Legal Document

Privacy Policy

Effective date: 1 January 2025 Last updated: 1 June 2025

On this page

  • Introduction
  • Data We Collect
  • How We Use Data
  • Legal Basis
  • Data Sharing
  • International Transfers
  • Data Retention
  • Security
  • Your Rights
  • Cookies
  • Children
  • Policy Changes
  • Contact Us
Summary This Privacy Policy describes how Company Name ("we", "us", or "our") collects, uses, shares, and protects personal data processed through our B2B fintech platform and services. Please read it carefully.

Section 01

Introduction

Company Name operates a business-to-business financial technology platform that provides payment processing, financial analytics, compliance tooling, and related services to corporate clients ("Clients") and their authorised users ("Users"). This Privacy Policy applies to all information we collect when you access or use our platform, APIs, websites, or any associated service (collectively, the "Services").

Where our Clients collect and process personal data using our platform, Company Name acts as a data processor on their behalf, and the Client acts as the data controller. For data we collect independently (e.g., account data, usage analytics), Company Name is the data controller. Both scenarios are explained in this document.

By accessing or using our Services, you acknowledge that you have read and understood this Privacy Policy.

Section 02

Data We Collect

We collect information in three ways: data you provide directly, data generated automatically, and data obtained from third parties.

Category Examples Source
Account & Identity Name, work email, job title, company name, phone number, government-issued ID (where required for KYC) Provided by you
Financial Data Bank account details, payment card data (tokenised), transaction records, account balances Provided by you / payment processors
Compliance & KYB/KYC Corporate registration documents, beneficial owner information, sanctions screening results Provided by Client / third-party verification providers
Usage Data API call logs, feature usage, session duration, error events, IP address, browser or SDK version Automatically collected
Communication Data Support tickets, email correspondence, chat transcripts Provided by you
Device & Technical Device type, operating system, referrer URL, time-zone settings, cookies and similar identifiers Automatically collected

We do not knowingly collect or process sensitive categories of personal data (special category data under GDPR) unless mandated by applicable financial regulation.

Section 03

How We Use Data

We use the data we collect for the following purposes:

  • Service delivery — to operate, maintain, and provide the features of our platform, including processing payments, generating financial reports, and executing API integrations.
  • Account management — to onboard Clients, verify authorised Users, and manage subscriptions and billing.
  • Compliance & fraud prevention — to conduct Know Your Business (KYB) and Know Your Customer (KYC) checks, monitor transactions for suspicious activity, and meet anti-money laundering (AML) obligations.
  • Security — to detect, prevent, and investigate security incidents, abuse, or unauthorised access.
  • Product improvement — to analyse usage patterns, conduct A/B testing, and develop new features.
  • Communications — to send transactional notifications, service updates, and (where you have opted in) marketing communications.
  • Legal obligations — to comply with applicable laws, respond to regulatory requests, and defend legal claims.

Section 04

Legal Basis for Processing

Where GDPR or equivalent legislation applies, we rely on the following legal bases:

Legal BasisProcessing Activity
Contract Providing our Services, processing payments, managing your account
Legal Obligation KYC/KYB verification, AML monitoring, regulatory reporting, fraud detection
Legitimate Interests Product analytics, security monitoring, prevention of fraud and abuse
Consent Marketing emails, optional cookies, participation in surveys

Where we rely on legitimate interests, we balance those interests against your rights and will not override your fundamental privacy interests.

Section 05

Data Sharing

Company Name does not sell your personal data. We share data only in the following circumstances:

  • Service providers — cloud hosting, payment processors, KYC providers, fraud detection engines, and customer support tools, all bound by data processing agreements.
  • Financial partners — correspondent banks, card schemes, and payment networks where required to complete a transaction.
  • Regulatory & law enforcement — where required by applicable law, court order, or financial regulator (e.g., FCA, RBI, MAS).
  • Group companies — subsidiaries and affiliates of Company Name for internal operational purposes, under equivalent data protection standards.
  • Business transfers — in connection with a merger, acquisition, or sale of assets, with prior notice to you where required by law.
  • With your consent — in any other case, only with your explicit consent.

Section 06

International Data Transfers

Our infrastructure is hosted in data centres across India, the European Economic Area (EEA), and the United States. If we transfer your personal data outside your country of residence, we ensure appropriate safeguards are in place, including:

  • Standard Contractual Clauses (SCCs) approved by the European Commission;
  • Adequacy decisions recognised by the relevant data protection authority;
  • Binding Corporate Rules or other approved transfer mechanisms.

You may request a copy of the applicable safeguards by contacting our Data Protection Officer.

Section 07

Data Retention

We retain personal data only for as long as necessary to fulfil the purposes described in this Policy, including legal and regulatory obligations. Typical retention periods are:

  • Transaction & financial records — 7 years from the date of transaction (as required by financial regulation in most jurisdictions).
  • KYC / KYB documentation — 5 years from the end of the business relationship.
  • Account data — duration of the contractual relationship plus 2 years.
  • Usage and log data — up to 12 months, after which data is aggregated or deleted.
  • Support correspondence — 3 years from closure of the ticket.

After the applicable retention period, personal data is securely deleted or anonymised.

Section 08

Security

We implement appropriate technical and organisational measures to protect your data against unauthorised access, loss, or destruction. Our security programme includes:

  • Encryption of data in transit (TLS 1.2+) and at rest (AES-256);
  • Role-based access controls (RBAC) and principle of least privilege;
  • Regular penetration testing and vulnerability assessments;
  • SOC 2 Type II certification (or equivalent) maintained annually;
  • Incident response procedures with defined notification timelines.
Security incident? If you suspect a security incident or data breach involving your account, contact us immediately at security@companyname.com. We will investigate and respond within 72 hours.

Section 09

Your Rights

Depending on your jurisdiction, you may have the following rights with respect to your personal data:

  • Right of access — obtain a copy of the personal data we hold about you.
  • Right to rectification — correct inaccurate or incomplete data.
  • Right to erasure — request deletion of your data, subject to legal retention obligations.
  • Right to restrict processing — ask us to limit how we use your data.
  • Right to data portability — receive your data in a structured, machine-readable format.
  • Right to object — object to processing based on legitimate interests or for direct marketing.
  • Right to withdraw consent — where processing is based on consent, withdraw it at any time without affecting the lawfulness of prior processing.
  • Right to lodge a complaint — complain to your local supervisory authority (e.g., India's Data Protection Board, the UK ICO, or an EU DPA).

To exercise any of these rights, submit a request to privacy@companyname.com. We will respond within 30 days (or as otherwise required by applicable law).

Section 10

Cookies

We use cookies and similar tracking technologies on our web properties. For full details on the types of cookies we use and your choices, please see our Cookie Policy.

Section 11

Children

Our Services are directed exclusively at businesses and their authorised personnel. We do not knowingly collect personal data from individuals under the age of 18. If you believe a minor has provided us with personal data, please contact us immediately and we will delete it.

Section 12

Policy Changes

We may update this Privacy Policy periodically to reflect changes in our practices or applicable law. When we make material changes, we will notify you by email (to the address associated with your account) and by displaying a prominent notice on our platform at least 30 days before the change takes effect.

Your continued use of the Services after the effective date constitutes acceptance of the revised Policy.

Section 13

Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy, please contact:

Data Protection Officer — Company Name Email: dpo@companyname.com
Registered Address: [Registered Office Address], India
Regulatory enquiries: compliance@companyname.com