Home Sign Up Sign In
  • End User Terms
  • Privacy Policy
  • Sub-processors

Privacy Policy

Effective 1 September 2026

Introduction

Finexer LTD (“Finexer”, “we”, “us” or “our”) is committed to protecting personal data and respecting privacy. This Privacy Policy explains how we collect, use, share and protect personal data when you visit our website, use our products, services, features or APIs, interact with us as a client or partner, or use services that are provided through our clients and partners.

Finexer LTD is a company registered in England and Wales with number 12191948, whose registered office is at 124 City Road, London, EC1V 2NX, England. Finexer is authorised by the Financial Conduct Authority (FCA) under the Payment Services Regulations 2017, firm reference number 925695, as an Authorised Payment Institution providing account information services and payment initiation services. Our services may involve processing account information, payment initiation records, Open Banking consent records, transaction data, technical logs and related operational data.

Finexer is registered with the Information Commissioner's Office (ICO) under registration number ZB841505. We may update this Privacy Policy from time to time by publishing a revised policy on this page. The effective date above will change when we do.

We never hold your money, and we never come into possession of your banking credentials. You always authenticate directly with your own bank, and we have no means of seeing your username, password, PIN or one-time passcode.

Which parts of this policy apply to you

If you are an individual or an account holder who has connected a bank account or authorised a payment through a business that uses Finexer, the sections most relevant to you are Our role, Open Banking consent, and how to withdraw it, Verification, Data retention and Your rights. Your rights in relation to the regulated service are also described in our End User Terms.

If you are a business that uses Finexer, or are considering doing so, the whole of this policy is relevant, and our processing of personal data on your behalf is governed by our Data Processing Agreement.

If you are a director, owner, officer or manager of a business that uses Finexer or has applied to do so, we process personal data about you in our own right, in order to carry out the customer due diligence and financial crime checks the law requires of us. The sections most relevant to you are Due diligence on our clients and the people behind them, Lawful basis for processing, Criminal offence data, Data retention and Your rights. You can exercise your rights with us directly, whether or not the business itself does so.

Our role: when we are a controller and when we are a processor

Data protection law distinguishes between a controller, which decides why and how personal data is processed, and a processor, which processes personal data on a controller's instructions. Our role depends on the activity, and it is worth being precise about it.

We act as a controller in our own right to the extent that, for an account information service, a payment initiation service or an account check, we determine the purposes and essential means of the consent journey, the security and fraud controls we apply, and the records we retain for regulatory accountability and our documented operational purposes, including the canonical consent, authorisation, status and audit record. This is the intended allocation for our standard flow. The legal role for any particular processing depends on what the parties actually determine and perform, not on this description or another contractual label alone.

We are a controller in our own right for other things we decide ourselves and that do not arise from a specific service, including:

  • customer due diligence, verification of businesses and their directors and beneficial owners, sanctions screening, and the prevention, detection and investigation of financial crime and fraud;
  • handling complaints, including complaints referred to the Financial Ombudsman Service;
  • the security, integrity, monitoring and protection of our systems, and the investigation of security incidents;
  • establishing, exercising or defending legal claims; and
  • operating our public website, and our own sales, marketing and client communications.

We act as a processor to the extent that, once we have provided information to a business client, we store it in, or make it available through, the Finexer Account or our APIs on that client's documented instructions, including a client-facing copy or extract of consent or audit data, or where we categorise transaction data at the client's request, or where we carry out a document check as part of our verification service on a client's documented instruction rather than as an account check. In those cases the client is the controller, decides what the data is used for, and is responsible for telling individuals about it under its own privacy policy. Our obligations as processor are set out in our Data Processing Agreement. Where the client is itself a processor acting for one of its own business customers, we act as a sub-processor.

More than one role can apply to the same journey. To the extent that the facts recorded in the applicable flow matrix establish it, when you connect your account or authorise a payment, we act as controller for retrieving or transmitting it, for our canonical consent and audit record, and for our fraud checks. We separately act as the business's processor for storing that information for it once we have provided it, including any client-facing copy or extract of the consent or audit data, and for any categorisation it has asked for. The business can instruct deletion of that client-facing copy under its own retention policy, but that does not control the separate canonical record for which we are controller. Once information has been made available to the business, the business decides what to do with it and is the controller for that. If you want to know why a business made a decision about you, or want it reconsidered, you need to ask the business, not us.

Roles in presenting the consent journey. The parties' status depends on what they actually determine, not solely on whose interface is used. If Finexer and a business jointly determine the purposes or essential means by which you are informed and your consent is obtained, we are joint controllers for that activity. If each determines its own purposes separately, each is an independent controller instead. Using Finexer's hosted journey does not, by itself, establish either result. Where the parties are joint controllers, Finexer specifies the information that must be shown, maintains the consent record and is the primary contact for rights relating to the regulated service. The business is responsible for presenting the approved information without amendment, for the design and operation of its interface, and for ensuring that your consent is freely given, specific, informed and unambiguous. You may exercise your rights against either party; the party you contact will cooperate with the other to respond. Each party remains responsible for its own part of the activity. This is the essence of the arrangement described in Section 8 of our Data Processing Agreement.

Before a new or materially changed processing flow goes live, we and the business record the data, purposes, essential means, disclosures, retention and intended role of each party in a signed or otherwise expressly agreed written flow matrix. We review that matrix when the flow changes. The matrix records the parties' assessment but does not override the role produced by the facts or by data protection law.

Banks are not our processors. When we access an account or transmit a payment instruction, your bank processes your personal data as a controller in its own right under its agreement with you.

Information we collect

Account and contact information. We may collect information such as name, business name, address, email address, telephone number, account registration details, business identifiers, verification information and communications with us.

Open Banking and payment-service information. Where our services are used, we may process bank account information, account holder information, balances, transaction data, payment initiation records, consent records, authorisation records and related service data. This data is processed only where required to provide the relevant service, comply with legal or regulatory obligations, prevent fraud, maintain security or support the operation of our platform.

Website and technical information. When you visit our website or use our services, we may collect technical information such as IP address, browser type, operating system, pages accessed, referral URLs, timestamps, device identifiers, log data and cookie preferences.

Location derived from an IP address. We resolve the IP address used to reach our services into an approximate location, comprising the country, region, city and postal area, approximate coordinates for that area, and the internet service provider or network operator carrying the connection. A location produced in this way describes the area associated with the internet connection and the network it runs on, to the level of accuracy that network data allows. We do this to prevent fraud and unauthorised access, to keep our systems secure, and to complete the consent records we retain to evidence the regulated service provided. We decide ourselves that it takes place, so we act as a controller for it. Where a Finexer account is created or signed in to, it allows us to identify access from a location we have not previously seen for that account, and we may then ask for additional verification, such as confirmation of a code sent by email. Where an End User completes a consent journey, we record it as part of the consent record, and we also make it available to the business whose journey it is so that it can guard against fraud on its own side. The lookup itself is carried out for us by one or more specialist providers established in the European Union, described at Sub-processors.

Customer and end-user information. Where our clients use Finexer services to provide account information or payment initiation functionality to their customers, we may process personal data relating to those end users in accordance with the applicable consent, contract and regulatory framework.

Special category data. Special category data comprises data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union membership, genetic data, biometric data used for unique identification, health data, and data concerning a person's sex life or sexual orientation. We do not seek that data as a separate data category. However, transaction data can sometimes indirectly reveal sensitive aspects of an individual's life. A payment to a place of worship, a clinic or a political party is an ordinary transaction record to us, but it may reveal more than that. We therefore treat transaction data as highly sensitive and protect it accordingly. We do not analyse transaction data in order to infer or derive any special category characteristic about an individual, and we do not permit our sub-processors to do so. Where a transaction description itself expressly names something sensitive, we do not seek it, we cannot prevent a bank from including it, and we pass the description on exactly as the bank recorded it without reading, interpreting or acting on it. To the extent that the facts recorded in the applicable flow matrix establish that we determine the purposes and essential means, we act as controller for retrieving it and initially disclosing it to the business. Where transaction data is requested, the consent page lists the categories of information that will be accessed, states that by confirming the individual permits us to access that information from their bank and to share it with the business, and shows the period for which the access will run. We retain records sufficient to establish the individual concerned, when the consent was submitted, the categories of information requested and the effective date of the consent information and terms displayed at that time. The individual may withdraw that consent at any time through the business or by contacting us. Withdrawal stops future retrieval and initial disclosure of the affected transaction descriptions but does not automatically delete information already disclosed to or retained for the business. We separately act as processor when we later store that information or otherwise process it on the business's instructions. The business is responsible for identifying its own Article 6 basis, Article 9 condition and retention rules for that later processing; the confirmation given to Finexer does not establish those matters for the business.

Identity documents and photographs. We handle identity documents in two situations, and each is described in its own section below. The first is where a business uses our Verification service and sends us a document belonging to one of its own customers, described under Verification. The second is where we carry out due diligence on a business that applies to use our services, and on the individuals who own, control or manage it, described under Due diligence on our clients and the people behind them. In each case we use a document solely for the purpose set out in the relevant section.

Where a document contains a photograph, such as a passport or a driving licence, we use that photograph only as part of the document itself: for Verification an automated service reads the text fields the check requires, and in due diligence a member of our compliance team reviews the document by eye. Because the technical means required to identify a person from a facial image are at no point applied, no biometric data within the meaning of Article 4(14) of the UK GDPR arises from either activity. A photograph may nevertheless reveal other special category information, including racial or ethnic origin, and the controller responsible for collecting it must identify an applicable Article 6 basis and, where Article 9 is engaged, an Article 9 condition.

Information from third parties. We may receive information from banks and other account providers, from our clients, partners and suppliers, and from public sources such as the Companies House register and sanctions lists, where this is necessary for our services, compliance, security, fraud prevention or support activities.

Due diligence information. Where a business applies to use our services, we are required to identify and verify the business and the individuals who own, control or manage it. This involves documents and identifiers relating to those individuals, and is described in full under Due diligence on our clients and the people behind them below.

Open Banking consent, and how to withdraw it

Where we access information about your payment account, or initiate a payment from it, we do so because you have given consent for that specific purpose, and only within the scope of that consent. Before anything happens you are shown what you are agreeing to, which accounts are involved, what will be shared or paid, with whom, and, for ongoing account information access, whether it runs for a fixed period or continues on an ongoing basis until you withdraw it.

Where you have given consent for ongoing access to account information lasting, or that may last, longer than 90 days, we are required to obtain your confirmation at least every 90 days that you remain content for access to continue. Depending on how you connected, that request may come from us or from the business you are using, and confirming does not require you to sign in at your bank again. If you do not confirm, we stop collecting new information from your bank, although information already shared with that business remains with it, and your consent does not end for that reason alone. Where your consent has a fixed end date, confirming does not extend it, and access stops on that date in any event; where it has no fixed end date, access continues on that basis, subject to this 90-day confirmation requirement, until you withdraw it. Your bank may in addition require you to authenticate, either because it does not apply the available exemption or for its own security or fraud prevention reasons, and access is unavailable until you have done so.

You can withdraw your consent at any time, without giving a reason. You can do this through the business whose service you are using, by contacting us, or through your own bank. Once you withdraw consent we stop accessing your account.

Withdrawing consent stops further collection. It does not, by itself, delete information already shared with the business you were dealing with, and it does not delete the limited consent and audit records we retain under our documented policy to evidence the regulated service provided, or records retained for applicable financial-crime and regulatory purposes. To ask a business to delete information it already holds, you need to contact that business.

Verification

Some businesses use our Verification service. There are two kinds of check, and which one applies to you depends on what the business has chosen.

An account check. We compare information the business gives us about you with the account holder information your bank holds for the account you connect, and we return the result to the business. This kind of check is delivered using our account information service, under the consent you give for it, so everything in the section above applies, including your right to withdraw consent.

A document check. The business asks you for an identity document, such as a passport or driving licence, and sends it to us together with information about you. We read the required fields from the document by automated means, compare them with the information the business gave us, produce the result and, during the 30-day retention period described below, use the document where reasonably necessary to resolve a query concerning that result. This kind of check does not involve your bank and does not access your payment account. We carry it out on the business's instructions, as its processor, and there is no consent journey from us, because we have no agreement with you in relation to it. The business is responsible for explaining why it needs the document and for having your agreement before sending it to us. If you were not expecting to be asked for an identity document, ask that business about it before you provide it.

Depending on the document and the check, the details read from it may include your name, date of birth, sex, the document type, its number, the country that issued it and an address. The reading is carried out on our behalf by a document-reading service operated by Microsoft Azure in the North Europe (Ireland) service region. A stated service region identifies the primary processing location; supplier support or administration from another country is assessed separately as described under International transfers.

How we use the document. We use it only to read the required fields, perform the comparison, produce the result and resolve a query concerning that result during the 30-day retention period. We do not use it to train or improve any technology. Our result speaks to the details compared and to those alone; whether the document itself is genuine is a matter for the business that asked you for it.

For an enabled document-check flow, the document image is removed from active systems no later than 30 days after the check. We require the deletion control for that flow to be verified before production use. An inaccessible residual copy may remain in a protected backup for no more than 90 further days, after which it expires under the verified backup lifecycle; it is not restored to active use except where recovery from that backup is required, in which case the deletion is re-applied. For an account check, we retain for the five-year period described below the outcome, the consent and audit evidence, and only the information reasonably necessary to demonstrate that we carried out the check as required; we do not retain every field compared for that period unless we have separately documented why it is necessary. For a document check, we keep the detail read from the document and the result for as long as the business's instructions require, and then delete them. The business that sent us the document may keep its own copy on its own terms, so a request to delete that copy should go to that business.

The result we return is information, not a decision. Any decision about you, such as whether to open an account, approve an application or release a payment, is taken by the business, not by us. If you want to understand or challenge such a decision, you should contact the business.

For an account check, our documented retention policy is to retain for five years the outcome, the consent and audit evidence, and only the information reasonably necessary to demonstrate that we carried out the check as required. We do this to evidence the regulated service provided, respond to complaints and regulatory enquiries, prevent and investigate misuse and protect our legal position. We do not retain every individual field compared for that period unless we have separately documented why it is necessary. For a document check, we act on the business's instructions and retain the outcome and the detail read from the document only for as long as those instructions require; where the business uses the check for the purposes of the Money Laundering Regulations 2017, the records those Regulations require are for the business to keep. The image of an identity document is removed from active systems no later than 30 days after the check, and any inaccessible residual backup copy expires within a further 90 days as described above; it is not retained as part of either longer retention period.

Due diligence on our clients and the people behind them

This section applies to you if you are a director, owner, beneficial owner, or another individual responsible for the management of a business that applies to use our services or already uses them. It does not apply to End Users whose accounts are accessed through our services.

As an FCA-authorised payment institution we are required by the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 to identify and verify our clients and the individuals behind them before we provide services, and to keep those checks up to date. For that purpose we may collect:

  • an identity document — a passport, driving licence or other government-issued identity document for each individual we are required to verify. This is requested in every case;
  • evidence of address — any document accepted in the United Kingdom as evidence of a residential address, such as a bank or building society statement or a utility bill;
  • a National Insurance number — requested where a business is applying to be registered as our agent, and in other cases where we need to establish an individual's identity or tax position more precisely;
  • a tax identification number issued outside the United Kingdom, where an individual is not resident in the United Kingdom;
  • evidence of source of funds or source of wealth, where the circumstances of a particular application make it necessary;
  • a photograph of the individual, where it is necessary to satisfy ourselves that the person presenting the documents is the person they are said to be. Any such photograph is reviewed by a member of our compliance team by eye, as described above; and
  • the results of sanctions, politically exposed person and adverse media screening carried out on the individual.

Only the identity document and the evidence of address are requested as a matter of course. The remaining items are requested where our compliance team, assessing the risk presented by a particular application, considers them necessary.

Our lawful basis. For everything the Money Laundering Regulations 2017 require us to obtain, our lawful basis is compliance with a legal obligation (Article 6(1)(c) UK GDPR). Where we go further than those Regulations strictly require, in order to satisfy ourselves that a client and the people behind it are who they say they are and that we can safely provide regulated payment services to them, our lawful basis is our legitimate interests in preventing financial crime, in protecting End Users and our other clients, and in protecting our own regulatory permissions (Article 6(1)(f)).

Screening results that concern alleged offences. Sanctions, politically exposed person and adverse media screening can return information about criminal convictions, offences or alleged offences. Where it does, that information is subject to the additional protection described under Criminal offence data below, and we process it only on the conditions set out there.

Decisions are taken by people. Documents given to us at this stage are read by a member of our compliance team rather than by an automated service, and every decision to accept or refuse an application is taken by a person. Where a screening tool returns a possible match, a member of our compliance team assesses it before any decision is taken.

Verification through an external provider. Where we consider it necessary, we ask Global Data Consortium, Inc., part of the London Stock Exchange Group, to confirm whether the identity details an individual has given us can be verified against independent reference sources. We send that provider those details alone, such as name, address, date of birth and telephone number, and the documents themselves remain with us. It returns only whether the details could be verified. That provider acts on our instructions, is listed on our Sub-processors page, and processes the data in the United States under an approved transfer mechanism described on that page. We use it only in relation to the individuals behind a business client.

How long we keep it. Where a business relationship begins, the Money Laundering Regulations 2017 require us to keep the applicable evidence and supporting records for five years beginning on the date that relationship ends. Where we carry out an occasional transaction to which regulation 40 applies, we keep the applicable records for five years beginning on the date the transaction is completed. We do not treat an abandoned or refused application that led to neither a business relationship nor an occasional transaction as automatically subject to that five-year rule. For such an application, we retain only the records and period justified by our documented risk assessment and legitimate interests in preventing duplicate or fraudulent applications, evidencing the decision and defending legal claims, and delete or anonymise them when that assessment no longer supports retention. A specific legal hold, financial-crime investigation or requirement from a regulator, tax authority or law enforcement authority may justify longer retention in an individual case.

Who sees it. Access is limited to our compliance team and to those who need it to perform their role. We may disclose it to the Financial Conduct Authority, to law enforcement or tax authorities, to a bank or other regulated firm where we are required to do so, and to our professional advisers and auditors.

Automated decision-making and profiling

We do not take decisions about you by automated means that produce legal effects or that otherwise significantly affect you.

Some of our services produce automated outputs. Where a business enables it, we can categorise transactions, for example by labelling a transaction as rent or as salary. Verification produces a comparison result. Both are automated, both are provided to the business as information, and both may be incomplete or wrong. The business decides what to do with them.

Where a business uses those outputs to make an automated decision about you, that business is responsible for that decision, for giving you meaningful information about the decision and its effect, and for enabling you to make representations, obtain human intervention and contest the decision.

We do use automated checks for fraud prevention, financial crime detection and security. Where those checks would lead to a decision that significantly affects an individual, a person reviews it before it takes effect.

One of those checks compares the approximate location of a sign-in with the locations already recorded for the same account. Where the location is one we have not previously seen, we may ask for additional verification before the sign-in completes. That step is automated, and it results in a request to confirm identity rather than in a decision about the individual.

Cookies and similar technologies

When you visit our public website, we use cookies and similar technologies, including browser local storage and session storage, to operate the website, remember your preferences, understand how the website is used and, where you have agreed, support our marketing. A cookie may be set by us (a first-party cookie) or by another organisation when you visit our website (a third-party cookie). We do not use cookies to store banking details.

Certain cookies are essential for the website to operate. We use all other cookies only with your consent. On your first visit, we ask you to accept all cookies, reject all cookies, or select which optional categories to allow. Rejecting non-essential cookies is no more difficult than accepting them.

We use the following categories of cookies:

  • Essential cookies. These cookies are required for the website to function and to remain secure. They include session, security, load-balancing and consent-preference cookies, together with measures we use to monitor for, and detect, potentially harmful or unlawful use of our services. These cookies are exempt from consent under the applicable rules. You may block them through your browser settings, but doing so may prevent parts of the website from functioning correctly. On certain forms we may also use Google reCAPTCHA to distinguish a human visitor from an automated submission; this involves a request to Google, which may process the resulting information as an independent controller, as described in Google's Privacy Policy.
  • Functional cookies. These cookies remember choices you make, such as display settings, in order to provide a more convenient experience. Certain features may not operate correctly without them. We use these cookies only with your consent.
  • Performance cookies. These cookies enable us to understand how visitors use our website so that we can improve it. They collect usage information in pseudonymised form and are not used to identify you personally. We use Google Analytics and Ahrefs Analytics for this purpose, and only with your consent.
  • Advertising cookies. These cookies enable us to measure the effectiveness of our marketing campaigns, display relevant Finexer advertising on other websites, and assess business interest in our services. They rely on browser or device information rather than banking details. We use Google Ads, Leadfeeder, Albacross and Snitcher for this purpose, and only with your consent.

Until you make a choice, we use only essential cookies. Optional cookies, and the related third-party tools, are not activated until you allow the corresponding category. Where you later withdraw your consent, we cease using the relevant cookies and remove them where technically possible.

You can change or withdraw your consent at any time by selecting Cookie Settings in the footer of our website. We keep a record of your choice, including the date, the effective date of this notice, the categories you selected and, where you are signed in to your Finexer account, your account identifier, so that we can demonstrate your consent. We remember your choice for up to 12 months, after which we will ask you again. We will also ask sooner if we make a material change to the cookies or similar technologies we use. You can also control cookies through your browser settings.

We retain consent records, including the IP address and browser information collected at the time of the consent decision, for a period of up to three years. After that period, those records are deleted. This data is used solely to demonstrate compliance with our legal obligations and is not used for any other purpose.

How we use information

We use personal data where necessary for lawful, legitimate and proportionate purposes, including to:

  • provide, operate and support our website, platform, services and APIs;
  • provide account information services and payment initiation services requested by users or our clients;
  • verify identity, account information and eligibility to use our services;
  • process transactions, payment instructions, account information requests and related notifications;
  • respond to enquiries and provide customer, client and partner support;
  • monitor, secure, maintain and improve our systems and services;
  • identify, prevent, investigate and report fraud, misuse, prohibited activity, security incidents or unlawful activity;
  • meet legal, regulatory, audit, accounting and record-keeping obligations;
  • measure and improve the performance, content and usability of our website and services; and
  • send service communications and, where permitted, marketing communications based on your preferences.

Lawful basis for processing

Where we act as a controller, the table below sets out the lawful basis we rely on for each purpose. Where we act as a processor for a business client, that client is responsible for identifying its own lawful basis, and our Data Processing Agreement governs our processing.

Purpose Lawful basis under Article 6 of the UK GDPR
Providing the account information service or payment initiation service you have asked for, including retrieving account information or transmitting a payment instruction Performance of a contract with you, being our End User Terms. Separately from this, the Payment Services Regulations 2017 require your explicit consent before we may access your account information or initiate a payment. That regulatory consent is not the same as consent as a lawful basis, and withdrawing it stops the service, as described above
Keeping the consent record and audit trail that evidence a valid consent was given Our legitimate interests in demonstrating that we provided a regulated service properly, responding to complaints and regulatory enquiries, preventing and investigating misuse and protecting our legal position; and legal obligation only where a specific applicable law or regulatory requirement requires the particular record
Customer due diligence, verification of a business and the individuals who own, control or manage it, including the collection of identity documents, evidence of address and identifiers such as a National Insurance number or a tax identification number, and sanctions, politically exposed person and adverse media screening Legal obligation under the Money Laundering Regulations 2017 and applicable sanctions law, and our legitimate interests in satisfying ourselves that a client and the people behind it are who they say they are, so far as we go beyond what those Regulations strictly require
Preventing, detecting and investigating fraud and financial crime Legal obligation, and our legitimate interests in protecting End Users, our clients, ourselves and the integrity of the payment system
Security of our systems, monitoring, logging and investigating security incidents Legitimate interests under Article 6(1)(f) in keeping the Services and the data in them secure, and legal obligation under Article 6(1)(c), the obligation in question being the requirement in Article 32 of the UK GDPR to implement appropriate technical and organisational measures to secure personal data
Determining the approximate location associated with the internet connection used to create or sign in to a Finexer account, or to complete a consent journey, and making that location available to the business whose journey it is Legitimate interests under Article 6(1)(f) in preventing fraud and unauthorised access to accounts and to the Services. Where the processing is necessary to meet a specific obligation to which we are subject, we rely in addition on legal obligation under Article 6(1)(c), the obligation in question being the requirement in Article 32 of the UK GDPR to implement appropriate technical and organisational measures to secure personal data. We act as a controller for this processing, and the provision of the resulting location to a business client is a disclosure by us as controller to that client as controller
Handling complaints, including complaints referred to the Financial Ombudsman Service, and data protection complaints under section 164A of the Data Protection Act 2018 Legal obligation
Regulatory record keeping and reporting as an authorised payment institution Legal obligation
Establishing, exercising or defending legal claims Legitimate interests in protecting our legal position
Operating our public website, and our own sales, marketing and client communications Legitimate interests in promoting and operating our business, and consent where required for electronic marketing or for non-essential cookies
Non-essential analytics and marketing cookies and similar technologies Consent, given through our cookie banner

Our legitimate interests. Where we rely on legitimate interests, the interests we rely on are: keeping the Services and the data in them secure; preventing and detecting fraud, financial crime and misuse of the Services; being able to evidence that a regulated service was properly provided; operating, maintaining and improving the Services; protecting our legal position; and promoting our business to other businesses. In each case we have considered whether the processing is necessary for that interest, and whether it is fair and proportionate to you. We have carried out and recorded a balancing assessment for each of these purposes, and you can ask us for a summary of the relevant assessment.

Criminal offence data

Our checks for financial crime, fraud and sanctions can involve personal data relating to criminal convictions, offences or alleged offences, which Article 10 of the UK GDPR treats as requiring additional protection. This can arise, for example, from a sanctions or adverse-media match, from a suspicion we are required to consider, or from information a bank or an authority gives us.

Where we process such data we do so in reliance on the substantial public interest conditions in Part 2 of Schedule 1 to the Data Protection Act 2018, in particular those concerning the prevention or detection of an unlawful act, the protection of the public against dishonesty, and the prevention of fraud. We rely on those conditions only so far as is necessary for those purposes.

We maintain the appropriate policy document that Part 4 of Schedule 1 to that Act requires in relation to those conditions, which records how we comply with the data protection principles when processing this data and our retention and erasure policy for it. You can ask us for a copy.

Where the law requires us not to tell you about processing of this kind, for example because doing so would prejudice the prevention or detection of crime or would amount to unlawfully tipping off a person, we may not be able to give you the information or access we would otherwise give.

Information we share

Other than as stated in this Privacy Policy, Finexer does not sell personal data. We may share your personal data with certain trusted third parties, as follows:

  • Service providers. We share information with service providers that help us operate and maintain our services, including cloud infrastructure and hosting, data storage, delivery of one-time passcodes and service emails, resolution of an IP address into an approximate location, verification of individuals responsible for managing a business applying to use our services, customer relationship management, IT support, analytics, marketing, monitoring and audit support. These providers may use personal data only as necessary to provide services to us and must protect it in accordance with applicable obligations. The current list is published at Sub-processors, together with the purpose each provider serves and where it processes data. We notify clients before we add a provider that processes personal data on their behalf.
  • Banks and other account providers. To provide account information services and payment initiation services we exchange information with the bank that holds the relevant account. Your bank acts as a controller in its own right under its agreement with you, and is not our processor.
  • Public registers. During onboarding we verify a business, its directors and its beneficial owners against the Companies House register. Companies House is a public authority and an independent controller.
  • Clients, partners and users. We may share information with clients, partners or users where this is necessary to provide the requested service, complete an Open Banking journey, support an integration, process a payment initiation request, resolve a support issue or meet contractual obligations.
  • Authorised third parties. Where you authorise a third party to access information through Finexer, or through a service that is integrated with Finexer, we may share information in accordance with that authorisation and the applicable consent journey.
  • Legal, regulatory and law-enforcement purposes. We may disclose information where required by law, regulation, court order, payment-service rules, the FCA, the ICO or other competent authorities, or where reasonably necessary to protect our rights, users, clients, partners, systems or services.

Where a third party acts as our processor, we remain responsible for ensuring that processing is governed by appropriate contractual, confidentiality and security obligations.

International transfers

Finexer's primary application hosting and storage are in Ireland, within the European Economic Area, using Microsoft Azure. The document-reading service described under Verification uses Microsoft Azure's North Europe (Ireland) service region. Amazon Web Services processes SMS and system-email delivery in Ireland. These locations are set out at Sub-processors. A stated data region identifies the primary service location but does not, by itself, establish every country from which authorised supplier personnel may provide remote support or administration, or every location involved in onward processing. We assess those access arrangements as part of our supplier and transfer reviews. Transfers to the European Economic Area are made in reliance on the United Kingdom's adequacy regulations for those countries. Some third-party providers used for website analytics, marketing, support, communications or operational services may process personal data outside the United Kingdom or European Economic Area. Where this occurs, we use appropriate safeguards, such as contractual protections and recognised transfer mechanisms, and assess suppliers before relying on their services.

You may request a copy of the safeguard that applies to a restricted transfer of your personal data, with confidential commercial information redacted where necessary, by emailing privacy@finexer.com.

Data retention

We retain personal data only for as long as reasonably necessary for the purposes described in this Privacy Policy, including to provide services, meet legal and regulatory obligations, evidence Open Banking consent, prevent fraud, resolve disputes, maintain security, support audits and enforce our terms.

The periods below are the ones we apply. Where a period is set by law we cannot shorten it, including where an individual asks us to delete the data. Where we are acting as a processor for a business client, that client's own retention instructions apply to the data we hold on its behalf, and the terms of our Data Processing Agreement govern deletion and return.

What we hold How long we keep it Why
Temporary operational copies of account information and transaction data handled by Finexer as controller during retrieval and initial disclosure Only for as long as reasonably necessary to complete the retrieval and initial disclosure and to operate the associated security and fraud controls; the separate consent and regulatory records below are retained for their stated periods To provide the regulated account information service and complete the initial disclosure requested by the End User
Account information and transaction data stored in, or made available through, the Finexer Account or APIs for a business client For as long as the business client's documented instructions require while the agreement remains in force. Withdrawal of the End User's consent stops further retrieval but does not automatically delete information already supplied to and retained for the business. On termination, the information remains available for export for 30 days and is then deleted or returned, with existing copies deleted, within a further 60 days, subject to the Data Processing Agreement Held by Finexer as processor for the business client, under that client's instructions and our Data Processing Agreement
Open Banking consent records and the associated audit trail 5 years from the end of the consent Our documented retention policy, based on the necessity of evidencing the consent and regulated service provided, responding to complaints and regulatory enquiries, preventing and investigating misuse and protecting our legal position
Payment initiation records 5 years from the date of the payment instruction Our documented retention policy, limited to the records necessary to evidence receipt, authentication, accurate recording, transmission, technical integrity, status and the information provided after initiation, and to respond to complaints, claims and regulatory enquiries
The outcome of an account check under our Verification service, the consent and audit evidence for it, and the information reasonably necessary to demonstrate the check was carried out as required (an additional field is kept for this period only where we have separately documented a necessity for it) 5 years from the date of the check Our documented retention policy, based on the necessity of evidencing the regulated account information service and check provided, responding to complaints and regulatory enquiries, preventing and investigating misuse and protecting our legal position
The outcome of a document check under our Verification service, and the details read from the identity document For as long as the business's instructions require We carry out a document check as the business's processor, on its instructions. Where the business uses the check for the purposes of the Money Laundering Regulations 2017, the records those Regulations require are for the business to keep
The image of an identity document submitted for a Verification check Removed from active systems no later than 30 days from the date of the check; an inaccessible residual backup copy expires within a further 90 days Kept in active systems only for as long as needed to produce the result and resolve a query. A backup copy is not restored to active use except where recovery is required, in which case the deletion is re-applied
Customer due diligence records where a business relationship began, including identity documents, evidence of address, identifiers, photographs obtained and screening records 5 years from the end of the business relationship Money Laundering Regulations 2017, regulation 40
Customer due diligence records for an occasional transaction to which regulation 40 applies 5 years from completion of the occasional transaction Money Laundering Regulations 2017, regulation 40
Records of an abandoned or refused application that led to neither a business relationship nor an occasional transaction Only for the risk-based period supported by the documented failed-applicant retention assessment, with deletion or anonymisation when no longer necessary; longer only for a specific legal hold, investigation or applicable legal duty Our legitimate interests in preventing duplicate or fraudulent applications, evidencing the onboarding decision and defending legal claims, balanced against the applicant's rights; not regulation 40 merely because a check occurred
Complaint records 3 years from the date the complaint was received The FCA's complaint-handling rules in DISP 1.9. Where a complaint record also forms part of a payment, consent or anti-money-laundering record, or where we need it to establish, exercise or defend a legal claim, we keep it for the longer period that applies to that record
Fraud and financial crime investigation records Up to 6 years, and longer where an investigation, dispute or legal claim is live Fraud prevention, and the defence of legal claims
Security, access and application logs Up to 12 months, and longer where relevant to a live security investigation Security monitoring and incident investigation
The IP address used to create or sign in to a Finexer account, and the approximate location derived from it Up to 12 months, as part of our security and access logs Identification of access from a location not previously seen for the account, and investigation of unauthorised access
The IP address used to complete a consent journey, and the approximate location derived from it 5 years, being the same period as the consent record of which it forms part It forms part of the Open Banking consent record and audit trail and is retained under the same documented policy, where necessary to evidence the journey, prevent and investigate fraud or unauthorised access, and protect our legal position
Cookie consent records Up to 3 years To demonstrate that consent was obtained
Marketing contact data and preferences Until consent is withdrawn or the data is no longer needed, and then a suppression record only To respect your choices and not contact you again

At the end of the applicable period we delete the personal data or irreversibly anonymise it. Where data is held in a backup, it is removed in the ordinary course of the backup cycle.

Security

We use technical and organisational measures designed to protect personal data against unauthorised access, loss, misuse, alteration or disclosure. Depending on the relevant system and risk, those measures may include transport and storage encryption, access and authentication controls, logging, monitoring, secure development practices and supplier security review. The implementation applicable at a particular time is recorded in our current control register and must be supported by current evidence; this summary is not a representation that every measure applies identically to every system or data category.
No method of transmitting data over the internet, and no method of electronic storage, can be guaranteed to be completely secure.

Your rights

Subject to applicable law, you have the right to request access to your personal data, the correction of inaccurate data, the erasure of data, the restriction of processing and the portability of data, and the right to object to processing. Where processing is based on consent, you can withdraw that consent at any time. You also have rights in relation to automated decision-making and profiling where it applies.

How to exercise your rights. Email us at privacy@finexer.com, or write to us at the address below. You do not need to give us any business or company details in order to make a request. You do not have to pay a fee. We will respond within one month. If your request is complex, or if you have made several requests, we may extend that by up to two further months, and we will tell you if we do and why. We may need to verify your identity before we act, and we will only ask for what we need to do that.

Where to send your request. You can bring a request to us directly, whichever business you came to us through, and we will deal with it. Where we hold the data as a processor for a business client, we are not permitted to act on it without that client's instruction, so we will forward your request to the client without undue delay, tell you that we have done so, and tell you who to contact. If your request is about what a business did with information after we passed it on, that business is the right place to send it.

Limits on these rights. Where we act as controller, we assess each request for erasure on its facts. We may refuse erasure only to the extent that continued retention remains necessary to comply with a legal obligation, because compelling legitimate grounds override the individual's interests, rights and freedoms following an objection, or for the establishment, exercise or defence of legal claims. This may apply to particular customer-due-diligence, consent or audit records, but it does not make every such record exempt from erasure automatically. If we refuse all or part of a request, we will explain the applicable ground unless the law prevents us from doing so.

You can review, correct or update certain account information by logging in to your Finexer account or by contacting us. You can also request account closure through the Contact us form or in your account. If you close your account, we may retain information where necessary to comply with legal or regulatory obligations, resolve disputes, prevent fraud, maintain security, enforce our terms or take other action required or permitted by law.

Data protection complaints

You have a statutory right under section 164A of the Data Protection Act 2018 to complain to us if you consider that we have infringed the UK GDPR or Part 3 of that Act in relation to your personal data. This is separate from a complaint about a payment service, which is dealt with in our End User Terms and, for business clients, in our Client Terms of Service.

How to complain. You can make a data protection complaint in any of the following ways, and you do not have to pay a fee:

  • electronically, by email to privacy@finexer.com. This is a dedicated address for data protection complaints and requests. You do not need to use our general contact form, and you do not need to give us any business or company details;
  • by post, to Data Protection, Finexer LTD, 124 City Road, London, EC1V 2NX, England; or
  • through the business whose service you were using, which will pass your complaint to us.

You do not need to use any particular format or wording. Please tell us what has happened and how you would like it resolved, and give us a way to reply to you. If you are an individual complaining on your own behalf, we will not ask you for business details in order to accept your complaint.

What we will do. We will acknowledge your complaint promptly, normally within five business days of receiving it and in every case within the 30 days required by section 164A. We will then make appropriate enquiries into the subject matter of the complaint, keep you informed of progress, and tell you the outcome without undue delay. Where we need information from you in order to investigate, we will ask for it and explain why.

We handle data protection complaints through a single complaints process, so that a complaint which raises both data protection and financial services issues is dealt with once and in full. Where a complaint also concerns a payment service, the response times in our End User Terms and Client Terms of Service apply to that part of it.

If you are not satisfied. If you are unhappy with our response, or we do not respond in time, you can complain to the Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, telephone 0303 123 1113, ico.org.uk. Complaining to us first does not affect your right to complain to the ICO, although the ICO will normally expect you to have raised the matter with us first.

If your complaint is about a payment service rather than about your personal data, you may be able to refer it to the Financial Ombudsman Service. Our End User Terms explain how.

Minors

Our services are not designed or marketed specifically for children. However, a person under 18 may hold or be authorised to use a payment account, and a business using Finexer or a bank may permit that person to enter a consent journey. We may therefore process personal data relating to a person under 18 where the requested payment service is lawfully available to them. The business that directs a person to the service is responsible for applying any age restriction its product requires and for giving age-appropriate information. We use the information only for the purposes and periods described in this policy, apply the same security and data protection safeguards, and will respond appropriately where we know that an individual needs additional support to understand or exercise their rights.

Contact us

If you have any questions or concerns regarding this Privacy Policy, if you wish to exercise your data protection rights, or if you wish to make a data protection complaint, email us at privacy@finexer.com. For anything else, you can use customer support or our Contact us page.

You can also write to us at: Data Protection, Finexer LTD, 124 City Road, London, EC1V 2NX, England.

Copyright © 2026 Finexer. Cookie Settings