Privacy Policy

Last updated: January 2025 · Effective date: 1 January 2025 · Version 1.0

Your privacy matters to us. This Privacy Policy explains what personal data we collect about you, why we collect it, how we use it, who we share it with, and what rights you have. Please read it carefully. This policy applies to all users of mbo.finance regardless of where you are located.

Table of Contents

  1. Who We Are
  2. Data We Collect
  3. How We Use Your Data
  4. Legal Basis for Processing
  5. Data Sharing
  6. International Data Transfers
  7. Data Retention
  8. Cookies
  9. Your Rights
  10. Children's Privacy
  11. Security
  12. Jurisdiction-Specific Rights
  13. Changes to This Policy
  14. Contact and Complaints

1. Who We Are (Data Controller)

The data controller responsible for your personal data is:

mbo.finance Ltd
Company Number: [COMPANY NUMBER]
Registered Address: [REGISTERED ADDRESS]
United Kingdom
Email: privacy@mbo.finance

As a data controller, mbo.finance Ltd determines the purposes and means of processing your personal data. Where we process data on behalf of regulatory or law enforcement authorities, we may act as a data processor.

We are registered with the Information Commissioner's Office (ICO) in the United Kingdom under registration number [ICO REGISTRATION NUMBER].

2. Personal Data We Collect

We collect personal data from you in the following categories:

2.1 Identity Data

2.2 Contact Data

2.3 Financial Data

2.4 Technical Data

2.5 Communications Data

2.6 Special Categories of Data

In certain circumstances, we may process special categories of personal data as defined under applicable data protection law, such as biometric data used for identity verification. We will only process such data where we have a specific legal basis to do so, and we implement enhanced safeguards for its protection.

3. How We Use Your Personal Data

PurposeData UsedLegal Basis
Creating and managing your accountIdentity, contactContract performance
Identity verification (KYC)Identity, contact, documentsLegal obligation
Processing transactionsIdentity, financialContract performance
AML/CTF screening and monitoringIdentity, financial, technicalLegal obligation
Fraud prevention and securityIdentity, technicalLegitimate interests
Customer supportIdentity, contact, communicationsContract performance
Regulatory reportingIdentity, financialLegal obligation
Service improvement and analyticsTechnical, usageLegitimate interests
Marketing communicationsContactConsent
Legal claims and disputesAll categories as relevantLegitimate interests / legal obligation

4. Legal Basis for Processing

We process your personal data on the following legal bases under UK GDPR and equivalent legislation:

5. Who We Share Your Data With

We share your personal data only where necessary and with appropriate safeguards in place. Recipients include:

5.1 Service Providers

Third-party companies that provide services on our behalf, including:

All service providers are contractually bound to process data only on our instructions and to maintain appropriate security measures.

5.2 Regulatory and Law Enforcement Authorities

We are legally obligated to share data with:

5.3 Business Transfers

In the event of a merger, acquisition, or sale of all or a portion of our assets, your personal data may be transferred to the acquiring entity, subject to the same privacy protections outlined in this policy.

5.4 Professional Advisers

Lawyers, accountants, auditors, and other professional advisers where necessary for the conduct of our business, subject to professional confidentiality obligations.

We do not sell your personal data to third parties for commercial purposes.

6. International Data Transfers

As a platform serving users in multiple countries, your personal data may be transferred to and processed in countries outside your country of residence, including countries outside the United Kingdom and European Economic Area (EEA).

Where we transfer personal data internationally, we ensure appropriate safeguards are in place, including:

You may request details of the specific safeguards we have in place for international data transfers by contacting privacy@mbo.finance.

7. How Long We Keep Your Data

Data CategoryRetention PeriodReason
Account and identity data5 years after account closureAML/CTF legal obligations (UK: MLR 2017)
Transaction records5 years after account closureAML/CTF legal obligations
KYC documents5 years after account closureAML/CTF legal obligations
Communications / support records3 years after last contactLegitimate interests / legal claims
Marketing consent recordsUntil withdrawn + 3 yearsProof of consent
Technical / log data12 monthsSecurity monitoring
Cookie dataUp to 12 monthsSee Cookie Policy below

Retention periods may be extended where required by applicable law, ongoing investigations, or legal proceedings. Where data is no longer required, it is securely deleted or anonymised.

Canada (PIPEDA): Personal data is retained only as long as necessary to fulfil the stated purposes and legal obligations, after which it is destroyed, erased, or anonymised.

Australia (Privacy Act): We take reasonable steps to destroy or de-identify personal data when it is no longer needed for any purpose for which it may be used or disclosed.

8. Cookies and Tracking Technologies

We use cookies and similar tracking technologies on our platform. Our use of cookies is limited to:

Cookie TypePurposeDuration
Essential / SessionMaintaining your login session, security, preventing fraudSession / Up to 24 hours
PreferenceRemembering your cookie consent choice12 months
AnalyticsUnderstanding how users interact with our platform (anonymised)Up to 12 months

We do not use advertising or tracking cookies. We do not share cookie data with advertising networks.

You can manage your cookie preferences through your browser settings. Disabling essential cookies may affect the functionality of our platform. You may withdraw your consent to non-essential cookies at any time by clearing your browser cookies.

9. Your Privacy Rights

Depending on your jurisdiction, you have the following rights regarding your personal data:

Right of Access

Request a copy of the personal data we hold about you (Subject Access Request).

Right to Rectification

Request correction of inaccurate or incomplete personal data.

Right to Erasure

Request deletion of your personal data, subject to legal retention obligations.

Right to Restriction

Request that we restrict processing of your data in certain circumstances.

Right to Data Portability

Receive your data in a structured, machine-readable format.

Right to Object

Object to processing based on legitimate interests, including for marketing.

Right to Withdraw Consent

Withdraw consent at any time where processing is based on consent.

Right to Lodge a Complaint

Complain to your national supervisory authority (see Section 12).

To exercise any of these rights, contact us at privacy@mbo.finance. We will respond within one month (extendable by two further months for complex requests). We may need to verify your identity before fulfilling a request.

Please note that some rights are subject to exceptions, particularly where we are required to retain data for legal or regulatory reasons.

10. Children's Privacy

mbo.finance does not knowingly collect personal data from individuals under the age of 18. Our services are not directed at children. If you believe we have inadvertently collected personal data from a child, please contact us immediately at privacy@mbo.finance and we will take steps to delete that information.

11. Security

We implement technical and organisational measures designed to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These measures include:

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach and, where required, notify affected individuals without undue delay.

12. Jurisdiction-Specific Privacy Rights

United Kingdom (UK GDPR)

UK users have the rights described in Section 9 above under the UK General Data Protection Regulation and the Data Protection Act 2018. You may lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113.

Sweden (GDPR + Swedish DPA)

Swedish users have rights under the EU General Data Protection Regulation (GDPR) and Swedish data protection legislation. Complaints may be lodged with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY) at imy.se.

Norway (GDPR + Norwegian DPA)

Norwegian users have rights under the EEA-applicable GDPR and Norwegian Personal Data Act (Personopplysningsloven). Complaints may be lodged with the Norwegian Data Protection Authority (Datatilsynet) at datatilsynet.no.

Germany (GDPR + BDSG)

German users have rights under the EU GDPR and the Federal Data Protection Act (Bundesdatenschutzgesetz, BDSG). Complaints may be lodged with the relevant State Data Protection Authority (Landesbeauftragte für Datenschutz) or the Federal Commissioner for Data Protection and Freedom of Information (BfDI) at bfdi.bund.de.

Canada (PIPEDA)

Canadian users have rights under the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial legislation. You have the right to access your personal information and challenge its accuracy. Complaints may be lodged with the Office of the Privacy Commissioner of Canada (OPC) at priv.gc.ca.

We have designated a Privacy Officer responsible for compliance with PIPEDA obligations. Contact our Privacy Officer at privacy@mbo.finance.

Australia (Privacy Act 1988)

Australian users have rights under the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). You have the right to access and correct your personal information. Complaints may be lodged with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

New Zealand (Privacy Act 2020)

New Zealand users have rights under the Privacy Act 2020 and the Information Privacy Principles (IPPs). You have the right to access and correct your personal information. Complaints may be lodged with the Privacy Commissioner at privacy.org.nz.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When we make material changes, we will:

We encourage you to review this Privacy Policy periodically. Your continued use of mbo.finance after any changes constitutes acceptance of the updated policy.

14. Contact Us and How to Complain

If you have any questions about this Privacy Policy, wish to exercise your rights, or have a complaint about how we handle your personal data, please contact our Data Protection team:

MethodDetails
Email (preferred)privacy@mbo.finance
General supportsupport@mbo.finance
PostData Protection Officer, mbo.finance Ltd, [Registered Address], United Kingdom

We will respond to all privacy-related requests within one calendar month. If you are not satisfied with our response, you have the right to lodge a complaint with the relevant supervisory authority in your jurisdiction (see Section 12).

This Privacy Policy was last reviewed and updated in January 2025. The effective date of this policy is 1 January 2025. This policy supersedes all previous versions and applies to all personal data processed by mbo.finance Ltd.