Privacy policy
1. Scope
This Policy explains how GEXFI HK collects, uses, retains, discloses and protects personal data when operating the GEXFI website, accounts and services it provides directly. The actual card issuer and other card service partners may issue separate privacy notices. The card application process will explain relevant information sharing and the parties' respective responsibilities. “Personal data” means information relating to an identifiable individual. This Policy also applies to personal data in business records about directors, beneficial owners, employees, authorised persons and transaction contacts.
2. Data we collect
Depending on the services you use, we may collect: Identity and contact data: name, date of birth, nationality, address, telephone number, email address, identity documents and verification results. Business and authority data: registration records, ownership and control structures, director and authorised person details, business activities and application documents. Account and transaction data: account identifiers, balances and order records, payment and receiving details, transaction purpose, source of funds information, wallet addresses, blockchain transaction identifiers, card application and transaction records. We do not display your complete sensitive records on public website pages. Compliance and security data: identity verification, watchlist and sanctions screening, fraud and transaction monitoring results, communications and review records. Device and website data: IP address, device and browser details, access logs, information from necessary cookies or similar technologies, and your communications with customer support. We generally obtain data from you or the business you represent. Where permitted by law, we may also obtain data from verification providers, payment and card partners, financial institutions, public registers, counterparties and other lawful sources. We will provide any notice required by applicable law when data is obtained indirectly.
3. How we use data
We process personal data as necessary to: 1. Review account and product applications, verify identity and business eligibility, and provide accounts and transactions; 2. Execute orders, verify receipt and settlement of funds, and handle refunds, disputes and support; 3. Meet applicable anti-money laundering, counter-terrorist financing, sanctions, tax, record-keeping and other legal obligations; 4. Detect unusual transactions, fraud and unauthorised access, and protect customers, partners and systems; and 5. Maintain and improve the website and services, analyse usage, and send marketing communications only to the extent permitted by law and consistent with your choices. If you do not provide information necessary for a service, we may be unable to verify your identity, open a service or execute a transaction. You may opt out of marketing using the method in a message or by contacting us. Essential account, security and transaction notices are not marketing communications.
4. Recipients of data
To the extent needed to provide services, fulfil legal duties or pursue another lawful purpose, we may disclose data to identity and business verification providers; banks and payment providers; wallet and blockchain technology providers; the actual card issuer; Visa Worldwide Pte. Limited, if it participates in the relevant card service; card processors; cloud and security providers; professional advisers; regulators or law enforcement agencies; and GEXFI affiliates performing related services. We require service providers processing data on our behalf to maintain appropriate confidentiality and security measures. We do not provide customers' personal data to data brokers in exchange for its sale. Blockchain addresses, transaction identifiers and records may be publicly visible and difficult to remove.
5. Processing and disclosure outside Hong Kong
GEXFI HK operates relevant services in Hong Kong and may, as needed for a product, disclose or transfer necessary personal data to card service participants, card processors and approved technology or data providers in Singapore. Singapore is the overseas recipient location described in this Policy. The actual processing locations of a card scheme or other recipients should be described in the specific notice provided during card enrolment. We will apply contractual, technical and organisational safeguards appropriate to the nature of the data under Hong Kong's Personal Data (Privacy) Ordinance (Cap. 486) and other applicable laws, and restrict processors acting on our behalf to agreed purposes. If additional overseas recipient locations are introduced, we will update the notice as required by applicable law.
6. Automated tools
We may use optical character recognition, rules-based systems, data analytics and approved automated tools to assist with reading documents, verifying identities, detecting fraud, screening names, monitoring transactions and providing support. Circumstances requiring human review, significant decisions that may affect service eligibility, and review channels depend on the actual product process and applicable law. This Policy does not replace a specific compliance review procedure.
7. Cookies and website analytics
The website may use necessary cookies for language settings, security and basic functions. If we use non-essential analytics or marketing technologies, we will provide notice and choices as required. You may also manage cookies in your browser, although disabling certain necessary features may affect the website.
8. Retention and security
We retain information for as long as needed to provide services, meet legal duties, resolve disputes and maintain security. Retention periods vary by data category. Closing an account does not necessarily result in immediate deletion of identity and transaction records that must be kept by law. At the end of the applicable retention period, we will delete or de-identify data as required. We use access controls, protections for transmission and storage, log monitoring and staff permission management proportionate to the risk. No system can guarantee absolute security. We will handle and notify relevant parties of a privacy incident where required by applicable law.
9. Your choices, access and correction
You may request access to or correction of personal data we hold, subject to applicable law, and contact us about marketing preferences, privacy handling or account security. We may verify your identity before responding. Anti-money laundering, regulatory, legal claims or other statutory requirements may prevent immediate deletion or disclosure of some information. Email info@gexfi.com to request access or correction or to submit a privacy complaint. We may verify your identity first. If your concern is not resolved, you may complain to the Office of the Privacy Commissioner for Personal Data in Hong Kong or exercise other rights under applicable law.
10. Children, updates and contact
GEXFI financial services are intended for eligible adults. We do not target children with account services. If we discover that an ineligible minor has submitted information, we will handle it in accordance with applicable law. We may update this Policy and show the updated date on the page. We will provide notice of material changes where required. For privacy enquiries, use the contact details above. Effective date: the date of formal publication on the website.