Powered by Global Enterprise Financial
Global Enterprise Financial

Privacy Policy

Effective 21 August 2026 (version 1.0, last updated 21 August 2026). Global Enterprise Financial, Inc. ("GEF", "we", "us" or "our") respects your privacy and is committed to protecting personal information. This Privacy Policy explains how GEF collects, holds, uses, discloses and protects personal information when you visit our websites, use GEF One, submit an application, communicate with us or use services made available through GEF One. GEF One is the customer platform brand of Global Enterprise Financial, Inc., a Delaware corporation. Where a financial product or service is provided by a third-party Licensed Partner, that provider may also collect and process your personal information under its own privacy policy and legal obligations.

Our role

GEF operates a technology and financial-services access platform. Depending on the product and jurisdiction, GEF may provide technology infrastructure, customer onboarding, identity verification, product and provider matching, account administration, customer support, compliance screening, platform analytics, integration services and other platform-related services. GEF's role in relation to personal information depends on the service: GEF may be responsible for personal information it collects and processes to operate GEF One and provide services directly provided by GEF. A Licensed Partner may separately provide the underlying banking, payment, card, investment, digital-asset or other regulated service and may act as an independent controller or responsible entity for information it independently processes in connection with that regulated product, under applicable law.

Responsible Entity

Global Enterprise Financial, Inc. is a Delaware corporation and operates the GEF One platform. For GEF services, GEF may be responsible for personal information it collects and processes to operate GEF One and provide GEF services. For a regulated service independently provided by a Licensed Partner, the applicable provider may separately determine the purposes and means of processing personal information and may therefore act as an independent controller, responsible entity or equivalent under applicable law, and the applicable provider's privacy policy will apply to its processing of personal information for its regulated services.

Personal information we collect

What we collect depends on how you interact with GEF and which services you apply for. Identity information can include your full legal name, date of birth, nationality or citizenship where required, residential address, tax residency, government-issued identification, identification document numbers where legally permitted, photographs, identity-document images, liveness or verification information, and other information reasonably required to establish identity. Tax information may include tax residency, tax identification numbers and information required for applicable tax reporting or financial-account reporting obligations. Contact information can include your email address, telephone number, postal address and other contact details. Account information can include account identifiers, usernames, authentication information, account preferences, product selections, account status and service history. For business and institutional customers we may also collect the legal entity name, registration information, registered address, business activities, directors, shareholders, beneficial owners, authorised representatives, control persons, ownership structures, corporate documents, source-of-funds and source-of-wealth information, and expected transaction activity. Depending on the product, we may collect financial and transaction information such as transaction information, account balances, payment information, banking information, transaction history, foreign-exchange activity, digital-asset transaction information, wallet addresses, source-of-funds information and other information required for compliance or service delivery, including information concerning the origin and purpose of transactions where required for compliance, risk assessment or service delivery. We also collect compliance information used for identity verification, AML/CTF checks, sanctions screening, politically exposed person screening, adverse-media screening, fraud prevention, risk assessment, source-of-funds and source-of-wealth checks, and regulatory reporting; technical information such as IP address, browser type, device type, operating system, approximate location derived from technical information, login information, timestamps, security events, device identifiers, platform activity and diagnostic information; and information contained in communications with GEF, including emails, support requests, application information and other correspondence.

Sensitive Information

Depending on the service and applicable law, GEF may collect or process information that is considered sensitive information or otherwise receives heightened legal protection. This may include information required for identity verification, compliance, sanctions screening, fraud prevention or regulatory purposes. GEF will only collect, use or disclose such information where permitted or required by applicable law and for legitimate purposes associated with providing services, complying with legal obligations, managing risk or protecting customers and the platform.

How we collect information

We may collect personal information directly from you, when you create an account, when you submit an application, when you complete identity verification, when you use GEF One, and through cookies and similar technologies. We may also collect it from Licensed Partners, Service Providers (including identity-verification, compliance, screening and fraud-prevention providers), publicly available sources, business registries, government or regulatory sources where legally permitted, and other third parties where lawful and necessary.

How We Hold Personal Information

GEF may hold personal information in electronic systems operated by GEF or by Service Providers acting on GEF's behalf. Information may be stored in cloud-based infrastructure, databases, customer-management systems, compliance systems, document-management systems and other systems reasonably required to operate GEF One and provide our services. Access to personal information is restricted according to operational, security, legal and compliance requirements.

Why we collect and use personal information

We may collect, hold, use and disclose personal information to provide services -- creating and administering accounts, connecting customers with appropriate Licensed Partners, providing platform functionality, facilitating transactions, providing customer support, managing applications and communicating with customers; to verify identity and eligibility -- verifying identity, verifying businesses, identifying beneficial owners, assessing eligibility, preventing impersonation, detecting fraud and meeting partner requirements; for financial crime and compliance purposes -- AML/CFT and financial-crime purposes including KYC, KYB, sanctions screening, PEP screening, adverse-media screening, source-of-funds and source-of-wealth checks, fraud prevention, transaction monitoring, blockchain monitoring, suspicious-activity investigation and regulatory reporting, and cooperating with regulators and law enforcement; for security -- protecting accounts, detecting unauthorised access, investigating security incidents, preventing cyberattacks, maintaining platform integrity and protecting customers and providers; and to improve GEF One -- analysing platform usage, improving functionality, troubleshooting problems, conducting service analytics, developing products and features, and improving customer experience. Where permitted by law, we may send service communications and, where appropriate, marketing communications -- you may opt out of marketing communications at any time, and opting out does not prevent us from sending essential service, security, compliance or account communications.

Legal bases and permitted grounds

Depending on the jurisdiction, we may process personal information where necessary to provide a requested service, necessary to perform a contract, necessary to comply with a legal obligation, necessary for fraud prevention or security, necessary for legitimate business purposes where permitted, required for regulatory or financial-crime compliance, where you have provided consent, or where another lawful basis applies. Where consent is relied upon, you may withdraw consent subject to legal and contractual limitations; withdrawal does not affect processing that was lawful before consent was withdrawn or processing that may continue under another lawful basis.

Financial crime and regulatory processing

GEF operates risk-based verification and monitoring processes. This may involve automated and manual processing of information to identify fraud, sanctions exposure, suspicious transactions, unusual account behaviour, identity inconsistencies, financial-crime risks and other regulatory risks, and may include information relating to regulatory investigations, compliance decisions, account restrictions and other information necessary to meet legal and regulatory obligations. A Licensed Partner may independently conduct additional compliance processing.

Automated decision-making

GEF may use automated systems, rules, algorithms or other technology to assist with identity verification, fraud detection, sanctions screening, risk assessment, transaction monitoring, account security, eligibility assessment and product or provider matching. Automated processing may identify activity requiring additional verification, delay or restrict a transaction, require additional information, or refer an application or activity for human review. GEF will not represent that an automated result is necessarily final where applicable law provides a right to human review, explanation, challenge or other remedy, and where applicable law provides specific rights concerning automated decision-making, GEF will comply with those requirements. GEF does not rely solely on automated processing where applicable law requires human review or provides a right to challenge a significant automated decision. Where automated processing is subject to additional transparency or review requirements under applicable privacy law, GEF will provide the information and rights required by that law.

Who we may share information with

We may disclose personal information to Licensed Partners, including banks and financial institutions, payment providers, card programmes and issuers, digital-asset service providers, and investment and securities providers; to Service Providers, including identity-verification, KYC/AML, sanctions-screening, fraud-prevention, blockchain-analytics, technology, cloud and cybersecurity providers; to professional advisers, auditors, insurers and legal advisers; to regulators, government authorities, law-enforcement agencies, courts and tribunals; and to other providers where reasonably necessary and lawful. Information is shared only where reasonably necessary for the relevant service, business purpose, legal obligation or other lawful purpose -- for example, identity-verification providers may receive identity information to verify a customer, banking or payment providers may receive information required to open or operate an account, card providers may receive information required to issue and administer cards, and blockchain analytics providers may receive wallet or transaction information for compliance and risk-management purposes. GEF does not sell personal information to third parties for their own independent marketing purposes.

Licensed Partners

Where you apply for or use a product provided by a Licensed Partner, we may need to disclose information to that provider. The provider may independently collect and process additional information under its own privacy policy, and you may be required to accept the provider's privacy policy and terms before the relevant product becomes available. Where the Licensed Partner independently determines the purposes and means of processing personal information for its regulated service, that provider may act as an independent controller or responsible entity, and the provider's own privacy policy will govern its processing of personal information to the extent applicable. Where a Licensed Partner independently processes personal information for its own regulated financial service, that provider's privacy policy and applicable legal obligations will govern its independent processing. GEF's responsibility for personal information does not automatically extend to processing independently carried out by the Licensed Partner, except to the extent required by applicable law.

Payment processing

Where you subscribe to a paid GEF One platform plan or purchase an optional platform add-on, GEF uses Stripe, Inc. as an independent third-party payment processor to process the applicable subscription payment. Stripe collects and processes payment card information, billing details and related transaction data under Stripe's own privacy policy and terms, and GEF does not itself store full payment card numbers. Subscription payment processing is separate from, and does not itself involve, custody or control of a customer's self-custodial cryptocurrency wallet or digital assets.

International transfers

GEF may disclose personal information to overseas recipients where reasonably necessary to provide services, operate GEF One, conduct identity verification, perform compliance screening, provide technology infrastructure, prevent fraud, provide customer support or meet legal and regulatory obligations. The countries in which overseas recipients are located will depend on the providers used for the relevant product and service. Where it is practicable and required by applicable law to identify those countries, GEF will identify them in this Privacy Policy, a jurisdiction-specific privacy notice or an up-to-date overseas-recipient schedule. GEF will take the steps required by applicable privacy law in relation to overseas disclosures.

Data security

GEF maintains administrative, technical and organisational safeguards designed to protect personal information against unauthorised access, misuse, alteration, disclosure, loss, destruction and other security threats. Security measures may include access controls, authentication, encryption where appropriate, monitoring, logging, network security, vulnerability management, staff controls, incident response procedures and third-party security controls. No electronic transmission or storage system can be guaranteed to be completely secure.

Data retention

We retain personal information only for as long as reasonably necessary for the purposes described in this Privacy Policy, including to provide services, maintain business records, comply with legal obligations, satisfy AML/CTF and financial-crime requirements, resolve disputes, investigate fraud, enforce agreements and protect legal rights. Different categories of information may have different retention periods, and information relating to regulated financial services may be retained for periods required by applicable laws, regulations or Licensed Partners. Retention periods may be longer where required by financial-crime, tax, accounting, regulatory, dispute-resolution or legal obligations, and the closure of an account does not necessarily mean that all personal information will be immediately deleted; information may continue to be retained where required for legal, regulatory, financial-crime prevention, tax, accounting, dispute-resolution, security or other lawful purposes. Where information is no longer required, it may be securely deleted, anonymised or otherwise disposed of in accordance with applicable requirements.

Access and correction

Subject to applicable law, you may request access to personal information GEF holds about you, and request correction of information that is inaccurate, incomplete or out of date. Requests should be directed to privacy@globalenterprisefinancial.com. GEF may need to verify your identity before processing an access or correction request, and certain information may be withheld where permitted or required by law, including where disclosure could prejudice legal, regulatory, security or financial-crime processes.

Your Privacy Rights

Depending on your jurisdiction and applicable law, you may have rights to access personal information held about you, request correction of inaccurate or incomplete information, request deletion or erasure in certain circumstances, request restriction of processing, object to certain processing, withdraw consent where processing is based on consent, request portability of certain information, opt out of direct marketing, and exercise rights relating to automated decision-making where applicable. These rights are subject to applicable legal, regulatory, security, financial-crime prevention and record-retention requirements.

Privacy complaints

If you believe GEF has mishandled your personal information, you may lodge a complaint with our Privacy Team at privacy@globalenterprisefinancial.com, providing sufficient information for us to identify the relevant account or issue and investigate the complaint. GEF will acknowledge and investigate privacy complaints in accordance with applicable law and will provide a response within the period required by applicable law or, where no specific period applies, within a reasonable period. Where your complaint concerns personal information processed independently by a Licensed Partner, you may also need to contact that provider through its own privacy or complaints process. Where applicable, you may also have the right to complain to the privacy regulator or other relevant authority in your jurisdiction; for Australian privacy matters, this may include the Office of the Australian Information Commissioner (OAIC).

Cookies and similar technologies

GEF may use cookies and similar technologies for essential website functions, security, authentication, remembering preferences, analytics, performance monitoring and other permitted purposes. Non-essential cookies will be managed in accordance with applicable consent requirements and the GEF Cookie Policy.

Children's privacy

GEF One is not intended for persons below the minimum age applicable to the relevant service. We do not knowingly collect personal information from children where prohibited by applicable law. Where we become aware that personal information has been collected from a person who is not eligible to use the service, we may take reasonable steps to delete or restrict that information.

Third-party websites

GEF One may contain links to third-party websites, applications or services. GEF is not responsible for the privacy practices of those third parties -- you should review the privacy policy of the relevant provider before providing personal information.

Marketing

Where permitted by law, GEF may send information about products, services, updates and opportunities that may be relevant to you. You may unsubscribe from marketing communications at any time; service, security, compliance and account communications may still be sent where necessary.

Data quality

GEF takes reasonable steps to ensure personal information is accurate, complete and current where required. You should notify us of material changes to your personal information.

Data breaches

GEF maintains procedures for identifying, assessing and responding to data-security incidents. Where a data breach occurs that triggers notification requirements under applicable law, GEF will make the required notifications to affected individuals, regulators or other relevant parties.

Changes to this Privacy Policy

We may update this Privacy Policy from time to time. The latest version will be published on the GEF website with an updated effective date, and where required by law, material changes will be communicated to affected individuals.

Jurisdiction-specific privacy notices

Privacy rights and obligations vary between jurisdictions. Where required, GEF may provide additional jurisdiction-specific privacy notices describing the rights, obligations, regulators, complaint mechanisms, international transfer requirements and other protections applicable to customers in that jurisdiction, and where a jurisdiction-specific notice conflicts with this Privacy Policy, the jurisdiction-specific notice will apply to the extent required by applicable law.

Contact details

For privacy enquiries: privacy@globalenterprisefinancial.com. For onboarding and identity verification: onboarding@globalenterprisefinancial.com. For compliance enquiries: compliance@globalenterprisefinancial.com. For complaints: complaints@globalenterprisefinancial.com. For business and institutional matters: admin@globalenterprisefinancial.com.

Company

Global Enterprise Financial, Inc. is a Delaware corporation. GEF One is the customer platform brand of Global Enterprise Financial, Inc. © 2026 Global Enterprise Financial, Inc. All rights reserved.

GEF One is a technology and financial-services access platform operated by Global Enterprise Financial, Inc. GEF is not itself a bank or other regulated financial-services provider unless expressly stated for a specific service and jurisdiction. Regulated banking, payment, card, investment and digital-asset services are provided by the applicable Licensed Partner or authorised provider. Availability depends on provider coverage, customer eligibility and jurisdiction.
Privacy Policy | GEF One