Legal details

Privacy Policy

Last updated: 20 August 2026

1. Introduction

This Privacy Policy explains how MAXMAKE LTD ("MAXMAKE", "we", "us", or "our") collects, uses, stores, and protects personal data when you visit or use our website maxmake.eu and our services.

MAXMAKE LTD is a company incorporated in the United Kingdom under company number 17332665.

We are committed to protecting your personal data and processing it in accordance with applicable data protection legislation, including the UK General Data Protection Act 2018, the UK GDPR, and other applicable privacy and data protection laws.

By using our website or services, you acknowledge that your personal data may be processed as described in this Privacy Policy.

2. Data Controller

For the purposes of applicable data protection legislation, MAXMAKE LTD is the data controller responsible for your personal data.

  • Company: MAXMAKE LTD
  • Company number: 17332665
  • Website: https://maxmake.eu
  • Privacy contact: info@maxmake.eu

If you have any questions about how we process your personal data or wish to exercise your data protection rights, you may contact us at info@maxmake.eu.

3. Personal Data We May Collect

Depending on how you use our website and services, we may collect and process the following categories of personal data:

3.1 Identification and contact information

This may include:

  • full name;
  • date of birth;
  • nationality;
  • country of residence;
  • residential or correspondence address;
  • email address;
  • telephone number.

3.2 Identity verification information

Where identity verification or KYC procedures are required, we may process:

  • identity document details;
  • passport, identity card or other identification documents;
  • photographs of identification documents;
  • photographs or selfies;
  • facial images or video recordings where required for verification;
  • information extracted from identity documents;
  • information relating to the validity or authenticity of identification documents.

3.3 KYC, AML and compliance information

Where required for compliance and risk management purposes, we may process information relating to:

  • sanctions screening;
  • politically exposed person (PEP) screening;
  • anti-money laundering (AML) checks;
  • fraud prevention;
  • identity verification results;
  • risk indicators;
  • information obtained from public registers, databases or other lawful sources.

3.4 Technical information

When you visit our website, we may automatically collect certain technical information, including:

  • IP address;
  • browser type and version;
  • operating system;
  • device information;
  • approximate location derived from IP address;
  • date and time of website access;
  • pages visited;
  • referring website;
  • technical logs and security information.

4. How We Collect Personal Data

We may collect personal data:

  • directly from you when you provide information through our website or services;
  • when you create or use an account;
  • when you contact us;
  • when you undergo identity verification or KYC procedures;
  • from documents that you submit for verification;
  • from third-party verification and compliance service providers;
  • from publicly available registers and databases;
  • automatically through your use of our website and technical systems.

Where we obtain personal data from a source other than you, we will process that information in accordance with applicable data protection laws.

5. Why We Process Your Personal Data

We may process personal data for the following purposes:

5.1 Providing our services

We may use your information to:

  • provide and administer our services;
  • communicate with you;
  • create and maintain your account;
  • process requests and transactions;
  • provide customer support.

5.2 Identity verification and KYC

We may process your personal data to verify your identity and establish that the information you provide is accurate.

Where required, we use third-party identity verification providers, including Sumsub, to perform identity verification and related checks.

5.3 AML, sanctions and fraud prevention

We may process personal data to:

  • comply with applicable anti-money laundering requirements;
  • conduct sanctions and PEP screening;
  • detect and prevent fraud;
  • identify suspicious or prohibited activity;
  • assess risks associated with our services;
  • protect our business, customers and systems.

5.4 Legal and regulatory compliance

We may process personal data where necessary to:

  • comply with applicable laws and regulations;
  • respond to lawful requests from competent authorities;
  • comply with court orders or legal proceedings;
  • maintain records required by law;
  • establish, exercise or defend legal claims.

5.5 Security

We may process personal data to protect our website, systems, users and business against:

  • fraud;
  • unauthorised access;
  • cyberattacks;
  • abuse;
  • other security threats.

5.6 Business administration

We may also process personal data for legitimate business purposes, including maintaining records, improving our services, managing our website and maintaining the security and functionality of our systems.

7. Identity Verification and Sumsub

To perform identity verification, KYC, AML, fraud prevention and related compliance checks, MAXMAKE LTD may use the services of Sumsub, provided by Sum and Substance Ltd. and/or its relevant affiliated companies.

Sumsub may process information provided during the verification process, including identification information, identity documents, photographs, selfies, biometric information where applicable, technical information and verification results.

The purpose of using Sumsub is to enable us to verify your identity and perform relevant compliance and fraud-prevention checks.

For service delivery, Sumsub describes its role as processing personal data on behalf of its clients, while MAXMAKE determines the purposes of processing. Sumsub also maintains its own privacy notices explaining processing it carries out in its own capacity.

Before personal data is transferred to Sumsub, applicable privacy disclosures and consents will be provided through the relevant verification flow. Depending on the technical integration used by MAXMAKE, certain consent and disclosure steps may be handled by the Sumsub SDK or may need to be implemented by MAXMAKE.

For more information about Sumsub's processing of personal data, you should also review the applicable Sumsub Privacy Notice (Service Delivery).

8. Biometric and Special Category Data

Certain identity verification processes may involve the processing of biometric information, such as facial images or other information used for identity verification.

Where such information constitutes special category data or biometric data under applicable law, MAXMAKE will process it only where an appropriate legal condition applies.

Where consent is required by applicable law, we will obtain the required consent through the relevant verification process.

9. Sharing Personal Data

We may share personal data with trusted third parties where necessary for the purposes described in this Privacy Policy.

These may include:

  • identity verification providers;
  • AML and sanctions screening providers;
  • fraud prevention providers;
  • hosting and cloud service providers;
  • IT and cybersecurity providers;
  • payment and financial service providers, where applicable;
  • professional advisers;
  • auditors;
  • legal advisers;
  • insurers;
  • regulators, government authorities and law enforcement agencies where legally required.

Third-party service providers are expected to process personal data only as necessary to provide their services to us and in accordance with applicable data protection requirements.

We do not sell your personal data.

10. International Data Transfers

Some of our service providers or their infrastructure may be located outside the United Kingdom.

Where personal data is transferred internationally, we will take appropriate steps to ensure that the transfer is lawful and that appropriate safeguards are in place as required by applicable data protection legislation.

Such safeguards may include:

  • an adequacy decision or adequacy regulations;
  • UK International Data Transfer Agreements;
  • UK Addendum to EU Standard Contractual Clauses;
  • other legally recognised transfer mechanisms and safeguards.

11. How Long We Keep Personal Data

We retain personal data only for as long as reasonably necessary for the purposes for which it was collected, including to satisfy legal, regulatory, accounting, compliance and reporting requirements.

The applicable retention period may depend on:

  • the type of personal data;
  • the purpose for which it was collected;
  • our legal and regulatory obligations;
  • whether a business relationship remains active;
  • the need to establish, exercise or defend legal claims;
  • security and fraud-prevention requirements.

Where we are required to retain KYC, AML or transaction-related information by law or regulation, we may retain such information for the legally required period.

When personal data is no longer required, we will securely delete it or anonymise it where appropriate.

12. Data Security

We take reasonable technical and organisational measures to protect personal data against:

  • accidental or unlawful destruction;
  • loss;
  • alteration;
  • unauthorised disclosure;
  • unauthorised access;
  • other unlawful forms of processing.

Access to personal data is limited to persons and service providers who require it for legitimate business or legal purposes.

However, no method of transmitting or storing information can be guaranteed to be completely secure.

13. Your Data Protection Rights

Subject to applicable law, you may have the following rights in relation to your personal data:

  • Right of access — to request a copy of the personal data we hold about you.
  • Right to rectification — to request correction of inaccurate or incomplete information.
  • Right to erasure — to request deletion of your personal data in certain circumstances.
  • Right to restriction — to request that we restrict the processing of your personal data in certain circumstances.
  • Right to object — to object to certain types of processing, including processing based on legitimate interests.
  • Right to data portability — where applicable, to receive certain personal data in a structured, commonly used and machine-readable format.
  • Right to withdraw consent — where processing is based on consent.
  • Rights relating to automated decision-making — where applicable under data protection law.

These rights are not absolute and may be subject to legal limitations or exemptions.

14. How to Exercise Your Rights

To exercise any of your rights or ask a question about the processing of your personal data, please contact:

Email: info@maxmake.eu

We may need to verify your identity before fulfilling certain requests in order to protect your personal data from unauthorised disclosure.

We will respond to valid requests within the timeframe required by applicable data protection legislation.

15. Automated Decision-Making and Profiling

Certain verification, AML, sanctions or fraud-prevention processes may involve automated tools or risk assessment systems.

Where applicable, such systems may generate risk indicators or verification results that assist MAXMAKE in assessing an application or transaction.

Where applicable data protection law provides rights in relation to solely automated decision-making that produces legal or similarly significant effects, we will provide the rights and safeguards required by law.

16. Cookies

Our website may use cookies and similar technologies to ensure that the website operates correctly, improve security and functionality, understand website usage and, where applicable, provide analytics or other features.

Where applicable, non-essential cookies will only be used in accordance with applicable cookie and privacy requirements.

You may be able to manage cookies through your browser settings or through any cookie management mechanism provided on our website.

17. Third-Party Websites

Our website may contain links to third-party websites or services.

We are not responsible for the privacy practices, content or security of third-party websites.

You should review the privacy policy of any third-party website before providing personal data to it.

18. Children's Data

Our services are not intended for children unless expressly stated otherwise.

We do not knowingly collect personal data from children where such collection is prohibited by applicable law.

If you believe that a child has provided us with personal data unlawfully, please contact us at info@maxmake.eu.

19. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our services, technology, legal requirements or data processing practices.

The latest version will always be made available on our website.

The date at the top of this Privacy Policy indicates when it was last updated.

20. Complaints

If you have concerns about the way MAXMAKE LTD processes your personal data, please contact us first at:

info@maxmake.eu

You also have the right to lodge a complaint with the UK's data protection supervisory authority:

Information Commissioner's Office (ICO)

Website: https://ico.org.uk/

The ICO is the independent supervisory authority responsible for data protection in the United Kingdom.

21. Contact Us

If you have any questions about this Privacy Policy or our processing of personal data, please contact:

  • MAXMAKE LTD
  • Company number: 17332665
  • United Kingdom
  • Website: https://maxmake.eu
  • Email: info@maxmake.eu

Last updated: 20 August 2026