat Currency transfers, we may be legally required to collect, verify, transmit or receive information about the originator and beneficiary. This information may be shared with the recipient service provider, payment participant, Travel Rule network, intermediary or competent authority, including where a transfer is reviewed, delayed, rejected, restricted or investigated.
10. International transfers
10.1 Our recipients and we may process personal data in St. Kitts and Nevis, the European Economic Area and other countries. Data-protection laws in those countries may differ from the laws applicable to you.
10.2 Where we make a restricted transfer from the EEA, we use an applicable lawful mechanism, such as an adequacy decision adopted by the European Commission; the European Commission Standard Contractual Clauses; approved binding corporate rules, codes of conduct or certification mechanisms where available; another safeguard recognised by EU data-protection law; or a limited statutory derogation, where the legal conditions are met.
10.3 We assess transfer risks and apply supplementary technical, contractual or organisational measures where appropriate.
11. Data retention
We keep personal data only for as long as reasonably necessary for the purposes for which it was collected or is further processed. This includes legal, regulatory, accounting, security, fraud-prevention, dispute-resolution, audit and evidential requirements. Account closure or deactivation does not automatically require deletion, because some records must be retained after the relationship ends.
The table below explains the main periods and criteria we use to decide how long different types of personal data are kept. Some retention periods are set by law. Other periods depend on the type of record, the purpose of processing, the risks involved, whether the Account remains active, and whether the information is needed for compliance, security, audit, dispute-resolution or legal-claims purposes.
Where applicable law requires data to be restricted, blocked or preserved instead of deleted, we apply the required measure using technical and organisational controls that prevent ordinary access or use. Such data are made available only where permitted or required by law, including to competent authorities or for the establishment, exercise or defence of legal claims. Once the applicable retention or limitation period ends, the data are securely deleted or irreversibly anonymised unless another lawful basis for retention applies.
When retention ends, we securely delete, destroy, block or irreversibly anonymise personal data, as applicable, unless continued retention is required or permitted by law. We periodically review retention rules and may apply a shorter period where the purpose can be achieved with less data.
| Record type | How long we keep it |
|---|---|
| Account, onboarding, KYC, AML, sanctions, Travel Rule and records of Orders, payments and Transactions | For the duration of the business relationship and ordinarily for at least five years after it ends, or for the period required by the AML/CTF, sanctions, tax, crypto-asset, payment or other laws applicable to the relevant record. Records relating to an occasional transaction are ordinarily retained for at least five years after the transaction. A longer period may apply where required by another law, a regulator or competent authority, an investigation, audit, legal hold, limitation period or dispute. Records are deleted, restricted, blocked or anonymised when retention ends, as applicable. |
| Contract, payment, accounting and tax records | For the period necessary to administer the relationship and meet contractual, payment, accounting, tax, audit and legal-claim requirements. These records are commonly retained for up to six years after the relevant relationship, transaction, payment, Account closure or financial year, but a different or longer period may apply under the law governing the record or an active audit, investigation or dispute. |
| Customer support and routine communications | For the period necessary to address the enquiry, administer the Account or provide the relevant Service. Routine operational communications are generally retained for a shorter period unless they become relevant to a complaint, investigation, Transaction, legal obligation or dispute. |
| Complaints, data protection rights requests and material communications | For the period necessary to investigate and resolve the matter and to demonstrate how it was handled. Material complaint, rights-request and dispute-related records may be retained for the applicable limitation period where necessary for legal compliance, accountability, evidence or legal claims. Where a specific regulatory complaint-retention rule applies to a particular Service or complaint type, we retain the record for at least the applicable regulatory period. |
| Fraud, security, device, access and incident records | For as long as necessary to identify, investigate and respond to fraud, unauthorised access, security threats and incidents; prevent recurrence; protect Users, assets and systems; and meet legal and regulatory requirements. Lower-risk technical logs may be retained for substantially shorter periods. Records may be retained for longer where an active threat, investigation, legal hold, regulatory matter or claim continues. |
| Identity documents, photographs and verification records | Where retained as part of a legally required customer due diligence record, identification documents, photographs and relevant verification results are retained for the applicable AML/CTF record-keeping period. This does not mean that every biometric or technical output generated during verification is retained for the same period. |
| Liveness captures and biometric-related information | Raw video, liveness captures, biometric templates, facial vectors, embeddings, comparison data and other technical outputs are retained only for as long as necessary for the specific verification, fraud-prevention, security or regulatory purpose for which they are used. Where biometric templates, vectors or embeddings are created only to complete a one-off 1:1 identity-matching or liveness event, they are deleted, de-linked or irreversibly rendered unusable after that event or after a short technical retention period, unless continued retention is necessary for fraud investigation, security, legal claims, regulatory evidence or another documented lawful purpose. CEX.IO does not retain biometric templates, vectors or embeddings for general marketing, advertising or unrelated profiling. To meet AML/CTF and regulatory record-keeping requirements, we may retain non-biometric verification results, audit logs, timestamps, decision records, confirmation codes and other evidence that required checks were completed. |
| Marketing data | Until you withdraw consent, object, unsubscribe or the information is no longer necessary for the relevant marketing purpose. We may retain a minimal suppression record for as long as necessary to respect your choice, prevent further marketing and demonstrate compliance. |
| Cookies and similar technologies | For the period shown in Consent Preferences for the relevant cookie or similar technology. Records of your consent, rejection and preferences may be retained for as long as reasonably necessary to demonstrate your choices, respect your preferences and comply with applicable law. We may ask you to renew or confirm your choices where required or appropriate, including where the purposes, technologies, providers or legal requirements materially change. |
| Legal holds, investigations and disputes | Until the relevant investigation, complaint, audit, regulatory review, enforcement action, claim, litigation, appeal or applicable limitation period has ended and any necessary follow-up or enforcement action is complete. Legal holds are reviewed and lifted when continued retention is no longer necessary. |
| Backups | For defined and limited backup, security and disaster-recovery cycles. Deleted, restricted or blocked data may remain in protected backups until the relevant backup is overwritten or securely deleted and is not restored for ordinary business use. If backup data are restored, applicable deletion, objection, restriction and blocking decisions are reapplied where technically and operationally appropriate. |
12. Security
We maintain technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure and unauthorised access. Depending on the system and risk, measures may include encryption in transit and at rest, access controls, segregation of duties, multi-factor authentication, logging and monitoring, secure development and change management, vulnerability management, incident response, resilience and backup controls, personnel confidentiality obligations, vendor due diligence and contractual security requirements.
Where payment card data are processed, CEX.IO applies card-payment security controls appropriate to the processing activity. Where applicable, CEX.IO and/or its trusted payment service providers maintain PCI DSS compliance for cardholder-data environments.
No method of transmission, storage or authentication is completely secure. You are responsible for protecting your security credentials and devices and for notifying us promptly of suspected compromise. We will notify affected individuals and the competent data protection or privacy authorities of a personal data breach where and within the period required by law, including, where the GDPR applies, notification to the competent EU/EEA supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of the breach.
13. Your data protection rights
| Right | What it means |
|---|---|
Access | Obtain confirmation of whether we process your personal data and receive a copy together with required supplementary information. |
Rectification | Ask us to correct inaccurate personal data or complete incomplete information. |
Erasure | Ask us to delete personal data where a legal ground applies. This right does not override legal retention, AML/CTF, fraud-prevention, legal-claims, data-blocking or public-blockchain limitations. |
Restriction | Ask us to restrict processing in specified circumstances. |
Data portability | Receive personal data you provided to us in a structured, commonly used and machine-readable format, and ask us to transmit it to another controller where technically feasible and legally applicable. |
Object | Object to processing based on legitimate interests. You have an absolute right to object to direct marketing, including related profiling. |
Withdraw consent | Withdraw consent at any time where processing is based on consent. Withdrawal does not affect earlier lawful processing. |
Automated decisions | Where applicable, receive information and request human intervention, make representations and contest a significant solely automated decision. |
Complain | Make a data protection complaint to us and lodge a complaint with a competent data protection or privacy authority. If the GDPR applies, this includes a competent EU/EEA supervisory authority. |
14. How to exercise your rights
14.1 You may submit a rights request through secure online live chat, dpo@cex.io, support@cex.io or by post using the details in section 2. You do not need to use a specific form, quote a legal provision or use particular wording. If you contact another official CEX.IO channel, we will route a clear data-protection request to the appropriate team.
14.2 Please describe what you want us to do and, where relevant, the Account, date range, transaction or communication concerned. A focused request helps us respond efficiently, but we will not require information that is not reasonably necessary.
14.3 We may ask for information needed to verify your identity, authority and Account ownership. This protects you and other individuals. Where possible, we use existing Account authentication rather than collecting additional identity documents. We may ask an authorised representative to provide evidence of authority and may confirm instructions with you directly.
14.4 We normally respond within one month after receiving a valid request and the information reasonably required to verify identity. If the request is complex or you make several requests, we may extend the period by up to two further months and will explain the extension within the first month. If a request is unclear, we may seek clarification as permitted by law. We carry out reasonable and proportionate searches.
14.5 Rights are usually free of charge. We may charge a reasonable fee or refuse to act where the law permits because a request is manifestly unfounded or excessive, including because it is repetitive. We will explain any refusal and the available complaint rights.
14.6 Some rights may be limited where necessary to comply with financial crime, sanctions, tax, security, legal claims or regulatory duties; protect the rights of another person; preserve confidential risk controls; or avoid prejudicing the prevention or detection of crime. We apply exemptions case by case and disclose as much as the law permits.
15. Data protection complaints
15.1 You may complain to us if you believe we have used personal data unfairly, failed to respect a right, disclosed information improperly, retained it too long, failed to keep it secure or otherwise breached data protection law. You may submit a data protection complaint through secure online live chat, dpo@cex.io, support@cex.io or by post using the details in section 2. You do not need to use a specific form, quote a legal provision or use particular wording.
15.2 If a complaint is received through social media or another insecure channel, we will take reasonable steps to recognise and route it, but may ask you to continue through an authenticated or secure channel before discussing personal or Account information.
15.3 We will take appropriate steps to investigate the complaint fairly and accurately, ask for clarification or evidence only where reasonably necessary, keep you informed where appropriate, and tell you about the outcome without undue delay, including the reasons and any action taken or proposed.
15.4 You may lodge a complaint with a data protection or privacy authority that is competent for your country or for the relevant processing. If the GDPR applies, you may complain to the supervisory authority in the EU/EEA country where you usually live, where you work or where you believe the infringement took place. You do not have to contact us before approaching an authority, although we welcome the opportunity to address your concern first.
15.5 This section concerns data protection complaints. Service, transaction and contractual complaints are handled under the relevant provisions in the Terms of Use. A complaint may involve both processes, and we may coordinate them while keeping the applicable legal routes distinct.
16. Marketing, advertising and social media
16.1 We may send service, security, legal, regulatory, Transaction and Account communications where necessary. These are not marketing and may continue after you opt out of promotional messages.
16.2 We send electronic marketing only where permitted by applicable electronic communications and marketing law, ePrivacy rules, data-protection law and applicable regulatory requirements. We may rely on your consent or, where legally available, our legitimate interests in informing existing customers about similar CEX.IO products and services. You can opt out of direct marketing at any time by using the unsubscribe link in our marketing messages or, where available, by changing the notification preferences in your Account.
16.3 With consent where required, we may use cookies, mobile advertising identifiers and hashed contact data to measure campaigns, create audiences or show relevant advertising through providers such as search engines, social networks and advertising platforms. The current providers and controls are available through Consent Preferences. These providers may act as independent controllers for their own purposes.
16.4 When you interact with an official CEX.IO social-media page, the platform provider processes information under its own privacy notice. We may receive comments, messages, engagement statistics and audience insights. Do not use social media for passwords, security codes, private keys or detailed Account information.
16.5 To reduce impersonation risk, you should use only CEX.IO Official Channels, applications and verified communication channels. Where we maintain a list of official social-media pages or support channels, you should use that list to check whether a page or message is genuine.
16.6 We keep suppression information after an opt-out so that we can respect your choice. Opting out of marketing does not affect legal, security, service or administrative messages.
17. Cookies and similar technologies
We use cookies, local storage, SDKs, pixels, tags, scripts and similar technologies on the Site, Platform, mobile application and communications. Some are Necessary for security, authentication, fraud prevention, consent management and requested functionality. Functional, Analytics and Advertisement technologies are optional and are used only in accordance with your choices in Consent Preferences and applicable law. The Consent Preferences interface is displayed when you first visit the Site and remains available through the “Consent Preferences” link or icon on the left-hand side of the Site footer. The Cookie Policy and Consent Preferences explain the current technologies, categories, providers, purposes and durations and allow you to update your choices.
For as long as the Site, Platform or communications remain accessible to, or used by, Users located in the EU/EEA, we apply cookie consent and disclosure standards equivalent to those required under the ePrivacy Directive and its national implementing measures, including prior opt-in consent for optional categories and giving equal prominence to “accept” and “reject” choices – regardless of where CEX OVRS LLC is established, as further described in the Cookie Policy.
18. Children
The Services are not intended for anyone under 18 and minors are not eligible to open an Account. We do not knowingly provide the Services to children. If you believe a child has provided personal data or an Account is being used by a minor, contact us promptly at support@cex.io or dpo@cex.io. We will investigate and take appropriate action, subject to legal record-keeping and safeguarding obligations.
19. Additional information where the GDPR applies
Where the GDPR applies to our processing under Article 3, including during an applicable EU/EEA service-transition or exit period described in section 1.5, CEX OVRS LLC acts as controller for the processing described in this Privacy Policy. The applicable Article 6 GDPR lawful bases are set out in section 5, the Article 9 and 10 conditions in section 6, your rights (including the right to object under Article 21) in sections 13 and 14, our complaint-handling routes in section 15, and our EEA transfer safeguards in section 10.
20. Third-party websites and services
The Site, Platform and communications may link to or integrate third-party websites, applications, wallets, payment pages or services that we do not control. The third party’s privacy notice applies to its processing. Review that notice before providing personal data. A link or integration does not mean that we accept responsibility for the third party’s privacy or security practices.
21. Changes to this Policy
We may update this Policy to reflect changes in law, regulation, guidance, the Services, technology or our processing. We will update the “Last updated” date and, where a change is material, provide an appropriate notice through the Site, Platform, Account, email or another official channel. Where consent is required for a new purpose, we will request it separately.
Controller: CEX OVRS LLC, company number L 22275, registered office at Suite 1, A.L. Evelyn LTD Building, Charlestown, Nevis, St. Kitts and Nevis. Data Protection Officer: dpo@cex.io.
Cookie Policy
Last updated: 24 September 2026
This Cookie Policy explains how CEX OVRS LLC uses cookies and other storage and access technologies in connection with the Site, Platform, mobile application and Services. It should be read together with the CEX OVRS LLC Privacy Policy.
1. Scope and status of this Policy
1.1 This Cookie Policy applies to cookies, local storage, session storage, software development kits (SDKs), pixels, tags, scripts, device identifiers and other technologies that store information on, or access information from, your device in connection with the Site, Platform, mobile application, hosted interfaces and electronic communications used to provide the Services.
1.2 If another CEX.IO entity is responsible for the Site, Platform or Services you use, that entity's own privacy and cookie information may apply instead of, or in addition to, this Policy.
1.3. Where our use of a technology involves processing personal data, the Privacy Policy provides further information about the applicable purposes and lawful bases, categories of recipients, international transfers, retention and your data protection rights.
2. Who we are and how to contact us
2.1 CEX OVRS LLC is the controller for the use of cookies and similar technologies described in this Cookie Policy where it determines the relevant purposes and means. CEX OVRS LLC is a limited liability company established in St. Kitts and Nevis with company number L 22275 and registered office at Suite 1, A.L. Evelyn LTD Building, Charlestown, Nevis, St. Kitts and Nevis.
2.2 You may contact us or our Data Protection Officer through secure online live chat available through the Site, mobile application and Help Centre, by email at dpo@cex.io or support@cex.io, or by post at Data Protection Officer, CEX OVRS LLC, Suite 1, A.L. Evelyn LTD Building, Charlestown, Nevis, St. Kitts and Nevis.
3. What cookies and similar technologies are
Cookies are small text files placed on your browser or device when a website is visited. Similar technologies include local and session storage, SDKs embedded in mobile applications, pixels or web beacons, tags, scripts, advertising identifiers, device identifiers and other techniques used to store or retrieve information from a browser, application or device.
Some technologies last only for a session and are deleted when the browser or application closes. Others are persistent and remain until their stated expiry date, until they are deleted, or until the relevant identifier is reset. First-party technologies are set by the service you are using. Third-party technologies are set or accessed by another organisation whose functionality is integrated into the service.
4. Consent Preferences
Consent Preferences means the cookie and similar-technology preference interface displayed when you first visit the Site and available at any time through a permanently accessible “Consent Preferences” link or icon on the left-hand side of the Site footer.
You can accept all optional cookies and similar technologies, reject all optional cookies and similar technologies, or manage optional cookies and similar technologies by category through Consent Preferences. The option to reject all optional categories is given the same visual prominence, and requires the same number of steps, as the option to accept all.
Rejecting optional technologies will not prevent you from using the Site, although some non-essential features may not work as intended. You can change your choices at any time through the permanently accessible Consent Preferences link or icon.
We do not treat closing the banner, ignoring it, scrolling, continuing to browse or any other pre-ticked, implied or bundled action as consent to optional cookies or similar technologies.
5. Consent and legal basis
5.1 Consent given through Consent Preferences is our record of your choice regarding storage and access technologies and, where applicable, is treated as consent for the purposes of applicable ePrivacy or equivalent electronic-communications law. It is separate from any GDPR lawful basis that applies where information collected through a cookie or similar technology is personal data.
5.2 Necessary technologies may be used without consent only where they are strictly necessary to transmit a communication, provide a Service or functionality requested by you, remember your Consent Preferences, maintain authentication or session security, protect against fraud, abuse or unauthorised access, apply security controls, or operate and secure the Site or Platform. Technologies that are useful or convenient for CEX.IO, but not strictly necessary for the requested service or functionality, are not treated as Necessary.
5.3 Where applicable law requires your prior consent, Functional, Analytics and Advertisement technologies are optional and are not activated before you select the relevant category in Consent Preferences. Where applicable law does not require your prior consent, these technologies may be active by default, and you may decline or withdraw at any time through Consent Preferences.
5.4 Where a technology involves personal data, the Privacy Policy provides further information about the applicable GDPR lawful bases, purposes, recipients, international transfers, retention and your rights.
5.5 You may withdraw or change your consent at any time through Consent Preferences. Withdrawal does not affect the lawfulness of processing carried out before consent was withdrawn. We stop the relevant storage or access and associated consent-based processing going forward. You may also need to delete existing cookies or identifiers through browser, application or device controls.
6. Categories of cookies and similar technologies
The table below sets out the categories of cookies and similar technologies we use. The current, detailed inventory of individual technologies (including provider, purpose, first-party or third-party status, duration and available choice) is maintained in Consent Preferences.
Category | What it is used for | Consent position | Default |
|---|---|---|---|
Necessary | Operate and secure the Site and Platform; maintain sessions; authenticate Users; prevent fraud and technical abuse; remember your Consent Preferences; and provide requested functionality. | Used without consent only where the technology is necessary to transmit a communication, provide a Service or functionality requested by you, or operate and secure the Site or Platform. Technologies that are useful or convenient for CEX.IO, but not strictly necessary for the requested service or functionality, are not treated as Necessary. | Always active and cannot be switched off through Consent Preferences. |
Functional | Provide optional features and personalisation, such as remembering selected preferences, collecting feedback, enabling live chat, displaying embedded content or supporting other enhanced functionality. | Used only with your consent through Consent Preferences, unless a specific narrow exception applies and has been assessed and documented. | Off until you select this category where applicable law requires your prior consent; otherwise may be on by default, subject to your right to decline |
Analytics | Understand how visitors use the Site or Platform; measure traffic, journeys and interactions; identify errors; test and improve performance, content and customer experience; and evaluate service effectiveness. | Used only with your consent through Consent Preferences, unless a specific narrow exception applies and has been assessed and documented. Analytics technologies may process identifiers and technical, device, session, usage and referral information. | Off until you select this category where applicable law requires your prior consent; otherwise may be on by default, subject to your right to decline |
Advertisement | Measure advertising campaigns; attribute referrals; limit repeated advertisements; create or match audiences; personalise advertising and understand advertising effectiveness, subject to your choices and applicable legal and regulatory restrictions on communications about crypto-asset services. | Used only with your consent through Consent Preferences. Advertisement technologies are never activated before you consent to the Advertisement category. Advertisement technologies may track activity across websites, applications or services and may involve third-party advertising providers. They are not used to override Service eligibility, jurisdictional restrictions, risk warnings or other regulatory controls. | Off until you select this category where applicable law requires your prior consent; otherwise may be on by default, subject to your right to decline |
7. Third-party technologies
We may use third-party providers for analytics, advertising, social media, customer engagement, consent management, security and technical services. Optional third-party technologies that require consent are activated only in accordance with your choices in Consent Preferences. Where these providers act on our behalf, they may use the information only for agreed purposes and subject to contractual controls. Where a provider acts as an independent controller, its own privacy notice and legal obligations apply.
Consent Preferences includes cookie-level information, including the cookie or technology name, provider or domain, category, purpose, whether it is first-party or third-party, duration or expiry period, and available choice where applicable. The information in Consent Preferences forms part of this Cookie Policy and is reviewed periodically and when material changes are introduced. If a provider, purpose, category, duration or similar material configuration changes, Consent Preferences and this Cookie Policy will be updated and fresh consent obtained where required.
8. Mobile application technologies
If you use our mobile application, we may use mobile SDKs and device identifiers, including advertising identifiers where enabled, for security, analytics, functionality or advertising purposes. Where platform rules or applicable law require permission, we request it before using such identifiers for tracking or advertising. You can also manage mobile permissions through your device settings, such as iOS App Tracking Transparency or Android advertising ID controls.
9. Marketing emails and tracking technologies
Our electronic communications may contain pixels, links or similar technologies that help us understand whether a message was delivered, opened or interacted with. Where consent is required, we use these technologies only with the required consent. Your choice about email tracking is separate from your choice to receive marketing emails. You can unsubscribe from marketing communications at any time by using the unsubscribe link in our marketing messages or, where available, by changing the notification preferences in your Account.
10. Managing cookies through your browser or device
Most browsers allow you to block, delete or manage cookies. Your browser or device settings may not control all technologies used in mobile applications or communications. If you block all cookies, some necessary or requested functionality may not operate correctly. Consent Preferences remains the primary method for managing optional categories on the Site. If you accept third-party cookies and later want to delete cookies already stored on your browser or device, you may need to delete them through your browser, device settings or the tools provided by the relevant third party, in addition to changing your choices in Consent Preferences.
Browser “Do Not Track” or similar signals are not by themselves a substitute for valid consent unless recognised by applicable law and supported by the relevant technology. We use Consent Preferences as the primary control for technologies used through CEX.IO.
11. Retention
Your choices may apply separately to each browser, device, application or domain where Consent Preferences are used. Cookies and similar technologies are stored for the period shown in Consent Preferences for the relevant technology. Records of your consent, rejection and preferences may be retained for as long as reasonably necessary to demonstrate your choices, respect your preferences and comply with applicable law. We do not ask you to renew your choice on every visit unless required by law, the relevant purposes, providers, categories or durations change, or the configured consent period expires. We generally do not treat a cookie consent choice as valid for more than 24 months unless applicable law or guidance permits a different approach.
12. International transfers
Information collected through cookies and similar technologies may be processed in St. Kitts and Nevis, the EEA and other countries. Where personal data are transferred outside the EEA, the international-transfer section of the Privacy Policy applies.
13. Questions, rights requests and complaints
Questions, rights requests or complaints about our use of cookies and similar technologies may be submitted through secure online live chat, dpo@cex.io, support@cex.io or by post using the contact details in section 2 of this Cookie Policy.
We handle complaints about cookies and similar technologies under the process described in the Privacy Policy. If the GDPR applies, you may lodge a complaint with the competent data protection supervisory authority in the EU/EEA Member State where you usually live, where you work, or where you believe the infringement took place.
14. Changes to this Cookie Policy
We may update this Cookie Policy to reflect changes in law, guidance, technology, providers, categories, purposes, durations or our use of cookies and similar technologies. Where a change affects optional technologies that require consent, we will request fresh consent where required. We will update the “Last updated” date when we make a change.
Controller: CEX OVRS LLC, company number L 22275, registered office at Suite 1, A.L. Evelyn LTD Building, Charlestown, Nevis, St. Kitts and Nevis. Data Protection Officer: dpo@cex.io.
CEX.IO EUROPE, S.L. (ES)
Privacy Policy
Last updated: 24 September 2026
This Privacy Policy explains how CEX.IO Europe S.L. collects, uses, shares, retains and protects personal data in connection with the Services.
Who is responsible for your personal data?
CEX.IO Europe S.L. is the controller where it provides Services to you or otherwise determines why and how your personal data is processed.
The CEX.IO entity responsible for your Account and Services depends on your country of residence, as provided by you, and on the Services made available to you through the Platform. If the entity providing Services to you changes, the applicable entity and legal documents will be presented to you through the Platform, in your Account and/or in relevant email notifications.
This Privacy Policy should be read together with the Terms of Use, the Cookie Policy and any product-specific notice presented when personal data is collected.
Contents
- Scope and status of this Policy
- Who we are and how to contact us
- Personal data we collect
- How we collect personal data
- How we use personal data and our lawful bases
- Special category data and information relating to criminal convictions, offences and related proceedings
- Automated decision-making and profiling
- How we share personal data
- Blockchain and transfer information
- International transfers
- Data retention
- Security
- Your data protection rights
- How to exercise your rights
- Data protection complaints
- Marketing, advertising and social media
- Cookies and similar technologies
- Children
- Third-party websites and services
- Changes to this Policy
1. Scope and status of this Policy
1.1 This Privacy Policy applies where CEX.IO Europe S.L. (“CEX.IO”, “we”, “us” or “our”) processes personal data as controller in connection with the Site, Platform, Account and Services provided to Users, including prospective Users, individual Users, representatives and beneficial owners of corporate Users, payers, beneficiaries, recipients, counterparties, website and application visitors, and persons who contact us.
1.2 If another CEX.IO entity provides a Service to you or determines its own purposes and means of processing, that entity’s privacy policy applies to that processing. If another CEX.IO entity processes personal data only on our instructions, it acts as our processor. In some cases, another CEX.IO entity may act with us as a joint controller where we jointly determine the purposes and essential means of a specific processing activity. Where this applies, we will provide the information required by applicable data protection law.
1.3 Capitalised terms not defined in this Privacy Policy have the meanings given to them in the Terms of Use. Terms defined in applicable data protection laws have the meanings given to them in those laws.
1.4 This Privacy Policy is primarily governed by the General Data Protection Regulation, formally Regulation (EU) 2016/679 (“GDPR”), Spanish Organic Law 3/2018 on Personal Data Protection and guarantee of digital rights, and other applicable EU or Spanish data protection and privacy laws. Law 34/2002 on services of the information society and electronic commerce may also apply to cookies, similar technologies, electronic commercial communications and online services. Other legal and regulatory requirements may also require or permit particular processing, including in relation to AML/CTF, sanctions, tax, crypto-asset services, payment services, customer and investor protection, complaints, legal claims and regulatory supervision.
1.5. Restricted service period for EU/EEA Users. In accordance with Regulation (EU) 2023/1114 (MiCA) and applicable regulatory requirements, CEX.IO Europe S.L. does not currently onboard new Users resident in the EU/EEA. Existing Accounts of Users resident in the EU/EEA remain accessible strictly for withdrawal-only and account-management purposes, including viewing balances and transaction history and withdrawing available Fiat Currency or Digital Asset balances, as further described in the Terms of Use. This Privacy Policy continues to apply to the processing of personal data of such Users for as long as we hold or process it.
2. Who we are and how to contact us
2.1 CEX.IO Europe S.L. is a limited liability company incorporated under Spanish law with tax identification number NIF B72550395 and registered office at Paseo de la Castellana 53, 1a, 28046 Madrid, Spain. It is registered with the Bank of Spain as a provider of virtual currency exchange services for fiat currency. Where CEX.IO Europe S.L. obtains authorisation as a crypto-asset service provider under MiCA, this information will be updated accordingly.
2.2 You may contact us or our Data Protection Officer using any of the following official channels:
- Secure online live chat available through the Site, mobile application and Help Centre;
- Data Protection Officer: dpo@cex.io;
- Customer support email: support@cex.io;
- Post: Data Protection Officer, CEX.IO Europe S.L., Paseo de la Castellana 53, 1a, 28046 Madrid, Spain.
2.3 For security, do not send passwords, one-time codes, private keys, recovery phrases or complete payment card details through live chat, email or social media. Where reasonably necessary to protect your personal data and Account, we may ask you to verify your identity or continue an Account-specific discussion through an authenticated channel designated by CEX.IO.
3. Personal data we collect
The personal data we process depends on how you interact with us, the Services you use, your Account type and the legal and risk requirements that apply. We may process the following categories of personal data:
Category | Examples |
|---|---|
Identity and contact data | Full name, previous names, date and place of birth, age, nationality, citizenship, residential and mailing address, email address, telephone number, signature, user ID, customer number and Account identifiers. |
Identity-verification and due-diligence data | Government-issued identity documents and document details; photographs, selfie images, video, liveness information and verification results; proof of address; tax identification numbers and tax residence; occupation, employer and professional information; source of funds and source of wealth; purpose and intended nature of the relationship; corporate documents, ownership and control information, directors, authorised representatives and beneficial owners; politically exposed person, sanctions and adverse-media screening information; and information requested during onboarding, ongoing monitoring or an Account Review. |
Financial and payment data | Bank and payment account details, payment card data or tokens, card issuer and payment method information, bank statements, payment references, payer and beneficiary information, balances, fees, charges, refunds, chargebacks, recalls, reversals, settlement information and accounting or tax records. |
Transaction and Digital Asset data | Orders, trades, conversions, Deposits, Withdrawals, transfers, staking activity, CEX.IO Pay activity, transaction dates and values, Trading Pairs, wallet addresses, destination addresses, transaction hashes, selected networks, memos and tags, originator and beneficiary information, Travel Rule information, counterparties and related instructions or confirmations. |
Compliance, fraud and risk data | Customer and transaction risk ratings, screening results, blockchain analytics, wallet attribution and exposure information, fraud indicators, device and behavioural risk signals, unusual or suspicious activity indicators, investigations, Account Review records, regulatory reports, law-enforcement requests and decisions concerning access, limits, holds, restrictions or closure. |
Technical, device and security data | IP address, approximate location derived from IP or device signals, device type and identifiers, browser and operating system, application version, language, time zone, session identifiers, cookies and similar technologies, login and authentication events, 2FA and security-event metadata, connected devices, API identifiers and activity logs, network and diagnostic information, crash and error data, and records of suspected compromise. |
Usage and interaction data | Pages, screens and features used, clicks, navigation, search and referral data, product and interface preferences, service configuration, activity timestamps, performance and analytics information, and responses to surveys or research. |
Communications, support and complaint data | Live-chat messages, emails, telephone or video call records where used, support tickets, complaints, requests, correspondence, attachments, screenshots, call or chat recordings where notified, verification responses, investigation notes and associated metadata. |
Marketing and preference data | Marketing choices, communication preferences, campaign engagement, referral and promotion information, survey responses, advertising identifiers, cookie or pixel identifiers, hashed contact data used for audience matching where permitted, and social-media interactions. |
Corporate User and representative data | Organisation name, registered and business addresses, company number, constitutional documents, business activity, regulatory status, ownership structure, beneficial ownership, directors, authorised signatories, employee or representative role, authority and permissions, and business contact details. |
Other data you provide | Any other personal data you choose to provide, or that we reasonably require for the Services, security, compliance, dispute resolution or legal obligations. Please provide only information relevant to your request. |
Certain information must be provided because it is necessary for us to enter into or perform our contract with you under the Terms of Use, verify identity, apply required AML/CTF, sanctions, Travel Rule, fraud-prevention and regulatory controls, process Transactions or comply with legal and regulatory requirements. If you do not provide required information, or if we cannot complete required checks using the information and verification methods available in the relevant circumstances, we may be unable to open or maintain an Account, provide a Service, process a Transaction, answer a request or continue the relationship.
If you have accessibility, technical or other legitimate difficulties completing an automated identity-verification or liveness process, you may contact us through the channels in section 2 so that we can assess whether an alternative verification route is available and appropriate in the circumstances.
4. How we collect personal data
We collect personal data from the following sources:
- Directly from you when you register, complete verification, use the Services, submit an instruction, contact support, make a complaint, exercise a right, participate in a survey or communicate with us.
- From your use of the Platform through Account records, Transactions, authentication, cookies, SDKs, APIs, logs, security tools and other technical systems.
- From affiliated CEX.IO entities where necessary for cooperation and operational arrangements relating to the Platform and Services, including customer administration, security, compliance, customer support, technology, internal audit and business administration.
- From service and infrastructure providers including identity and liveness verification providers, sanctions and PEP screening providers, blockchain analytics providers, Travel Rule providers, fraud and device-intelligence providers, cloud and communications providers, customer-support providers, custodians, staking or validator providers, liquidity providers, exchanges and market infrastructure providers.
- From banks, payment and financial institutions including payment service providers, card networks such as Visa and Mastercard, card issuers, acquirers, correspondent banks, e-money institutions and other payment participants.
- From authorised crypto-asset service providers, custodians, wallet providers or other regulated providers where necessary to process a transfer, migration, withdrawal, reallocation, closure, safeguarding measure or other regulatory-transition action.
- From other persons including corporate customers, authorised representatives, beneficial owners, counterparties, originators, beneficiaries, CEX.IO Pay senders or recipients, referral partners and persons who report suspected fraud or unauthorised activity.
- From public and official sources including company registers, sanctions lists, PEP lists, court and insolvency records, professional registers, public websites, public blockchain data, regulators, law-enforcement authorities, tax authorities and other competent bodies.
- From advertising, analytics and social-media partners where you have consented or the processing is otherwise permitted by law.
5. How we use personal data and our lawful bases
We process personal data only where we have a lawful basis. More than one lawful basis may apply to a particular processing activity. Depending on the purpose and circumstances, we may rely on contractual necessity, compliance with a legal obligation, our legitimate interests, consent or another lawful basis available under applicable data protection laws.
Where we rely on legitimate interests, we consider the nature and purpose of the processing, whether the processing is necessary, and its possible impact on your interests, rights and freedoms.
Where we rely on consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before consent was withdrawn or processing we carry out under another lawful basis.
Regulatory changes and service availability. Where the availability of Services changes because of MiCA, CNMV or ESMA requirements, guidance or expectations, AML/CTF, sanctions, licensing or other regulatory matters, we may continue to process personal data where necessary to administer your Account, communicate with you, process withdrawals or transfers, support migration or orderly wind-down, safeguard Users and assets, keep records, provide support, maintain security, comply with law and respond to regulatory matters. The relevant lawful basis depends on the activity and may include contractual necessity, compliance with a legal obligation and/or our legitimate interests.
Purpose | Personal data we use
| Lawful basis |
Open, administer and maintain Accounts; verify eligibility and authority; establish the Account relationship; provide Account interfaces and functionality; and maintain Account details and preferences. | Identity and contact data; identity-verification data; corporate and representative data; technical, device and security data; usage data; and communications data. | Contract: to take steps at your request before entering into our contract with you and to perform our contract under the Terms of Use. Legitimate interests: where you act for a corporate User, and for secure and efficient Account administration. |
Provide and operate the Services, where available, including Account, wallet and balance functionality; Fiat Currency and Digital Asset deposits and withdrawals; spot trading; purchase, sale, exchange and conversion of supported Digital Assets and Fiat Currency; order placement, execution, matching, routing and settlement; internal transfers; Instant Buy and Instant Sell; CEX.IO Pay; staking; API access; supported payment methods; market information; and related Platform functionality. | Identity and contact data; corporate and representative data; financial and payment data; Account data; Order, Transaction and Digital Asset data; wallet addresses; payment and beneficiary details; internal-transfer and CEX.IO Pay information; staking, validator and unstaking information; API activity; technical, device and security data; usage data; and communications data. | Contract: to provide the Services and perform our contract under the Terms of Use. Legal obligation: where transaction information, controls, records or disclosures are required by law. Legitimate interests: operating the Platform, administering Transactions, reconciling balances, maintaining reliable Services and managing operational risk. |
Apply customer-protection, investor-protection, eligibility and regulatory controls, including customer categorisation, appropriateness assessments, risk warnings, required waiting periods before certain Services can be accessed or completed, product and jurisdictional restrictions, acknowledgements and other measures required or permitted in connection with the Services. | Identity and contact data; date of birth and age; residence and location data; customer-category information; knowledge and experience information; assessment responses and results; risk-warning acknowledgements; Account and Transaction data; technical data; and compliance and risk data. | Legal obligation: to comply with applicable crypto-asset services, payment services, customer and investor protection, consumer and user protection, marketing, disclosure and regulatory requirements. |
Verify identity and conduct customer due diligence, enhanced due diligence, sanctions and politically exposed person screening, source-of-funds and source-of-wealth checks, beneficial-ownership and authority checks, ongoing monitoring, Travel Rule compliance, tax compliance and regulatory reporting. | Identity and contact data; identity-verification data; photographs, video or liveness information where used; corporate and representative data; beneficial-ownership information; financial and payment data; Account, Transaction and Digital Asset data; wallet information; tax information; compliance, fraud and risk data; and supporting documents and declarations. | Legal obligation: including anti-money laundering, counter-terrorist financing, sanctions, proliferation-financing, transfer-of-funds, tax and regulatory requirements, including Law 10/2010 and Regulation (EU) 2023/1113 where applicable. Legitimate interests: where appropriate, preventing unlawful use of the Services, preventing impersonation and fraud, protecting Users, CEX.IO and the Platform, and maintaining reliable verification and security controls. Where special category data or information relating to criminal convictions, offences or related proceedings is processed, we also rely on an applicable condition or authorisation under the GDPR, LOPDGDD and other applicable law. |
Prevent, detect and investigate unlawful, fraudulent or prohibited activity, including fraud, money laundering, terrorist financing, proliferation financing, sanctions evasion, market abuse, account takeover, payment abuse, cybersecurity incidents and misuse of the Platform or Services. | Any relevant categories of personal data, particularly identity and verification data; Account, Order, Transaction and Digital Asset data; financial and payment data; wallet and blockchain information; technical, device and security data; compliance, fraud and risk data; and communications data. | Legal obligation: where monitoring, prevention, investigation, reporting or disclosure is required by law. Legitimate interests: preventing loss, crime, fraud and misuse; protecting Users, CEX.IO, affiliated CEX.IO entities and third parties; and maintaining the security and integrity of the Platform. |
Manage Accounts, supported assets and operational or regulatory changes, including Account Reviews, risk scoring, investigations, limits, holds, restrictions, suspension and closure; inactive and deactivated Accounts; reactivation; unsupported assets; product, jurisdictional or regulatory changes; MiCA transition, authorisation, migration, service-restriction, suspension, wind-down or orderly-exit measures; client communications; withdrawal, transfer, reallocation or closure instructions; residual balances; protocol events; system upgrades; and related transfers or conversions permitted under the Terms of Use or required by applicable law. | Identity and contact data; identity-verification data; Account status; jurisdiction and eligibility information; Account and balance data; supported and unsupported asset information; financial and payment data; Orders, Transactions and Digital Asset data; wallet information; withdrawal, transfer, closure or migration instructions; technical, device and security data; usage data; client communications; regulatory-status information; compliance, AML/CTF, sanctions, fraud and risk data; and records of actions taken to safeguard Users and comply with applicable regulatory requirements. | Contract: to administer the Account, process instructions and apply the Terms of Use. Legal obligation: where restrictions, communications, records, disclosures, migration, wind-down, reporting or other actions are required by MiCA, AML/CTF, sanctions, tax, crypto-asset services, payment services, customer and investor protection or other applicable legal or regulatory requirements. Legitimate interests: maintaining operational continuity and system integrity; managing regulatory transition, unsupported assets, inactive Accounts and residual balances; protecting Users, CEX.IO and affiliated CEX.IO entities; safeguarding client assets; and applying proportionate operational, legal and risk controls. |
Authenticate Users and protect Accounts, assets, systems and information, including password and authentication management, two-factor authentication, approved devices, API access, access controls, fraud controls, activity logging, security monitoring, vulnerability management, incident detection and response, operational resilience and security testing. | Identity and contact data; authentication data; technical, device and security data; IP addresses and device identifiers; API keys and activity logs; usage data; Account and Transaction information; compliance and risk data; and communications data. | Legal obligation: to maintain appropriate technical and organisational security measures and meet applicable legal and regulatory requirements. Contract: to provide secure access to the Account and Services. Legitimate interests: protecting systems, Users, assets, personal data and the integrity of the Platform. |
Process payments, corrections and recoveries, including deposits and withdrawals, settlement, fees, refunds, chargebacks, recalls, reversals, clawbacks, set-off, payment disputes, erroneous credits, incorrectly sent Fiat Currency or Digital Assets, reconciliation, recovery of amounts due and cooperation with banks, payment providers and other relevant participants. | Identity and contact data; Account data; financial and payment data; bank-account, payment-card and payment-method information; Order and Transaction data; wallet and beneficiary information; compliance, fraud and risk data; technical and security data; communications data; and supporting evidence. | Contract: to process and administer payments and Transactions under the Terms of Use. Legal obligation: where payment, record-keeping, fraud-prevention, tax or regulatory requirements apply. Legitimate interests: reconciliation, correcting errors, recovering funds and amounts due, resolving payment disputes, preventing fraud and protecting the rights and assets of Users, CEX.IO and relevant third parties. |
Provide customer support and communicate with you, including responding to questions, requests and complaints; investigating Account and Transaction issues; providing service, legal, regulatory, security and incident communications; communicating about legal, regulatory, product or service changes, Account restrictions, migration options, withdrawal or transfer deadlines, wind-down measures, safeguarding arrangements and actions required from you; making reasonable adjustments; and operating live-chat, email and other support channels. | Identity and contact data; Account, Order and Transaction data; financial and payment data; technical and security data; communications data; support history; call or chat records; and any other information relevant to the matter raised. | Contract: to provide support in connection with the Account and Services. Legal obligation: including complaint-handling, accessibility and data-protection obligations. Legitimate interests: providing effective support, maintaining service quality, investigating issues, resolving disputes and keeping appropriate records. |
Respond to and administer data protection rights and complaints, including identifying and locating relevant personal data, verifying identity where reasonably necessary, communicating with the requester, investigating complaints and recording the response and outcome. | Identity and contact data; identity-verification information where necessary; Account data; communications data; complaint and request details; and any personal data relevant to the request or complaint. | Legal obligation: to comply with applicable data protection rights and complaint-handling requirements. Legitimate interests: preventing unauthorised disclosure, maintaining evidence of compliance and resolving requests and complaints fairly and securely. |
Maintain records and evidence, including records of notices, disclosures, instructions, Orders, Transactions, consents, preferences, acknowledgements, communications, Account activity, investigations and decisions; and establish, exercise or defend legal rights and claims. | Communications data; Account, Order and Transaction data; financial and payment data; technical logs; consent and preference records; compliance, fraud and risk data; complaint and support records; and other relevant evidence. | Legal obligation: where records must be retained or produced by law. Contract: to evidence and administer the Account, Services and Transactions. Legitimate interests: maintaining appropriate evidence, resolving disputes, enforcing the Terms of Use and establishing, exercising or defending legal claims. |
Comply with legal and regulatory duties and respond to competent authorities, including court orders, statutory notices, lawful requests and duties involving regulators, law-enforcement agencies, tax authorities, supervisory authorities and other competent bodies, including AEPD, SEPBLAC, the Bank of Spain, CNMV and ESMA where applicable. | Any categories of personal data that are necessary and proportionate to the relevant request, duty, investigation or proceeding. | Legal obligation: where disclosure, reporting or cooperation is required by law. Legitimate interests: where cooperation is lawful, proportionate and not legally mandatory, including protecting rights, preventing harm and responding appropriately to competent authorities. |
Analyse, develop, test, maintain and improve the Site, Platform and Services, including monitoring performance, troubleshooting, analysing use, improving interfaces, security and customer experience, and developing, testing and evaluating new, beta, pilot or limited-release products, tools and features. | Account and user identifiers; cookie, device and session identifiers; IP addresses; technical, device and security data; usage and interaction data; communications data; feedback; testing information; and relevant Account and Transaction data, including data that has been pseudonymised where appropriate. | Legitimate interests: product development, testing, service improvement, reliability, operational efficiency, security and resilience. Contract: where processing is necessary to provide a beta, pilot or other feature selected by you. Consent: where applicable law requires consent for cookies, SDKs or similar technologies. |
Send marketing and product communications, including information about products, Services, features, market developments, events and offers; conduct surveys; measure communications and campaigns; and build or use audiences where permitted. | Identity and contact data; marketing preferences; consent and opt-out records; limited Account-relationship data; usage and interaction data; cookie, advertising and device identifiers; survey responses; and campaign information. | Consent: where required by LSSI-CE, ePrivacy/cookie rules or other applicable law. Legitimate interests: for communications that may lawfully be sent to existing customers without consent and for appropriate campaign measurement. Legal obligation: to apply applicable regulatory requirements, restrictions, warnings and controls to communications. You may opt out of direct marketing at any time. |
Administer promotions, referral arrangements, surveys and research, including checking eligibility, managing participation, delivering any applicable benefit, preventing misuse and evaluating outcomes. | Identity and contact data; Account and Transaction data necessary to establish eligibility; referral information; marketing preferences; survey and research responses; communications data; and fraud and risk data. | Contract: where you choose to enter or participate in a promotion or arrangement. Consent: where required. Legitimate interests: administering and evaluating promotions, referrals, surveys and research and preventing misuse. |
Manage our business and relationships with affiliated CEX.IO entities and other organisations, including cooperation and operational arrangements with affiliated CEX.IO entities; governance; audits; insurance; professional advice; financing; restructuring; corporate transactions; business continuity; and internal administration. | Relevant identity and contact data; corporate and representative data; Account and contractual information; financial data; compliance and risk data; technical and security data; and communications data. | Legitimate interests: operating, administering, protecting, financing and reorganising our business and managing relationships with affiliated CEX.IO entities, service providers, advisers and business partners. Legal obligation: where records, audits, disclosures or other actions are required by law. |
Create anonymised or aggregated information that no longer identifies an individual, including for analytics, research, reporting, security, risk management and product development. | Any categories of personal data capable of lawful anonymisation or aggregation. | Legitimate interests: analysing and improving our business, Services, security and risk management. Information that has been effectively anonymised is no longer personal data. |
6. Special category data and information relating to criminal convictions, offences and related proceedings
6.1 Facial images, liveness and biometric-related information. Photographs, video, selfie images, liveness information and verification outputs are personal data. They become special category biometric data only where they are processed through specific technical means for the purpose of uniquely identifying or authenticating an individual.
We may use facial images, document images, video, selfie checks, liveness checks and related verification outputs to verify identity, confirm that the person presenting an identity document corresponds to that document, prevent impersonation and fraud, protect Account security, and comply with AML/CTF, sanctions, Travel Rule and other legal and regulatory requirements.
Where a specific verification process involves special category biometric data, we use it only where the processing is necessary and proportionate for the relevant verification, fraud-prevention, security or regulatory purpose, and where both an Article 6 GDPR lawful basis and an applicable Article 9 GDPR condition are identified and documented. We do not rely on legitimate interests alone to process special category biometric data.
Depending on the specific technology and purpose, the relevant Article 9 GDPR condition may include explicit consent where required for a specific video-identification, liveness or recording process, substantial public interest where the processing is necessary and proportionate for AML/CTF, sanctions, fraud-prevention or regulatory compliance and is supported by EU or Spanish law, or legal claims where the processing is necessary for the establishment, exercise or defence of legal claims. We do not use special category biometric data for marketing, advertising or unrelated commercial profiling.
We apply safeguards including data minimisation, human review where required or appropriate, access restrictions, vendor controls, security measures, retention limits, DPIA review where required, and controls designed to avoid retaining biometric templates, embeddings or comparison data for longer than necessary.
6.2 Other special category data. We do not seek special category data unless it is necessary. It may be processed if you voluntarily disclose health or disability information when requesting reasonable support, or if information obtained during compliance or legal processes reveals a special category. We process it only where an applicable Article 9 of the GDPR condition is met, such as explicit consent, substantial public interest or the establishment, exercise or defence of legal claims.
6.3 Information relating to criminal convictions, offences and related proceedings. Compliance, fraud, security and dispute records may include information about criminal convictions, offences, investigations, proceedings or related precautionary or security measures. We process such information under Article 10 of the GDPR and Article 10 of the LOPDGDD only where authorised by EU or Spanish law, including where necessary for regulatory compliance, the prevention or detection of unlawful acts, fraud prevention, regulatory action or the establishment, exercise or defence of legal claims. We use enhanced access, retention and governance controls.
7. Automated decision-making and profiling
7.1 We use automated systems, rules, models and profiling to support identity verification, document and liveness checks, sanctions and PEP screening, fraud detection, blockchain and transaction monitoring, device and behavioural risk analysis, customer and Transaction risk scoring, eligibility checks, security controls, product functionality, marketing preferences and service improvement.
7.2 The factors considered may include identity-match and document-authenticity results; screening matches; Account history; Transaction patterns and values; wallet and blockchain exposure; source-of-funds information; location, device and network signals; links to other Accounts or payment methods; security events; legal restrictions; and information supplied during an Account Review. We do not disclose detailed detection rules where doing so could undermine security, fraud prevention, financial-crime controls or the rights of others.
7.3 Automated outputs may result in a request for further information, enhanced authentication, a delay or hold, a Transaction being rejected, access to a feature being limited, or an Account application or activity being referred for review. Some decisions may be made without meaningful human involvement where permitted by law.
7.4 Where a decision based solely on automated processing has a legal or similarly significant effect on you, we apply the safeguards required by law. These include giving you information about the decision, enabling you to make representations, request human intervention, and contest the decision, except where a lawful exemption applies. You may request a review through the channels in section 14.
7.5 AI-enabled tools may be used in customer support to classify or summarise requests, retrieve support information, propose answers, or provide an automated first response. You may request a human agent. Support AI is not used to make final decisions about onboarding, Account restrictions, or Transactions. Contractual and technical controls are used to limit provider access and use of support data.
8. How we share personal data
We disclose personal data only where necessary, proportionate and lawful. Recipients may include:
- affiliated CEX.IO entities, where necessary for cooperation and operational arrangements relating to the Platform and Services, including customer administration, security, compliance, customer support, technology, internal audit and business administration. Depending on the relevant processing activity, an affiliated CEX.IO entity may act as our processor, as a separate controller for its own purposes and legal obligations, or, where we jointly determine the purposes and essential means of a specific processing activity, as a joint controller with us.
- identity, compliance and risk providers, including identity-document, selfie, liveness and biometric verification providers; sanctions, PEP and adverse-media screening providers; blockchain analytics and wallet intelligence providers; Travel Rule providers; fraud, device-intelligence and cybersecurity providers.
- banks and payment participants, including payment service providers, e-money institutions, card networks such as Visa and Mastercard, issuers, acquirers, banking partners, correspondent banks and settlement providers. Some act as independent controllers and provide their own privacy information.
- Digital Asset and market infrastructure providers, including custodians, wallet and node infrastructure providers, validators and staking providers, liquidity providers, exchanges, market makers, market-data providers, blockchain networks and protocol participants.
- authorised crypto-asset service providers, payment institutions, custodians, wallet providers or other regulated providers where necessary to process a transfer, migration, withdrawal, reallocation, closure, safeguarding measure or other action requested by you, required by law or implemented as part of an orderly regulatory transition or wind-down process.
- technology and business service providers, including cloud hosting, data storage, software, analytics, communications, email and SMS delivery, live-chat and customer support, document management, consent management, auditing, accountancy, legal, insurance and professional-advisory providers.
- other Users and counterparties where necessary to provide a requested transaction or feature, including the limited CEX.IO Pay information described in section 9.2.
- regulators and public authorities, including the AEPD, SEPBLAC, Bank of Spain, CNMV where applicable, tax authorities, sanctions authorities, courts, law-enforcement bodies, financial-intelligence units and other competent authorities, where required or permitted by law.
- persons involved in disputes or legal proceedings, including counterparties, their representatives, courts, tribunals, mediators, insurers and professional advisers.
- corporate transaction recipients, including prospective buyers, investors, lenders and advisers in connection with a merger, acquisition, financing, reorganisation or transfer of business or assets, subject to appropriate confidentiality and data-protection measures.
- advertising, analytics and social-media providers only where the required consent or other lawful basis exists and subject to your choices in Consent Preferences and your marketing choices.
Service providers acting on our behalf are authorised to process personal data only for agreed purposes and are subject to contractual confidentiality, security, assistance, and deletion or return obligations. Where a recipient acts as an independent controller, its own privacy notice and legal obligations apply.
9. Blockchain and transfer information
9.1 Platform records and public blockchain records
Where you deposit Digital Assets from an external wallet, withdraw Digital Assets to an external wallet or otherwise initiate a transfer that is transmitted to or recorded on a public blockchain, information relating to the relevant transfer may become publicly accessible on a decentralised and potentially immutable network. This may include wallet addresses, transaction hashes, amounts, timestamps and other network information.
Public blockchain information may be viewed by anyone and may be analysed or combined with other information in a manner that could identify or relate to an individual. CEX.IO cannot delete, correct or restrict information recorded on a public blockchain. However, where we hold related information in our own systems, we may be able to provide access to that information, correct inaccurate internal records, restrict or stop certain internal uses, delete or block off-chain records when retention is no longer required, or explain why a legal exemption or retention requirement applies.
9.2 CEX.IO Pay and other internal transfers
Where CEX.IO Pay or another internal transfer functionality is available, transfers between eligible CEX.IO Accounts are generally processed within CEX.IO systems and are not necessarily recorded as individual transfers on a public blockchain.
When you send Digital Assets using CEX.IO Pay, the recipient may see your registered first name, the first letter of your last name and your unique CEX.IO user identification number. This limited disclosure is used to identify the transaction counterparty and provide the relevant functionality.
We do not authorise recipients to use that information for unrelated purposes. However, recipients are independently responsible for any further use of information they receive.
9.3 Travel Rule and payment information
For certain Digital Asset or Fiat Currency transfers, we may be legally required to collect, verify, transmit or receive information about the originator and beneficiary. This information may be shared with the recipient service provider, payment participant, Travel Rule network, intermediary or competent authority, including where a transfer is reviewed, delayed, rejected, restricted or investigated.
10. International transfers
10.1 Our recipients and we may process personal data in Spain, the European Economic Area and other countries. Data-protection laws in those countries may differ from Spanish and EU law.
10.2 Where we make a restricted transfer from the EEA, we use an applicable lawful mechanism, such as an adequacy decision adopted by the European Commission; the European Commission Standard Contractual Clauses; approved binding corporate rules, codes of conduct or certification mechanisms where available; another safeguard recognised by EU data-protection law; or a limited statutory derogation, where the legal conditions are met.
10.3 We assess transfer risks and apply supplementary technical, contractual or organisational measures where appropriate.
11. Data retention
We keep personal data only for as long as reasonably necessary for the purposes for which it was collected or is further processed. This includes legal, regulatory, accounting, security, fraud-prevention, dispute-resolution, audit and evidential requirements. Account closure or deactivation does not automatically require deletion, because some records must be retained after the relationship ends.
The table below explains the main periods and criteria we use to decide how long different types of personal data are kept. Some retention periods are set by law. Other periods depend on the type of record, the purpose of processing, the risks involved, whether the Account remains active, and whether the information is needed for compliance, security, audit, dispute-resolution or legal-claims purposes.
Where Spanish law requires data blocking, we block the data instead of ordinary deletion. Blocking means that the data are identified and reserved using technical and organisational measures that prevent ordinary access or use. Blocked data may be made available only to judges and courts, the Public Prosecutor, competent public authorities, including data protection authorities, and only for the purpose of addressing possible liabilities during the applicable limitation period. Once that period ends, the data are securely destroyed unless another lawful basis for retention applies.
Record type | How long we keep it |
| Account, onboarding, KYC, AML, sanctions, Travel Rule and records of Orders, payments and Transactions | For the duration of the business relationship and for ten years after it ends. Records relating to an occasional operation are normally retained for ten years after the operation is executed. After five years from the end of the relationship or execution of the occasional operation, AML/CTF records retained under Law 10/2010 are normally accessible only by internal control or prevention units and, where applicable, those responsible for CEX.IO’s legal defence. MiCA records relating to crypto-asset services, activities, Orders and Transactions are normally retained for five years and, where requested by a competent authority before that period expires, for up to seven years. Where the same record is also required for AML/CTF, tax, audit, legal-claims, regulatory, enforcement or safeguarding purposes, it may be retained for the longer applicable period. Records are deleted or blocked when retention ends, unless another lawful retention ground applies. |
| Contract, payment, accounting and tax records | For the period necessary to administer the relationship and meet accounting, tax, audit and legal-claim requirements. Accounting and commercial records are normally kept for up to six years where applicable, subject to longer statutory, audit, regulatory-review, investigation or dispute-related requirements. |
| Customer support and routine communications | For the period necessary to address the enquiry, administer the Account or provide the relevant Service. Routine operational communications are generally retained for a shorter period unless they become relevant to a complaint, investigation, Transaction, legal obligation or dispute. |
| Complaints, data protection rights requests and material communications | For the period necessary to investigate and resolve the matter and to demonstrate how it was handled. Material complaint, rights-request and dispute-related records may be retained for the applicable limitation period where necessary for legal compliance, accountability, evidence or legal claims. Where a specific regulatory complaint-retention rule applies to a particular Service or complaint type, we retain the record for at least the applicable regulatory period. |
| Fraud, security, device, access and incident records | For as long as necessary to identify, investigate and respond to fraud, unauthorised access, security threats and incidents; prevent recurrence; protect Users, assets and systems; and meet legal and regulatory requirements. Lower-risk technical logs may be retained for substantially shorter periods. Records may be retained for longer where an active threat, investigation, legal hold, regulatory matter or claim continues. |
| Identity documents, photographs and verification records | Where retained as part of a legally required customer due diligence record, identification documents, photographs and relevant verification results may normally be retained for the applicable ten-year AML/CTF record-keeping period. |
| Liveness captures and biometric-related information | Raw video, liveness captures, biometric templates, facial vectors, embeddings, comparison data and other technical outputs are retained only for as long as necessary for the specific verification, fraud-prevention, security or regulatory purpose for which they are used. Where biometric templates, vectors or embeddings are created only to complete a one-off 1:1 identity-matching or liveness event, they are deleted, de-linked or irreversibly rendered unusable after that event or after a short technical retention period, unless continued retention is necessary for fraud investigation, security, legal claims, regulatory evidence or another documented lawful purpose. CEX.IO does not retain biometric templates, vectors or embeddings for general marketing, advertising or unrelated profiling. To meet AML/CTF and regulatory record-keeping requirements, we may retain non-biometric verification results, audit logs, timestamps, decision records, confirmation codes and other evidence that required checks were completed. |
| Marketing data | Until you withdraw consent, object, unsubscribe or the information is no longer necessary for the relevant marketing purpose. We may retain a minimal suppression record for as long as necessary to respect your choice, prevent further marketing and demonstrate compliance. |
| Cookies and similar technologies | For the period shown in Consent Preferences for the relevant cookie or similar technology. Records of your consent, rejection and preferences may be retained for as long as reasonably necessary to demonstrate your choices, respect your preferences and comply with applicable law. We may ask you to renew or confirm your choices where required or appropriate, including where the purposes, technologies, providers or legal requirements materially change. |
| Legal holds, investigations and disputes | Until the relevant investigation, complaint, audit, regulatory review, enforcement action, claim, litigation, appeal or applicable limitation period has ended and any necessary follow-up or enforcement action is complete. Legal holds are reviewed and lifted when continued retention is no longer necessary. |
| Backups | For defined and limited backup, security and disaster-recovery cycles. Deleted, restricted or blocked data may remain in protected backups until the relevant backup is overwritten or securely deleted and is not restored for ordinary business use. If backup data are restored, applicable deletion, objection, restriction and blocking decisions are reapplied where technically and operationally appropriate. |
When retention ends, we securely delete, destroy, block or irreversibly anonymise personal data, as applicable, unless continued retention is required or permitted by law. We periodically review retention rules and may apply a shorter period where the purpose can be achieved with less data.
12. Security
We maintain technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure and unauthorised access. Depending on the system and risk, measures may include encryption in transit and at rest, access controls, segregation of duties, multi-factor authentication, logging and monitoring, secure development and change management, vulnerability management, incident response, resilience and backup controls, personnel confidentiality obligations, vendor due diligence and contractual security requirements.
Where payment card data are processed, CEX.IO applies card-payment security controls appropriate to the processing activity. Where applicable, CEX.IO and/or its trusted payment service providers maintain PCI DSS compliance for cardholder-data environments.
No method of transmission, storage or authentication is completely secure. You are responsible for protecting your security credentials and devices and for notifying us promptly of suspected compromise. We will notify affected individuals and the AEPD and/or other competent supervisory authorities of a personal data breach where and within the period required by law.
13. Your data protection rights
Right | What it means |
Access | Obtain confirmation of whether we process your personal data and receive a copy together with required supplementary information. |
Rectification | Ask us to correct inaccurate personal data or complete incomplete information. |
Erasure | Ask us to delete personal data where a legal ground applies. This right does not override legal retention, AML/CTF, fraud-prevention, legal-claims, data-blocking or public-blockchain limitations. |
Restriction | Ask us to restrict processing in specified circumstances. |
Data portability | Receive personal data you provided to us in a structured, commonly used and machine-readable format, and ask us to transmit it to another controller where technically feasible and legally applicable. |
Object | Object to processing based on legitimate interests. You have an absolute right to object to direct marketing, including related profiling. |
Withdraw consent | Withdraw consent at any time where processing is based on consent. Withdrawal does not affect earlier lawful processing. |
Automated decisions | Where applicable, receive information and request human intervention, make representations and contest a significant solely automated decision. |
Complain | Make a data protection complaint to us and lodge a complaint with the AEPD or another competent EU data protection supervisory authority. |
14. How to exercise your rights
14.1 You may submit a rights request through secure online live chat, dpo@cex.io, support@cex.io or by post using the details in section 2. You do not need to use a specific form, quote a legal provision or use particular wording. If you contact another official CEX.IO channel, we will route a clear data-protection request to the appropriate team.
14.2 Please describe what you want us to do and, where relevant, the Account, date range, transaction or communication concerned. A focused request helps us respond efficiently, but we will not require information that is not reasonably necessary.
14.3 We may ask for information needed to verify your identity, authority and Account ownership. This protects you and other individuals. Where possible, we use existing Account authentication rather than collecting additional identity documents. We may ask an authorised representative to provide evidence of authority and may confirm instructions with you directly.
14.4 We normally respond within one month after receiving a valid request and the information reasonably required to verify identity. If the request is complex or you make several requests, we may extend the period by up to two further months and will explain the extension within the first month. If a request is unclear, we may seek clarification as permitted by law. We carry out reasonable and proportionate searches.
14.5 Rights are usually free of charge. We may charge a reasonable fee or refuse to act where the law permits because a request is manifestly unfounded or excessive, including because it is repetitive. We will explain any refusal and the available complaint rights.
14.6 Some rights may be limited where necessary to comply with financial crime, sanctions, tax, security, legal claims or regulatory duties; protect the rights of another person; preserve confidential risk controls; or avoid prejudicing the prevention or detection of crime. We apply exemptions case by case and disclose as much as the law permits.
15. Data protection complaints
15.1 You may complain to us if you believe we have used personal data unfairly, failed to respect a right, disclosed information improperly, retained it too long, failed to keep it secure or otherwise breached data protection law. You may submit a data protection complaint through secure online live chat, dpo@cex.io, support@cex.io or by post using the details in section 2. You do not need to use a specific form, quote a legal provision or use particular wording.
15.2 If a complaint is received through social media or another insecure channel, we will take reasonable steps to recognise and route it, but may ask you to continue through an authenticated or secure channel before discussing personal or Account information.
15.3 We will take appropriate steps to investigate the complaint fairly and accurately, ask for clarification or evidence only where reasonably necessary, keep you informed where appropriate, and tell you about the outcome without undue delay, including the reasons and any action taken or proposed.
15.4 You may lodge a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos, AEPD) or with another competent data protection supervisory authority in the EU Member State where you usually live, where you work, or where you believe the infringement took place. The AEPD can be contacted through www.aepd.es. You do not have to contact us before approaching a supervisory authority, although we welcome the opportunity to address your concern first.
15.5 This section concerns data protection complaints. Service, transaction and contractual complaints are handled under the relevant provisions in the Terms of Use. A complaint may involve both processes, and we may coordinate them while keeping the applicable legal routes distinct.
16. Marketing, advertising and social media
16.1 We may send service, security, legal, regulatory, Transaction and Account communications where necessary. These are not marketing and may continue after you opt out of promotional messages.
16.2 We send electronic marketing only where permitted by LSSI-CE, ePrivacy rules, data-protection law and applicable regulatory requirements. We may rely on your consent or, where legally available, our legitimate interests in informing existing customers about similar CEX.IO products and services. You can opt out of direct marketing at any time by using the unsubscribe link in our marketing messages or, where available, by changing the notification preferences in your Account.
16.3 With consent where required, we may use cookies, mobile advertising identifiers and hashed contact data to measure campaigns, create audiences or show relevant advertising through providers such as search engines, social networks and advertising platforms. The current providers and controls are available through Consent Preferences. These providers may act as independent controllers for their own purposes.
16.4 When you interact with an official CEX.IO social-media page, the platform provider processes information under its own privacy notice. We may receive comments, messages, engagement statistics and audience insights. Do not use social media for passwords, security codes, private keys or detailed Account information.
16.5. To reduce impersonation risk, you should use only CEX.IO Official Channels, applications and verified communication channels. Where we maintain a list of official social-media pages or support channels, you should use that list to check whether a page or message is genuine.
16.6 We keep suppression information after an opt-out so that we can respect your choice. Opting out of marketing does not affect legal, security, service or administrative messages.
17. Cookies and similar technologies
We use cookies, local storage, SDKs, pixels, tags, scripts and similar technologies on the Site, Platform, mobile application and communications. Some are Necessary for security, authentication, fraud prevention, consent management and requested functionality. Functional, Analytics and Advertisement technologies are optional and are used only in accordance with your choices in Consent Preferences and applicable law. The Consent Preferences interface is displayed when you first visit the Site and remains available through the “Consent Preferences” link or icon on the left-hand side of the Site footer. The Cookie Policy and Consent Preferences explain the current technologies, categories, providers, purposes and durations and allow you to update your choices.
18. Children
The Services are not intended for anyone under 18 and minors are not eligible to open an Account. We do not knowingly provide the Services to children. If you believe a child has provided personal data or an Account is being used by a minor, contact us promptly at support@cex.io or dpo@cex.io. We will investigate and take appropriate action, subject to legal record-keeping and safeguarding obligations.
19. Third-party websites and services
The Site, Platform and communications may link to or integrate third-party websites, applications, wallets, payment pages or services that we do not control. The third party’s privacy notice applies to its processing. Review that notice before providing personal data. A link or integration does not mean that we accept responsibility for the third party’s privacy or security practices.
20. Changes to this Policy
We may update this Policy to reflect changes in law, regulation, guidance, the Services, technology or our processing. We will update the “Last updated” date and, where a change is material, provide an appropriate notice through the Site, Platform, Account, email or another official channel. Where consent is required for a new purpose, we will request it separately.
Controller: CEX.IO Europe S.L., NIF B72550395, registered office at Paseo de la Castellana 53, 1a, 28046 Madrid, Spain. Data Protection Officer: dpo@cex.io.
Cookie Policy
Last updated: 24 September 2026
1. What this Cookie Policy covers
1.1 This Cookie Policy explains how CEX.IO Europe S.L. uses cookies and similar technologies on the Site, Platform, mobile application, and electronic communications for which CEX.IO Europe S.L. is responsible. It should be read together with the CEX.IO Europe S.L. Privacy Policy.
1.2. If another CEX.IO entity is responsible for the Site, Platform or Services you use, that entity’s privacy and cookie information may apply.
1.3. Where our use of a technology involves processing personal data, the Privacy Policy provides further information about the applicable purposes and lawful bases, categories of recipients, international transfers, retention and your data protection rights.
2. Who we are and how to contact us
2.1 CEX.IO Europe S.L. is the controller for the use of cookies and similar technologies described in this Cookie Policy where it determines the relevant purposes and means. CEX.IO Europe S.L. is incorporated under Spanish law with tax identification number NIF B72550395 and registered office at Paseo de la Castellana 53, 1a, 28046 Madrid, Spain.
2.2 You may contact us or our Data Protection Officer through secure online live chat available through the Site, mobile application and Help Centre, by email at dpo@cex.io or support@cex.io, or by post at Data Protection Officer, CEX.IO Europe S.L., Paseo de la Castellana 53, 1a, 28046 Madrid, Spain.
3. What cookies and similar technologies are
Cookies are small files placed on your browser or device. Similar technologies include local storage, SDKs, pixels, tags, scripts, mobile identifiers, web beacons and similar storage or access technologies. These technologies may remember information about your device, browser, session, preferences, interactions or use of the Site and Services.
4. Consent Preferences
Consent Preferences means the cookie and similar-technology preference interface displayed when you first visit the Site and available at any time through a permanently accessible “Consent Preferences” link or icon on the Site.
You can accept all optional cookies and similar technologies, reject all optional cookies and similar technologies, or manage optional cookies and similar technologies by category through Consent Preferences.
Rejecting optional technologies will not prevent you from using the Site, although some non-essential features may not work as intended. You can change your choices at any time through the permanently accessible Consent Preferences link or icon on the Site.
We do not treat closing the banner, ignoring it, scrolling or continuing to browse as consent to optional cookies or similar technologies.
The option to reject all optional categories is given the same visual prominence, and requires the same number of steps, as the option to accept all.
5. Consent and legal basis
5.1 Consent given through Consent Preferences is consent for the purposes of LSSI-CE and applicable ePrivacy rules. It is separate from the GDPR lawful basis that applies where information collected through a cookie or similar technology is personal data.
5.2 Necessary technologies may be used without consent only where they are strictly necessary to transmit a communication, provide a Service or functionality requested by you, remember your Consent Preferences, maintain authentication or session security, protect against fraud, abuse or unauthorised access, apply security controls, or operate and secure the Site or Platform. Technologies that are useful or convenient for CEX.IO, but not strictly necessary for the requested service or functionality, are not treated as Necessary.
5.3 Where a technology involves personal data, the Privacy Policy provides further information about the applicable GDPR lawful bases, purposes, recipients, international transfers, retention and your rights.
6. Categories of cookies and similar technologies
| Category shown in Consent Preferences | What it is used for | Consent position | Default |
|---|---|---|---|
| Necessary | Operate and secure the Site and Platform; maintain sessions; authenticate Users; prevent fraud and technical abuse; remember your Consent Preferences; and provide requested functionality. | Used without consent only where the technology is necessary to transmit a communication, provide a Service or functionality requested by you, or operate and secure the Site or Platform. Technologies that are useful or convenient for CEX.IO, but not strictly necessary for the requested service or functionality, are not treated as Necessary. | Always active and cannot be switched off through Consent Preferences. |
| Functional | Provide optional features and personalisation, such as remembering selected preferences, collecting feedback, enabling live chat, displaying embedded content or supporting other enhanced functionality. | Used only with your consent through Consent Preferences, unless a specific LSSI-CE exception applies and has been assessed and documented. | Off until you select this category. |
| Analytics | Understand how visitors use the Site or Platform; measure traffic, journeys and interactions; identify errors; test and improve performance, content and customer experience; and evaluate service effectiveness. | Used only with your consent through Consent Preferences, unless a specific LSSI-CE exception applies and has been assessed and documented. Analytics technologies may process identifiers and technical, device, session, usage and referral information. | Off until you select this category. |
| Advertisement | Measure advertising campaigns; attribute referrals; limit repeated advertisements; create or match audiences; personalise advertising and understand advertising effectiveness, subject to your choices and applicable legal and regulatory restrictions on communications about crypto-asset services. | Used only with your consent through Consent Preferences. Advertisement technologies are never activated before you consent to the Advertisement category. Advertisement technologies may track activity across websites, applications or services and may involve third-party advertising providers. They are not used to override Service eligibility, jurisdictional restrictions, risk warnings or other regulatory controls. | Off until you select this category. |
7. Third-party technologies
We may use third-party providers for analytics, advertising, social media, customer engagement, consent management, security and technical services. Optional third-party technologies that require consent are activated only in accordance with your choices in Consent Preferences. Where these providers act on our behalf, they may use the information only for agreed purposes and subject to contractual controls. Where a provider acts as an independent controller, its own privacy notice and legal obligations apply.
Consent Preferences includes cookie-level information, including the cookie or technology name, provider or domain, category, purpose, whether it is first-party or third-party, duration or expiry period, and available choice where applicable. The information in Consent Preferences forms part of this Cookie Policy and is reviewed periodically and when material changes are introduced. If a provider, purpose, category, duration or similar material configuration changes, Consent Preferences and this Cookie Policy will be updated and fresh consent obtained where required.
8. Marketing emails and tracking technologies
Our electronic communications may contain pixels, links or similar technologies that help us understand whether a message was delivered, opened or interacted with. Where consent is required, we use these technologies only with the required consent. Your choice about email tracking is separate from your choice to receive marketing emails. You can unsubscribe from marketing communications at any time by using the unsubscribe link in our marketing messages or, where available, by changing the notification preferences in your Account.
9. Mobile application identifiers
If you use our mobile application, we may use mobile SDKs and device identifiers, including advertising identifiers where enabled, for security, analytics, functionality or advertising purposes. Where platform rules or applicable law require permission, we request it before using such identifiers for tracking or advertising. You can also manage mobile permissions through your device settings, such as iOS App Tracking Transparency or Android advertising ID controls.
10. Managing cookies through your browser or device
Most browsers allow you to block, delete or manage cookies. Your browser or device settings may not control all technologies used in mobile applications or communications. If you block all cookies, some necessary or requested functionality may not operate correctly. Consent Preferences remains the primary method for managing optional categories on the Site. If you accept third-party cookies and later want to delete cookies already stored on your browser or device, you may need to delete them through your browser, device settings or the tools provided by the relevant third party, in addition to changing your choices in Consent Preferences.
11. Retention
Your choices may apply separately to each browser, device, application or domain where Consent Preferences are used. Cookies and similar technologies are stored for the period shown in Consent Preferences for the relevant technology. Records of your consent, rejection and preferences may be retained for as long as reasonably necessary to demonstrate your choices, respect your preferences and comply with applicable law. We do not ask you to renew your choice on every visit unless required by law, the relevant purposes, providers, categories or durations change, or the configured consent period expires. We generally do not treat a cookie consent choice as valid for more than 24 months unless applicable law or guidance permits a different approach.
12. International transfers
Information collected through cookies and similar technologies may be processed in Spain, the EEA and other countries. Where personal data are transferred outside the EEA, the international-transfer section of the Privacy Policy applies.
13. Questions, rights requests and complaints
Questions, rights requests or complaints about our use of cookies and similar technologies may be submitted through secure online live chat, dpo@cex.io, support@cex.io or by post using the contact details provided in Section 2 of this Cookie Policy. You do not need to use a particular form, quote a legal provision or use particular wording.
We handle complaints about cookies and similar technologies under the process described in the Privacy Policy. You may lodge a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos, AEPD) or another competent data protection supervisory authority in the EU Member State where you usually live, where you work, or where you believe the infringement took place. The AEPD can be contacted through www.aepd.es.
14. Changes to this Cookie Policy
We may update this Cookie Policy to reflect changes in law, guidance, technology, providers, categories, purposes, durations or our use of cookies and similar technologies. Where a change affects optional technologies that require consent, we will request fresh consent where required.
CEX.IO Markets UK LTD (UK)
Privacy Policy
Last updated: 29 June 2026
This Policy explains how CEX.IO Markets UK LTD collects, uses, shares, retains and protects personal data in connection with the Services.
Who is responsible for your personal data?
CEX.IO Markets UK LTD is responsible as controller for the processing described in this Policy. For particular processing, an affiliated CEX.IO entity may act as a separate controller, a joint controller with us or our processor, as explained in sections 1.2 and 8.
This Privacy Policy should be read together with the Terms of Use, the Cookie Policy and any product-specific notice presented when personal data is collected.
Contents
- Scope and status of this Policy
- Who we are and how to contact us
- Personal data we collect
- How we collect personal data
- How we use personal data and our lawful bases
- Special category and criminal offence data
- Automated decision-making and profiling
- How we share personal data
- Blockchain and transfer information
- International transfers
- Data retention
- Security
- Your data protection rights
- How to exercise your rights
- Data protection complaints
- Marketing, advertising and social media
- Cookies and similar technologies
- Children
- Third-party websites and services
- Changes to this Policy
1. Scope and status of this Policy
1.1 This Policy applies where CEX.IO Markets UK LTD (“CEX.IO”, “we”, “us” or “our”) processes personal data as controller in connection with the Site, Platform, Account and Services provided to Users, including prospective Users, individual Users, representatives and beneficial owners of corporate Users, payers, beneficiaries, recipients, counterparties, website and application visitors, and persons who contact us.
1.2 Different affiliated CEX.IO entities may use the CEX.IO Platform to provide services to their respective users. The entity responsible for your personal data depends on the relevant Service and the purposes and essential means of the processing. Depending on the activity, an affiliated CEX.IO entity may act as a separate controller, a joint controller with us or our processor acting on our instructions. Where another entity acts as a controller, its privacy notice or other applicable privacy information applies.
1.3 Capitalised terms not defined in this Policy have the meanings given to them in the Terms of Use. Other terms used in this Policy have the meanings given to them under applicable data protection laws.
1.4 This Policy is primarily governed by the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 (DPA 2018), the Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR), and those laws as amended, including by the Data (Use and Access) Act 2025. Other laws may apply to particular processing or individuals.
2. Who we are and how to contact us
2.1 CEX.IO Markets UK LTD is a private limited company incorporated in England and Wales with company number 15140258 and registered office at 78-79 Pall Mall, London, England, SW1Y 5ES. It is registered with the Financial Conduct Authority as a cryptoasset business under the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017, firm reference number 1007192, for certain cryptoasset activities.
2.2 You may contact us or our Data Protection Officer using any of the following official channels:
- Secure online live chat: available through the Site, mobile application and Help Centre;
- Data Protection Officer: dpo@cex.io;
- Customer support email: support@cex.io;
- Post: Data Protection Officer, CEX.IO Markets UK LTD, 78-79 Pall Mall, London, England, SW1Y 5ES.
2.3 For security, do not send passwords, one-time codes, private keys, recovery phrases or complete payment card details through live chat, email or social media. Where reasonably necessary to protect your personal data and Account, we may ask you to verify your identity or continue an account-specific discussion through an authenticated channel designated by CEX.IO.
3. Personal data we collect
The personal data we process depends on how you interact with us, the Services you use, your Account type and the legal and risk requirements that apply. We may process the following categories:
| Category | Examples |
|---|---|
| Identity and contact data | Full name, previous names, date and place of birth, age, nationality, citizenship, residential and mailing address, email address, telephone number, signature, user ID, customer number and Account identifiers. |
| Identity-verification and due-diligence data | Government-issued identity documents and document details; photographs, selfie images, video, liveness information and verification results; proof of address; tax identification numbers and tax residence; occupation, employer and professional information; source of funds and source of wealth; purpose and intended nature of the relationship; corporate documents, ownership and control information, directors, authorised representatives and beneficial owners; politically exposed person, sanctions and adverse-media screening information; and information requested during onboarding, ongoing monitoring or an Account Review. |
| Financial and payment data | Bank and payment account details, payment card data or tokens, card issuer and payment method information, bank statements, payment references, payer and beneficiary information, balances, fees, charges, refunds, chargebacks, recalls, reversals, settlement information and accounting or tax records. |
| Transaction and Digital Asset data | Orders, trades, conversions, Deposits, Withdrawals, transfers, staking activity, CEX.IO Pay activity, transaction dates and values, Trading Pairs, wallet addresses, destination addresses, transaction hashes, selected networks, memos and tags, originator and beneficiary information, Travel Rule information, counterparties and related instructions or confirmations. |
| Compliance, fraud and risk data | Customer and transaction risk ratings, screening results, blockchain analytics, wallet attribution and exposure information, fraud indicators, device and behavioural risk signals, unusual or suspicious activity indicators, investigations, Account Review records, regulatory reports, law-enforcement requests and decisions concerning access, limits, holds, restrictions or closure. |
| Technical, device and security data | IP address, approximate location derived from IP or device signals, device type and identifiers, browser and operating system, application version, language, time zone, session identifiers, cookies and similar technologies, login and authentication events, 2FA and security-event metadata, connected devices, API identifiers and activity logs, network and diagnostic information, crash and error data, and records of suspected compromise. |
| Usage and interaction data | Pages, screens and features used, clicks, navigation, search and referral data, product and interface preferences, service configuration, activity timestamps, performance and analytics information, and responses to surveys or research. |
| Communications, support and complaint data | Live-chat messages, emails, telephone or video call records where used, support tickets, complaints, requests, correspondence, attachments, screenshots, call or chat recordings where notified, verification responses, investigation notes and associated metadata. |
| Marketing and preference data | Marketing choices, communication preferences, campaign engagement, referral and promotion information, survey responses, advertising identifiers, cookie or pixel identifiers, hashed contact data used for audience matching where permitted, and social-media interactions. |
| Corporate User and representative data | Organisation name, registered and business addresses, company number, constitutional documents, business activity, regulatory status, ownership structure, beneficial ownership, directors, authorised signatories, employee or representative role, authority and permissions, and business contact details. |
| Other data you provide | Any other personal data you choose to provide, or that we reasonably require for the Services, security, compliance, dispute resolution or legal obligations. Please provide only information relevant to your request. |
Certain information is mandatory because we need it to enter into or perform our contract with you under the Terms of Use, verify identity, process transactions or comply with legal and regulatory requirements. If you do not provide required information, we may be unable to open or maintain an Account, provide a Service, process a Transaction, answer a request or continue the relationship.
4. How we collect personal data
We collect personal data from the following sources:
- Directly from you when you register, complete verification, use the Services, submit an Instruction, contact support, make a complaint, exercise a right, participate in a survey or communicate with us.
- From your use of the Platform through Account records, Transactions, authentication, cookies, SDKs, APIs, logs, security tools and other technical systems.
- From affiliated CEX.IO entities, where necessary for cooperation and operational arrangements relating to the Platform and Services, including customer administration, migration, security, fraud prevention, legal and regulatory compliance, technology and business administration.
- From service and infrastructure providers including identity and liveness verification providers, sanctions and PEP screening providers, blockchain analytics providers, Travel Rule providers, fraud and device-intelligence providers, cloud and communications providers, customer-support providers, custodians, staking or validator providers, liquidity providers, exchanges and market infrastructure providers.
- From banks, payment and financial institutions including payment service providers, card schemes, issuers, acquirers, correspondent banks, e-money institutions and other payment participants.
- From other persons including corporate customers, authorised representatives, beneficial owners, counterparties, originators, beneficiaries, CEX.IO Pay senders or recipients, referral partners and persons who report suspected fraud or unauthorised activity.
- From public and official sources including Companies House and other company registers, sanctions lists, PEP lists, court and insolvency records, professional registers, public websites, public blockchain data, regulators, law-enforcement authorities and tax authorities.
- From advertising, analytics and social-media partners where you have consented or the processing is otherwise permitted by law.
5. How we use personal data and our lawful bases
We process personal data only where we have a lawful basis. More than one lawful basis may apply to a particular processing activity. Depending on the purpose and circumstances, we may rely on contractual necessity, compliance with a legal obligation, our legitimate interests, consent or another lawful basis available under applicable data protection laws. Consent is therefore not the only, or necessarily the primary, lawful basis for processing personal data in connection with the Services.
Where we rely on legitimate interests, we consider the nature and purpose of the processing, whether the processing is necessary, and its possible impact on your interests, rights and freedoms.
Where we rely on consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before consent was withdrawn or processing we carry out under another lawful basis.
Purpose | Personal data we use | Lawful basis |
Open, administer and maintain Accounts; verify eligibility and authority; establish the Account relationship; provide Account interfaces and functionality; and maintain Account details and preferences. | Identity and contact data; identity-verification data; corporate and representative data; technical, device and security data; usage data; and communications data. | Contract: to take steps at your request before entering into our contract with you and to perform our contract with you under the Terms of Use. Legitimate interests: where you act for a corporate User, and for secure and efficient Account administration. |
Provide and operate the Services, where available, including Account, wallet and balance functionality; Fiat Currency and Digital Asset Deposits and Withdrawals; spot trading; the purchase, sale, exchange and conversion of supported Digital Assets and Fiat Currency; Order placement, execution, matching, routing and settlement; internal transfers; Instant Buy and Instant Sell; CEX.IO Pay; Staking; API access; supported payment methods; market information; and related Platform functionality. | Identity and contact data; corporate and representative data; financial and payment data; Account data; Order, Transaction and Digital Asset data; wallet addresses; payment and beneficiary details; internal-transfer and CEX.IO Pay information; staking, delegation, validator, Staking Proceeds and unstaking information; API activity; technical, device and security data; usage data; and communications data. | Contract: to provide the Services and perform our contract with you under the Terms of Use. Legal obligation: where transaction information, controls, records or disclosures are required by law. Legitimate interests: operating the Platform, administering Transactions, reconciling balances, maintaining reliable Services and managing operational risk. |
Apply customer-protection, eligibility and financial-promotion controls, including customer categorisation, appropriateness assessments, risk warnings, cooling-off periods, product and jurisdictional restrictions, acknowledgements and other measures required or permitted in connection with the Services. | Identity and contact data; date of birth and age; residence and location data; customer-category information; knowledge and experience information; appropriateness-assessment responses and results; risk-warning acknowledgements; cooling-off records; Account and Transaction data; technical data; and compliance and risk data. | Legal obligation: to comply with applicable financial-promotion, consumer-protection and regulatory requirements. Legitimate interests: where appropriate, ensuring that Services and communications are provided only to eligible Users and managing regulatory, product and customer-protection risk. |
Verify identity and conduct customer due diligence, enhanced due diligence, sanctions and politically exposed person screening, source-of-funds and source-of-wealth checks, beneficial-ownership and authority checks, ongoing monitoring, Travel Rule compliance, tax compliance and regulatory reporting. | Identity and contact data; identity-verification data; photographs, video or liveness information where used; corporate and representative data; beneficial-ownership information; financial and payment data; Account, Transaction and Digital Asset data; wallet information; tax information; compliance, fraud and risk data; and supporting documents and declarations. | Legal obligation: including anti-money laundering, counter-terrorist financing, sanctions, proliferation-financing, transfer-of-funds, tax and regulatory requirements. Legitimate interests: where appropriate, preventing unlawful use of the Services and protecting Users, CEX.IO and the Platform. Where special-category or criminal-offence data are processed, we also rely on an applicable condition under the UK GDPR and the Data Protection Act 2018. |
Prevent, detect and investigate unlawful, fraudulent or prohibited activity, including fraud, money laundering, terrorist financing, proliferation financing, sanctions evasion, market abuse, account takeover, payment abuse, cybersecurity incidents and misuse of the Platform or Services. | Any relevant categories of personal data, particularly identity and verification data; Account, Order, Transaction and Digital Asset data; financial and payment data; wallet and blockchain information; technical, device and security data; compliance, fraud and risk data; and communications data. | Legal obligation: where monitoring, prevention, investigation, reporting or disclosure is required by law. Legitimate interests: preventing loss, crime, fraud and misuse; protecting Users, CEX.IO, affiliated CEX.IO entities and third parties; and maintaining the security and integrity of the Platform. Recognised legitimate interest: where processing is necessary to prevent, detect or investigate crime and the applicable statutory condition is met. |
Manage Accounts, supported assets and operational changes, including Account Reviews, risk scoring, investigations, limits, holds, restrictions, suspension and closure; inactive and deactivated Accounts; reactivation; Maintenance Fees and Storage Fees; delisting and unsupported assets; dust and residual balances; protocol events; product changes; internal User migrations; system upgrades; and related transfers or conversions permitted under the Terms of Use. | Identity and contact data; identity-verification data; Account and balance data; financial and payment data; Order, Transaction and Digital Asset data; wallet information; technical, device and security data; usage data; compliance, fraud and risk data; and communications data. | Contract: to administer the Account and apply the Terms of Use. Legal obligation: where restrictions, investigations, records, disclosures or other action are required by law. Legitimate interests: maintaining accurate balances, operational continuity and system integrity; managing unsupported assets and inactive Accounts; protecting Users and CEX.IO; and applying proportionate operational and risk controls. |
Authenticate Users and protect Accounts, assets, systems and information, including password and authentication management, two-factor authentication, approved devices, API access, access controls, fraud controls, activity logging, security monitoring, vulnerability management, incident detection and response, operational resilience and security testing. | Identity and contact data; authentication data; technical, device and security data; IP addresses and device identifiers; API keys and activity logs; usage data; Account and Transaction information; compliance and risk data; and communications data. | Legal obligation: to maintain appropriate technical and organisational security measures and meet applicable legal and regulatory requirements. Contract: to provide secure access to the Account and Services. Legitimate interests: protecting systems, Users, assets, personal data and the integrity of the Platform. |
Process payments, corrections and recoveries, including Deposits and Withdrawals, settlement, fees, refunds, chargebacks, recalls, reversals, clawbacks, set-off, payment disputes, erroneous credits, incorrectly sent Fiat Currency or Digital Assets, reconciliation, recovery of amounts due and cooperation with banks, payment providers and other relevant participants. | Identity and contact data; Account data; financial and payment data; bank-account, payment-card and payment-method information; Order and Transaction data; wallet and beneficiary information; compliance, fraud and risk data; technical and security data; communications data; and supporting evidence. | Contract: to process and administer payments and Transactions under the Terms of Use. Legal obligation: where payment, record-keeping, fraud-prevention, tax or regulatory requirements apply. Legitimate interests: reconciliation, correcting errors, recovering funds and amounts due, resolving payment disputes, preventing fraud and protecting the rights and assets of Users, CEX.IO and relevant third parties. |
Provide customer support and communicate with you, including responding to questions, requests and complaints; investigating Account and Transaction issues; providing service, legal, regulatory, security and incident communications; making reasonable adjustments; and operating live-chat, email and other support channels. | Identity and contact data; Account, Order and Transaction data; financial and payment data; technical and security data; communications data; support history; call or chat records; and any other information relevant to the matter raised. | Contract: to provide support in connection with the Account and Services. Legal obligation: including complaint-handling, accessibility and data-protection obligations. Legitimate interests: providing effective support, maintaining service quality, investigating issues, resolving disputes and keeping appropriate records. |
Respond to and administer data protection rights and complaints, including identifying and locating relevant personal data, verifying identity where reasonably necessary, communicating with the requester, investigating complaints and recording the response and outcome. | Identity and contact data; identity-verification information where necessary; Account data; communications data; complaint and request details; and any personal data relevant to the request or complaint. | Legal obligation: to comply with applicable data protection rights and complaint-handling requirements. Legitimate interests: preventing unauthorised disclosure, maintaining evidence of compliance and resolving requests and complaints fairly and securely. |
Maintain records and evidence, including records of notices, disclosures, instructions, Orders, Transactions, consents, preferences, acknowledgements, communications, Account activity, investigations and decisions; and establish, exercise or defend legal rights and claims. | Communications data; Account, Order and Transaction data; financial and payment data; technical logs; consent and preference records; compliance, fraud and risk data; complaint and support records; and other relevant evidence. | Legal obligation: where records must be retained or produced by law. Contract: to evidence and administer the Account, Services and Transactions. Legitimate interests: maintaining appropriate evidence, resolving disputes, enforcing the Terms of Use and establishing, exercising or defending legal claims. |
Comply with legal and regulatory duties and respond to competent authorities, including court orders, statutory notices, lawful requests and duties involving regulators, law-enforcement agencies, tax authorities, supervisory authorities and other competent bodies. | Any categories of personal data that are necessary and proportionate to the relevant request, duty, investigation or proceeding. | Legal obligation: where disclosure, reporting or cooperation is required by law. Legitimate interests: where cooperation is lawful, proportionate and not legally mandatory, including protecting rights, preventing harm and responding appropriately to competent authorities. |
Analyse, develop, test, maintain and improve the Site, Platform and Services, including monitoring performance, troubleshooting, analysing use, improving interfaces, security and customer experience, and developing, testing and evaluating new, beta, pilot or limited-release products, tools and features. | Account and user identifiers; cookie, device and session identifiers; IP addresses; technical, device and security data; usage and interaction data; communications data; feedback; testing information; and relevant Account and Transaction data, including data that has been pseudonymised where appropriate. | Legitimate interests: analysing and improving the Site, Platform and Services; understanding service use; product development and testing; troubleshooting; reliability; operational efficiency; security and resilience. Contract: where processing is necessary to provide a beta, pilot or other feature selected by you. Consent: where applicable law requires consent for cookies, SDKs or similar technologies. |
Send marketing and product communications and lawful financial promotions, including information about products, Services, features, market developments, events and offers; conduct surveys; measure communications and campaigns; and build or use audiences where permitted. | Identity and contact data; marketing preferences; consent and opt-out records; limited Account-relationship data; usage and interaction data; cookie, advertising and device identifiers; survey responses; and campaign information. | Consent: where required by PECR or other applicable law. Legitimate interests: for communications that may lawfully be sent to existing customers without consent and for appropriate campaign measurement. Legal obligation: to apply applicable financial-promotion requirements, restrictions, warnings and controls to communications. You may opt out of direct marketing at any time. |
Administer promotions, referral arrangements, surveys and research, including checking eligibility, managing participation, delivering any applicable benefit, preventing misuse and evaluating outcomes. | Identity and contact data; Account and Transaction data necessary to establish eligibility; referral information; marketing preferences; survey and research responses; communications data; and fraud and risk data. | Contract: where you choose to enter or participate in a promotion or arrangement. Consent: where required. Legitimate interests: administering and evaluating promotions, referrals, surveys and research and preventing misuse. |
Manage our business and relationships with affiliated CEX.IO entities and other organisations, including cooperation and operational arrangements with affiliated CEX.IO entities; governance; audits; insurance; professional advice; financing; restructuring; corporate transactions; business continuity; and internal administration. | Relevant identity and contact data; corporate and representative data; Account and contractual information; financial data; compliance and risk data; technical and security data; and communications data. | Legitimate interests: operating, administering, protecting, financing and reorganising our business and managing relationships with affiliated CEX.IO entities, service providers, advisers and business partners. Legal obligation: where records, audits, disclosures or other actions are required by law. |
Create anonymised or aggregated information that no longer identifies an individual, including for analytics, research, reporting, security, risk management and product development. | Any categories of personal data capable of lawful anonymisation or aggregation. | Legitimate interests: analysing and improving our business, Services, security and risk management. Information that has been effectively anonymised is no longer personal data. |
6. Special category and criminal offence data
6.1 Facial images, liveness and biometric data
Photographs and video are personal data. They become special category biometric data only where they are processed through specific technical means for the purpose of uniquely identifying or authenticating an individual. We may use facial images, liveness checks and related outputs to verify identity, prevent impersonation and fraud, protect Account security, and comply with anti-money laundering, sanctions and other legal and regulatory requirements.
Where this processing involves special category biometric data, we identify an Article 6 lawful basis and an Article 9 condition appropriate to the specific processing. Depending on the purpose and implementation, this may include explicit consent or a substantial public interest condition under the DPA 2018, where the relevant statutory requirements are met. We maintain an appropriate policy document where required and apply data minimisation, access restrictions, vendor controls, retention limits and human review safeguards.
6.2 Other special category data
We do not seek special category data unless it is necessary. It may be processed if you voluntarily disclose health or disability information when requesting reasonable support, or if information obtained during compliance or legal processes reveals a special category. We process it only where an applicable Article 9 condition is met, such as explicit consent, substantial public interest or the establishment, exercise or defence of legal claims.
6.3 Criminal offence data
Compliance, fraud, security and dispute records may include information about criminal convictions, offences, investigations, proceedings or sufficiently specific allegations. We process such information under Article 10 of the UK GDPR and the DPA 2018, where authorised by law, including for regulatory requirements, prevention or detection of unlawful acts, fraud prevention, safeguarding against dishonesty, regulatory action and legal claims. We use enhanced access, retention and governance controls and maintain an appropriate policy document where required.
7. Automated decision-making and profiling
7.1 We use automated systems, rules, models and profiling to support identity verification, document and liveness checks, sanctions and PEP screening, fraud detection, blockchain and transaction monitoring, device and behavioural risk analysis, customer and Transaction risk scoring, eligibility checks, security controls, product functionality, marketing preferences and service improvement.
7.2 The factors considered may include identity-match and document-authenticity results; screening matches; Account history; Transaction patterns and values; wallet and blockchain exposure; source-of-funds information; location, device and network signals; links to other Accounts or payment methods; security events; legal restrictions; and information supplied during an Account Review. We do not disclose detailed detection rules where doing so could undermine anti-money laundering, sanctions, fraud-prevention or security controls, or the rights of others.
7.3 Automated outputs may result in a request for further information, enhanced authentication, a delay or hold, a Transaction being rejected, access to a feature being limited, or an Account application or activity being referred for review. Some decisions may be made without meaningful human involvement, where permitted by law.
7.4 Where a decision based solely on automated processing has a legal or similarly significant effect on you, we apply the safeguards required by law. These include giving you information about the decision, enabling you to make representations, request human intervention, and contest the decision, except where a lawful exemption applies. You may request a review through the channels in section 14.
7.5 Where AI-enabled tools are used in customer support, they may classify or summarise requests, retrieve support information, suggest responses or provide an automated first response. You may ask to communicate with a human agent. These tools are not used to make final decisions about onboarding, Account restrictions or Transactions. We use contractual and technical controls to limit provider access to and use of support data.
8. How we share personal data
We disclose personal data only where necessary, proportionate and lawful. Recipients may include:
- affiliated CEX.IO entities, where necessary for cooperation and operational arrangements relating to the Platform and Services, including customer administration, security, compliance, customer support, technology, internal audit and business administration. Depending on the relevant processing activity, an affiliated CEX.IO entity may act as our processor acting on our instructions, as a separate controller for its own purposes and legal obligations, or as a joint controller with us where we jointly determine the purposes and essential means of the processing.
- Identity, compliance and risk providers including identity-document, selfie, liveness and biometric verification providers; sanctions, PEP and adverse-media screening providers; blockchain analytics and wallet intelligence providers; Travel Rule providers; fraud, device-intelligence and cybersecurity providers.
- Banks and payment participants including payment service providers, e-money institutions, card schemes, issuers, acquirers, banking partners, correspondent banks and settlement providers. Some act as independent controllers and provide their own privacy information.
- Digital Asset and market infrastructure providers including custodians, wallet and node infrastructure providers, validators and staking providers, liquidity providers, exchanges, market makers, market-data providers, blockchain networks and protocol participants.
- Technology and business service providers including cloud hosting, data storage, software, analytics, communications, email and SMS delivery, live-chat and customer support, document management, consent management, auditing, accountancy, legal, insurance and professional-advisory providers.
- Other Users and counterparties where necessary to provide a requested transaction or feature, including the limited CEX.IO Pay information described in section 9.2.
- Regulators and public authorities including the FCA, the ICO, tax authorities, sanctions authorities, courts, law-enforcement bodies, financial-intelligence units and other competent authorities, where required or permitted by law.
- Persons involved in disputes or legal proceedings including counterparties, their representatives, courts, tribunals, mediators, insurers and professional advisers.
- Corporate transaction recipients, including prospective buyers, investors, lenders, and advisers in connection with a merger, acquisition, financing, reorganisation, or transfer of business or assets, subject to appropriate confidentiality and data-protection measures.
- Advertising, analytics and social-media providers only where the required consent or other lawful basis exists and subject to your choices in Consent Preferences and your marketing choices.
Service providers acting on our behalf are authorised to process personal data only for agreed purposes and are subject to contractual confidentiality, security, assistance, and deletion or return obligations. Where a recipient acts as an independent controller, its own privacy notice and legal obligations apply.
9. Blockchain and transfer information
9.1 Public blockchain information
Where a Digital Asset Transaction is transmitted to or recorded on a public blockchain, information relating to that Transaction may become publicly accessible on a decentralised and potentially immutable network. This may include wallet addresses, transaction hashes, amounts, timestamps, and other network information.
Public blockchain information may be viewed by anyone and may be analysed or combined with other information in a manner that could identify or relate to an individual. CEX.IO does not control the operation of public blockchains and may be unable to delete, correct or restrict information recorded on-chain.
This section does not generally apply to internal transfers between CEX.IO Accounts, including transfers made through CEX.IO Pay, unless the relevant transfer is expressly processed through a public blockchain. Where possible, we address data protection rights in relation to off-chain records and processing that remain under our control.
9.2 CEX.IO Pay and other internal transfers
Where CEX.IO Pay or another internal transfer functionality is available, transfers between eligible CEX.IO Accounts are generally processed within the CEX.IO Platform and are not recorded as individual transfers on a public blockchain.
When you send Digital Assets using CEX.IO Pay, the recipient may see your registered first name, the first letter of your last name, and your unique CEX.IO user identification number. This limited disclosure is used to identify the transaction counterparty and provide the relevant functionality.
We do not authorise recipients to use that information for unrelated purposes. However, recipients are independently responsible for any further use of information they receive.
9.3 Travel Rule and payment information
For certain Digital Asset or Fiat Currency transfers, we may be legally required to collect, verify, transmit, or receive information about the originator and beneficiary. This information may be shared with the recipient service provider, payment participant, Travel Rule network, intermediary, or competent authority, including where a transfer is reviewed, delayed, rejected, restricted, or investigated.
10. International transfers
10.1 We and our recipients may process personal data in the United Kingdom, the European Economic Area, and other countries. Data-protection laws in those countries may differ from UK law.
10.2 Where we make a restricted transfer from the United Kingdom, we use an applicable lawful mechanism, such as:
- UK adequacy regulations;
- the UK International Data Transfer Agreement or the UK Addendum to the European Commission Standard Contractual Clauses;
- approved binding corporate rules, codes or certification mechanisms where available;
- another safeguard recognised by UK data-protection law; or
- a limited statutory exception, where the legal conditions are met.
10.3 We assess transfer risks and apply supplementary technical, contractual or organisational measures where appropriate.
11. Data retention
We keep personal data only for as long as reasonably necessary for the purposes for which it was collected, including legal, regulatory, accounting, security, fraud-prevention, dispute-resolution, and evidential requirements. Account closure or deactivation does not automatically require deletion.
Record type | How long we keep it |
| Account, onboarding, KYC, AML, sanctions, Travel Rule and records of Orders, payments and Transactions | Normally for the duration of the business relationship and for five years after it ends. Records relating to an occasional transaction are normally retained for five years after the transaction is completed. Transaction records created during an ongoing business relationship may be deleted once they are more than 10 years old, where they are no longer required for another lawful purpose. Records may be retained for longer where required by another applicable law, a competent authority, a valid legal hold, court or other legal proceedings, or an ongoing investigation or dispute. |
| Contract, payment, accounting and tax records | Contractual and payment records are normally retained for the period necessary to administer the relationship and for up to six years after the relevant relationship, Transaction, payment, Account closure or other relevant event. Accounting and tax records are normally retained for six years from the end of the relevant company financial year, or longer where required by tax law, an audit, regulatory review, investigation or dispute. |
| Customer support and routine communications | For the period necessary to address the enquiry, administer the Account or provide the relevant Service. Routine operational communications are generally retained for a shorter period unless they become relevant to a complaint, investigation, Transaction, legal obligation or dispute. |
| Complaints, data protection rights requests and material communications | For the period necessary to investigate and resolve the matter and to demonstrate how it was handled. Material complaint, rights-request and dispute-related records may normally be retained for up to six years after the matter is closed where necessary for legal compliance, accountability, evidence or the establishment, exercise or defence of legal claims. Where a specific regulatory complaint-retention rule applies to a particular Service, we retain the record for at least the applicable regulatory period. |
| Fraud, security, device, access and incident records | For as long as necessary to identify, investigate and respond to fraud, unauthorised access, security threats and incidents; prevent recurrence; protect Users, assets and systems; and meet legal and regulatory requirements. Depending on the nature and significance of the record, this may normally be up to six years after the relevant event or the end of the relationship. Records may be retained for longer where an active threat, investigation, legal hold, regulatory matter or claim continues. Lower-risk technical logs may be retained for substantially shorter periods. |
| Identity documents, photographs and verification records | Where retained as part of a legally required customer due diligence record, identification documents, photographs and relevant verification results may normally be retained for the applicable five-year AML record-keeping period. |
| Liveness captures and biometric-related information | Raw video, liveness captures, biometric templates, embeddings, comparison data and other technical outputs are retained only for as long as necessary for the specific verification, fraud-prevention or security purpose for which they are used. Different technical components may have different retention periods. They are not automatically retained for the full AML period merely because they were used during identity verification, unless their continued retention is necessary and supported by an applicable legal basis and, where relevant, a special-category condition. |
| Marketing data | Until you withdraw consent, object, unsubscribe or the information is no longer necessary for the relevant marketing purpose. We may retain a minimal suppression record for as long as necessary to respect your choice, prevent further marketing and demonstrate compliance. |
| Cookies and similar technologies | For the period shown in Consent Preferences for the relevant cookie or similar technology. Records of your consent, rejection and preferences may be retained for as long as reasonably necessary to demonstrate your choices and comply with applicable law. |
| Legal holds, investigations and disputes | Until the relevant investigation, complaint, audit, regulatory review, enforcement action, claim, litigation, appeal or applicable limitation period has ended and any necessary follow-up or enforcement action is complete. Legal holds are reviewed and lifted when continued retention is no longer necessary. |
| Backups | For defined and limited backup, security and disaster-recovery cycles. Deleted or restricted data may remain in protected backups until the relevant backup is overwritten or securely deleted and is not restored for ordinary business use. If backup data are restored, applicable deletion, objection and restriction decisions are reapplied where technically and operationally appropriate. |
When retention ends, we securely delete, destroy or irreversibly anonymise personal data, unless continued retention is required or permitted by law. We periodically review retention rules and may apply a shorter period where the purpose can be achieved with less data.
12. Security
We maintain technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, and unauthorised access. Depending on the system and risk, measures may include encryption in transit and at rest, access controls, segregation of duties, multi-factor authentication, logging and monitoring, secure development and change management, vulnerability management, incident response, resilience and backup controls, personnel confidentiality obligations, vendor due diligence, and contractual security requirements.
No method of transmission, storage, or authentication is completely secure. You are responsible for protecting your Security Credentials and devices and for notifying us promptly of suspected compromise. We will notify affected individuals and the ICO of a personal-data breach where and within the period required by law.
13. Your data protection rights
Subject to legal conditions, exemptions and limitations, you may have the following rights:
Right | What it means |
|---|---|
Access | Obtain confirmation of whether we process your personal data and receive a copy together with required supplementary information. |
Rectification | Ask us to correct inaccurate personal data or complete incomplete information. |
Erasure | Ask us to delete personal data where a legal ground applies. This right does not override legal retention, fraud-prevention, legal-claims or public-blockchain limitations. |
Restriction | Ask us to restrict processing in specified circumstances. |
Data portability | Receive personal data you provided to us in a structured, commonly used and machine-readable format, and ask us to transmit it to another controller where technically feasible and legally applicable. |
Object | Object to processing based on legitimate interests, including a recognised legitimate interest. You have an absolute right to object to direct marketing, including related profiling. |
Withdraw consent | Withdraw consent at any time where processing is based on consent. Withdrawal does not affect earlier lawful processing. |
Automated decisions | Where applicable, receive information and request human intervention, make representations and contest a significant solely automated decision. |
Complain | Make a data-protection complaint to us and lodge a complaint with the Information Commissioner’s Office. |
14. How to exercise your rights
14.1 You may submit a rights request through secure online live chat, dpo@cex.io, support@cex.io or by post using the details in section 2. You do not need to use a specific form, quote a legal provision or call the request a subject access request. If you contact us through another channel, we will take reasonable steps to recognise and route a request that concerns your data protection rights.
14.2 Please describe what you want us to do and, where relevant, the Account, date range, transaction or communication concerned. A focused request helps us respond efficiently, but we will not require information that is not reasonably necessary.
14.3 We may ask for information needed to verify your identity, authority and Account ownership. This protects you and other individuals. Where possible, we use existing Account authentication rather than collecting additional identity documents. We may ask an authorised representative to provide evidence of authority and may confirm instructions with you directly.
14.4 We normally respond within one month of receiving your request or, where we reasonably require information to verify your identity, from when we receive that information. If the request is complex or you make several requests, we may extend the period by up to two further months and will explain the extension within the first month. If a request is unclear, we may seek clarification, and the response period may be paused as permitted by law. We carry out reasonable and proportionate searches.
14.5 Rights are usually free of charge. We may charge a reasonable fee or refuse to act where the law permits because a request is manifestly unfounded or excessive, including because it is repetitive. We will explain any refusal and the available complaint rights.
14.6 Some rights may be limited where necessary to comply with anti-money laundering, sanctions, tax, security, legal claims or regulatory requirements; protect the rights of another person; preserve confidential risk controls; or avoid prejudicing the prevention or detection of crime. We apply exemptions case by case and disclose as much as the law permits.
15. Data protection complaints
15.1 You may complain if you believe we have used personal data unfairly, failed to respect a right, disclosed information improperly, retained it too long, failed to keep it secure or otherwise breached data protection law. You may make a complaint through any of the channels in section 2. We will also recognise and route a data protection complaint received through another CEX.IO channel. You do not need to use a particular form, refer to a legal provision or use legal language.
15.2 If you complain through social media, we will take reasonable steps to recognise and route the complaint but may ask you to continue through a private or authenticated channel before discussing personal or Account information.
15.3 We will:
- acknowledge receipt within 30 days;
- take appropriate steps without undue delay to investigate the complaint fairly and accurately;
- ask for clarification or evidence only where reasonably necessary;
- keep you informed about progress where the investigation is not promptly completed; and
- tell you about the outcome without undue delay, including the reasons and any action taken or proposed.
15.4 You may complain to the Information Commissioner’s Office at any time. Information about how to make a complaint, together with the ICO’s current contact details, is available at ico.org.uk/make-a-complaint/data-protection-complaints/. We would welcome the opportunity to address your concern first, but you do not have to wait for our process to finish before contacting the ICO.
15.5 This section concerns data protection complaints. Service, transaction, and contractual complaints are handled under the relevant provisions in the Terms of Use. A complaint may involve both processes, and we may coordinate them while keeping the applicable legal routes distinct.
16. Marketing, advertising and social media
16.1 We may send service, security, legal, regulatory, Transaction and Account communications where necessary. These are not marketing and may continue after you opt out of promotional messages.
16.2 We send electronic marketing only where permitted by PECR, data-protection law and applicable FCA financial-promotion rules. We may rely on your consent or, where legally available, the existing-customer exception and our legitimate interests in informing customers about similar CEX.IO products and services. You can opt out at any time through the unsubscribe link, Account preferences, live chat or dpo@cex.io.
16.3 With consent where required, we may use cookies, mobile advertising identifiers and hashed contact data to measure campaigns, create audiences or show relevant advertising through providers such as search engines, social networks and advertising platforms. The current providers and controls are available through Consent Preferences. These providers may act as independent controllers for their own purposes.
16.4 When you interact with an official CEX.IO social-media page, the platform provider processes information under its own privacy notice. We may receive comments, messages, engagement statistics and audience insights. Do not use social media for passwords, security codes, private keys or detailed Account information.
16.5 We keep suppression information after an opt-out so that we can respect your choice. Opting out of marketing does not affect legal, security, service or administrative messages.
17. Cookies and similar technologies
We use cookies, local storage, SDKs, pixels, tags, scripts and similar technologies on the Site, Platform, mobile application and communications. Some are Necessary for security, authentication, fraud prevention, consent management and requested functionality. Functional, Analytics and Advertisement technologies are optional and are used only in accordance with your choices in Consent Preferences and applicable law. Consent Preferences is displayed when you first visit the Site and remains available through the “Consent Preferences” link or icon on the left-hand side of the Site footer. The Cookie Policy and Consent Preferences explain the current technologies, categories, providers, purposes and durations and allow you to update your choices.
18. Children
The Services are not intended for anyone under 18 and minors are not eligible to open an Account. We do not knowingly provide the Services to children. If you believe a child has provided personal data or an Account is being used by a minor, contact us promptly at dpo@cex.io. We will investigate and take appropriate action, subject to legal record-keeping and safeguarding obligations.
19. Third-party websites and services
The Site, Platform and communications may link to or integrate third-party websites, applications, wallets, payment pages or services that we do not control. The third party’s privacy notice applies to its processing. Review that notice before providing personal data. A link or integration does not mean that we accept responsibility for the third party’s privacy or security practices.
20. Changes to this Policy
We may update this Policy to reflect changes in law, regulation, guidance, the Services, technology or our processing. We will update the “Last updated” date and, where a change is material, provide an appropriate notice through the Site, Platform, Account, email or another official channel. Where consent is required for a new purpose, we will request it separately.
Controller: CEX.IO Markets UK LTD, company number 15140258, registered office at 78-79 Pall Mall, London, England, SW1Y 5ES.
Data Protection Officer: dpo@cex.io
Cookie Policy
Last updated: 29 June 2026
This Policy explains how CEX.IO Markets UK LTD uses cookies and other storage and access technologies in connection with the Site, Platform, mobile application and Services.
Your choice
Necessary technologies are always active because they support the operation and security of the Site and requested Services. When you first visit the Site, Consent Preferences allows you to accept all optional technologies, reject them or choose separately whether to allow Functional, Analytics and Advertisement technologies. You can change your choices at any time through the “Consent Preferences” icon on the left-hand side of the Site footer.
Contents
- Scope
- Who we are
- What cookies and similar technologies are
- How we use them
- Consent and legal basis
- Consent Preferences and current technology list
- Third-party technologies
- Mobile application technologies
- Email technologies
- How to manage your choices
- Retention and consent records
- International processing
- Changes
- Contact and complaints
1. Scope
1.1 This Cookie Policy applies to cookies, local storage, session storage, software development kits (SDKs), pixels, tags, scripts, device identifiers, and other technologies that store information on, or access information from, your device in connection with the Site, Platform, mobile application, hosted interfaces, and electronic communications used to provide the Services.
1.2 This Cookie Policy should be read together with the CEX.IO Markets UK LTD Privacy Policy. Where our use of a technology involves processing personal data, the Privacy Policy provides further information about the applicable purposes and lawful bases, categories of recipients, international transfers, retention, and your data protection rights.
1.3 This Policy reflects the Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR), the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and those laws as amended, including by the Data (Use and Access) Act 2025. PECR applies to storage and access technologies whether or not the information is personal data.
2. Who we are
For the processing described in this Policy, CEX.IO Markets UK LTD is responsible for the storage and access technologies it selects and controls in connection with the Services. CEX.IO Markets UK LTD is a private limited company incorporated in England and Wales with company number 15140258 and registered office at 78-79 Pall Mall, London, England, SW1Y 5ES. Depending on the relevant activity, an affiliated CEX.IO entity or third-party provider may act as our processor acting on our instructions, as a separate controller for its own purposes and legal obligations, or as a joint controller with us where we jointly determine the purposes and essential means of the processing. Further information is provided in the Privacy Policy and, where relevant, the other controller’s own privacy information.
3. What cookies and similar technologies are
Cookies are small text files placed on a device when a website is visited. Similar technologies include local and session storage, SDKs embedded in mobile applications, pixels or web beacons, tags, scripts, advertising identifiers, device identifiers, and other techniques used to store or retrieve information from a browser, application, or device.
Some technologies last only for a session and are deleted when the browser or application closes. Others are persistent and remain until their stated expiry date, until they are deleted, or until the relevant identifier is reset. First-party technologies are set by the service you are using. Third-party technologies are set or accessed by another organisation whose functionality is integrated into the service.
4. How we use cookies and similar technologies
| Category | What it is used for | Consent position | Default |
|---|---|---|---|
| Necessary | Operate and secure the Site, Platform and requested Services; maintain sessions; authenticate Users; prevent fraud and technical abuse; remember your consent choices; route communications; process forms and Transactions; and provide requested Account, payment, live-chat or other core functionality. | Used without consent only where the technology is necessary to transmit a communication or provide a service or functionality you request, or another applicable PECR exception applies. Where personal data is processed, the applicable UK GDPR lawful basis is described in the Privacy Policy. | Always active. |
| Functional | Provide optional features and personalisation, such as remembering selected settings, collecting feedback, enabling social-media sharing, displaying embedded content and supporting other third-party functionality. | Used only with your consent. Where personal data is processed, the applicable UK GDPR lawful basis is described in the Privacy Policy. | Off until you select this category. |
| Analytics | Understand how visitors use the Site, Platform or application; measure traffic, journeys and interactions; identify errors; monitor performance; assess feature use; and improve reliability, usability and Services. | Used only with your consent. Analytics technologies may process identifiers and technical, device, session, usage and referral information. Where this information is personal data, the applicable UK GDPR lawful basis is described in the Privacy Policy. | Off until you select this category. |
| Advertisement | Measure advertising campaigns; attribute referrals; limit repeated advertisements; create or match audiences; personalise advertising; and display or measure CEX.IO advertising on third-party websites, applications or services. | Used only with your prior consent under PECR. Where related information is personal data, we rely on consent for advertising, audience matching and tracking, as further described in the Privacy Policy. | Off until you select this category. |
A single technology may support more than one purpose. We assess each purpose separately. If any purpose is not covered by a PECR exception, we do not use the technology for that purpose without the required consent.
5. Consent and legal basis
5.1 Unless an exception applies, we provide clear and comprehensive information and obtain prior consent before storing information on or accessing information from your device. Consent is requested separately from the Terms of Use and requires a clear affirmative action. Continuing to use the Site is not consent.
5.2 Consent Preferences allows you to accept all optional technologies, reject them or choose separately whether to allow the Functional, Analytics and Advertisement categories. Technologies that require consent are not activated before you make the relevant choice. We design the interface so that rejecting optional technologies is as easy as accepting them.
5.3 Where a third party relies on consent collected through Consent Preferences, its identity and the relevant purpose are made available before consent. We record the choice made and the information presented so that we can demonstrate consent.
5.4 You may withdraw or change consent at any time through Consent Preferences. Withdrawal does not affect the lawfulness of processing carried out before consent was withdrawn. We stop the relevant storage or access and associated consent-based processing and take any further steps required by law in relation to personal data already collected. You may also need to delete existing cookies or identifiers through browser, application or device controls.
5.5 In the current configuration, Necessary technologies are always active. Functional, Analytics and Advertisement technologies are optional and are used only after you select the relevant category in Consent Preferences. If we materially change the categories, purposes or consent model, we will update this Policy and Consent Preferences and request a new choice where required.
6. Consent Preferences and current technology list
6.1 The current list of cookies and similar technologies is maintained in Consent Preferences. Consent Preferences is displayed when you first visit the Site and remains available at any time through the “Consent Preferences” link or icon on the left-hand side of the Site footer. It forms part of this Cookie Policy.
6.2 Consent Preferences provides, for each current technology where applicable:
- the cookie, identifier or technology name;
- the provider or third party;
- the purpose and category;
- whether it is first-party or third-party;
- the duration or expiry period; and
- the available choice or control.
6.3 The dynamic list is used because the Platform and Services are updated regularly and different technologies may apply by page, feature, device, application version or jurisdiction. Technologies may not be activated for every User. We review the inventory, category allocation and consent configuration periodically and when material changes are introduced.
7. Third-party technologies
Third parties may store or access information when their services are integrated into the Site, Platform or mobile application. These may include providers of analytics, advertising, social media, customer support, consent management, security, fraud prevention, cloud and content delivery, payment functionality, identity verification and embedded media. Consent Preferences identifies the current third parties used for each relevant purpose.
Some third parties process information only on our instructions. Others may act as separate controllers for their own purposes or, in limited cases, as joint controllers where we jointly determine the purposes and essential means of the processing. Their own privacy and cookie information applies to their controller processing. A third party may combine information obtained through our Services with information from other services only where the applicable legal requirements and your choices in Consent Preferences allow it.
8. Mobile application technologies
Mobile applications may use SDKs, local storage, push-notification tokens, crash and performance tools, device identifiers and advertising identifiers such as Apple’s Identifier for Advertisers or the Android Advertising ID. The PECR rules apply to these technologies in the same way as website cookies.
Where required, we obtain consent through the application, an operating-system permission or Consent Preferences before using mobile identifiers for analytics, cross-service tracking or advertising. Apple App Tracking Transparency and Android privacy controls operate in addition to, and do not replace, any consent required through CEX.IO. You can change operating-system permissions or reset advertising identifiers in device settings and use in-app privacy or consent controls where available.
9. Email technologies
Emails may contain pixels, tagged links, or similar technologies used to confirm delivery, protect communications, detect abuse, understand whether a message was opened or a link selected, and measure campaigns. We use marketing tracking only where permitted by PECR and, where required, with your consent. Your choice about receiving marketing messages and your choice about marketing tracking are managed separately, where necessary. Transactional or security messages may still generate necessary delivery and security logs. You can opt out of marketing emails through the unsubscribe link, but service, legal, security, and Account communications may continue.
10. How to manage your choices
10.1 You can change your choices at any time through Consent Preferences. It is available through the “Consent Preferences” icon on the left-hand side of the Site footer. Choices may need to be repeated if you use a different browser or device, clear storage, use private browsing, reset an application or advertising identifier, or if we introduce a materially different purpose.
10.2 Most browsers allow you to block, delete or receive alerts about cookies. Device and application settings may also control SDK permissions, advertising identifiers, tracking and push notifications. Browser or device controls may be less granular than Consent Preferences and may not remove information already stored.
10.3 Blocking Necessary technologies may prevent secure login, session maintenance, consent recording, payment or Transaction flows, fraud prevention, live chat or other requested functionality from working. Rejecting Functional, Analytics, or Advertisement technologies does not prevent access to core Services, although optional features, personalisation, or embedded content may be limited.
10.4 Browser “Do Not Track” or similar signals are not by themselves a substitute for valid consent unless recognised by applicable law and supported by the relevant technology. We apply such signals where legally required and use Consent Preferences as the primary control for technologies used through CEX.IO.
11. Retention and consent records
The duration of each cookie or similar technology is shown in Consent Preferences. We choose a duration that is proportionate to the purpose and review persistent technologies periodically. Session technologies normally expire when the browser or application session ends. The technology used to remember your choice is retained for the period shown in Consent Preferences, unless you change your choice, delete the relevant storage, use another device or browser, or we need to ask again sooner because the technologies, purposes, providers or legal requirements change.
We may retain records of the consent request, the choice made and subsequent changes for as long as reasonably necessary to demonstrate your choices and comply with applicable law, resolve disputes and respect preferences. These records may be retained longer than the individual cookie or technology to which they relate.
12. International processing
Some providers may process identifiers and related information outside the United Kingdom. Where personal data is transferred internationally, the safeguards described in section 10 of the Privacy Policy apply. Information stored on or accessed from a device remains subject to PECR regardless of where the supporting service is hosted.
13. Changes to this Cookie Policy
We may update this Policy to reflect changes in law, guidance, technologies, providers or the Services. We will update the “Last updated” date and, where required, provide additional notice or request fresh consent. Introducing a new purpose that requires consent is not treated as covered by an earlier consent unless that consent was sufficiently specific and remains valid.
14. Contact and complaints
Questions, rights requests or complaints about our use of cookies and similar technologies may be submitted through secure online live chat, dpo@cex.io, support@cex.io or by post using the contact details provided in Section 2 of this Cookie Policy. You do not need to use a particular form, quote a legal provision or use particular wording.
We handle complaints about cookies and similar technologies under the process described in Section 15 of the Privacy Policy, including acknowledging receipt within 30 days, investigating the complaint without undue delay and informing you of the outcome.
You may raise a concern with the Information Commissioner’s Office at any time. You do not have to contact us before approaching the ICO, although we welcome the opportunity to address your concern first.