Privacy Policy
Last updated: 17 July 2026
This Privacy Policy describes how the personal data of users who access the website www.hareusbullion.com, its reserved area, the digital platform and the services offered under the Hareus Bullion brand is collected, used, stored and protected.
The processing of personal data is carried out in compliance with EU Regulation 2016/679 ("GDPR"), the applicable Portuguese data protection legislation, the UK General Data Protection Regulation ("UK GDPR"), the Data Protection Act 2018, the UK PECR rules where applicable, and any further national provisions applicable based on the data subject's residence.
The GDPR has applied since 25 May 2018 and governs the processing of the personal data of natural persons in the European Union and the European Economic Area.
1.Data controllers
In relation to the management of the website, the Hareus Bullion platform and the services offered, data processing may be carried out, according to their respective competences, by:
HAREUS BULLION LTD
More London Riverside, London, England, SE1 2PL, United Kingdom — Company Number: 13979379.
General email: info@hareusbullion.com — Privacy email: privacy@hareusbullion.com.
CRONOMÉTRÀMANEIRA – UNIPESSOAL, LDA
Rua da Carreira, n.º 115-117, Funchal, freguesia de São Pedro, Região Autónoma da Madeira, Portugal — NIF/VAT: PT517808463.
General email: info@hareusbullion.com — Privacy email: privacy@hareusbullion.com.
The two companies may act, depending on the specific service:
- as autonomous data controllers;
- as joint data controllers;
- or one company as data processor on behalf of the other.
Information on the specific allocation of responsibilities can be requested by writing to privacy@hareusbullion.com.
2.Data protection officer
Should a Data Protection Officer (DPO) be formally appointed, the relevant contact will be: DPO – Hareus Bullion, email dpo@hareusbullion.com.
In the absence of a mandatory or voluntary appointment of a DPO, any privacy-related request can be sent to privacy@hareusbullion.com.
3.Scope of application
This policy applies to data collected through:
- the website www.hareusbullion.com;
- the platform and the personal area;
- registration and contact forms;
- KYC and AML identification procedures;
- purchases of physical gold;
- custody and delivery services;
- sale or buyback requests;
- Memberships and Gold plans;
- the Partner Program and affiliation program;
- assistance requests;
- communications via email, telephone, chat or messaging;
- events, presentations and promotional activities;
- cookies and similar tools.
4.Types of data processed
4.1 Identification data
The following may be collected:
- first and last name;
- date and place of birth;
- nationality;
- gender, where necessary for identification;
- tax code or tax number;
- document number;
- copy of the identity document;
- identification photograph;
- signature.
4.2 Contact data
The following may be processed:
- residential address;
- domicile;
- email address;
- telephone number;
- professional contacts;
- language preferences.
4.3 Economic and financial data
In relation to purchases and services, the following may be processed:
- bank details;
- IBAN;
- account holder name;
- payment information;
- origin and destination of funds;
- amounts purchased;
- movements relating to the gold;
- invoices and accounting documentation;
- transaction history;
- liquidation or buyback requests;
- data required to verify the capacity and lawfulness of the transaction.
The Company does not retain full payment card data when transactions are managed directly by authorised payment service providers.
4.4 KYC and anti-money-laundering data
To fulfil identification and control obligations, the following may be requested:
- identity document;
- proof of residence;
- occupation information;
- economic activity carried out;
- source of funds;
- source of wealth;
- beneficial ownership;
- declarations relating to politically exposed persons (PEPs);
- information on directors, shareholders and beneficial owners;
- results of checks against sanctions lists;
- further documents required by anti-money-laundering regulations.
4.5 Account data
The following are processed:
- username;
- account identifier;
- password in encrypted form;
- preferences;
- access history;
- activities carried out in the dashboard;
- consents and contractual acceptances;
- assistance tickets.
4.6 Partner Program data
For partners and affiliates, the following may be processed:
- partner code;
- sponsor or referrer;
- structure of the sales network;
- clients introduced;
- qualification;
- personal and network volumes;
- GPV or other commercial parameters;
- commissions accrued;
- payment details;
- tax documentation;
- participation in courses and certifications;
- compliance checks.
4.7 Technical and browsing data
IT systems may collect:
- IP address;
- device identifier;
- browser type;
- operating system;
- date and time of access;
- pages visited;
- system logs;
- session data;
- approximate geographic location;
- information on security and abnormal access attempts.
4.8 Communications
The following may be retained:
- email messages;
- requests submitted through forms;
- chats with support;
- records of requests;
- commercial communications;
- complaints and reports.
Any telephone calls will be recorded only where permitted by law and after adequate notice.
5.Purposes and legal bases of processing
5.1 Registration and account management
The data is used to:
- create the account;
- verify the user's identity;
- allow access to the platform;
- manage credentials, authorisations and security;
- provide assistance.
Legal basis: performance of a contract or of pre-contractual measures requested by the data subject.
5.2 Purchase, custody and sale of physical gold
The data is processed to:
- process orders;
- receive and verify payments;
- allocate and register the purchased gold;
- manage custody;
- organise physical delivery;
- manage buyback or liquidation requests;
- issue invoices and documents.
Legal basis: performance of the contract and fulfilment of legal obligations.
5.3 KYC, AML and international sanctions checks
The processing is carried out to:
- identify the client;
- verify the beneficial owner;
- prevent money laundering and terrorist financing;
- check PEPs and sanctions lists;
- detect abnormal transactions;
- comply with requests from the Authorities.
Legal basis: legal obligation and, where permitted, legitimate interest in preventing fraud and unlawful activities.
5.4 Membership and Gold plans
The data is processed to:
- activate the selected plan;
- apply the applicable economic conditions;
- manage duration, renewal and termination;
- assign any benefits;
- communicate updates about the plan.
Legal basis: performance of the contract.
5.5 Partner Program
The data is used to:
- assess the application;
- carry out onboarding and training;
- assign the partner code;
- manage clients and referrals;
- calculate qualifications and commissions;
- make payments;
- verify compliance with commercial rules;
- prevent abuse and unfair practices.
Legal basis: performance of the contract, legal obligation and legitimate interest in managing and protecting the sales network.
5.6 Assistance and service communications
The data may be used to:
- respond to requests;
- provide technical and administrative assistance;
- send order confirmations;
- communicate contractual updates;
- report suspicious activities or security issues.
Legal basis: performance of the contract and legitimate interest.
5.7 Legal, tax and accounting obligations
The processing is carried out for:
- invoicing;
- keeping accounts;
- tax obligations;
- document retention;
- handling controls and audits;
- cooperation with the Authorities.
Legal basis: fulfilment of a legal obligation.
5.8 Fraud prevention and security
The data may be processed to:
- protect accounts and infrastructure;
- detect abnormal access;
- prevent fraud;
- counter unlawful use;
- protect the rights of the Company and users;
- ensure the security of transactions.
Legal basis: legitimate interest of the controller and, where applicable, legal obligation.
5.9 Direct marketing
Subject to consent, the Company may use email and telephone number to send:
- news;
- offers;
- commercial updates;
- invitations to events;
- communications about Hareus Bullion services;
- information relating to the Partner Program.
Legal basis: consent of the data subject, except where the law allows communications regarding similar services to existing clients.
Marketing consent is optional and can be withdrawn at any time through the unsubscribe link or by writing to privacy@hareusbullion.com.
When processing is based on consent, it must be freely given, specific, informed, unambiguous and withdrawable without any negative consequences for the user.
5.10 Statistical analysis and service improvement
Subject to consent where required, browsing data may be used to:
- analyse how the website works;
- understand how the pages are used;
- improve services, content and interface;
- measure the effectiveness of campaigns.
Legal basis: consent for non-essential cookies and tracking; legitimate interest for strictly aggregated and technically exempt statistics, where permitted.
5.11 Defence of rights
The data may be used to:
- handle disputes;
- prevent abuse;
- exercise or defend rights in court;
- recover debts;
- retain contractual evidence.
Legal basis: legitimate interest and protection of rights.
6.Mandatory or optional nature of providing data
Providing the data marked as mandatory is necessary to:
- register the account;
- complete KYC checks;
- purchase gold;
- make payments;
- request deliveries or liquidations;
- join the Partner Program;
- comply with regulatory obligations.
Failure to provide this data may prevent the activation or continuation of the service.
Providing data for marketing, commercial profiling and non-essential cookies is optional.
7.Methods of processing
The data is processed using electronic, IT, telematic and, where necessary, paper-based tools.
Technical and organisational measures proportionate to the risk are adopted, including:
- access control;
- encryption, where applicable;
- authentication;
- access logging;
- backups;
- segregation of roles;
- incident management procedures;
- staff training;
- confidentiality agreements;
- supplier vetting.
No IT system, however, can be considered completely immune from risk.
8.Recipients of the data
The data may be disclosed to:
- companies belonging to the same group or connected to the project;
- platform and CRM providers;
- hosting and cloud companies;
- cybersecurity providers;
- payment service providers;
- banks and financial institutions;
- operators in the precious metals sector;
- refineries, distributors and suppliers;
- vault operators;
- insurers;
- couriers and logistics operators;
- legal, tax and accounting advisors;
- KYC, AML, PEP and sanctions screening providers;
- email and support providers;
- electronic signature platforms;
- statistical analysis and marketing providers, subject to consent;
- judicial, administrative, tax and supervisory Authorities.
Parties that process data on behalf of the Company are appointed as data processors through agreements compliant with the applicable regulations.
9.International transfers
Given the international structure of the project, data may be transferred between:
- the United Kingdom;
- Portugal;
- other countries of the European Union or the EEA;
- countries in which technology or commercial providers operate.
International transfers are carried out on the basis of one of the mechanisms provided for by law, including:
- adequacy decisions;
- standard contractual clauses;
- UK International Data Transfer Agreement;
- UK Addendum to the standard clauses;
- other recognised safeguards;
- specific derogations provided for by the regulations.
The user can request information on the safeguards applied by writing to privacy@hareusbullion.com.
10.Data retention
The data is retained for the period necessary for the purposes for which it was collected.
As a guide:
| Category | Indicative period |
|---|---|
| Active account | For the entire duration of the relationship |
| Contractual data | Duration of the relationship and subsequent limitation periods |
| Accounting and tax data | Period provided for by the applicable regulations |
| KYC/AML documents | Period provided for by anti-money-laundering regulations |
| Orders and transactions | Duration of the relationship and subsequent legal period |
| Assistance tickets | Up to 5 years, unless further needs arise |
| Security logs | Generally from 6 to 24 months |
| Unsuccessful partner applications | Generally up to 24 months |
| Marketing data | Until consent is withdrawn or after a period of inactivity |
| Consents | For the time needed to demonstrate compliance |
| Cookies | According to the durations indicated in the Cookie Policy |
Data may be retained longer where necessary for regulatory obligations, investigations, litigation, fraud prevention or the defence of rights.
11.Automated decision-making and profiling
The platform may use automated checks for:
- fraud prevention;
- risk assessment;
- identification of suspicious access;
- KYC and sanctions checks;
- segmentation of communications;
- application of Membership conditions;
- management of Partner Program qualifications.
Unless otherwise communicated, no decisions are taken based solely on automated processing that produce significant legal effects on the data subject without the safeguards provided for by the regulations.
Should a relevant automated process be used, the data subject will be informed and may request:
- human intervention;
- explanations;
- to contest the decision.
12.Rights of the data subject
Within the limits and under the conditions provided for by law, the data subject may exercise the following rights:
- obtain confirmation of the existence of the processing;
- access their data;
- obtain the rectification of inaccurate data;
- obtain erasure;
- request the restriction of processing;
- object to the processing;
- receive the data in a structured and readable format;
- request portability;
- withdraw consent;
- object to direct marketing;
- not be subject to solely automated decisions;
- lodge a complaint with the competent Authority.
The withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
13.How to exercise your rights
Requests can be sent to privacy@hareusbullion.com or by post to one of the addresses indicated in the "Data controllers" section.
The request must contain sufficient information to identify the data subject. The Company may request identity verification to prevent unauthorised access or changes.
Requests will be handled within the timeframes provided for by the applicable regulations.
14.Complaints to supervisory Authorities
Data subjects residing in the European Union may lodge a complaint with the supervisory Authority of the country in which they reside, work or believe the breach occurred.
For processing connected to the Portuguese company, the competent Authority is the Comissão Nacional de Proteção de Dados (CNPD).
For processing subject to UK legislation, the competent Authority is the Information Commissioner's Office (ICO).
The right to lodge a complaint does not limit the possibility of applying to the judicial Authority.
15.Data of minors
The Hareus Bullion website and services are not intended for persons under 18 years of age.
The Company does not knowingly collect data of minors for the purchase of gold, the opening of accounts or joining the Partner Program.
Should an account registered to a minor be detected, it may be suspended and the data deleted, subject to retention obligations.
16.Account security
The user is responsible for the correct safeguarding of their credentials.
The user must:
- use a secure password;
- not share their credentials;
- protect the devices used;
- promptly report suspicious access;
- keep their contact details up to date.
The Company will never ask the user to communicate the full password via email, telephone or messaging.
17.Links to external sites
The website may contain links to third-party sites or services.
The Company does not control how such parties process data. The user is invited to consult the relevant privacy policies before providing personal information.
18.Social networks and embedded content
The pages may integrate content or links from:
- Facebook;
- Instagram;
- LinkedIn;
- YouTube;
- Vimeo;
- WhatsApp;
- Google Maps;
- other external platforms.
Interaction with such services may involve the transmission of data to their respective providers. External content and its non-essential cookies must be blocked until any consent is given by the user.
19.Data breach
In the event of a personal data breach, the Company will take the necessary measures to:
- contain the incident;
- assess its risks;
- document the event;
- inform the competent Authority when required;
- inform the data subjects when the breach presents a high risk to their rights and freedoms.
20.Amendments to the Privacy Policy
This Privacy Policy may be updated as a result of:
- regulatory changes;
- the introduction of new services;
- organisational changes;
- changes of providers;
- new processing methods.
The updated version will be published on the website with the date of revision.
Substantial changes may also be communicated by email, platform or specific notice.
21.Privacy contacts
For questions or requests — Privacy email: privacy@hareusbullion.com.
HAREUS BULLION LTD
More London Riverside, London, England, SE1 2PL, United Kingdom — Company Number 13979379.
CRONOMÉTRÀMANEIRA – UNIPESSOAL, LDA
Rua da Carreira, n.º 115-117, Funchal, São Pedro, Madeira, Portugal — NIF: PT517808463.
