Privacy Policy
Introduction
This Privacy Policy explains how GC Exchange Limited, GC Exchange A/S, and GC Exchange FZE (together “GCEX”, “we”, “us” or “our”) collect, use, disclose and protect your personal information. It applies when you use our websites, including www.gc.exchange, www.globalblock.eu/ and www.globalblock.co.uk, or otherwise interact with us.
​
GCEX processes personal data in accordance with the UK General Data Protection Regulation, the EU General Data Protection Regulation and applicable local data protection laws.
GCEX operates under the trading name “GCEX”, which includes associated brands such as GlobalBlock. Following GCEX’s acquisition of GlobalBlock, all services previously provided under that name are now operated and managed by GC Exchange A/S.
The entity responsible for processing your personal data depends on your location and the services you use.
​
Regulatory Information
GC Exchange Limited is incorporated in England and Wales (No. 11382809) and authorised and regulated by the UK Financial Conduct Authority (FRN 828730).
GC Exchange A/S is incorporated and registered in Denmark (CVR 43088777) and authorised by the Danish Financial Supervisory Authority (FTID 45020) as a Currency Exchange and registered as a Virtual Asset Service Provider (FTID 17524) under the Danish Act on the Prevention of Money Laundering and Financing of Terrorism.
GC Exchange FZE is incorporated under the Dubai World Trade Centre Authority (Licence No. 1896) and holds a Virtual Asset Service Provider Licence issued by the Dubai Virtual Assets Regulatory Authority (VARA).
​
What Personal Information We Collect
We may collect personal information from you in the following ways:
-
Information you provide to us: such as your name, contact details, identification documents, financial information, and any other data you provide when applying for or using our services.
-
Information collected automatically: such as your IP address, browser type, device identifiers, and usage data when you visit our websites.
-
Information from third parties: including identity verification providers, credit reference agencies, banks, and publicly available sources.
​
How We Use Your Information
We process your personal information for the following purposes and lawful bases:
-
Client onboarding and service delivery: to verify identity, assess suitability, open accounts, and provide our products and services (performance of a contract; legal obligation; legitimate interest).
-
Regulatory compliance: to meet our obligations under applicable laws, including anti-money laundering, counter-terrorist financing, sanctions screening and financial reporting (legal obligation; substantial public interest).
-
Business administration and improvement: to manage systems, maintain accurate records, improve our services, and test new products (legitimate interest; performance of a contract).
-
Financial crime prevention: to detect, investigate and prevent fraud and other unlawful activity (legal obligation; legitimate interest).
-
Marketing and communications: to inform you about our services where legally permitted (consent or legitimate interest, as applicable).
​
Who We Share Your Information With
We may share your personal information with:
-
Other GCEX Group entities for internal administration and service delivery.
-
Regulatory authorities, law enforcement agencies, and supervisory bodies when required by law.
-
Third-party service providers such as payment institutions, IT infrastructure providers, and data verification partners.
-
Professional advisers, auditors, and legal representatives assisting us in our operations.
We ensure that any third parties processing your information do so securely and in accordance with applicable data protection laws.
International Transfers
Your personal information may be transferred to and processed in other jurisdictions where GCEX or its service providers operate. Where such transfers occur, we ensure appropriate safeguards are in place in line with applicable data protection legislation, such as standard contractual clauses or equivalent mechanisms.
How We Protect Your Information
We use technical and organisational measures to safeguard your personal information, including:
-
Secure servers and encrypted transmission channels.
-
Access controls and authentication systems to prevent unauthorised access.
-
Regular audits and reviews of data protection practices.
-
Confidentiality obligations for all staff and contractors handling personal data.
Data Retention
We retain personal information for as long as necessary to fulfil the purposes outlined in this Privacy Policy, or as required by law, regulation, or internal compliance requirements. When no longer required, data is securely deleted or anonymised.
​
Your Rights
Subject to applicable law, you have the right to:
-
Access your personal information and receive a copy of it.
-
Request correction of inaccurate or incomplete information.
-
Request deletion of your personal information where legally permissible.
-
Object to or restrict the processing of your data.
-
Withdraw consent at any time, where processing is based on consent.
-
Request data portability in certain circumstances.
-
Lodge a complaint with a supervisory authority if you believe your data is not being handled lawfully.
For UK clients, you may contact the Information Commissioner’s Office (ICO) at www.ico.org.uk.
For EEA clients, you may contact the Danish Data Protection Agency (Datatilsynet) at www.datatilsynet.dk.
For UAE clients, you may contact the Virtual Assets Regulatory Authority (VARA) or the relevant local data protection authority.
Automated Decisions
In some cases, we may use automated systems to assess applications or detect suspicious activity. You have the right to request a human review of any decision made solely by automated means that significantly affects you.
Cookies and Similar Technologies
We use cookies and similar technologies to operate our websites and improve user experience. For more information, please see our Cookie Policy.
​
Policy Updates
We may update this Privacy Policy from time to time to reflect legal, technical, or operational changes. Any updates will be published on our websites, and material changes will be notified to you directly where appropriate.
​
Contact Us
If you have any questions or wish to exercise your data protection rights, you can contact us at:
Email: compliance@gc.exchange
Address: GC Exchange A/S, Amager Strandvej 390, 2770 Kastrup, Denmark
