Contents
- Information We Collect
- How We Use Your Information
- How We Protect Your Information
- Information Sharing and Disclosure
- Cookies and Tracking Technologies
- Data Retention
- Your Rights and Choices
- Children's Privacy
- International Data Transfers
- Third-Party Links and Services
- Changes to This Policy
- Contact Us
1. Information We Collect
We collect various types of information to provide and improve our banking services. The information we collect falls into the following categories:
a. Personal Identifying Information
- Full name, date of birth, nationality, and gender
- Government-issued identification documents (passport, national ID, driver's licence)
- Residential address, email address, and telephone numbers
- Social Security Number, Tax Identification Number, or equivalent national identifiers
b. Financial Information
- Bank account details, account balances, and transaction history
- Credit and debit card information (card number, expiry date, billing address)
- Credit score, income details, employment information, and financial history
- Loan application data, repayment records, and creditworthiness assessments
c. Technical and Usage Information
- IP address, browser type, operating system, and device identifiers
- Login credentials (encrypted usernames and passwords)
- Geolocation data (when enabled for fraud prevention)
- Session recordings, clickstream data, and pages visited on our platform
- Time and date of access, referral URLs, and exit pages
d. Communication Records
- Records of correspondence with our customer support team
- Feedback, reviews, and survey responses
- Transaction-related notifications and alerts
2. How We Use Your Information
We use the information we collect for the following purposes:
- Providing Services: Processing transactions, managing accounts, and delivering banking products and services you have requested
- Identity Verification: Verifying your identity during account opening, authentication, and transaction processing in compliance with anti-money laundering (AML), know-your-customer (KYC), and Counter-Terrorism Financing (CTF) regulations applicable across our operating jurisdictions
- Security and Fraud Prevention: Detecting, preventing, and investigating fraudulent activities, unauthorised access, and security breaches
- Regulatory Compliance: Meeting legal, regulatory, and reporting obligations under applicable banking, tax, and anti-money laundering laws in the UK and other jurisdictions where we operate
- Communication: Sending transaction confirmations, account statements, security alerts, service updates, and marketing communications (with your consent where required)
- Service Improvement: Analysing usage patterns, conducting research, and improving the functionality, user experience, and security of our platform
- Credit Assessment: Evaluating loan and credit card applications, determining creditworthiness, and setting account limits
- Customer Support: Responding to inquiries, resolving disputes, and providing personalised assistance
3. How We Protect Your Information
We implement multiple layers of security to safeguard your personal and financial data:
- Encryption: All data transmitted between your browser and our servers is encrypted using 256-bit Secure Socket Layer (SSL) technology. Sensitive data at rest is encrypted using AES-256 encryption standards
- Multi-Factor Authentication (MFA): We offer and encourage the use of multi-factor authentication for account access and high-risk transactions
- Firewalls and Intrusion Detection: Enterprise-grade firewalls, intrusion detection systems, and continuous network monitoring protect against unauthorised access
- Access Controls: Strict role-based access controls ensure that only authorised personnel can access your information, and only to the extent necessary for their duties
- Secure Facilities: Our data centres are housed in physically secured facilities with 24/7 surveillance, biometric access controls, and environmental protections
- Regular Audits: We undergo regular independent security audits, penetration testing, and vulnerability assessments
- Staff Training: All employees receive mandatory data protection and security awareness training upon hiring and on an ongoing basis
Important: While we take every reasonable measure to protect your information, no method of electronic storage or transmission over the Internet is 100% secure. We encourage you to use strong, unique passwords and enable two-factor authentication on your account.
4. Information Sharing and Disclosure
We do not sell, rent, or trade your personal information. We may share your information only in the following circumstances:
- With Your Consent: When you explicitly authorise us to share your information with specific third parties
- Service Providers: With trusted third-party vendors who assist us in operating our platform (payment processors, cloud infrastructure providers, identity verification services), bound by contractual obligations to protect your data
- Regulatory and Legal Requirements: When required by law, regulation, court order, or governmental authority, including compliance with AML, KYC, and Counter-Terrorism Financing (CTF) obligations
- Financial Institutions: With correspondent banks, payment networks (Visa, Mastercard, SWIFT), and other financial institutions worldwide as necessary to process your transactions
- Business Transfers: In connection with a merger, acquisition, reorganisation, or sale of assets, your information may be transferred as part of that transaction, subject to the receiving entity honouring this Privacy Policy
- Protection of Rights: When we believe disclosure is necessary to protect our rights, your safety, or the safety of others, investigate fraud, or respond to a lawful request
5. Cookies and Tracking Technologies
We use cookies and similar technologies to enhance your experience on our platform:
- Essential Cookies: Required for core platform functionality, session management, and security. These cannot be disabled
- Performance Cookies: Help us understand how visitors interact with our platform by collecting anonymised usage data
- Functionality Cookies: Remember your preferences, language settings, and display options to provide a personalised experience
- Security Cookies: Assist in fraud detection and help verify your identity during login
You can manage your cookie preferences through your browser settings. Disabling essential cookies may impair platform functionality.
6. Data Retention
We retain your personal information for as long as necessary to fulfil the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law in the applicable jurisdiction. Specifically:
- Account Data: Retained for the duration of your account relationship and for a minimum of seven (7) years after account closure, in accordance with applicable banking regulations
- Transaction Records: Retained for a minimum of seven (7) years from the date of the transaction, as required by anti-money laundering legislation
- Communication Records: Retained for a minimum of three (3) years from the date of communication
- Technical Logs: Retained for a maximum of twelve (12) months from the date of collection
7. Your Rights and Choices
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Right of Access: Request a copy of the personal information we hold about you
- Right to Rectification: Request correction of inaccurate or incomplete personal information
- Right to Erasure: Request deletion of your personal information, subject to legal retention obligations
- Right to Restrict Processing: Request that we limit the processing of your personal information in certain circumstances
- Right to Data Portability: Receive your personal data in a structured, commonly used, machine-readable format
- Right to Object: Object to the processing of your personal information for direct marketing purposes
- Right to Withdraw Consent: Withdraw previously given consent at any time, without affecting the lawfulness of processing conducted prior to withdrawal
To exercise any of these rights, please contact our Data Protection Officer using the details provided in the Contact Us section below. We will respond to your request within thirty (30) calendar days.
8. Children's Privacy
Our services are not directed to individuals under the age of eighteen (18). We do not knowingly collect personal information from children. If we become aware that we have collected personal data from a child without parental consent, we will take immediate steps to delete that information. If you believe we have collected information from a child, please contact us immediately.
9. International Data Transfers
As a UK-based bank serving customers globally, your information may be transferred to and processed in the United Kingdom or in countries other than your country of residence. When we transfer data across borders, we ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses (SCCs) approved by relevant regulatory authorities
- Adequacy decisions confirming adequate data protection in the recipient jurisdiction
- Binding Corporate Rules where applicable
- Compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018
10. Third-Party Links and Services
Our platform may contain links to third-party websites, plugins, or services that are not operated by us. We are not responsible for the privacy practices of these third parties. We encourage you to review the privacy policy of every site you visit. A link to a third-party site does not constitute our endorsement of that site or its services.
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will notify you by:
- Posting the updated policy on this page with a revised "Last Updated" date
- Sending an email notification to the address associated with your account
- Displaying a prominent notice on our platform prior to the changes taking effect
We encourage you to review this page periodically for the latest information on our privacy practices.
12. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Data Protection Officer
Trust Union Holdings
United Kingdom
Email: info@trustunionholdings.com
Phone: +44 7508 275625
If you are located outside the United Kingdom, you may also have the right to lodge a complaint with your local data protection supervisory authority.
