Privacy information
Data Privacy Notice
Website visitors, business contacts, counterparties and other external stakeholders
Publication date: 26 August 2026 | Effective date: 26 August 2026
Download the Data Privacy Notice (PDF)1. Who We Are
FEREX GLOBAL TRADING GROUP COMPANY LIMITED, trading as Ferex Group ('Ferex', 'we', 'us' or 'our'), is the controller for the processing described in this notice unless we tell you otherwise.
- Legal name: FEREX GLOBAL TRADING GROUP COMPANY LIMITED
- Company number: 17421201
- Registered in: England and Wales
- Registered office: Office 3, Lower Ground Floor, 88 Cambridge Street, London, England, SW1V 4QG
- Website: www.ferexgroup.com
- Privacy contact: info@ferexgroup.com
If your relationship is directly with another legally established Ferex Group entity, that entity may be a separate controller and will provide any additional notice required for its processing.
2. Scope
This notice covers personal data relating to Website visitors, prospective and existing customers and suppliers, professional advisers, banking and logistics contacts, other business counterparties, applicants and people who communicate with us. Separate notices may apply to employees, directors, shareholders, formal recruitment, compliance investigations or specific transactions.
3. Personal Data We May Collect
- Identity and professional information, including name, title, employer, role, business credentials and signature.
- Business contact information, including email address, telephone number and correspondence address.
- Corporate and counterparty information supplied during enquiries, onboarding, due diligence or a commercial relationship.
- Communications and records of meetings, enquiries, instructions, feedback and correspondence.
- Compliance information where necessary and proportionate, including identification, ownership and control information, sanctions or politically exposed person screening, and screening results.
- Transaction and relationship information connected with contracts, invoices, payments, shipments, banking arrangements and the administration of our own commercial activities.
- Technical and usage information, including IP address, browser and device data, security logs, pages visited and cookie choices, to the extent actually collected.
- Information you choose to provide through a form, application, rights request, complaint or other interaction.
Special-category and criminal-offence data
We do not seek special-category or criminal-offence data through the general Website. If limited processing becomes necessary for a defined compliance purpose, legal claim or other lawful reason, we will use it only where an Article 9 or Article 10 UK GDPR condition and the relevant Data Protection Act 2018 requirements apply, with appropriate safeguards.
When information is required
We will identify information needed to answer an enquiry, take requested pre-contract steps, perform a contract or complete a legally required check. If necessary information is not provided, we may be unable to proceed. Information not needed for the interaction may be omitted.
4. How We Obtain Personal Data
We may obtain personal data directly from you; from the organisation you represent; from a legally established Ferex Group entity; from banks, advisers, logistics providers or counterparties involved in an authorised process; from public company registers, sanctions and professional sources; from compliance and screening providers; and through permitted Website technologies. Where required, we provide privacy information within the period prescribed by law.
Current Website features
The Website includes business enquiry forms and a Google Maps section to help visitors locate Ferex Group's offices. Enquiry forms transmit information securely, provide a clear link to the Data Privacy Notice, and request only the information reasonably necessary to respond to the enquiry.
5. Purposes and Legal Bases
| Purpose | Typical UK GDPR legal basis and legitimate interest |
|---|---|
| Respond to enquiries and take requested pre-contract steps | Steps requested before entering a contract where the individual may be a party; otherwise legitimate interests in responding and developing lawful business relationships. |
| Establish and manage commercial relationships and transactions | Legitimate interests in operating our business; contract only where the individual is personally a party; and legal obligations where applicable. |
| KYC, sanctions, fraud-prevention and counterparty risk checks | Legal obligations where applicable and legitimate interests in lawful, secure and responsible trading and protecting Ferex Group and third parties. |
| Manage contracts, payments, shipments, records and disputes | Legitimate interests in performing and documenting business; contract where applicable; and legal obligations. |
| Operate, secure and improve the Website and systems | Legitimate interests in secure and reliable systems; consent where required for storage and access technologies. |
| Maintain corporate, tax, accounting, regulatory and audit records | Legal obligations and legitimate interests in governance, audit and accountability. |
| Send relevant business communications | Legitimate interests in B2B communications, or consent where required, subject to direct-marketing and PECR rules and the right to object. |
| Establish, exercise or defend legal claims | Legitimate interests and applicable legal conditions, including special-category conditions where relevant. |
Where we rely on legitimate interests, we assess necessity and balance our interests against the individual's rights and reasonable expectations. Where we rely on consent, it may be withdrawn at any time without affecting earlier lawful processing.
7. International Transfers
Our international activities may require personal data to be accessed from or transferred to countries outside the United Kingdom or European Economic Area. Where UK restricted-transfer rules apply, we use a lawful mechanism such as UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to approved EU clauses, or a permitted exception. Where EU GDPR applies, an EU adequacy decision, EU Standard Contractual Clauses or another lawful mechanism may be used. Supplementary safeguards are applied where appropriate.
To request information about the mechanism used for a particular transfer or a copy of relevant safeguards, subject to lawful redactions, contact info@ferexgroup.com.
8. Retention
We keep personal data only as long as reasonably necessary for the purpose collected and for contractual, corporate, tax, accounting, sanctions, compliance, limitation, audit and dispute-resolution requirements. We determine the period by considering the record type, relationship, legal duties, limitation periods, risk and whether the information is needed for an actual or potential claim. When no longer required, data is securely deleted, anonymised or isolated from routine use.
9. Security
We use organisational and technical measures designed to protect personal data from unauthorised access, alteration, disclosure, loss or destruction. Access is limited by role and business need. Internet-based transmission carries inherent security risks. Users exercise appropriate care when sending information online.
10. Your Rights
Depending on the applicable law and circumstances, you may have rights to be informed; request access; correct inaccurate or incomplete data; request erasure; restrict processing; receive portable data; object to processing; withdraw consent; and obtain safeguards in relation to solely automated decisions producing legal or similarly significant effects. Rights are not absolute and may be subject to conditions, exemptions and the rights of others. We may request proportionate information to verify identity or authority.
YOUR RIGHT TO OBJECT: Where we rely on legitimate interests, you may object on grounds relating to your particular situation. You may object to direct marketing at any time. If you object to direct marketing, we will stop using your personal data for that purpose.
To exercise a right, email info@ferexgroup.com or use the contact details in Section 15. You do not have to use a particular form, and rights requests are normally free of charge. We may charge a lawful fee or refuse a request only where the law permits.
12. Data Protection Complaints
You may make a data protection complaint by emailing info@ferexgroup.com or writing to the registered office, marked 'Data Protection Complaint'. We will acknowledge receipt within 30 days.
Without undue delay, we will take appropriate steps to investigate, keep you informed and tell you the outcome. This process is separate from the statutory response periods for individual-rights requests.
You may also complain to the UK Information Commissioner's Office (ICO) at ico.org.uk/make-a-complaint or telephone 0303 123 1113. If EU GDPR or another local law applies, you may also have the right to contact the competent supervisory authority for your habitual residence, place of work or the alleged infringement.
13. Children
The Website is intended for a professional and business audience and is not directed at children. We do not knowingly collect children's personal data through the general Website.
14. Automated Decision-Making
We do not currently use information collected through the general Website to make solely automated decisions that produce legal or similarly significant effects. If this changes, we will provide the information and safeguards required by law.
15. Updates and Contact
We may revise this notice when our activities, systems or legal obligations change. Material updates will be highlighted where appropriate. Privacy enquiries, rights requests and complaints should be sent to info@ferexgroup.com or to: Privacy Contact, FEREX GLOBAL TRADING GROUP COMPANY LIMITED, Office 3, Lower Ground Floor, 88 Cambridge Street, London, England, SW1V 4QG.