KereX/Legal Documents
v1
kerex.io
Legal documents Regulatory Status
Regulatory StatusTerms of UsePrivacy PolicyCookie PolicyComplaints PolicyFraud & Security Policy
LEGAL DOCUMENTS
Regulatory StatusTerms of UsePrivacy PolicyProhibited JurisdictionsCookie PolicyComplaints PolicyFraud & Security Policy
On this page
1. Who We Are and Scope2. Personal Data We Collect3. How We Collect Personal Data4. How and Why We Use Personal Data5. How We Share Personal Data6. International Data Transfers7. Data Retention8. Information Security and Data Incidents9. Your Rights and Choices10. Cookies, Children, Updates and Contact

Last updated: July 2026

PRIVACY POLICY

This Privacy Policy explains how KereX Technologies L.L.C-FZ (“KereX”, “we”, “us” or “our”) collects, uses, shares, stores and protects personal data.

It applies when you visit our website, submit an enquiry, take part in onboarding, use our documentation, dashboards, APIs or testing environments, or otherwise communicate with KereX.

This Policy primarily covers business contacts, representatives of clients and partners, authorised platform users and other individuals who interact with KereX in a professional capacity.

1. Who We Are and Scope

KereX Technologies L.L.C-FZ is a technology company incorporated in Meydan Free Zone, Dubai, United Arab Emirates.

For personal data collected through our website, contact forms, business relationships, onboarding and platform administration, KereX generally acts as the controller responsible for deciding why and how that data is processed.

Where KereX processes personal data contained in transactions, API requests or client systems solely on the instructions of a client or service partner, KereX may act as a processor. That processing is governed by the relevant services agreement or data processing agreement.

This Policy does not replace the privacy notices of banks, payment institutions, PSPs or other partners that independently determine how they process personal data.

2. Personal Data We Collect

Depending on how you interact with KereX, we may collect the following categories of personal data:

• identity and contact information, including name, job title, work email address, telephone number and professional profile;

• company and onboarding information, including organisation name, role, ownership or control information and authorised representative details;

• account information, including usernames, permissions, authentication records and account settings;

• technical information, including IP address, browser, device, operating system, timestamps, API activity, log files and security events;

• transaction and payment-flow metadata, including transaction references, amounts, currencies, timestamps, status information, routing data and partner identifiers;

• communications, including enquiries, support requests, meeting notes and correspondence;

• compliance information, including identity documents, screening information and business verification data where required for onboarding or partner review;

• marketing preferences and records of your consent or opt-out choices.

We do not ask you to provide sensitive personal data through public website forms unless it is specifically required and supported by an appropriate legal basis and secure collection process.

KereX does not intentionally collect full card credentials, online banking passwords or private cryptographic keys through its public website.

3. How We Collect Personal Data

We may collect personal data:

• directly from you when you contact us, complete a form, create an account or participate in onboarding;

• from your employer, organisation or an authorised representative;

• through your use of our website, APIs, dashboards and technical environments;

• from banks, PSPs, payment networks, technology vendors and other service partners involved in an approved integration;

• from publicly available corporate registers, professional networks and business information sources;

• from compliance, identity verification, sanctions screening, fraud prevention and information-security providers.

Our website may use cookies and similar technologies to operate securely, remember preferences and understand website performance.

More information is available in our Cookie Policy.

4. How and Why We Use Personal Data

We may process personal data to:

• respond to enquiries and evaluate potential partnerships or integrations;

• onboard clients, partners, users and authorised representatives;

• provide, administer and support the KereX platform;

• configure APIs, payment routes, permissions and technical environments;

• monitor transactions, system activity, performance and service status;

• protect accounts, systems and integrations against fraud, misuse and security threats;

• conduct business, compliance, sanctions, technical and risk reviews;

• maintain records, issue invoices and manage commercial relationships;

• comply with applicable law, court orders, regulatory requirements and lawful authority requests;

• establish, exercise or defend legal claims;

• improve our products, documentation and operational processes;

• send relevant business communications where permitted by law.

Where required, we process personal data with your consent.

We may also process data where necessary to take steps at your request, perform a contract, comply with a legal obligation, protect rights and security, or rely on another basis permitted by applicable law.

You may withdraw consent at any time where consent is the basis for processing. Withdrawal does not affect processing completed before the withdrawal.

5. How We Share Personal Data

We may share personal data with:

• banks, payment institutions, PSPs, payment networks, payout providers and settlement partners involved in an approved route;

• cloud hosting, communications, analytics, identity verification, compliance, security and technical service providers;

• professional advisers, including lawyers, auditors, accountants and insurers;

• government authorities, regulators, courts or law-enforcement bodies where disclosure is required or legally permitted;

• a prospective buyer, investor or successor in connection with a corporate transaction, subject to appropriate confidentiality measures.

Recipients may use personal data only for the purpose for which it was disclosed and subject to applicable law and contractual obligations.

Banks, PSPs and other regulated institutions may act as independent controllers and apply their own privacy notices.

KereX does not sell personal data or provide it to third parties for their unrelated advertising purposes.

6. International Data Transfers

KereX operates internationally and may process personal data in the United Arab Emirates and in other countries where our clients, partners and service providers are located.

Those countries may have data protection rules that differ from the rules in your country.

Where personal data is transferred across borders, KereX uses measures permitted by applicable law. Depending on the circumstances, these may include:

• transferring data to a jurisdiction recognised as providing an appropriate level of protection;

• contractual safeguards requiring the recipient to protect the data;

• your consent where legally valid and appropriate;

• transfers necessary to perform a contract, establish or defend legal rights, or meet another permitted legal condition.

We take reasonable steps to ensure that recipients maintain appropriate confidentiality, security and data protection standards.

7. Data Retention

KereX retains personal data only for as long as reasonably necessary for the purposes described in this Policy.

Retention periods depend on:

• the nature of the data and the purpose for which it was collected;

• the duration of the relevant client, partner or user relationship;

• contractual, accounting, tax, compliance and regulatory requirements;

• fraud prevention, security and audit needs;

• applicable limitation periods and the need to establish or defend legal claims.

When personal data is no longer required, we delete, anonymise or securely isolate it, unless continued retention is required or permitted by law.

Data held in backups may remain for a limited period until it is securely overwritten or deleted in accordance with normal backup procedures.

8. Information Security and Data Incidents

KereX uses organisational and technical measures designed to protect personal data against unauthorised access, loss, misuse, alteration or disclosure.

These measures may include access controls, authentication, encryption, logging, monitoring, secure development practices, vendor reviews, backups and incident response procedures.

Access to personal data is limited to personnel and service providers who require it for an authorised business purpose.

No system or transmission method can be guaranteed to be completely secure. You are responsible for protecting credentials issued to you and for notifying KereX promptly if you suspect unauthorised access.

Where a personal data incident creates a notification obligation, KereX will notify the relevant authority, affected client or individual as required by applicable law and the circumstances of the incident.

Fraud & Security Policy

9. Your Rights and Choices

Subject to applicable law and relevant exceptions, you may have the right to:

• receive information about how your personal data is processed;

• request access to personal data held about you;

• request correction or completion of inaccurate or incomplete data;

• request deletion of personal data;

• request restriction or stopping of processing;

• withdraw consent where processing is based on consent;

• receive certain personal data in a structured, machine-readable format and request its transfer where technically feasible;

• object to certain automated decisions and request human review where applicable;

• opt out of direct marketing communications;

• submit a complaint to the relevant data protection authority.

To protect personal data, KereX may request information needed to verify your identity and authority before acting on a request.

Some requests may be restricted or refused where retention or processing is required by law, necessary for legal claims, affects the rights of another person or is subject to another lawful exception.

To exercise a right, contact legal@kerex.io.

10. Children, Updates and Contact

Children

The KereX platform is intended for organisations and professional users. It is not directed to children, and we do not knowingly collect personal data from children through our business services.

Policy updates

KereX may update this Privacy Policy to reflect changes in our services, processing activities or legal requirements.

The updated version will be published on this page with a revised “Last updated” date. Where appropriate, we may provide additional notice of material changes.

Contact

Questions, privacy requests and complaints may be sent to:

legal@kerex.io
KereX Technologies L.L.C-FZ
Meydan Free Zone
Dubai, United Arab Emirates

Our website uses cookies and similar technologies as described in the KereX Cookie Policy.

ON THIS PAGE
1. Who We Are and Scope2. Personal Data We Collect3. How We Collect Personal Data4. How and Why We Use Personal Data5. How We Share Personal Data6. International Data Transfers7. Data Retention8. Information Security9. Your Rights and Choices10. Cookies, Updates and Contact

© 2026 KereX Technologies L.L.C-FZ

ContactLegal Documentskerex.io