Nelum

Legal

Privacy Notice

Last updated: July 2026

1. Who we are

Nelum operates a marketplace facilitation service for the precious-metals trade. We are the controller of the personal data described in this notice. We operate from the United Kingdom and the United Arab Emirates.

2. What we collect

Account and contact data: name, email address, telephone number, company, and role.

Business verification (KYB) data: company registration and incorporation documents, tax registration, proof of address, ownership and control structure, beneficial ownership details, licences, and bank confirmations.

Identity verification (KYC) data: government identity documents, a photograph of your face, and, where identity verification is performed by our provider, a liveness check.

Transaction data: listings, offers, order terms, trade documents, shipment and customs records, assay results, and wallet addresses used for settlement.

Technical data: log data, IP address, device and browser information, and usage data.

3. Identity photographs and biometric data

We collect a photograph of each representative because counterparties in this trade meet in person and need to confirm that the individual in front of them is the registered representative of the company they claim.

Where a photograph is processed by automated face-matching or liveness detection for the purpose of uniquely identifying you, that is biometric data and is treated as a special category of personal data. We process it on the basis of your explicit consent and to meet our obligations in relation to the prevention of money laundering.

Your photograph is stored privately. It is displayed on your representative credential page — which is accessible to anyone holding the link — only where you have given separate, explicit consent to that publication. You may withdraw that consent at any time, and the photograph will be removed from the credential page. Withdrawal does not affect the underlying identity record, which we are required to retain (see section 7).

4. Why we use it, and our lawful bases

To provide the platform and perform our contract with you: account, transaction, and document data.

To comply with legal obligations: anti-money-laundering and counter-terrorist-financing checks, sanctions screening, record keeping, and reporting to authorities where required.

For our legitimate interests in operating a safe marketplace: fraud prevention, security, service improvement, and support. We balance these against your rights.

With your consent: publication of your photograph on your credential page, and any non-essential cookies.

5. Who we share it with

Counterparties: on the platform your company is initially identified by a pseudonymous reference. Your company's legal name and the details of your representative become visible to a counterparty once you enter into an order together, and through your representative credential where you have consented to publish it.

Service providers, who process data on our instructions: our hosting and database provider, our identity verification provider, our document signing provider, our blockchain data provider, our email provider, and the provider of the AI model used to extract terms from documents you upload.

Authorities and professional advisers, where we are required or permitted to disclose. In some circumstances we are prohibited by law from telling you that a disclosure has been made.

We do not sell personal data.

6. International transfers

Personal data is transferred between the United Kingdom, the European Economic Area, the United Arab Emirates, and other countries where our service providers operate. Where data leaves the UK or EEA we rely on adequacy decisions where they exist, and otherwise on standard contractual clauses together with any additional safeguards required.

7. How long we keep it

Verification records, transaction records, and the documents supporting them are retained for at least five years after the end of our business relationship with you, as required by anti-money-laundering law. In some jurisdictions a longer period applies.

This retention obligation takes precedence over a request for erasure. Where you ask us to delete data that we are required to retain, we will restrict its use to meeting that legal obligation rather than deleting it, and we will tell you that we have done so.

Account and technical data not subject to that obligation is retained only as long as needed for the purpose it was collected.

8. Your rights

Subject to the retention obligations above, you have the right to access your personal data, to have inaccurate data corrected, to request erasure, to restrict or object to processing, to data portability, and to withdraw consent where processing is based on consent. Withdrawing consent does not affect processing carried out before withdrawal.

To exercise a right, contact us via our contact page. You also have the right to complain to a supervisory authority — in the United Kingdom, the Information Commissioner's Office.

9. Security

Verification documents and identity photographs are held in private storage that is not publicly accessible. Access is restricted, and access by our staff is logged. Documents you submit for business verification cannot be retrieved through the platform once submitted, including by you.

10. Cookies

We use cookies that are strictly necessary for the platform to function, including for authentication. Any analytics or marketing cookies are used only with your consent where consent is required.

11. Changes and contact

We may update this notice. Material changes will be notified through the platform. Questions, or requests relating to your rights, can be directed to us via our contact page.