Privacy policy
How Krexum handles personal data — both the data we control through this website, and the data we process on behalf of partners inside the platforms we operate for them. Those are different roles with different obligations, and this page separates them.
- Our role, this site
- Controller
- Our role, partner platforms
- Processor
- Entity
- Krexum Technologies FZCO
- Last updated
- August 2026
1. Who is responsible for your data
This policy is issued by Krexum Technologies - FZCO, Dubai Silicon Oasis, United Arab Emirates, commercial licence 77813.
There are two distinct situations, and they are governed differently.
When you visit this website or contact us about working together, Krexum is the controller of that personal data and this policy applies.
When personal data is processed inside a platform we build and operate for a partner — that partner’s customers, their traders, their applicants — the partner is the controller and Krexum acts as a processor on their documented instructions. In that case the partner’s own privacy notice governs the relationship with their customers, and our obligations are set out in the data-processing terms of our agreement with them.
2. What we collect through this website
Information you give us: your name, company, email address, and anything else you choose to include when you contact us about an engagement.
Technical information: IP address, browser and device type, pages viewed and referring source. This is standard server and delivery-network logging.
We do not run advertising trackers on this site, we do not sell personal data, and we do not build advertising profiles.
3. Why we process it
To respond to an enquiry and to scope, negotiate and perform an engagement.
To operate, secure and improve this website, including detecting and preventing abuse.
To meet legal, regulatory and record-keeping obligations that apply to us.
Where required, our basis is your consent, the performance of a contract or steps taken at your request before entering one, our legitimate interests in running and securing our business, or compliance with a legal obligation.
4. Data inside partner platforms
Each partner is deployed into a dedicated environment. There is no shared database and no shared credential path between partners, and we do not use one partner’s data to serve another.
We do not use partner or end-customer data to train models for other partners.
Access by our engineers is role-based, attributable to a named individual, logged, and limited to what is necessary to operate and support the platform.
Data residency is selected per partner to match the licence and regulator they answer to.
5. Sharing
We share personal data with service providers who help us run our business and this website — hosting, content delivery, email and analytics — under contract and only as necessary.
We share data where we are legally required to, or to establish, exercise or defend legal claims.
We do not sell personal data.
6. Retention
Website enquiry data is kept for as long as needed to deal with the enquiry and for a reasonable period afterwards for our own records.
Data processed on behalf of a partner is retained according to that partner’s instructions and the retention terms of our agreement with them, not according to this page.
7. Your rights
Depending on where you are, you may have rights to access, correct, delete, restrict or object to our processing of your personal data, and to data portability.
If your data is held inside a partner’s platform, please contact that partner — they are the controller. If they ask us to act, we will support them.
For data we control, contact [email protected].
8. Security
We apply access control, encryption in transit, monitoring and patching appropriate to the systems we operate, and we treat security patching as our responsibility rather than a ticket we raise with a partner.
No system is perfectly secure. Where an incident affects a partner, our commitment is to tell them — incident history is shared with partners rather than hidden.
9. International transfers
We operate from the United Arab Emirates and use infrastructure in multiple regions. Where personal data is transferred across borders, we use appropriate safeguards and, for partner platforms, the region agreed with that partner.
10. Changes and contact
We may update this policy. The version published here is the version in force.
Privacy questions: [email protected]. General: [email protected]. Post: Krexum Technologies - FZCO, Dubai Silicon Oasis, Dubai, United Arab Emirates.
The questions you will be asked in diligence.
- Controller or processor?
- Controller for this website and for enquiries. Processor for personal data inside a platform we operate for you, acting on your documented instructions.
- Is our data isolated?
- Dedicated environment per partner. No shared database, no shared credentials, no cross-partner access path.
- Do you train models on our data?
- No. Partner and end-customer data is not used to train models for other partners.
- Who at Krexum can see it?
- Role-based access, attributable to a named engineer, logged, and limited to operating and supporting the platform.
- Where is it stored?
- Region selected per partner to match your licence and your regulator.
- Can we get it back?
- Yes. Documented export formats, available during the relationship and on exit, so you can verify the export works before you need it.
- How are incidents handled?
- Defined response, and incident history shared with partners rather than hidden behind a status page.