Privacy Policy
Last updated: June 2026
1. Data Controller
The Exedra Gate platform and website are operated by ATRUM STUDIOS LTD, a company incorporated in the Republic of Cyprus (Company No. HE 478783), with its registered address in Paphos, Cyprus. Personal-data processing is carried out in accordance with the EU General Data Protection Regulation (GDPR) and applicable Cypriot data-protection law, and — where Exedra Gate serves clients in those jurisdictions — is designed to support compliance with the UAE Federal Personal Data Protection Law (PDPL), DIFC and ADGM data-protection regimes.
2. Data Collected
- Account data: name, email address, phone number, company name.
- Identity-verification data: as required by KYC/KYB and AML obligations of our regulated clients, processed through certified third-party providers.
- Usage data: IP address, browser type, access timestamps, and page interactions, for security and audit purposes.
- Signing data: document hashes, signature artifacts, device metadata, and timestamps, retained as legal evidence.
- Screening data (certification): where an issuer is screened, special- category/criminal-offence data about directors and beneficial owners (e.g. adverse media, litigation, insolvency) may be processed on a lawful basis, with the rights described in section 6.
3. Purpose of Processing
Personal data is processed for: account management, supporting our clients’ regulatory compliance (KYC/KYB/AML), signing integrity, audit-trail maintenance, certification screening, and platform security. Exedra Gate provides infrastructure to regulated entities; it does not itself make AML, suitability, or compliance determinations.
4. Data Sharing
Data is never sold. It may be shared with identity-verification providers, hosting and infrastructure providers under data-processing agreements, and — only on lawful request — competent authorities. Our clients act as controllers for the data they process about their own investors and counterparties.
5. Data Retention
Account data is retained for the duration of the relationship. Audit logs and signing evidence are retained for the legally required period (a minimum of 10 years is typical for financial-compliance records). Screening data is held only for as long as a certificate is active plus any required retention period, then deleted.
6. Your Rights
You have the right to access, rectify, restrict, or request deletion of your personal data, and to object to processing, subject to legal retention obligations. Because adverse-media screening can produce false matches (e.g. name collisions), individuals named in screening have a rectification and dispute path: a contested or stale record will not persist unresolved. Requests can be directed to privacy@exedragate.com.
7. Security
Data is encrypted in transit (TLS 1.3) and at rest. Strong, phishing-resistant authentication (AAL2; device-bound scan-to-approve — no SMS or email OTP) is required for platform access. Audit trails are tamper-evident and hash-chained.
8. Contact
For privacy enquiries: privacy@exedragate.com. Postal contact is provided on our Imprint.