Legal

Privacy notice

What personal data we process, why, on what legal basis, who it is shared with, how long it is kept and the rights you can exercise.

Last updated 29 August 2026 — Draft for legal review.

1. Who is responsible for your data

GBF Payment Services is the controller of the personal data described in this notice. The controlling entity depends on the market in which your account is held; the entity, its registration details and its contact address are provided at account opening and on the company page.

A data protection lead is appointed and can be contacted through the support route. In markets where a representative or data protection officer is required, the relevant contact is published.

2. Personal data we process

We process: identification data, including name, date of birth, nationality and identity document details; contact data, including address, email and telephone number; verification data, including document images, liveness images and the results of electronic verification checks; financial data, including account positions, instructions, counterparties, references and fees; technical data, including device identifiers, IP address, session data and security events; communications, including support messages and complaint records; and compliance data, including screening results, alert dispositions and internal reports.

We do not process special category data as a routine matter. Biometric data derived from a liveness check is processed only where verification requires it and only for that purpose.

3. Why we process it and on what basis

To provide the service. Opening and operating your account, executing instructions and providing support. Basis: performance of a contract with you.

To meet legal obligations. Customer due diligence, sanctions screening, transaction monitoring, reporting to competent authorities, record keeping, tax reporting and responding to lawful requests. Basis: compliance with a legal obligation, and substantial public interest where special category or criminal offence data is involved.

To prevent fraud and secure the platform. Device binding, authentication, anomaly detection and incident investigation. Basis: legitimate interests in protecting customers and the platform, and legal obligation where applicable.

To improve the service. Aggregate analysis of product usage and failure patterns. Basis: legitimate interests, using the least identifying data that meets the purpose.

To communicate with you. Service messages are sent on the basis of contract. Marketing messages, where offered, are sent only with consent, and consent can be withdrawn at any time without affecting the service.

4. Automated decisions

Verification, screening and monitoring involve automated processing. Where an automated decision produces a legal or similarly significant effect, you may request human review, express your point of view and contest the outcome, except where disclosure or review is restricted by financial crime law. Where a decision is restricted in this way, we tell you that a restriction applies without disclosing the underlying reason.

5. Who we share data with

We share personal data with: locally licensed payment partners and financial institutions necessary to execute an instruction; identity verification, screening and fraud prevention providers; technology providers that host and secure the platform, acting on our instructions under written terms; professional advisers; and competent authorities, regulators and courts where the law requires it.

We do not sell personal data. We do not share personal data for cross-context behavioural advertising.

6. International transfers

Personal data may be transferred outside the country in which it was collected, including to jurisdictions that do not provide an equivalent standard of protection. Where data leaves the United Kingdom or the European Economic Area, we rely on an adequacy decision where one exists, or otherwise on standard contractual clauses or the UK addendum, supported by a transfer risk assessment and additional technical and organisational measures where required.

7. How long we keep it

Identification and due diligence records, transaction records, screening results and related reports are retained for five years from the end of the relationship or the date of the transaction, and longer where a competent authority, ongoing investigation or legal claim requires it. Support and complaint records are retained for the period required in the relevant market. Technical security logs are retained for a shorter period proportionate to their purpose. When a retention period ends, data is deleted or irreversibly anonymised.

8. Your rights

Subject to the applicable law you may request access to your personal data, correction of inaccurate data, deletion where no legal obligation requires us to retain it, restriction of processing, portability of data you provided to us, and objection to processing based on legitimate interests. You may withdraw consent where processing is based on consent.

Rights are limited where financial crime law requires retention or prohibits disclosure. In particular, we cannot delete due diligence records within the statutory retention period, and we cannot disclose the content of a suspicious activity report.

Residents of California, Colorado, Connecticut, Virginia and other states with comparable law have rights to know, delete, correct and opt out of sale or sharing and of targeted advertising. As stated above, we do not sell or share personal data for those purposes. Requests are handled without discrimination in the level of service provided.

9. How to exercise a right

Submit a request through the support route from the account concerned. We verify identity before acting on a request, because acting on an unverified request would itself be a security risk. We respond within the period set by the applicable law and tell you if an extension applies and why.

10. Complaints about data

If you are dissatisfied with how we handle your personal data, contact us first so we can address it. You also have the right to complain to the supervisory authority in your country, including the Information Commissioner in the United Kingdom or the relevant supervisory authority in an EU member state.

11. Changes to this notice

We update this notice when our processing changes. The current version and its effective date are shown on this page. Where a change materially affects you, we tell you directly.