Privacy policy
Everything about membership, payments, verification and trust on JewelTec.
Can’t find it? Our team is one message away.
Can’t find it? Our team is one message away.
Last updated: 9 August 2026
1. DEFINITIONS AND INTERPRETATION
1.1 In this Privacy Policy, the following terms have the meanings set out below:
Business Data means information relating to a User’s business, including company name, registration number, trading address and beneficial ownership details.
Contact Data means email address, telephone number and other contact details provided to JewelTec.
Data Protection Laws means the UK GDPR (General Data Protection Regulation), the Data Protection Act 2018 (as amended from time to time) and any other applicable EU GDPR principles.
Identity Data means personal information identifying an individual, including name, date of birth and nationality.
JewelTec means JEX Holdings Ltd, a company incorporated in England and Wales under company number 16479946, whose registered office is at 8-9 Greville Street, Greville Street, London, England, EC1N 8SB.
Marketing Data means information relating to marketing preferences and communications.
Platform means the JewelTec digital marketplace, including its website, applications and associated services, through which Users may register accounts, list, buy, sell and trade goods, communicate with other Users and access escrow, compliance and related services.
Technical Data means technical information including IP address, device identifiers, browser type, logs and similar data.
Transaction means a binding agreement for the sale or purchase of goods entered into between Users via the Platform.
Transaction Data means information relating to Transactions, including listings, offers, messages, escrow records and dispute records.
Usage Data means information about how the Platform is accessed and used.
User means any individual or entity that has registered an account on the Platform (including authorised users acting on behalf of a business account).
Verification Data means data collected for identity verification purposes, including government-issued identification, proof of address and KYB/KYC documentation.
1.2 Headings are for convenience only and do not affect interpretation.
2. INTRODUCTION
2.1 This Privacy Policy explains how JewelTec collects, uses, stores and discloses personal data in connection with its operation of the Platform.
2.2 JewelTec is committed to protecting personal data and complying with applicable Data Protection Laws.
2.3 The Platform is a business-to-business service and is not directed at, or intended for use by, consumers or individuals under the age of 18. We do not knowingly collect personal data relating to children.
3. REGULATORY FRAMEWORK
3.1 This Privacy Policy is drafted in accordance with:
•the UK General Data Protection Regulation (“UK GDPR”);
•the Data Protection Act 2018; and
•where a User is established in the European Economic Area (“EEA”) or the processing otherwise falls within its territorial scope, the EU General Data Protection Regulation (“EU GDPR”), applied directly (and not merely by reference to its principles).
3.2 Where the EU GDPR applies to our processing of a User’s personal data and JewelTec has no establishment in the EEA, we will, where required, appoint a representative in the EEA in accordance with Article 27 of the EU GDPR and will publish that representative’s contact details.
4. DATA CONTROLLER
JewelTec is the data controller for all personal data processed in connection with the Platform.
5. CATEGORIES OF PERSONAL DATA
5.1 JewelTec may collect and process the following categories of personal data:
•Identity Data;
•Contact Data;
•Business Data;
•Verification Data;
•Transaction Data;
•Technical Data;
•Usage Data;
•Marketing Data; and
•Special Category Data, being biometric data (such as facial mapping or liveness-check data) collected as part of our identity verification process for the purpose of uniquely identifying a User, and any criminal offence data arising from sanctions, politically exposed person (PEP) or adverse media screening carried out as part of our anti-money laundering checks.
6. LAWFUL BASES FOR PROCESSING
6.1 JewelTec processes personal data on the following lawful bases:
•performance of a contract;
•compliance with legal obligations;
•legitimate interests including fraud prevention and platform security; and
•consent, where required.
6.2 Where we process Special Category Data comprising biometric data for identity verification, we do so on the basis of the User’s explicit consent and/or, where applicable, on the basis that the processing is necessary for reasons of substantial public interest (fraud prevention and prevention of money laundering) in accordance with Article 9(2) UK GDPR and Schedule 1 of the Data Protection Act 2018.
6.3 Where our sanctions, PEP or adverse media screening involves data relating to criminal convictions or offences, we process that data only to the extent necessary for compliance with our legal obligations under the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017, in accordance with Article 10 UK GDPR and the applicable condition in Schedule 1 of the Data Protection Act 2018.
7. PURPOSES OF PROCESSING
7.1 Personal data is processed for the purposes of:
•onboarding and verification;
•enabling Transactions and escrow processes;
•fraud prevention and compliance;
•dispute resolution;
•customer support;
•platform improvement; and
•legal and regulatory compliance.
8. DATA SHARING
8.1 JewelTec may share personal data with:
•identity verification and compliance providers;
•payment service providers and escrow partners;
•regulators, law enforcement and courts; and
•professional advisers.
9. DATA RETENTION
Personal data is retained only for as long as necessary to fulfil the purposes for which it was collected and to comply with legal obligations. In particular:
•Verification Data and records relating to our anti-money laundering and know-your-customer checks are retained for a minimum of five years from the end of the business relationship, in accordance with the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017;
•Transaction Data is retained for as long as the relevant Transaction remains capable of being disputed, and thereafter for the period necessary to satisfy our accounting, tax and audit obligations;
•Marketing Data is retained until a User withdraws consent or objects to marketing, and is then deleted or anonymised save where we are required to retain a record of the withdrawal itself; and
•Technical Data and Usage Data are retained for no longer than is necessary for the security, fraud-prevention and analytics purposes described in this Policy.
10. DATA SUBJECT RIGHTS
10.1 Users have the right to:
•access their personal data;
•request rectification or erasure;
•restrict or object to processing;
•request data portability;
•withdraw consent at any time, where processing is based on consent, without affecting the lawfulness of processing carried out before withdrawal;
•not be subject to a decision based solely on automated processing (including profiling) which produces legal effects concerning them or similarly significantly affects them, save where permitted by law — see paragraph 17 (Automated Decision-Making) below; and
•lodge a complaint with the Information Commissioner’s Office.
11. COOKIES
11.1 The Platform uses cookies and similar technologies.
11.2 Categories of cookies include:
•strictly necessary cookies;
•analytics cookies;
•preference cookies; and
•marketing cookies (consent-based).
12. SECURITY
JewelTec implements appropriate technical and organisational measures to protect personal data against unauthorised access, loss or misuse.
13. THIRD-PARTY LINKS
The Platform may contain links to third-party websites. JewelTec is not responsible for their privacy practices.
14. CHANGES TO THIS POLICY
JewelTec may update this Privacy Policy from time to time. Material changes will be notified to Users as appropriate.
15. GOVERNING LAW
This Privacy Policy is governed by the laws of England and Wales.
16. INTERNATIONAL TRANSFERS
16.1 Some of the recipients described in paragraph 8 are located, or process personal data, outside the UK, including in the United States and other jurisdictions not covered by UK adequacy regulations.
16.2 Where we transfer personal data outside the UK, we do so on the basis of an applicable UK adequacy regulation, the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, the UK-US Data Bridge (where the recipient is certified under it), or another lawful transfer mechanism recognised under UK GDPR.
16.3 Users may request further information about the safeguards that apply to a specific international transfer by contacting us using the details in paragraph 19.
17. AUTOMATED DECISION-MAKING
17.1 We use automated tools, which may include a “Trust Score” and related risk indicators, to support decisions about onboarding, monitoring and account restriction.
17.2 Where any such decision is taken solely by automated means and produces legal effects concerning a User or similarly significantly affects them, the User has the right to obtain human review of that decision, to express their point of view, and to contest the decision, save to the extent the decision is necessary for entering into or performing a contract with the User, is authorised by law, or is based on the User’s explicit consent.
18. CRIMINAL OFFENCE DATA
18.1 As part of our anti-money laundering and counter-terrorist financing programme, we carry out sanctions, politically exposed person (PEP) and adverse media screening. This may involve processing data relating to criminal convictions, offences or alleged offences.
18.2 We process this data only where necessary to comply with our legal and regulatory obligations, in accordance with Article 10 UK GDPR and the applicable condition in Schedule 1 to the Data Protection Act 2018, and we do not maintain a comprehensive register of criminal convictions otherwise than as permitted by law.
19. CONTACT DETAILS
19.1 If you have any questions about this Privacy Policy, or wish to exercise any of the rights described in paragraph 10, please contact us at: [email protected].
19.2 If you are not satisfied with our response, you have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO) at ico.org.uk or by telephone on 0303 123 1113, or, where the EU GDPR applies to you, with your local supervisory authority.
Still have questions?
Request access and our team will walk you through membership, verification and getting set up.
