§ LEGAL · PRIVACY POLICY
Privacy Policy
Effective Date: 1 June 2025 · Last Updated: 1 June 2026 ·
Governing Law: International · Operator: DEALEXUS
This Privacy Policy explains how DEALEXUS ("we", "us", "our") collects, uses, stores, and protects personal data when you use the DEALEXUS platform at dealexus.com and its associated services.
By registering for or using the Platform, you consent to the practices described in this Policy. If you do not agree, do not use the Platform.
Where you access the Platform from Singapore, the EU, or other jurisdictions with their own data protection laws, we apply the higher standard to the extent reasonably practicable.
1. Data Controller
The data controller responsible for your personal data is DEALEXUS. For all data-related enquiries, contact us at info@dealexus.com.
2. Data We Collect
2.1 Account & Identity Data
- Full name, display name, email address, password (hashed — never stored in plain text)
- Organisation name, registered country, business role (broker, principal, mandate, banker)
- IP address, device type, browser fingerprint (for security and fraud prevention)
- Login timestamps and session activity logs
2.2 KYC / CIS Documents (Sensitive)
- Passport or national ID (certified copy)
- Certificate of Incorporation / company registration
- Proof of address (utility bill, bank statement)
- Bank reference letter / Bank Comfort Letter (BCL)
- Ultimate Beneficial Owner (UBO) declaration
- Source of funds declaration
KYC documents are stored in an encrypted, access-controlled document store (AWS S3 + KMS). They are referenced in the Platform database only by a verification token — the raw documents are never stored in the main database. Counterparties only ever see your ● KYC VERIFIED badge — they cannot access your documents.
2.3 Deal & Transaction Data
- Deal identifiers, instrument type, deal value, currency, corridor
- Parties to each deal and their verification status
- Deal lifecycle transitions, timestamps, and audit trail
- Signed documents (NCNDA, DOA, IMFPA, Term Sheet, Bank Submission Package)
- Compliance declarations and flag records
2.4 Billing Data
- Subscription tier, billing cycle, deal usage count
- Payment method details are processed and stored exclusively by Stripe — we do not store card numbers or bank account details
- Invoice history and payment status
2.5 Usage & Technical Data
- Pages visited, features used, time on platform
- Error logs and performance telemetry (no PII in logs)
- Referral source (how you found us)
3. How We Use Your Data
| PURPOSE | DATA USED | LEGAL BASIS |
| Provide and operate the Platform | Account, deal, billing data | Contractual necessity |
| KYC / AML identity verification | KYC documents, UBO declaration | Legal obligation (FATF, AMLA 2001) |
| Sanctions & PEP screening | Name, nationality, UBO data | Legal obligation |
| Fraud prevention & security | IP, device, session data | Legitimate interests |
| Process payments & subscriptions | Billing data via Stripe | Contractual necessity |
| Enforce NCNDA & commission protection | Deal data, party identities | Contractual necessity |
| Maintain audit trail (7-year retention) | All deal & compliance events | Legal obligation (financial records) |
| Platform improvements & analytics | Anonymised usage data | Legitimate interests |
| Send transactional emails (deal updates, invoices) | Email address | Contractual necessity |
| Respond to support requests | Account + deal context | Legitimate interests |
We do not use your data for targeted advertising and do not sell your personal data to third parties.
4. Information Barriers
DEALEXUS enforces strict data segregation between deal parties. This is a core product commitment, not a courtesy:
- Each party can only read their own deal-side data.
- Counterparties can only see your KYC verification status — never your documents, pricing, or identity details.
- These barriers are enforced at both the application layer and the database layer (PostgreSQL row-level security).
- DEALEXUS staff access to deal data is logged, audited, and role-restricted.
5. Data Sharing
We share your data only as follows:
- Stripe: Payment processing. Governed by Stripe's Privacy Policy.
- AWS (Amazon Web Services): Cloud infrastructure hosting (servers, storage, KMS encryption). Data is hosted in Singapore / Asia Pacific regions.
- KYC/AML screening providers: Name and identity data may be submitted to sanctions screening services (e.g. Dow Jones, Refinitiv, or equivalent) to fulfil our compliance obligations.
- Regulatory authorities: We may disclose data to MAS, HKMA, DIFC/ADGM, or other competent authorities where legally required or where we have a good-faith belief that disclosure is necessary to prevent financial crime.
- Legal proceedings: We may disclose data pursuant to a valid court order, subpoena, or equivalent legal process.
We do not share your data with counterparties in a deal beyond the verification badges described above.
6. Data Retention
| DATA TYPE | RETENTION PERIOD | REASON |
| Account & identity data | Duration of account + 7 years | Financial record-keeping obligations |
| KYC documents | 7 years from last deal | FATF / AMLA 2001 requirements |
| Deal & transaction records | 7 years from deal closure | Audit, legal, and regulatory compliance |
| Audit trail (immutable) | 7 years minimum | Cannot be deleted — append-only by design |
| Billing records | 7 years | Tax and accounting obligations |
| Usage/technical logs | 90 days | Security monitoring, then deleted |
| Deleted accounts | Data anonymised within 30 days, retained 7 years in anonymised form | Regulatory compliance |
7. Security
We implement appropriate technical and organisational measures to protect your data:
- All data in transit encrypted via TLS 1.2+
- KYC documents encrypted at rest using AWS KMS (AES-256)
- Passwords hashed with bcrypt (cost factor 10+)
- Multi-factor authentication available for all accounts
- Database row-level security enforcing information barriers
- Append-only, hash-chained audit log for all deal events
- Access controls and staff privilege separation
- Regular security assessments
No security measure is 100% guaranteed. In the event of a data breach affecting your personal data, we will notify you and relevant regulators in accordance with applicable law.
8. Your Rights
Under applicable data protection frameworks, you have the right to:
- Access: Request a copy of the personal data we hold about you.
- Correction: Request correction of inaccurate or incomplete data.
- Withdrawal of Consent: Withdraw consent for processing where consent is the legal basis. Note that withdrawal may prevent us from providing the Platform to you.
- Deletion: Request deletion of your account and personal data, subject to our legal retention obligations (KYC and deal records cannot be deleted during the mandatory retention period).
- Portability: Request your account data in a machine-readable format.
- Objection: Object to processing based on legitimate interests.
To exercise any right, email info@dealexus.com with the subject line "DATA REQUEST — [your name]". We will respond within 21 days. We may require identity verification before processing your request.
9. Cookies & Tracking
The Platform uses minimal, essential cookies for session management and authentication. We do not use third-party advertising cookies or tracking pixels. The only third-party scripts that may set cookies are:
- Stripe.js — for payment security (fraud detection)
- Vercel Analytics — anonymous page-level analytics (no PII)
You can disable cookies in your browser, but this will prevent you from logging in.
10. International Transfers
Your data is primarily stored on AWS infrastructure in Singapore (ap-southeast-1). Where data is processed outside Singapore (e.g. by Stripe in the US), we rely on standard contractual clauses and the provider's adequacy certifications to ensure equivalent protection.
11. Children
The Platform is intended for business use only. We do not knowingly collect data from individuals under 18. If you believe a minor has registered, contact us immediately at info@dealexus.com.
12. Changes to This Policy
We may update this Policy at any time. Material changes will be notified by email or in-platform notice at least 14 days before taking effect. The "Last Updated" date at the top of this page reflects the most recent revision. Continued use of the Platform after the effective date constitutes acceptance.
13. Contact & Complaints
For privacy questions, data requests, or complaints: