LEGAL

Privacy Policy

Last updated: August 2026

1. Data Controller

The Exedra Gate platform and website are operated by ATRUM STUDIOS LTD, a company incorporated in the Republic of Cyprus (Company No. HE 478783), with its registered address in Paphos, Cyprus. Personal-data processing is carried out in accordance with the EU General Data Protection Regulation (GDPR) and applicable Cypriot data-protection law, and, where Exedra Gate serves clients in those jurisdictions, is designed to support compliance with the UAE Federal Personal Data Protection Law (PDPL), DIFC and ADGM data-protection regimes.

2. Data Collected

  • Account data: name, email address, phone number, company name.
  • Identity-verification data: as required by KYC/KYB and AML obligations of our regulated clients, processed through certified third-party providers.
  • Usage data: IP address, browser type, access timestamps, and page interactions, for security and audit purposes.
  • Signing data: document hashes, signature artifacts, device metadata, and timestamps, retained as legal evidence.
  • Screening data (certification): where an issuer is screened, special- category/criminal-offence data about directors and beneficial owners (e.g. adverse media, litigation, insolvency) may be processed on a lawful basis, with the rights described in section 6.
  • Application data: what a person sends through the careers form, including any CV or supporting document. It is emailed rather than stored, and it is dealt with separately in section 8.

3. Purpose of Processing

Personal data is processed for: account management, supporting our clients’ regulatory compliance (KYC/KYB/AML), signing integrity, audit-trail maintenance, certification screening, and platform security. Exedra Gate provides infrastructure to regulated entities; it does not itself make AML, suitability, or compliance determinations.

4. Data Sharing

Data is never sold. It may be shared with identity-verification providers, hosting and infrastructure providers under data-processing agreements, and, only on lawful request, competent authorities. Our clients act as controllers for the data they process about their own investors and counterparties.

5. Data Retention

Account data is retained for the duration of the relationship. Audit logs and signing evidence are retained for the legally required period (a minimum of 10 years is typical for financial-compliance records). Screening data is held only for as long as a certificate is active plus any required retention period, then deleted.

6. Your Rights

You have the right to access, rectify, restrict, or request deletion of your personal data, and to object to processing, subject to legal retention obligations. Because adverse-media screening can produce false matches (e.g. name collisions), individuals named in screening have a rectification and dispute path: a contested or stale record will not persist unresolved. Requests can be directed to privacy@exedragate.com.

7. Security

Data is encrypted in transit (TLS 1.3) and at rest. Strong two-factor authentication (AAL2, meaning an authenticator app as the second factor, with device-bound passkeys for signing; no SMS or email OTP) is required for platform access. Audit trails are tamper-evident and hash-chained.

8. Applications and Recruitment

This section covers personal data sent through the application form on our careers page, including any CV or supporting document attached to it. It is separate from everything above because an application is not a client relationship and is not processed like one. The roles advertised there are remote and open to candidates anywhere in the world, so this section is written for an applicant who may be reading it from any country.

What is collected. Name, email address, the area of interest and the role applied for, any link supplied, the message written in the form, and any documents attached: typically a CV, and sometimes a cover letter, portfolio or references. Those documents commonly contain more than the form asks for, such as education, employment history, nationality or date of birth.

Lawful basis. Where an application answers an advertised role, the basis is Article 6(1)(b) GDPR: steps taken at the request of the applicant before entering into a contract. Where an application is unsolicited, the basis is Article 6(1)(f) GDPR, the legitimate interest in assessing whether a person fits work the company has or expects to have, balanced against the applicant's interests by keeping the data for a short defined period and using it for nothing else. Consent is not used as the basis, and no consent box is presented, because in a recruitment setting consent would be the weakest of the available bases and describing the processing as consent-based would misdescribe it.

Who receives it. The application is sent as a single email to Exedra Gate's own mailboxes, through our email delivery provider, and is read by the people responsible for hiring. It is not shared with recruiters, job boards, or any other third party, and it is never sold. It is not screened, scored or filtered by any automated system, and no decision about an application is made by automated means.

Where it is kept. Applications and their documents are not stored on this website or in any database. The email that carries them is the only copy.

It crosses borders, and here is exactly how. Because the roles are open worldwide, an application usually begins in one country and is read in another. When the form is sent, the application and any attached documents leave the country the applicant is in, pass through the systems of the email delivery provider that sends the message, and arrive in Exedra Gate's mailboxes, where they are read by the people responsible for hiring at ATRUM STUDIOS LTD in Cyprus. Nothing is copied into a database, a storage bucket or an applicant-tracking system on the way, because none of those exists here. That is the whole route.

No safeguard is claimed here that has not been arranged. Nothing has been put in place specifically for applications beyond the ordinary terms the email provider operates under, so this policy names no adequacy decision, no set of contractual clauses and no certification scheme for this route: naming one would be the kind of statement this company refuses to make anywhere else. What is described above is what happens, and an applicant who is not willing for their data to travel that route should not send it. If a mechanism is adopted later, this section will say so.

Retention. Applications and their documents are kept for six months from the point the application is decided, so that the company can answer a question about its own decision and can come back to a person when a matching role opens, and are then deleted. Deletion can be requested sooner, at any time.

Your rights, and how to have it deleted. The rights in section 6 apply here in full: access, rectification, restriction, objection, portability, and erasure. To have an application and its documents deleted, or to ask what is held, write to privacy@exedragate.com. Where the basis is legitimate interest, an objection under Article 21 GDPR can be made on the same route and there is no disadvantage in making one, because an application that has been withdrawn is not considered.

Special-category data is not requested. Please do not include health information, trade-union membership, religious or political affiliation, sexual orientation, criminal-record detail, or a photograph. None of it is asked for, none of it is used to assess an application, and anything of that kind that arrives unsolicited is deleted rather than filed.

9. Contact

For privacy enquiries: privacy@exedragate.com. Postal contact is provided on our Imprint.