SyncroFi

Legal

Privacy Policy

This Privacy Policy explains how Softsyncron Limited (“Softsyncron,” “we,” “us,” or “our”), operating SyncroFi, collects, uses, shares, and protects personal data, including in connection with identity verification required by financial regulation. It is designed to align with the EU/UK General Data Protection Regulation (GDPR) and comparable data protection frameworks.

Effective date: [Effective Date] · Softsyncron Limited, operating as SyncroFi

1. Introduction & Scope

This Policy applies to personal data we process about visitors to our website, prospective customers completing onboarding, and active customers — individuals and, for business accounts, the authorized representatives, Ultimate Beneficial Owners (UBOs), and directors associated with that business.

2. Data Controller Information

Softsyncron Limited, 20 Wenlock Road, London, N1 7GU, is the data controller responsible for your personal data in connection with the Services, except where a Partner Bank or BaaS provider acts as an independent controller for data it processes to provide regulated banking or payment services directly, as disclosed in Section 5. Our contact details for data protection matters are set out in Section 13.

3. Categories of Personal Data We Collect

We collect the following categories of personal data:

Account & contact data

  • Full legal name, date of birth, nationality, residential address, and email/phone contact details.

KYC identity verification data (individual customers)

  • Government-issued identity document images and extracted data (e.g., passport, national ID, driver’s license);
  • Biometric data captured during liveness verification (e.g., a selfie or short video, and the facial-match result derived from it);
  • Proof-of-address documents, where required;
  • Tax identification number (e.g., SSN or local equivalent), occupation, and self-declared source of funds.

KYB and UBO data (business customers)

Business & beneficial ownership data

For business accounts, we additionally collect: legal business name, registration number, date of incorporation, legal structure, registered business address and supporting proof-of-address document, business website or social presence, and — for every Ultimate Beneficial Owner holding 25% or more equity in the business — that individual’s full legal name, date of birth, nationality, ownership percentage, and independent identity verification data equivalent to the KYC data described above.

Transaction & usage data

  • Transaction history, balances, invoices you create, and counterparties you transact with;
  • Device, log, and cookie data described in Section 9.

4. How We Use Your Data

We process personal data under the following legal bases:

  • Performance of a contract — to open and operate your account, process transactions, and provide customer support;
  • Legal obligation — to perform identity verification, sanctions and PEP screening, transaction monitoring, and recordkeeping required by AML/CFT law and by our Partner Banks’ regulatory obligations;
  • Legitimate interests — to detect and prevent fraud, secure our systems, and improve the Services, balanced against your rights and interests; and
  • Consent — for optional communications or cookies where consent is the applicable basis, which you may withdraw at any time.

5. Sharing Your Data with Third Parties

We share personal data, limited to what is necessary for the purpose, with:

  • Identity verification vendors (illustrative examples: Sumsub, Onfido), who process your identity documents and biometric data to perform document authentication, liveness verification, and sanctions/PEP screening on our behalf, including for every UBO and director on a business account;
  • Partner Banks and BaaS providers (including our banking partners and cross-border payment rail providers), who receive account and transaction data necessary to issue your virtual account, hold funds, and execute payouts, and who may independently act as data controllers for their own regulatory compliance;
  • Regulators and law enforcement, where required by law, in connection with a regulatory examination, or in response to a valid legal request;
  • Service providers supporting hosting, analytics, customer support, and communications, under contractual confidentiality and data protection obligations; and
  • A successor entity in connection with a merger, acquisition, or asset sale, subject to equivalent data protection commitments.

We do not sell personal data.

6. International Data Transfers

Because SyncroFi operates across multiple currency corridors and engages Partner Banks and vendors in different jurisdictions, personal data may be transferred outside your country of residence, including to [List of Transfer Jurisdictions]. Where required, such transfers are made subject to appropriate safeguards, such as Standard Contractual Clauses or an equivalent adequacy mechanism recognized under applicable data protection law.

7. Data Retention

We retain identity verification records, transaction history, and related compliance data for a minimum of [5 years / applicable statutory minimum] from the date of the relevant transaction or the end of the customer relationship, whichever is later, consistent with the recordkeeping obligations described in our AML Policy. We retain other personal data only as long as necessary for the purposes described in this Policy, or as required by law.

8. Your Rights Under GDPR

Subject to applicable law and the exceptions that apply to regulated financial data, you may have the right to:

  • Access the personal data we hold about you;
  • Request correction of inaccurate or incomplete data;
  • Request erasure of your data, subject to our overriding legal obligation to retain compliance records;
  • Request restriction of, or object to, certain processing;
  • Receive a copy of your data in a portable format; and
  • Lodge a complaint with your local data protection supervisory authority.

To exercise these rights, contact us using the details in Section 13. We may need to verify your identity before actioning a request.

9. Cookies & Tracking

We use strictly necessary cookies to operate the Services (e.g., session authentication) and, where you consent, analytics cookies to understand how the Services are used. You can manage cookie preferences through your browser settings.

10. Data Security

We apply administrative, technical, and physical safeguards designed to protect personal data, including encryption of data in transit and at rest, access controls limiting visibility to authorized personnel on a need-to-know basis, and the signature-verification and immutable audit-logging controls described in our Flow of Funds documentation. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

11. Children's Privacy

The Services are not directed to, and are not intended for use by, individuals under 18 years of age. We do not knowingly collect personal data from children.

12. Changes to This Policy

We may update this Policy from time to time. We will notify you of material changes electronically, consistent with our Electronic Communications Consent, before they take effect.

13. Contact Our Data Protection Officer

Questions about this Policy or requests to exercise your data rights can be directed to support@syncrofi.co.