Platform Solutions How it works Security Pricing Company Sign in Request access

Legal · Privacy

Privacy Policy

How Dealium collects, uses, shares, and protects personal data — the lawful bases we rely on, the processors we work with, how long we keep information, and the rights you can exercise at any time.

Status: Draft template · Last updated 11 July 2026 · Effective date to be set on publication · Jump to contact

DEALIUMAI LIMITED (Hong Kong company no. 80235730). Last updated 11 July 2026. Questions: hello@dealiumai.eu. This is a working draft. The data-controller entity, registered address, VAT number, Data Protection Officer details, exact retention periods, and the definitive sub-processor list are placeholders and must be completed and verified by qualified legal counsel before this policy is relied upon or published.

Dealium provides a software platform — the transaction control layer for B2B commodity trade. This policy explains how we handle personal data when you visit our website, request access, or use the Dealium application. It is written to meet the requirements of the EU General Data Protection Regulation (Regulation (EU) 2016/679, the "GDPR") and, where applicable, the UK GDPR.

A note on money. Dealium is a software provider. It is non-custodial: it never holds, transmits, or converts your funds. Payments are executed by licensed third-party providers on a user-approved instruction. Where those providers process your personal data to move money, they act as independent controllers under their own privacy notices; this policy covers the data Dealium processes.

1. Who we are (data controller)

The controller responsible for your personal data is:

  • Legal entity: DEALIUMAI LIMITED (a company incorporated in Hong Kong)
  • Registered address: Unit 2904-05, 29/F, Universal Trade Centre, No. 3 Arbuthnot Road, Central, Hong Kong — operating from the EU (Barcelona, Spain)
  • Company / VAT registration: Hong Kong company no. 80235730 (Hong Kong does not levy VAT)
  • Data Protection Officer: Not appointed; privacy queries go to the contact below
  • Privacy contact: hello@dealiumai.eu

Where Dealium processes personal data on behalf of a customer organisation using the platform (for example, data one counterparty enters about another), we act as a processor for that customer and process such data under our customer agreement and data-processing terms.

2. Scope of this policy

This policy applies to personal data we process about: visitors to dealiumai.eu; people who request access, apply to the Design Partner Program, or contact us; and authorised users of the Dealium application and the organisations they represent. It does not cover third-party websites we link to, or the independent processing carried out by the licensed payment, verification, and logistics providers described in section 5.

3. Personal data we collect

We collect only what we need to operate the platform, verify counterparties, and keep a trustworthy record of a deal. Categories include:

  • Account & identity data — name, work email, phone, role, and the organisation you represent; authentication data managed through our identity provider (we use a backend-for-frontend model, so your browser never holds the access token).
  • Verification data (KYB / KYC / AML) — business-registry details, ultimate-beneficial-owner (UBO) information, identity-document images, liveness and face-match checks, and sanctions/PEP screening results. Most of this is collected and checked through specialist processors (see section 5); we receive and store the verification outcome, risk rating, and supporting records needed to evidence compliance.
  • Deal & transaction data — term sheets and their versions, counterparties, quantities, prices, Incoterms, ports, quality specifications, documents you upload, shipment and quality milestones, invoices, ledger entries, and dispute records. This may include personal data about your colleagues and counterparties.
  • Communications — messages, notifications, and support requests you send us or exchange in the platform, and records of our correspondence.
  • Usage & technical data — log data, device and browser information, IP address, approximate location derived from IP, and product-interaction events used for security, diagnostics, and improving the service.
  • Cookies & similar technologies — as described in section 11.

We do not seek to collect special-category data. Identity-document and biometric checks used for KYC are carried out by our verification processors to meet legal anti-money-laundering obligations; we retain the outcome and audit record rather than raw biometric templates.

4. How we use data & lawful bases (GDPR Art. 6)

We only process personal data where the GDPR gives us a lawful basis. The table below maps each purpose to its basis. Exact retention periods are set out in section 7.

PurposeLawful basis (Art. 6)
Provide the platform, run a deal, and give you access to your accountContract (Art. 6(1)(b)) — performance of our terms of service
Verify counterparties (KYB/KYC/UBO) and screen for sanctions/PEP exposureLegal obligation (Art. 6(1)(c)) and legitimate interests (Art. 6(1)(f)) in preventing fraud and financial crime
Keep records for anti-money-laundering, accounting, and auditLegal obligation (Art. 6(1)(c))
Secure the service, prevent abuse, and maintain an audit trailLegitimate interests (Art. 6(1)(f)) in the security and integrity of the platform
Diagnose problems, and improve and develop the serviceLegitimate interests (Art. 6(1)(f)) — balanced against your rights
Respond to enquiries, run the Design Partner Program, and send service communicationsLegitimate interests (Art. 6(1)(f)) and/or consent (Art. 6(1)(a)) where required
Send optional marketing about DealiumConsent (Art. 6(1)(a)) — withdrawable at any time
Establish, exercise, or defend legal claims, and resolve disputesLegitimate interests (Art. 6(1)(f)) and/or legal obligation (Art. 6(1)(c))

Where we rely on legitimate interests, we carry out a balancing assessment and you have the right to object (see section 8). Where we rely on consent, you can withdraw it at any time without affecting processing that already took place.

5. Processors and sub-processors

We use a small number of carefully selected service providers ("processors") to run the platform. Each is bound by a data-processing agreement, may only process personal data on our instructions, and must apply appropriate security measures. The categories below are representative; the definitive, up-to-date sub-processor list will be maintained separately and is to be finalised by counsel before publication.

Provider / categoryPurposeLocation
Identity verification (KYC) — e.g. SumsubIdentity-document, liveness, and face-match checksEEA where available
Sanctions & PEP screening — e.g. OpenSanctionsScreening counterparties and individualsEEA / under SCCs
Business registry (KYB) — e.g. OpenCorporatesCompany verification and UBO discoveryEEA / under SCCs
Licensed payment providers — WorldFirst, Airwallex, BridgeExecuting deposits and releases (they act as independent controllers for the payment itself)Per provider (see their notices)
Cloud hosting & infrastructureHosting the application and dataEU-hosted
Identity & access (Keycloak)Authentication and single sign-onSelf-hosted, EU
AI copilot modelsRole-aware document and deal analysisSelf-hosted — no cloud LLM; your data does not leave our environment or train any third party's model

We may also disclose personal data to professional advisers, auditors, and public authorities where required by law, and to a successor entity in the context of a merger, acquisition, or reorganisation (subject to this policy). We do not sell personal data.

6. International transfers

We aim to store and process personal data within the European Economic Area (EEA). Some processors listed in section 5 may process data outside the EEA. Where that happens, we rely on an appropriate transfer mechanism — an adequacy decision of the European Commission, the Standard Contractual Clauses (SCCs), or another lawful safeguard — and, where needed, supplementary measures. You can request details of the safeguards in place using the contact in section 14.

7. How long we keep data

We keep personal data only as long as necessary for the purposes above, then delete or anonymise it. Indicative periods:

  • Account data — for the life of your account, then a limited period after closure.
  • KYB/KYC and AML records — retained for the statutory anti-money-laundering period (typically five years after the end of the business relationship under EU AMLD rules).
  • Deal, invoice, and ledger records — retained for the period required by applicable accounting and tax law.
  • Audit and dispute records — retained on an append-only basis for the integrity of the record and to defend legal claims.
  • Usage and log data — retained for a limited period for security and diagnostics.

Where a statutory retention obligation applies (for example, AML record-keeping), that obligation can override a request to erase the affected records — see section 8.

8. Your rights (incl. Article-17 erasure)

Subject to the conditions in the GDPR, you have the right to:

  • Access the personal data we hold about you (Art. 15).
  • Rectify inaccurate or incomplete data (Art. 16).
  • Erasure — request deletion of your data, the "right to be forgotten" (Art. 17). We have built erasure into the platform. Note that we may need to keep certain records where a legal obligation (such as AML record-keeping) or the establishment or defence of legal claims requires it; in that case we will restrict, rather than delete, the affected data.
  • Restrict processing in certain circumstances (Art. 18).
  • Data portability — receive data you provided in a structured, commonly used, machine-readable format (Art. 20).
  • Object to processing based on legitimate interests, and to direct marketing at any time (Art. 21).
  • Withdraw consent at any time where we rely on consent (Art. 7).
  • Not be subject to solely automated decisions that produce legal or similarly significant effects — see section 9 (Art. 22).
  • Lodge a complaint with a supervisory authority (see section 14).

To exercise any right, contact us using section 14. We will respond within the timeframes required by law (generally one month) and will not charge a fee unless a request is manifestly unfounded or excessive. We may ask you to verify your identity first.

9. Automated processing and AI

Dealium uses a deterministic, explainable risk engine to screen counterparties and a role-aware AI copilot to check documents and flag issues. These tools are designed to assist, not replace, human judgement — the AI checks and flags; people decide. We do not make decisions producing legal or similarly significant effects about you based solely on automated processing without a lawful basis and appropriate safeguards, including the ability to request human review. Our AI models are self-hosted: your pricing, documents, and counterparties are not sent to any public model, and every AI action is schema-validated and audit-logged.

10. How we protect your data

We apply appropriate technical and organisational measures to protect personal data, including: authentication via Keycloak OIDC with PKCE behind a backend-for-frontend, so the browser never holds an access token; a three-axis, role-based access-control model; an append-only audit trail of every state, document, and decision; encryption in transit; and least-privilege access for our team. We have passed an internal OWASP Top-10 / ASVS adversarial audit with regression tests, and an independent penetration test is planned before the platform handles live funds. No system is perfectly secure, but we work continuously to protect your information and will notify you and the relevant authority of a personal-data breach where the law requires.

11. Cookies and similar technologies

We use strictly necessary cookies to run the site and keep you signed in, and — only with your consent — optional analytics or preference cookies. You can decline non-essential cookies without losing access to core functionality. For details of the specific cookies we use and how to manage them, see our Cookies notice. (The cookies notice is being finalised alongside this policy.)

12. Children

Dealium is a business-to-business service and is not directed to children. We do not knowingly collect personal data from anyone under 18. If you believe a child has provided us with personal data, contact us and we will delete it.

13. Changes to this policy

We may update this policy to reflect changes in our practices, technology, or legal requirements. We will post the updated version here with a revised "last updated" date and, where changes are material, provide additional notice. Please review it periodically.

14. Contact and complaints

For any privacy question, to exercise a right, or to reach our Data Protection Officer, contact:

  • Email: hello@dealiumai.eu
  • Data controller: DEALIUMAI LIMITED, Unit 2904-05, 29/F, Universal Trade Centre, No. 3 Arbuthnot Road, Central, Hong Kong (operating from the EU — Barcelona, Spain)
  • Data Protection Officer: Not appointed; contact hello@dealiumai.eu

If you are in the EEA and believe we have not handled your data lawfully, you have the right to complain to your local data-protection supervisory authority. Given our operations in Spain, that authority is likely the Agencia Española de Protección de Datos (AEPD). We would, however, appreciate the chance to address your concern first.

Dealium is a software provider and is not a bank, payment institution, or escrow agent; it never holds client funds. This document is a draft template and does not constitute legal advice.

Dealium AI copilotAdvisory · self-hosted

A role-aware copilot inside every deal — it reviews term sheets and documents, flags risks and missing steps, and suggests the next action. AI flags, you decide. Self-hosted models; your data never leaves the tenant.

What’s my next action? Any red flags in these terms? Is the counterparty verified?

Illustrative — the copilot runs inside the Dealium app.