Aller au contenu

Privacy Policy

Mis à jour le 5 août 2026

Ce document n’est pour l’instant disponible qu’en EN. Cette version fait foi ; une traduction sera publiée après relecture.

This policy explains what personal data UEX collects when you use this trading platform, why we hold it, how long we keep it and what you can ask us to do with it. It covers the trading platform and its operator console; the separate UEX App account service has its own notice, and the two are described together below where data moves between them.

Who is responsible for your data

The operator of this platform is the controller of the data described here. Contact routes are listed under "How to reach us" at the end of this document. Identity verification (KYC) is carried out by the UEX App account service, which acts as controller for the identity documents themselves; this platform receives only the verification outcome and the account identifiers it needs to let you trade.

What we collect

  • Account identifiers: your account id, email address, display name, account role and verification tier. Your account is mirrored from the UEX App service, which is where it is created.
  • Trading records: every order you place, every trade it produces, the balances behind them and the ledger entries that move them. These are the record of your activity on the platform and cannot be deleted while they are needed for accounting and regulatory purposes.
  • Transfer records: movements between your UEX App balance and your trading balance, including amounts, assets, timestamps and the reference that links the two sides.
  • Technical data: IP address, browser user agent, session cookies, request identifiers and timestamps of the requests you make. Operator actions and security-relevant events are written to an audit journal.
  • Security data: API key identifiers and their permissions, device fingerprints for operator sessions, two-factor enrolment state. API secrets are stored encrypted and are never displayed again after they are issued.
  • Support content: tickets you file, the messages in them, the files you attach, the contact address a reply is owed to and the language you filed in. Product feedback is stored the same way.
  • Preferences: interface language, theme, accessibility settings, watchlists and layout choices. Most of these are held in your browser rather than on our servers.

We do not collect payment card data on this platform, and we do not ask for identity documents here.

Why we hold it

  • To perform the service you asked for: matching your orders, keeping your balances correct, showing you your history, answering your support tickets.
  • To meet legal and regulatory obligations: anti-money-laundering rules, record-keeping duties, and lawful requests from competent authorities.
  • To keep the platform and your account safe: detecting abuse, market manipulation, unauthorised access and automated attacks; rate-limiting; investigating incidents.
  • To operate and improve the product: diagnosing errors, understanding which features are used, and acting on the feedback you send us.

Where a legal basis is required, we rely on the performance of our contract with you for the first purpose, on legal obligation for the second, on our legitimate interest in a safe and functioning market for the third, and on your consent where we ask for it explicitly.

How long we keep it

  • Audit and compliance journal: five years, in monthly partitions. This is a regulatory retention period, not a preference.
  • Orders, trades, balances and ledger entries: for as long as your account exists and for the retention period that applies to financial records afterwards. Trade data is also projected into an analytics store with a three-year lifetime.
  • Support tickets and their attachments: while the case is open and afterwards for as long as needed to handle a follow-up or a dispute.
  • Technical logs: short-lived, measured in days to weeks, except where an entry has been retained because it belongs to a security investigation.
  • Backups: encrypted, on a rolling schedule. Data deleted from the live system disappears from backups as those backups age out.

Who else sees it

  • The UEX App account service, which holds your account and your verification status; balances and transfers are reconciled between the two.
  • Infrastructure providers who host the platform, store uploaded files, deliver our email and receive error reports. They act on our instructions and only for those purposes.
  • Competent authorities, where we are legally required to respond, and where we are permitted to disclose in order to prevent or investigate a crime.
  • Nobody else. We do not sell personal data and we do not share it for third-party advertising.

Market data we publish — the order book, the trade tape, tickers and charts — is anonymous. It shows prices and quantities, not who traded. Public surfaces such as leaderboards, chat and competitions show only the identity you chose to display there.

Where your data is processed

The platform runs on infrastructure that may be located outside your country. Where data is transferred internationally, we rely on the safeguards required by the applicable data-protection law for that transfer.

Cookies and local storage

We use a session cookie to keep you signed in, a separate cookie for the operator console, and short-lived cookies for security purposes such as request forgery protection and recognising a device you have already confirmed. Your interface preferences (language, theme, accessibility settings, layout, watchlists) are stored in your browser. We do not use advertising cookies.

Your rights

Depending on where you live, you can ask us to give you a copy of your data, correct it, delete it, restrict or object to how we use it, or send it to another provider. Two limits are worth stating plainly rather than in a footnote:

  • Trading and audit records cannot be deleted on request while the retention periods above apply. This is the same rule that lets us prove what happened to your money if you ever dispute it.
  • Identity documents are held by the UEX App account service, so a request about them is directed there.

You can also complain to your data-protection supervisory authority. We would rather you told us first, and we answer requests within the period the applicable law sets.

How we protect it

Access to production data is restricted and logged. Operator accounts require a second factor, and actions that move money require a further confirmation code; sensitive operator actions require a second administrator's approval. API secrets are encrypted with a rotating key-encryption key. Transport is encrypted. None of this makes a breach impossible, and if one occurs that affects you we will tell you and the relevant authority as the law requires.

Automated processing

Risk and abuse controls evaluate your trading activity automatically and can block an order, flag an account for review or freeze trading on it. These decisions are reviewable by a human operator, and you can ask for that review through a support ticket.

Children

The platform is not for people under 18, and we do not knowingly hold their data.

Changes to this policy

We update this document when the platform changes. The date it was last edited is shown on this page. Material changes are announced in the product before they take effect.

How to reach us

Open a support ticket at /support — it reaches an operator and keeps the exchange in one place, which matters for a request about your own data. Product suggestions go to /feedback. Availability incidents are published at /status.

Le support répond aux questions sur ce document. Les incidents de disponibilité sont publiés sur la page d’état.