Privacy Policy

Steliux Logistics โ€” Privacy Policy

Privacy document

Privacy Policy

Steliux Logistics is committed to protecting your personal data. This policy explains what we collect, why we collect it, how we use it, and the rights you hold over your information.

Effective dateMay 7, 2026
Governing entitySteliux Logistics Ltd.
Applicable lawGDPR, CCPA & global equivalents
Versionv2.4
01
Who we are

Steliux Logistics Ltd. ("Steliux", "we", "us", "our") is the data controller responsible for personal data collected through our website at steliux.com, our investment platform at i.steliux.com, our shipment tracking portal, and all related mobile and API services.

We operate a global freight and logistics network spanning 200+ countries, offering air, sea, and road freight, warehousing, customs brokerage, and Secure Elite consignment services. Our investment platform provides logistics-linked investment products to eligible participants.

If you have questions about this policy or how your data is handled, contact our Data Protection Officer at privacy@steliux.com or write to: Steliux Logistics Ltd., Data Protection Office, London, United Kingdom.

02
Data we collect

We collect personal data only to the extent necessary to provide our services. The categories of data we may collect include:

  • Identity data โ€” full name, date of birth, government-issued ID (for KYC/AML compliance on investment accounts)
  • Contact data โ€” email address, phone number, postal address, billing address
  • Shipment data โ€” sender and recipient details, parcel contents descriptions, tracking numbers, delivery instructions, proof-of-delivery records
  • Financial data โ€” payment card details (tokenised via PCI-DSS compliant processors), bank account information, transaction history
  • Investment data โ€” portfolio holdings, investment preferences, risk profile, source of funds declarations
  • Technical data โ€” IP address, browser type and version, device identifiers, operating system, referral source, time zone, page interaction data
  • Usage data โ€” pages visited, features used, search queries, click paths, session duration
  • Communications data โ€” records of correspondence with our support, sales, and compliance teams

We do not knowingly collect sensitive personal data (health, religion, ethnicity, biometrics) except where explicitly required by customs regulations or Secure Elite service verification, in which case your explicit consent will be sought.

03
How we use your data

We process personal data for the following purposes:

  • To create and manage your Steliux account and authenticate your identity
  • To book, process, track, and deliver shipments on your behalf
  • To calculate shipping costs, duties, taxes, and issue invoices
  • To facilitate customs clearance and comply with export/import regulations
  • To onboard you onto our investment platform and manage your portfolio
  • To comply with KYC, AML, and financial crime prevention obligations
  • To send service notifications, delivery alerts, and billing communications
  • To improve our platform through analytics, A/B testing, and user research
  • To detect, investigate, and prevent fraud, abuse, or security incidents
  • To send marketing communications where you have opted in (you may unsubscribe at any time)
  • To meet legal, regulatory, and contractual obligations
04
Legal basis for processing

Where the GDPR or equivalent data protection laws apply, we process your personal data on the following legal bases:

Contract
Processing is necessary to fulfil a contract with you, such as executing a shipment booking or investment transaction.
Legal obligation
We are required to process certain data to comply with customs, tax, AML, and financial regulations across jurisdictions.
Legitimate interest
We process data to improve our services, prevent fraud, and maintain platform security, where this does not override your rights.
Consent
For marketing emails, non-essential cookies, and sensitive data, we rely on your freely given, specific, and revocable consent.
05
Sharing your data

Steliux does not sell your personal data to third parties. We may share your data with the following categories of recipients strictly as necessary to deliver our services:

  • Courier and freight partners โ€” DHL, FedEx, UPS, Maersk, Aramex, and our 250+ carrier network, to execute shipments
  • Customs authorities โ€” government agencies in origin, transit, and destination countries as required by law
  • Payment processors โ€” PCI-DSS certified processors to handle card and bank transactions securely
  • KYC/AML providers โ€” identity verification and fraud screening services for investment platform onboarding
  • Cloud and infrastructure providers โ€” hosting, storage, and technical infrastructure partners operating under data processing agreements
  • Analytics providers โ€” anonymised or pseudonymised usage data shared with analytics tools to improve platform performance
  • Legal and regulatory bodies โ€” where required by court order, law enforcement request, or regulatory directive

All third-party processors are bound by data processing agreements that require them to handle your data in accordance with applicable privacy laws and Steliux's instructions.

06
International data transfers

Steliux operates globally. Your personal data may be transferred to and processed in countries outside your country of residence, including countries that may not provide the same level of data protection as your home jurisdiction.

Where we transfer data outside the European Economic Area (EEA) or other regions with data transfer restrictions, we ensure appropriate safeguards are in place, including:

  • European Commission adequacy decisions for qualifying countries
  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Binding Corporate Rules for intra-group transfers where applicable
  • Derogations for specific situations, such as execution of a shipment contract

You may request a copy of the safeguards we rely on for any specific international transfer by contacting privacy@steliux.com.

07
Cookies & tracking technologies

Our website and platforms use cookies and similar technologies to operate core functionality, remember your preferences, and analyse usage patterns. Cookies are categorised as follows:

Essential
Required for login sessions, security tokens, and core platform functions. Cannot be disabled.
Analytics
Help us understand how visitors interact with our site. Require your consent. Anonymised where possible.
Functional
Remember your preferences such as language, currency, and saved addresses. Require consent.
Marketing
Used to deliver relevant advertising and measure campaign performance. Always require explicit consent.

You can manage or withdraw your cookie consent at any time via our Cookie Preferences panel, accessible from the footer of any Steliux page. You may also configure your browser to block or delete cookies, though this may affect platform functionality.

08
Data retention

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law. Our standard retention periods are as follows:

Account data
Retained for the duration of your account plus 3 years after closure, unless a longer period is required by law.
Shipment records
7 years from date of delivery, to comply with customs and tax record-keeping obligations.
Investment records
10 years from the end of the investment relationship, as required by financial regulation.
KYC/AML records
5 years from the end of the business relationship, per FATF and local AML legislation.

When data is no longer required, it is securely deleted or anonymised. Physical documents containing personal data are shredded in accordance with our data destruction policy.

09
Your privacy rights

Depending on your country of residence, you may hold some or all of the following rights regarding your personal data:

AccessRequest a copy of personal data we hold about you.
RectificationAsk us to correct inaccurate or incomplete data.
ErasureRequest deletion of your data where no legal basis remains.
RestrictionAsk us to limit how we process your data in certain circumstances.
PortabilityReceive your data in a structured, machine-readable format.
ObjectObject to processing based on legitimate interest or for direct marketing.
Withdraw consentRevoke consent at any time without affecting prior lawful processing.
Opt out of saleCalifornia residents may opt out of any sale or sharing of personal data.

To exercise any of these rights, submit a request to privacy@steliux.com. We will respond within 30 days (extendable by a further 60 days for complex requests). We may need to verify your identity before processing your request. There is no charge for making a request, though we may charge a reasonable fee for manifestly unfounded or repetitive requests.

You also have the right to lodge a complaint with your local data protection authority. In the UK, this is the Information Commissioner's Office (ICO) at ico.org.uk. In the EU, contact your national supervisory authority.

10
Security

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, disclosure, alteration, or destruction. Our security practices include:

  • TLS encryption for all data in transit across our platforms and APIs
  • AES-256 encryption for sensitive data at rest, including financial and KYC records
  • Role-based access controls limiting employee access to data on a strict need-to-know basis
  • Regular penetration testing, vulnerability assessments, and security audits by independent third parties
  • Multi-factor authentication enforced on all internal systems and admin accounts
  • ISO 27001-aligned information security management framework
  • Incident response procedures with regulatory notification within 72 hours of discovering a qualifying breach

Despite our measures, no system is completely immune to risk. If you suspect your account has been compromised, contact us immediately at security@steliux.com.

11
Children's privacy

Our services are not directed at individuals under the age of 18. We do not knowingly collect personal data from minors. If we become aware that a minor has provided us with personal data, we will take steps to delete that data promptly.

If you believe a minor has submitted personal data through our platform, please contact us at privacy@steliux.com so we can investigate and act accordingly.

12
Contact & policy updates

We may update this Privacy Policy from time to time to reflect changes in our services, legal requirements, or data practices. Material changes will be communicated via email to registered users or via a prominent notice on our website at least 14 days before taking effect.

Data protection officer
privacy@steliux.com
Security incidents
security@steliux.com
Phone support
+1 (585) 286-6062