Privacy policy
Last updated: 20 July 2026
This privacy policy explains how we process personal data when you use this website and our onboarding form. Because we are established in the United Kingdom and offer services to individuals in the European Union, both the EU General Data Protection Regulation (EU GDPR, Art. 3(2)) and the UK GDPR apply to us.
1. Controller
GLOBALBANK LIMITED (“ONPEX”)
Unity House, Suite 888 Westwood Park, Wigan, WN3 4HE, United Kingdom
Company number 04600600, represented by its Director Heiko Schröter
E-mail: accounts@onpex.co
2. Data we process
- Identity data: first and last name, date of birth
- Contact data: e-mail address, phone number
- Company data: company name, description of business activity, marketing and ownership information, LinkedIn/UpWork profile where provided, voucher code
- Uploaded supporting documents: incorporation documents, tax IDs, registered agent appointment, CV and personal bank statements for the last three months. These documents contain identity and financial data.
- Technical data: IP address, time of submission, browser/device information, captcha verification data.
3. Purposes and legal bases
- Providing our service (facilitating and setting up bank/payment accounts with partner institutions) – Art. 6(1)(b) GDPR (contract / pre-contractual measures).
- Identity verification (KYC), anti-money-laundering and fraud prevention – Art. 6(1)(c) (legal obligation) and Art. 6(1)(f) (legitimate interest).
- Transferring your data and documents to partner banks in third countries – your explicit consent under Art. 6(1)(a) together with Art. 49(1)(a) GDPR (see sections 7 and 8).
- Website operation, security and abuse prevention (incl. captcha) – Art. 6(1)(f) GDPR.
4. Recipients and processors
- Hosting / server operation: [add and confirm provider and server location — the server IP known to us is registered to an organisation in Panama; the actual storage location must be confirmed as it determines the transfer safeguard].
- Cloudflare, Inc. (“Turnstile” captcha), USA.
- Pipedrive (CRM used to process your application), [confirm data location].
- Partner banks and institutions in the USA, the United Kingdom and the United Arab Emirates, to which we transfer your application and supporting data for account opening (independent controllers).
5. Transfers to third countries
- United Kingdom: covered by an EU adequacy decision; an adequate level of protection is ensured.
- USA (e.g. Cloudflare, possibly partner institutions): transfer under the EU-US Data Privacy Framework where the recipient is certified, otherwise on the basis of standard contractual clauses (Art. 46 GDPR). [confirm certification/basis per recipient]
- United Arab Emirates and possibly Panama: no adequacy decision exists. The transfer of your documents to partner banks in the UAE therefore relies on your explicit consent under Art. 49(1)(a) GDPR, which you give during onboarding. You are aware that these countries may not provide a level of protection comparable to the EU. You may withdraw your consent at any time with future effect.
6. Consent and withdrawal
Where we process data based on your consent or transfer it to a third country, you may withdraw your consent at any time with future effect, without affecting the lawfulness of processing before withdrawal. Withdrawal may mean we cannot continue the requested account opening.
7. Retention
We keep your data only as long as necessary for the stated purposes or as required by law. Statutory anti-money-laundering retention periods generally apply to KYC documents. [add concrete retention periods and deletion concept.]
8. Your rights
You have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20), objection (Art. 21) and withdrawal of consent (Art. 7(3)). You may also lodge a complaint with a supervisory authority – in Germany with the state data protection authority for your place of residence, in the UK with the Information Commissioner’s Office (ICO).
9. Captcha (Cloudflare Turnstile)
To protect our form against automated access we use Cloudflare Turnstile, which transmits technical data (incl. IP address, browser information) to Cloudflare. The legal basis is our legitimate interest in security and abuse prevention (Art. 6(1)(f) GDPR).
10. No automated decision-making
No solely automated decision-making, including profiling, within the meaning of Art. 22 GDPR takes place. Account opening is decided solely by the respective partner institutions.
11. Data security
We apply technical and organisational measures to protect your data, in particular transport encryption (TLS), access controls and separate storage of uploaded documents. [before go-live: confirm encryption at rest for uploaded documents/database, otherwise adjust this statement.]
12. Changes
We update this policy when processing or the legal situation changes. The version published here applies.