Draft — under legal review
Privacy Policy
Last updated 19 September 2026
How ELX collects, uses and protects the personal data of the people who act for companies on the marketplace — and what you can ask of us.
1.Who we are
European Longevity Exchange (ELX) (Zurich, Switzerland) runs the ELX marketplace and is the controller of the personal data described here. For anything about your data, write to contact@elx.com.
ELX is a business-to-business marketplace. Our customers are companies; the personal data we handle is that of the people who act for them — owners, directors, employees and representatives.
2.What we collect
| Category | What | Where it comes from |
|---|---|---|
| Account | Email address, password (stored only as a one-way hash), the companies you act for and your role in them. | You, at registration |
| Company | Legal name, country, registration number, VAT number, addresses, bank details for payouts. | You |
| Verification | Register extract or certificate of incorporation, power of attorney or board resolution, your identity card or passport. | You |
| Trading | Products and lots you list, purchases, negotiated terms, delivery details, shipments, disputes, messages and the history of who did what and when. | You and the companies you trade with |
| Payments | Payment reports, proofs of payment you upload, invoices. Card and bank-transfer details entered with Stripe are handled by Stripe; we do not see or store card numbers. | You, Stripe |
| Usage | Pages visited, device and browser type, an anonymous session identifier. | Your browser |
3.Why we use it, and on what legal basis
| Purpose | Legal basis (GDPR art. 6) |
|---|---|
| Running your account and the marketplace: listings, purchases, deliveries, samples, notifications. | Performance of our contract with your company |
| Verifying companies and the people who act for them; sanctions screening; keeping records. | Legal obligation (anti-money-laundering, sanctions) and legitimate interest in a trustworthy marketplace |
| Issuing commission invoices and keeping accounting records. | Legal obligation (tax and accounting law) |
| Resolving disputes, preventing fraud and misuse, securing the platform. | Legitimate interest |
| Understanding how the platform is used, to improve it. | Legitimate interest — first-party, without advertising or cross-site tracking |
| Alerts about lots matching your interests. | Your choice — you can switch alerts off at any time |
4.Identity documents used for verification
Before a company can trade on ELX, we verify that it exists, that the person using the account may act for it, and that this person is who they say they are. For the last check we ask for an identity card or passport.
- Why: to confirm the identity of the person acting for a company, as anti-money-laundering and know-your-customer rules require, and to protect other companies from impersonation.
- Who sees it: only ELX staff who review verifications. It is never shown to other users. It is kept in private, access-controlled storage and opened only through short-lived links issued to a reviewer.
- How long: as long as your company uses ELX, then five years after the business relationship ends — the period anti-money-laundering law requires. After that it is deleted.
5.Sanctions screening
Company names are compared automatically with the European Union’s consolidated sanctions list — at registration, before each payment and whenever the list is updated. A possible match never leads to a decision on its own: it holds the account or the transaction until a person at ELX has reviewed it.
7.International transfers
Some providers, such as Stripe, may process data outside the European Economic Area and Switzerland. Where they do, the transfer is covered by an adequacy decision or by the European Commission’s standard contractual clauses.
8.How long we keep it
| Data | Kept for |
|---|---|
| Account and company data | While the account is active, then as long as the records below require |
| Verification documents, including identity documents | Five years after the business relationship ends |
| Transactions, invoices and payment records | As long as tax and accounting law requires — up to ten years |
| Usage data | Up to 24 months |
9.Security
Access to personal data is limited to the people who need it. Passwords are stored only as one-way hashes; files are kept in private storage and opened through short-lived signed links; issued invoices cannot be altered.
10.Your rights
You can ask to access, correct, delete or restrict your data, to receive it in a portable format, and to object to how we use it. How to do that, and what we have to keep regardless, is explained on the GDPR & your data page.
11.Changes to this policy
When we change this policy in a way that matters, we tell account holders by email before the change applies.