Last updated: January 2025 · Effective date: 1 January 2025 · Version 1.0
Your privacy matters to us. This Privacy Policy explains what personal data we collect about you, why we collect it, how we use it, who we share it with, and what rights you have. Please read it carefully. This policy applies to all users of mbo.finance regardless of where you are located.
The data controller responsible for your personal data is:
mbo.finance Ltd
Company Number: [COMPANY NUMBER]
Registered Address: [REGISTERED ADDRESS]
United Kingdom
Email: privacy@mbo.finance
As a data controller, mbo.finance Ltd determines the purposes and means of processing your personal data. Where we process data on behalf of regulatory or law enforcement authorities, we may act as a data processor.
We are registered with the Information Commissioner's Office (ICO) in the United Kingdom under registration number [ICO REGISTRATION NUMBER].
We collect personal data from you in the following categories:
In certain circumstances, we may process special categories of personal data as defined under applicable data protection law, such as biometric data used for identity verification. We will only process such data where we have a specific legal basis to do so, and we implement enhanced safeguards for its protection.
| Purpose | Data Used | Legal Basis |
|---|---|---|
| Creating and managing your account | Identity, contact | Contract performance |
| Identity verification (KYC) | Identity, contact, documents | Legal obligation |
| Processing transactions | Identity, financial | Contract performance |
| AML/CTF screening and monitoring | Identity, financial, technical | Legal obligation |
| Fraud prevention and security | Identity, technical | Legitimate interests |
| Customer support | Identity, contact, communications | Contract performance |
| Regulatory reporting | Identity, financial | Legal obligation |
| Service improvement and analytics | Technical, usage | Legitimate interests |
| Marketing communications | Contact | Consent |
| Legal claims and disputes | All categories as relevant | Legitimate interests / legal obligation |
We process your personal data on the following legal bases under UK GDPR and equivalent legislation:
We share your personal data only where necessary and with appropriate safeguards in place. Recipients include:
Third-party companies that provide services on our behalf, including:
All service providers are contractually bound to process data only on our instructions and to maintain appropriate security measures.
We are legally obligated to share data with:
In the event of a merger, acquisition, or sale of all or a portion of our assets, your personal data may be transferred to the acquiring entity, subject to the same privacy protections outlined in this policy.
Lawyers, accountants, auditors, and other professional advisers where necessary for the conduct of our business, subject to professional confidentiality obligations.
We do not sell your personal data to third parties for commercial purposes.
As a platform serving users in multiple countries, your personal data may be transferred to and processed in countries outside your country of residence, including countries outside the United Kingdom and European Economic Area (EEA).
Where we transfer personal data internationally, we ensure appropriate safeguards are in place, including:
You may request details of the specific safeguards we have in place for international data transfers by contacting privacy@mbo.finance.
| Data Category | Retention Period | Reason |
|---|---|---|
| Account and identity data | 5 years after account closure | AML/CTF legal obligations (UK: MLR 2017) |
| Transaction records | 5 years after account closure | AML/CTF legal obligations |
| KYC documents | 5 years after account closure | AML/CTF legal obligations |
| Communications / support records | 3 years after last contact | Legitimate interests / legal claims |
| Marketing consent records | Until withdrawn + 3 years | Proof of consent |
| Technical / log data | 12 months | Security monitoring |
| Cookie data | Up to 12 months | See Cookie Policy below |
Retention periods may be extended where required by applicable law, ongoing investigations, or legal proceedings. Where data is no longer required, it is securely deleted or anonymised.
Canada (PIPEDA): Personal data is retained only as long as necessary to fulfil the stated purposes and legal obligations, after which it is destroyed, erased, or anonymised.
Australia (Privacy Act): We take reasonable steps to destroy or de-identify personal data when it is no longer needed for any purpose for which it may be used or disclosed.
We use cookies and similar tracking technologies on our platform. Our use of cookies is limited to:
| Cookie Type | Purpose | Duration |
|---|---|---|
| Essential / Session | Maintaining your login session, security, preventing fraud | Session / Up to 24 hours |
| Preference | Remembering your cookie consent choice | 12 months |
| Analytics | Understanding how users interact with our platform (anonymised) | Up to 12 months |
We do not use advertising or tracking cookies. We do not share cookie data with advertising networks.
You can manage your cookie preferences through your browser settings. Disabling essential cookies may affect the functionality of our platform. You may withdraw your consent to non-essential cookies at any time by clearing your browser cookies.
Depending on your jurisdiction, you have the following rights regarding your personal data:
Request a copy of the personal data we hold about you (Subject Access Request).
Request correction of inaccurate or incomplete personal data.
Request deletion of your personal data, subject to legal retention obligations.
Request that we restrict processing of your data in certain circumstances.
Receive your data in a structured, machine-readable format.
Object to processing based on legitimate interests, including for marketing.
Withdraw consent at any time where processing is based on consent.
Complain to your national supervisory authority (see Section 12).
To exercise any of these rights, contact us at privacy@mbo.finance. We will respond within one month (extendable by two further months for complex requests). We may need to verify your identity before fulfilling a request.
Please note that some rights are subject to exceptions, particularly where we are required to retain data for legal or regulatory reasons.
mbo.finance does not knowingly collect personal data from individuals under the age of 18. Our services are not directed at children. If you believe we have inadvertently collected personal data from a child, please contact us immediately at privacy@mbo.finance and we will take steps to delete that information.
We implement technical and organisational measures designed to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These measures include:
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach and, where required, notify affected individuals without undue delay.
UK users have the rights described in Section 9 above under the UK General Data Protection Regulation and the Data Protection Act 2018. You may lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113.
Swedish users have rights under the EU General Data Protection Regulation (GDPR) and Swedish data protection legislation. Complaints may be lodged with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY) at imy.se.
Norwegian users have rights under the EEA-applicable GDPR and Norwegian Personal Data Act (Personopplysningsloven). Complaints may be lodged with the Norwegian Data Protection Authority (Datatilsynet) at datatilsynet.no.
German users have rights under the EU GDPR and the Federal Data Protection Act (Bundesdatenschutzgesetz, BDSG). Complaints may be lodged with the relevant State Data Protection Authority (Landesbeauftragte für Datenschutz) or the Federal Commissioner for Data Protection and Freedom of Information (BfDI) at bfdi.bund.de.
Canadian users have rights under the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial legislation. You have the right to access your personal information and challenge its accuracy. Complaints may be lodged with the Office of the Privacy Commissioner of Canada (OPC) at priv.gc.ca.
We have designated a Privacy Officer responsible for compliance with PIPEDA obligations. Contact our Privacy Officer at privacy@mbo.finance.
Australian users have rights under the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). You have the right to access and correct your personal information. Complaints may be lodged with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
New Zealand users have rights under the Privacy Act 2020 and the Information Privacy Principles (IPPs). You have the right to access and correct your personal information. Complaints may be lodged with the Privacy Commissioner at privacy.org.nz.
We may update this Privacy Policy from time to time. When we make material changes, we will:
We encourage you to review this Privacy Policy periodically. Your continued use of mbo.finance after any changes constitutes acceptance of the updated policy.
If you have any questions about this Privacy Policy, wish to exercise your rights, or have a complaint about how we handle your personal data, please contact our Data Protection team:
| Method | Details |
|---|---|
| Email (preferred) | privacy@mbo.finance |
| General support | support@mbo.finance |
| Post | Data Protection Officer, mbo.finance Ltd, [Registered Address], United Kingdom |
We will respond to all privacy-related requests within one calendar month. If you are not satisfied with our response, you have the right to lodge a complaint with the relevant supervisory authority in your jurisdiction (see Section 12).
This Privacy Policy was last reviewed and updated in January 2025. The effective date of this policy is 1 January 2025. This policy supersedes all previous versions and applies to all personal data processed by mbo.finance Ltd.