Legal

Privacy Policy

Last updated 2026-07-15

1. Who we are

The European Defence Exchange ("EDE", "we") is a B2B defence and security marketplace operated by Atlantic Edge Group LLC, a Delaware limited liability company, which is the data controller for personal data processed through the Platform and its modules (EDE, Drone Ex, Procurion and Vault). Where we process personal data on behalf of a business customer, we act as a processor under a Data Processing Agreement.

2. What we collect

3. Why we collect it (legal basis)

4. Who we share data with (processors)

We only share what is necessary, on data-processing agreements where applicable.

We do not sell your data. We do not share it for advertising.

5. How we use data across our platforms

The European Defence Exchange is one ecosystem with four modules — EDE, Drone Ex, Procurion and Vault. Data generated in one module may be combined with data from the others to improve the service: a supplier verified on EDE may be surfaced in Procurion, and a transaction may be settled through Vault. This is what makes the platform more useful the more it is used. Where personal data is involved we do this only on the lawful bases set out in section 3, and only for the purposes stated there. We build aggregated and derived insight (benchmarks, scores and indices) from platform activity; where we license that insight to third parties it is aggregated or anonymised so that individuals and individual organisations are not identifiable. See our Data Rights & Use page for a plain-English explanation of what we may and may not do with your data.

6. How long we keep it

Active member data is retained while your account is active. Approved-submission archives are kept for 7 years for compliance traceability. Rejected or withdrawn applications are kept for 1 year and then deleted unless we are legally required to keep them longer (e.g., sanctions hits).

6. Your rights (EEA / UK GDPR)

7. Where data is stored

Primary database in the EU. Some processors (Resend, OpenSanctions, public registries) may process data in the US or third countries under standard contractual clauses.

8. Security

Transport encryption (TLS 1.2+), encryption at rest, row-level access control, principle of least privilege for staff, signed and short-lived session tokens. We are not yet ISO 27001 certified.

9. Changes

We may update this policy. Material changes will be emailed to active vendors. The current version is always available at this URL.

Read alongside our Terms of Service. Questions: privacy@eudefex.com.