1. Introduction & Scope
This Policy applies to personal data we process about visitors to our website, prospective customers completing onboarding, and active customers — individuals and, for business accounts, the authorized representatives, Ultimate Beneficial Owners (UBOs), and directors associated with that business.
2. Data Controller Information
Softsyncron Limited, 20 Wenlock Road, London, N1 7GU, is the data controller responsible for your personal data in connection with the Services, except where a Partner Bank or BaaS provider acts as an independent controller for data it processes to provide regulated banking or payment services directly, as disclosed in Section 5. Our contact details for data protection matters are set out in Section 13.
3. Categories of Personal Data We Collect
We collect the following categories of personal data:
Account & contact data
- Full legal name, date of birth, nationality, residential address, and email/phone contact details.
KYC identity verification data (individual customers)
- Government-issued identity document images and extracted data (e.g., passport, national ID, driver’s license);
- Biometric data captured during liveness verification (e.g., a selfie or short video, and the facial-match result derived from it);
- Proof-of-address documents, where required;
- Tax identification number (e.g., SSN or local equivalent), occupation, and self-declared source of funds.
KYB and UBO data (business customers)
Business & beneficial ownership data
For business accounts, we additionally collect: legal business name, registration number, date of incorporation, legal structure, registered business address and supporting proof-of-address document, business website or social presence, and — for every Ultimate Beneficial Owner holding 25% or more equity in the business — that individual’s full legal name, date of birth, nationality, ownership percentage, and independent identity verification data equivalent to the KYC data described above.
Transaction & usage data
- Transaction history, balances, invoices you create, and counterparties you transact with;
- Device, log, and cookie data described in Section 9.
4. How We Use Your Data
We process personal data under the following legal bases:
- Performance of a contract — to open and operate your account, process transactions, and provide customer support;
- Legal obligation — to perform identity verification, sanctions and PEP screening, transaction monitoring, and recordkeeping required by AML/CFT law and by our Partner Banks’ regulatory obligations;
- Legitimate interests — to detect and prevent fraud, secure our systems, and improve the Services, balanced against your rights and interests; and
- Consent — for optional communications or cookies where consent is the applicable basis, which you may withdraw at any time.
6. International Data Transfers
Because SyncroFi operates across multiple currency corridors and engages Partner Banks and vendors in different jurisdictions, personal data may be transferred outside your country of residence, including to [List of Transfer Jurisdictions]. Where required, such transfers are made subject to appropriate safeguards, such as Standard Contractual Clauses or an equivalent adequacy mechanism recognized under applicable data protection law.
7. Data Retention
We retain identity verification records, transaction history, and related compliance data for a minimum of [5 years / applicable statutory minimum] from the date of the relevant transaction or the end of the customer relationship, whichever is later, consistent with the recordkeeping obligations described in our AML Policy. We retain other personal data only as long as necessary for the purposes described in this Policy, or as required by law.
8. Your Rights Under GDPR
Subject to applicable law and the exceptions that apply to regulated financial data, you may have the right to:
- Access the personal data we hold about you;
- Request correction of inaccurate or incomplete data;
- Request erasure of your data, subject to our overriding legal obligation to retain compliance records;
- Request restriction of, or object to, certain processing;
- Receive a copy of your data in a portable format; and
- Lodge a complaint with your local data protection supervisory authority.
To exercise these rights, contact us using the details in Section 13. We may need to verify your identity before actioning a request.
10. Data Security
We apply administrative, technical, and physical safeguards designed to protect personal data, including encryption of data in transit and at rest, access controls limiting visibility to authorized personnel on a need-to-know basis, and the signature-verification and immutable audit-logging controls described in our Flow of Funds documentation. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
11. Children's Privacy
The Services are not directed to, and are not intended for use by, individuals under 18 years of age. We do not knowingly collect personal data from children.
12. Changes to This Policy
We may update this Policy from time to time. We will notify you of material changes electronically, consistent with our Electronic Communications Consent, before they take effect.
13. Contact Our Data Protection Officer
Questions about this Policy or requests to exercise your data rights can be directed to support@syncrofi.co.