Skip to policy content
Maubex Capital
PlatformServicesRegulationLiquidityContact
Client Portal

Maubex Capital · Legal

Privacy Policy

How we handle your information, wherever you connect with us.

Last updated 15 September 2026

Privacy PolicyTerms & Conditions

On this page

  1. 01Who we are and how to contact us
  2. 02Information we collect
  3. 03Purposes and lawful grounds
  4. 04Website, email and cookies
  5. 05Disclosures and international transfers
  6. 06Retention and security
  7. 07Your privacy rights and requests
  8. 08South Africa — POPIA
  9. 09EEA and United Kingdom — GDPR
  10. 10Australia — Privacy Act and APPs
  11. 11California — CCPA / CPRA
  12. 12Mauritius — Data Protection Act
  13. 13Other jurisdictions and children
  14. 14Changes to this policy

Your information. Clear choices.

This notice explains our public website and enquiry handling, the information involved, and how to exercise your rights. It includes specific provisions for South Africa, the EEA and UK, Australia, California and Mauritius.

For a privacy request, contact us directly. You do not need to open an account.

01Who we are and how to contact us

Maubex Capital operates internationally. For this website and enquiries addressed to it, Maverick Trading 1388 CC, trading as Maubex Capital, is the organisation responsible for deciding how personal information is used (the “controller” or, under POPIA, the “responsible party”).

Maverick Trading 1388 CC, trading as Maubex Capital
63 Chelsea Drive, Durban, KwaZulu-Natal, South Africa
jeanluc@maubex.com · +27 83 232 9448

Use these contact details for privacy questions, complaints or requests, and mark your message “Privacy / Information Officer”. You can request an accessible copy of this policy through the same contact.

This policy covers visitors to our public Maubex Capital websites, including maubexcapital.com and maubexcapital.co.za and their www subdomains, prospective clients, business contacts and people whose information is included in their communications. It explains our website and enquiry handling. Client onboarding, identity verification, trading, custody, employment and other services require the relevant additional privacy information at the point of collection. Where another group entity is responsible, its identity and contact details must be identified in that notice or your service documentation.

The jurisdiction sections below supplement this policy when those laws apply to the individual, organisation or processing involved. A global presence does not mean that every law applies to every interaction. Mandatory local protections take priority over any conflicting wording here.

02Information we collect

The following describes the categories collected through this website and related enquiries, their sources and purposes, and the recipients involved in ordinary handling.

Identifiers and contact information
Your name, email address and optional telephone number, provided by you or a person contacting us on your behalf. Used to identify and answer your enquiry and keep related correspondence. Recipients: staff handling the enquiry and email, communications and IT providers supporting that work.
Professional or business information
Your optional company name and any role or business details you include. Used to understand your organisation and route the enquiry. Sources: you, your organisation or your representative. Recipients: relevant staff and the same communications and IT providers.
Enquiry and correspondence information
Your selected enquiry type, message and subsequent communications, including information about an intended service or transaction if you choose to include it. Used to respond, assess next steps and maintain an appropriate record. Sources: you and people you authorise. Recipients: relevant staff, communications providers and advisers where needed to address a legal or compliance issue.
Internet, device and connection information
When your browser requests a page or video, it sends information such as its IP address, browser details, requested URL and request time to the serving infrastructure. Hosting and content-delivery providers may log this information for delivery, security and troubleshooting. The homepage video is delivered through Amazon CloudFront. Recipients: the relevant hosting, content-delivery and security providers, and authorised technical staff where logs are available to them.

The enquiry form requires a name, email address and message to prepare a useful reply. Company and telephone details are optional. Providing an enquiry is voluntary; without sufficient contact information or a description of your request, we may be unable to respond. There is no statutory requirement to submit this website form.

Please do not include passwords, wallet private keys, seed phrases, payment-card details, identity documents, health information or other sensitive information in an initial enquiry. This website has no identity-document upload or account-verification facility. If verification is necessary later, we will explain the required information, purpose and appropriate submission channel separately.

If you provide another person’s information, do so lawfully, provide only what is needed, and make this policy available to them. We provide any additional notice required when information comes from someone other than the individual concerned.

03Purposes and lawful grounds

  • Responding and taking requested steps: we use contact, professional and enquiry information to reply and discuss services. Where you are a prospective contracting individual, this can be necessary to take steps at your request before a contract. For general enquiries or representatives of organisations, we rely on the legitimate interest in handling relevant business communications, where local law permits and your interests do not override it.
  • Operating and protecting the website: connection information supports page and video delivery, fault diagnosis and security. Our legitimate interests are maintaining a usable site and preventing misuse, subject to the applicable balancing and necessity requirements.
  • Legal obligations and disputes: we may retain or disclose relevant records to comply with a binding legal duty or to establish, exercise or defend legal claims. A legal-obligation basis is used only where the obligation qualifies under the law governing the processing; otherwise another valid ground must apply.
  • Optional communications: if we ask to use information for a separate purpose that requires consent, we will explain it and request a separate choice. A general enquiry does not subscribe you to a marketing list.

These grounds apply only to the extent recognised by the relevant law. Where consent is required, including for sensitive information or certain marketing, we obtain it before that processing unless a lawful exception applies. We do not treat reading this policy, browsing the website or accepting website terms as consent to unrelated processing.

You may withdraw consent at any time through the contact above, without affecting earlier lawful processing. You may object to direct marketing at any time, free of charge, by contacting us or using an unsubscribe facility in the communication. Withdrawing optional consent does not prevent an ordinary enquiry.

04Website, email and cookies

The enquiry form currently prepares an email in your own email application. It does not transmit your entries to Maubex as you type. Submitting the form passes those entries to your email application; Maubex receives the enquiry only if you send the email. Your email application or provider may save a draft and processes information under its own terms. If no email application opens, you can contact us directly at the address above.

The website does not currently include advertising pixels, behavioural analytics, social-media embeds or a marketing-cookie system. It does not deliberately set application cookies or store enquiry entries in browser local storage. Fonts and the illustrated location map are served with the site. Your browser can still cache files, and delivery or security infrastructure may process connection information.

The homepage automatically requests its background video from an Amazon CloudFront domain. That request exposes connection information to the video-delivery infrastructure and may involve international processing. It is separate from sending an enquiry. External links only take you to another service when you follow them; that service has its own privacy practices.

If optional cookies or similar tracking are introduced, we will provide information and any required consent or opt-out controls before activating them. Where consent is required, declining or withdrawing it must be as straightforward as accepting it.

Browser signals: there is currently no advertising or cross-site tracking feature for a Global Privacy Control (GPC) or Do Not Track signal to switch off. Do Not Track does not change necessary website delivery. GPC expresses an opt-out of sale or sharing where applicable law recognises it; any future sale or sharing feature must honour applicable signals before operating.

05Disclosures and international transfers

We limit disclosure to the purpose concerned. In addition to the recipients described above, information may be disclosed to a group entity where needed to handle a request directed to it; to professional advisers, courts or regulators where legally justified; or to parties involved in a proposed business transfer with appropriate confidentiality and data-protection safeguards. Public access to this website does not authorise unrestricted sharing within the group.

Providers processing information on our instructions must be subject to appropriate confidentiality, security and processing terms. An independent provider or regulator may instead be responsible for its own processing. We do not authorise enquiry recipients to use your details for unrelated advertising.

Our published group locations include South Africa and Mauritius. Enquiries sent to our South African contact are handled in South Africa; a request involving our Mauritius presence may involve that location. Hosting, email and global video-delivery infrastructure can involve other countries. Contact us for the destinations and protections relevant to your enquiry; a service-specific notice must identify additional overseas recipients and destinations where required.

A cross-border transfer needs the protections required by the law governing it. For EEA or UK data, this may require a recognised adequacy decision or appropriate contractual safeguards, such as European Commission Standard Contractual Clauses and the applicable UK transfer instrument, with a transfer assessment and additional safeguards where necessary. POPIA section 72 and Mauritius Data Protection Act section 36 have their own transfer requirements. Australian overseas disclosures are subject to APP 8 where it applies.

These are legal mechanisms that may be required, not a statement that every destination is adequate or that a particular contract is in place for every provider. We must establish the applicable transfer basis before a restricted transfer. You may request information about, and a copy of applicable safeguards, with necessary confidential details removed. Merely contacting us does not waive transfer protections or amount to consent to an otherwise unlawful transfer.

06Retention and security

Information should be kept only for as long as needed for its disclosed purpose or a valid legal requirement. Because the nature of an enquiry and any resulting relationship vary, we use the following retention criteria rather than a single period for all visitors:

  • Contact and professional details: for handling the enquiry and relevant follow-up, then only while needed for an ongoing relationship, a required record or a specific dispute.
  • Messages and correspondence: for resolving the matter, documenting the outcome and satisfying applicable record-keeping or claim requirements. Enquiries that lead to a regulated service become subject to that service’s retention notice.
  • Connection and delivery records: for the operational or security window needed to deliver the site, diagnose an issue or investigate abuse, subject to the provider’s applicable logging and deletion arrangements.
  • Privacy requests and communication preferences: to administer the request, demonstrate how it was handled and retain the minimum information needed to respect an objection or opt-out.

Legal holds may require relevant records to be preserved until the matter is resolved. When there is no remaining lawful need, records should be deleted or irreversibly anonymised; backup copies are subject to the applicable backup replacement and deletion process. Ask us about the retention period applying to your particular record.

Security measures must be proportionate to the information and risk, including restricted access, appropriate protection in transmission and storage, and oversight of providers. No website or email channel can guarantee absolute security. Report a suspected privacy incident using the contact above; please do not send a private key or password as evidence. Where a breach triggers a legal notification duty, we will notify the relevant authority and affected people within the applicable time limits.

07Your privacy rights and requests

Depending on applicable law, you can ask to know whether we hold your information, access or obtain a copy, correct it, delete it, restrict its use, object to processing, withdraw consent or receive a portable copy. Some laws also provide opt-outs from sale, sharing, targeted advertising or certain profiling, and a right to appeal a refusal. These rights are subject to the conditions and exceptions in the relevant law.

Maverick Trading 1388 CC, trading as Maubex Capital
63 Chelsea Drive, Durban, KwaZulu-Natal, South Africa
jeanluc@maubex.com · +27 83 232 9448

Email, telephone or write to us with the right you want to exercise, enough detail to locate the record, and a reply address. Mention your country or state if useful for identifying the applicable rules. You do not need an account or a particular legal phrase. The contact page also offers an enquiry form; choose “Privacy or personal information request”.

We may ask for proportionate information to verify your identity or an agent’s authority, using existing contact details where possible. We do not require unnecessary identity documents. An authorised representative may make a request, subject to any legally permitted proof of authority or direct confirmation. An opt-out must not be subjected to identity verification where the law prohibits it.

We will respond within the applicable deadline. If a lawful extension, fee or refusal applies, we will explain the reason and available complaint or appeal route. Requests are ordinarily free; any charge must be specifically permitted by law and explained in advance. Exercising a right will not result in unlawful discrimination or retaliation. Some records may need to be retained for legal obligations or other lawful exceptions even if you request deletion.

If you disagree with our response, reply with “Privacy appeal” and explain why you wish it to be reconsidered. This does not replace or restrict any right to complain to a regulator or seek a judicial remedy. You do not have to complete an internal appeal first where the law permits direct escalation.

08South Africa — POPIA

Where the Protection of Personal Information Act 4 of 2013 (POPIA) applies, the responsible party is identified above. POPIA can also protect information about an existing juristic person, such as a company. The collection details, purposes, voluntary and required fields, consequences, recipients and transfer considerations are set out in this policy.

You may request confirmation and access under section 23, correction or deletion under section 24, and object to processing under section 11 where applicable. Direct marketing by electronic communication must meet section 69, including the consent or qualifying existing-customer requirements and a way to object. We do not use the enquiry form to obtain blanket marketing consent.

Requests for records may also involve the Promotion of Access to Information Act (PAIA) and its procedures. Ask the contact above for assistance and the applicable PAIA manual or request process. Prescribed forms are available from the Information Regulator.

You may complain to the Information Regulator of South Africa, including through its eServices portal. The regulator’s published general contact is enquiries@inforegulator.org.za, telephone +27 10 023 5200. Access requests are handled within applicable POPIA and PAIA time limits; other rights are addressed as required by POPIA.

09EEA and United Kingdom — GDPR

Where the EU General Data Protection Regulation or UK GDPR applies, our purposes and corresponding legal grounds appear above. You have the applicable rights of access, rectification, erasure, restriction, portability and objection. In particular, you may object to processing based on legitimate interests for reasons relating to your situation, and to direct marketing at any time.

We normally respond without undue delay and within one month. Where legally justified by complexity or number of requests, this can be extended by up to two additional months, with notice and reasons within the initial month. Any lawful identity-verification or clarification rules will be explained where relevant.

This public website does not make decisions about you solely by automated means that produce legal or similarly significant effects. If a later service involves such processing, its notice must explain the logic, significance, consequences and applicable safeguards and rights before it is used.

You may complain to a supervisory authority in the EEA, particularly where you live or work or where an alleged infringement occurred; see the EDPB’s authority directory. In the UK, contact the Information Commissioner’s Office. Applicable representative or Data Protection Officer details must be supplied in the relevant processing notice where such an appointment is required.

10Australia — Privacy Act and APPs

Where the Privacy Act 1988 (Cth) and Australian Privacy Principles (APPs) apply, you may request access to and correction of your personal information. We respond within a reasonable period, ordinarily within 30 days. If access or correction is refused, we provide reasons and complaint options unless the law allows otherwise. You may also request association of a statement of disagreement with a record where required.

We collect sensitive information only with consent where required or under a lawful exception. Where lawful and practicable, you may make a general enquiry anonymously or using a pseudonym, including by contacting us directly; verification may be necessary for a specific account or regulated service.

Our overseas handling is described in the international-transfers section, including South Africa and potential handling in Mauritius. APP 8 may require reasonable steps to ensure an overseas recipient handles information consistently with the APPs, and we may remain accountable. This policy does not seek consent to waive that protection.

Raise a privacy complaint with us using the contact above. We will investigate and communicate an outcome, ordinarily within 30 days. If unresolved, you may complain to the Office of the Australian Information Commissioner; its guidance ordinarily asks you to complain to the organisation first and allow a response.

11California — CCPA / CPRA

Where Maubex is a covered business and the information is subject to the California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA / CPRA), California residents have rights to know and access, correct and delete personal information, subject to statutory exceptions. You may also opt out of sale or sharing for cross-context behavioural advertising and limit certain uses or disclosures of sensitive personal information where those activities occur.

The collection section identifies this website’s identifiers, professional or business information, enquiry or commercial information and internet activity, including sources, purposes and recipient categories. The retention section explains the criteria for each category. The website does not request sensitive personal information, infer sensitive characteristics, operate targeted advertising or offer a financial incentive for providing personal information. Its current features do not sell personal information or share it for cross-context behavioural advertising, including information about people under 16.

Use the email, postal contact or enquiry form in Your privacy rights for a request, including through an authorised agent. Know, correction and deletion requests may require verification. Where the CCPA applies, we acknowledge these requests within 10 business days and normally respond within 45 calendar days of receipt; a permitted extension of up to a further 45 days will be explained within the initial period. Sale/sharing opt-outs and applicable sensitive-information limits are handled as soon as feasible and within 15 business days, without a verifiable consumer request requirement.

See the browser-signals section for GPC and Do Not Track. The absence of a current sale or sharing feature does not waive your rights. If practices change, the required notices and controls must be provided before that processing begins. We do not discriminate against you for exercising CCPA rights.

Some financial information may be subject to statutory exemptions; an exemption must be assessed for the information and activity involved and is not a blanket exemption for all website visitors. For guidance and complaints, visit the California Privacy Protection Agency or the California Attorney General’s CCPA page.

12Mauritius — Data Protection Act

Where the Mauritius Data Protection Act 2017 applies, you may exercise rights of access, rectification, erasure or restriction, and objection, subject to the Act’s conditions. Protections also apply to automated individual decisions and to the lawful processing of special categories of personal data. You can withdraw consent where processing relies on it.

For access requests under section 37, we inform you of the action taken within one month. Where necessary because of complexity or the number of requests, a further month is permitted under the Act. We explain any applicable extension or refusal and the available complaint route.

Transfers outside Mauritius must satisfy section 36 and any applicable authorisation or consultation requirements. A group relationship alone is not a transfer safeguard. You may complain to the Mauritius Data Protection Office, whose published contact is dpo@govmu.org or +230 460 0251.

13Other jurisdictions and children

Visitors elsewhere can use the same contact and request process. Where another applicable law provides additional notice, consent, access, correction, deletion, portability, appeal, localisation or transfer protections, those requirements continue to apply. This includes relevant US state privacy laws and applicable protections in other countries; this policy does not claim that one jurisdiction’s law replaces them.

If a local privacy law gives you an appeal right, send a “Privacy appeal” to the contact above. We will explain the result and applicable regulator route within that law’s deadline. You may also contact your local privacy or consumer-protection authority.

Our website and services are directed to adults and business representatives, not children. We do not knowingly solicit children’s personal information through this website. If you believe a child has supplied information, contact us so we can investigate and remove it or handle it as the applicable law requires. Regulated service eligibility is governed by the relevant service terms.

14Changes to this policy

We update this policy when relevant practices or requirements change and show the revision date at the top. Material changes will be brought to your attention in an appropriate way, and further notice or consent will be provided before a new use where required. A policy update cannot retrospectively authorise processing that requires a separate legal basis or consent.

For the rules governing this public website, read our Terms & Conditions.

Back to contents ↑
Maubex Capital

Regulated. Disciplined. Built for Africa.

PlatformServicesRegulationLiquidityContact

Head office

63 Chelsea Drive, Durban, KwaZulu-Natal, South Africa

Group presence · South Africa · Cape Town · Mauritius

Contact

jeanluc@maubex.com

+27 83 232 9448

Languages · English · French

Regulatory

FSCA FSP No. 53778 · Category I & II

Registered Crypto Asset Service Provider

Maubex Capital is the trading name of Maverick Trading 1388 CC, an authorised Financial Services Provider (FSCA FSP No. 53778, Category I & II) and a registered Crypto Asset Service Provider in the Republic of South Africa. Crypto assets are not regulated as a financial product in all respects and their value can be volatile. Nothing on this page constitutes financial advice.

Privacy PolicyTerms & ConditionsYour privacy rights

© 2026 Maubex Capital · Maverick Trading 1388 CC · All rights reserved.