Legal
What we collect, why we hold it, and what you can ask us to do with it.
Last updated 1 January 2026
Identity data: your name, date of birth, nationality, address and the documents you supply for verification. Contact data: email and mobile number. Financial data: your accounts, balances, transactions and the postings behind them. Technical data: the device and IP address a session was created from, so you can recognise your own sessions and spot one that is not yours.
To operate your account and execute your instructions. To verify your identity and meet anti-money-laundering obligations. To detect and prevent fraud. To produce statements and regulatory reports. We do not sell your data and we do not use it to train models.
Card numbers and national identifiers are encrypted at rest. Passwords are hashed with argon2id and are never recoverable, by us or by anyone else. Logs are passed through a redaction filter that strips card numbers, tokens, passwords and dates of birth before anything is written.
Access to customer data by staff is role-gated and every access is written to an append-only, hash-chained audit log.
You can request a copy of your data, ask for a correction, or ask us to delete it where we are not required to keep it. Request a data export from Settings; we respond within 30 days.
Where we must keep records for regulatory reasons we will tell you which records and for how long.