Legal Hub
Privacy Policy
Privacy policy for the PWX website: how PWX LLC collects, uses, stores, and protects personal data when you visit our site, submit enquiries, or otherwise interact with our institutional communications.
PWX Privacy Policy Document
PWX LLC (“PWX,” “we,” “us,” or “our”) is committed to protecting the privacy and confidentiality of individuals who interact with our website and institutional communications. This Privacy Policy describes our practices in accordance with applicable data protection legislation, including the UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data and, where applicable, the General Data Protection Regulation (GDPR).
Introduction
This Privacy Policy applies to personal data collected through the PWX LLC website (the “Site”), enquiry forms, email correspondence, and related institutional communications. It does not govern the data practices of our operating divisions, portfolio companies, or counterparties, which may maintain separate privacy notices appropriate to their regulated activities.
By accessing or using the Site, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our practices, please discontinue use of the Site. For questions regarding this policy, please contact us using the details in Section 14 below or visit our Contact page.
Data Controller
The data controller responsible for personal data processed through this Site is PWX LLC, headquartered in Lewes, Delaware, United States. Where PWX processes personal data on behalf of an operating division or subsidiary, that entity may act as an independent or joint controller depending on the nature of the processing activity.
For institutional enquiries relating to a specific division — including PWA (Energy Trading & Commodity Markets), PWS (Maritime Logistics & Shipping), PWF (Institutional Investment Management), PWE (Energy Engineering & Technical Services), PWT (Digital Transformation & Enterprise Technology), PWD (Infrastructure Construction & EPC), or PWH (Healthcare Infrastructure & Life Sciences) — data may be shared internally on a need-to-know basis to respond to your request. Learn more about our platform on the About page or explore our operating divisions.
2.1 Scope & Applicability
If you are located in the European Economic Area, United Kingdom, or Switzerland, the GDPR (or UK GDPR) applies to our processing of your personal data through this Site. If you are in the United Arab Emirates, Federal Decree-Law No. 45 of 2021 applies. Where both frameworks apply, we apply the higher standard of protection.
Information We Collect
We collect personal data that you voluntarily provide and certain technical data generated automatically when you use the Site.
3.1 Information You Provide
- Contact and identity data: name, title, organisation, email address, telephone number, and country of residence submitted through enquiry forms or correspondence.
- Enquiry content: subject matter, message body, and any attachments or supplementary information you choose to share.
- Professional information: role, institutional affiliation, and nature of proposed engagement, where relevant to routing and response.
3.2 Automatically Collected Data
- Technical request data: IP address, requested URL or path, HTTP request headers (including user-agent), timestamps, and similar metadata recorded by our hosting and security infrastructure when you access the Site.
- Security and abuse-prevention data: rate-limit counters and related operational records used to protect the Site against automated abuse.
- Cookie and preference data: as described in Section 6 below. We do not currently deploy third-party analytics, advertising, or behavioural tracking technologies on the public Site.
We do not intentionally collect sensitive personal data (such as health information, biometric data, or government-issued identification numbers) through the Site. Please refrain from submitting such information unless specifically requested in a regulated context.
How We Use Personal Data
We process personal data for legitimate institutional purposes, including:
- Responding to enquiries, partnership proposals, and institutional correspondence submitted through the Site or by email.
- Routing communications to the appropriate corporate affairs, divisional, or compliance function.
- Operating, maintaining, and securing the Site, including infrastructure logging, rate limiting, and security analysis.
- Complying with legal obligations, regulatory requests, and internal governance requirements.
- Protecting the rights, property, and safety of PWX, our personnel, counterparties, and the public.
- Recording and honouring cookie and consent preferences so that we can respect your choices.
We do not sell personal data. We do not use enquiry information for unsolicited marketing without your explicit consent.
We do not use automated decision-making or profiling that produces legal or similarly significant effects on individuals.
Legal Bases for Processing
Where the GDPR or equivalent legislation applies, we rely on one or more of the following legal bases:
- Legitimate interests: to respond to enquiries, operate the Site, maintain security, and conduct institutional communications — balanced against your privacy rights.
- Consent: where you have provided explicit consent, such as for non-essential cookies or optional communications.
- Contractual necessity: where processing is required to take steps at your request prior to entering into a formal engagement.
- Legal obligation: where processing is necessary to comply with applicable law, regulation, or lawful governmental request.
5.1 Processing Activity Mapping
The following table summarises the principal legal bases we rely on for common processing activities:
- Responding to enquiry forms: legitimate interests and, where applicable, pre-contractual steps at your request.
- Site security and rate limiting: legitimate interests and legal obligation.
- Non-essential cookies and analytics: consent.
- Record-keeping of correspondence: legitimate interests and legal obligation.
Third-Party Processors & Disclosure
We may share personal data with trusted third parties who assist us in operating the Site and conducting our institutional activities, including:
- Hosting, cloud infrastructure, and content delivery providers.
- Analytics and performance monitoring services, where deployed on the public Site with your consent.
- Email and communication platform providers.
- Professional advisers, including legal, audit, and compliance consultants, bound by confidentiality obligations.
- Regulatory authorities, law enforcement, or judicial bodies where required by applicable law.
All third-party processors are subject to contractual safeguards requiring appropriate technical and organisational measures to protect personal data. We do not authorise third parties to use your data for their own marketing purposes.
In the event of a corporate transaction — such as a merger, acquisition, or restructuring — personal data may be transferred to the successor entity subject to equivalent privacy protections.
International Data Transfers
As a globally oriented institutional platform headquartered in Lewes, Delaware, United States, PWX may transfer personal data to jurisdictions outside your country of residence, including the UAE, European Economic Area, United Kingdom, United States, and other markets where our divisions maintain operations. Learn more about our footprint on the Global Presence page.
Where personal data is transferred to countries not recognised as providing an adequate level of data protection, we implement appropriate safeguards — such as standard contractual clauses, binding corporate rules, or other mechanisms approved under applicable law — to ensure your data receives a commensurate level of protection.
Data Retention
We retain personal data only for as long as necessary to fulfil the purposes described in this policy. Indicative retention periods include:
- Enquiry data: 24 months after last correspondence, or until the matter is closed and any applicable limitation period has expired.
- Server and security logs: 90 days.
- Cookie consent records: 12 months.
We review retention periodically and delete or anonymise data when no longer required.
Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Access: request a copy of the personal data we hold about you.
- Rectification: request correction of inaccurate or incomplete data.
- Erasure: request deletion of your data, subject to legal retention obligations.
- Restriction: request limitation of processing in certain circumstances.
- Portability: request transfer of your data to another controller, where technically feasible.
- Objection: object to processing based on legitimate interests or for direct marketing purposes.
- Withdraw consent: where processing is based on consent, withdraw it at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, email privacy@pwx.group with the subject line “Data Subject Request” and a description of your request. We may require reasonable identity verification before responding. We will respond within 30 days where the GDPR applies, or within the timeframe required under UAE law.
You also have the right to lodge a complaint with a supervisory authority. In the UAE, you may contact the UAE Data Office. In the EEA, UK, or Switzerland, you may contact the data protection authority in your country of residence.
Data Security
PWX implements technical and organisational measures designed to protect personal data against unauthorised access, alteration, disclosure, or destruction. These measures include access controls, encryption in transit, secure hosting environments, and staff training on data protection obligations.
While we take reasonable precautions, no method of transmission over the internet or electronic storage is entirely secure. We cannot guarantee absolute security but are committed to promptly addressing any confirmed data breach in accordance with applicable notification requirements.
Children’s Privacy
The Site is intended for institutional and professional audiences. We do not knowingly collect personal data from individuals under the age of 18. If you believe we have inadvertently collected data from a minor, please contact us and we will take steps to delete such information promptly.
Changes to This Policy
We may update this Privacy Policy periodically to reflect changes in our practices, technology, legal requirements, or business operations. The “Last updated” date at the top of this page indicates when the policy was most recently revised. Material changes will be communicated through the Site or, where appropriate, by direct notice.
We encourage you to review this policy regularly. Your continued use of the Site after changes are posted constitutes acknowledgment of the updated policy. For related legal terms governing use of the Site, please see our Terms of Use.
Contact Us
For questions, requests, or complaints regarding this Privacy Policy or our data protection practices, please contact:
PWX LLC — Data Protection
PWX LLC
Corporate Registry No. 10688455
16192 Coastal Highway, Lewes, Delaware 19958, United States
Branch: Offices 809 to 811, Level 8, Burj Daman, DIFC, UAE
Email: privacy@pwx.group
For general institutional enquiries unrelated to data protection, please use our Contact form or email enquiries@pwx.group.
Questions about how we handle your personal data?