Effective 1 April 2024
Content
1. About us
2. Why do I need to read this notice?
3. When and why we collect personal data about you
4. Do you make automated decisions about me?
5. Do you run credit checks on me?
6. How do you use my personal data for marketing?
7. What are my rights?
8. How do I exercise my rights?
9. Do you share my personal data with anyone else?
10. Will my personal data go outside the United Kingdom or Europe?
11. How do you protect my personal data?
12. How long will you keep my personal data for?
13. How will you keep me updated about how you use my personal data?
We are committed to protecting your data, and your privacy. We will not sell your personal data.
This privacy notice describes who we are and how and why we collect, store, use, and share your personal data in accordance with the Data Protection Legislation. It explains your associated rights and how to contact us or the supervisory authorities if you are unsatisfied with the response.
This Privacy Notice is relevant to anyone who interacts with our services, including website users. If you have signed an agreement with us, the agreement shall prevail and this notice shall be used for information purposes only.
We are subject to the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. We are also subject to the EU General Data Protection Regulation (EU GDPR) in relation to goods and services we offer to individuals and our wider operations in the European Economic Area (EEA).
In this notice, MonRemit means Mon Remit Limited a company incorporated under the laws of England and Wales, registration No 11821649, whose registered office is at Suite 17, Unit 9 Liberty Centre, Mount Pleasant, Wembley, HA0 1TX.
We have appointed a Data Protection Manager (DPM) to oversee our data protection obligations and compliance with this privacy notice. Please see below for more information on how to contact our DPM.
MonRemit is responsible for deciding the way your personal data is processed in relation to any product or service MonRemit provides, and we are therefore defined as a ‘data controller’ of your personal data.
We collect your personal data when you use
⦁ Our website at www.monremit.com.
⦁ The MonRemit Apple or Android mobile app, available via the Apple or Play store.
⦁ Any of the services available to you through the MonRemit mobile apps or website.
We may also collect your personal data from other people or companies. We explain how this can happen in the “When and why we collect personal data about you” section below.
‘Personal data’ includes information which:
⦁ We know about you, and
⦁ Can be used to personally identify you.
This notice explains what information we collect, how we use it, and your rights over your personal data.
On occasion, we may provide you with ‘just in time’ privacy explanations in the app or on the website to help you to better understand what specific personal data we collect, use or share about you for that product or service. Where relevant, you will be prompted to review your privacy preferences.
We may provide privacy notices and explanations in languages other than English. If there are any discrepancies between other language versions and the English language version, the English language version is authoritative.
If you wish to enquire or raise concerns about how we use your personal data, you can contact The Data Protection Manager at dataprotection@monremit.com.
We may collect personal data when you:
⦁ Browse our website.
⦁ Correspond with us for pre-sales, or where unrelated to a contractual engagement with us, and via any form e.g., survey social media, live chat, telephone; or you correspond with us for any reason in any form, for example, social media, live chat, telephone, or email.
⦁ Register to use the MonRemit services via the Mobile app or web service, or correspond with us regarding services we provide to you.
⦁ Use our payment service.
We may collect data if you opt in to our analytics collection:
⦁ Information about your visit to our website or app, including the links you’ve clicked on, and date and time, services you viewed or searched for, page response times, download errors, length of visits to certain pages, page interaction information (such as scrolling and clicks), and methods used to browse away from the page.
⦁ Technical information, including the internet protocol (IP) address used to connect your computer to the internet, the browser type and version, the time zone setting, device language, the operating system, and type of device.
We use your personal data to improve and manage our website, including troubleshooting, data analysis, testing, and research, and to make sure that content is presented in the most effective way for you and your device.
We use cookies to analyse how you use our website. Please read our Cookie policy for more information about cookies.
Consent, where you agree to us collecting your personal data.
Legitimate interests, to gather data useful for improving the delivery our website.
We may collect from you:
⦁ Your name.
⦁ Email address, phone number.
⦁ Company name (if applicable).
If you agree, we use this communication information to provide you with information about our promotions or offers which we think you might be interested in.
You can ask us to stop sending you marketing information by clicking ‘unsubscribe’ or requesting in reply that we do not continue to send you marketing communications.
We use pixels or web beacons in our direct marketing emails. These pixels track whether our email was delivered and opened, and whether links within the email were clicked. They also allow us to collect information such as your IP address, browser, email client type, and other similar details. We use this information to measure the performance of our email campaigns, and for analytics purposes.
Legitimate interests (to send direct marketing, ensuring it is relevant to your interests).
Consent (where we’re legally required to get your consent to send you direct marketing about our products or services).
We may collect:
⦁ Your name.
⦁ Your address.
⦁ Your email address.
⦁ Your phone number.
⦁ Your date of birth.
⦁ Details of your bank account, including the account number, sort code, and IBAN.
⦁ copies of your identification documents (for example, your passport or driving licence).
⦁ Copies of utility bills or bank statements.
⦁ Your country of residence, tax residency information, and tax identification number.
⦁ Records of our discussions, if you contact us or we contact you (including records of phone calls).
⦁ Your image in photo or video form, and facial scan data extracted from your photo or video (known as ‘biometric data’), to verify your identity during onboarding as part of our Know-Your-Customer (KYC) checks, to authenticate you as an authorised user of our services, or to detect and prevent fraud.
⦁ Details of recent transactions made using our services.
⦁ Reason for payments.
⦁ Information about other people, such as your spouse or family, or source of funds for a payment order.
(If you give us personal data about other people (such as, your spouse or family), or you ask us to share their personal data with third parties, you must confirm you have brought this notice to their attention beforehand.)
⦁ Technical information, including the internet protocol (IP) address, biometric or behavioural signature/hash data, browser type and version, time zone, device language, operating system and hardware platform, unique device identifiers (for example, IMEI number, or mobile phone number), mobile network name.
⦁ Information on transactions enabled by our services, including the date, time, amount, currencies, exchange rate, beneficiary information (name, sort code, bank account number, IBAN).
We may collect information from third parties such as:
⦁ Sanctions and politically exposed persons status information from official registers and Know Your Customer information provider databases.
⦁ Publicly available social media information, and information and contact details from publicly available sources, such as media stories, online registers or directories, and websites.
This information, including facial scan data extracted from any photo or video you submit (known as ‘biometric data’), may be checked against public sources or KYC provider databases to authenticate you as an authorised user of our services, and verify your identity. It enables us to comply with our obligations under KYC, anti-money laundering, and other laws and to assist with fraud monitoring and prevention.
Whenever you apply for or use our services, we may use your personal data to:
⦁ Decide whether to approve your application.
⦁ Meet our contractual and legal obligations relating to any products or services you use
⦁ Authenticate you as an authorised user of our services when necessary (for example, if you contact our customer support).
⦁ Provide you with customer support services. We may record and monitor any communications between you and us, including phone calls, to maintain appropriate records, check your instructions, analyse, assess, and improve our services, and for training and quality control purposes.
We use your personal data to check your address and identity, protect against fraud, keep to financial crime laws and to confirm that you’re eligible to use our services.
We use your personal data to inform you of information, or products and services, where relevant and interesting to you (where allowed by law). This may include analysing how you use our products, services and your transactions.
You can ask us to stop sending you marketing information by clicking ‘unsubscribe’ or requesting in reply that we do not continue to send you marketing communications.
We prepare anonymous statistical datasets about our customers’ transaction patterns:
⦁ For forecasting purposes.
⦁ To understand how customers use our services.
⦁ To comply with governmental requirements and requests.
⦁ To inform business strategy, including product development.
These datasets may be shared internally or externally with other companies, such as compliance support or audit companies, and industry regulators. We produce these reports using information about you and other customers. The information used and shared in this way is never personal data and you will never be identifiable from it. Anonymous statistical data cannot be linked back to you as an individual.
We use your personal data:
⦁ To share it with other organisations (for example, government authorities, law enforcement authorities, tax authorities, fraud prevention agencies).
⦁ If this is necessary to meet our legal or regulatory obligations.
⦁ To identify and support vulnerable customers by letting you tell us if you need help via customer support communications and through transactions. For example, we will try to identify whether you are vulnerable so we can provide you with enhanced support.
⦁ In connection with legal claims.
⦁ To help detect or prevent crime.
Sometimes, we’re legally required to ask you to provide information about other people. For example, we might ask you to explain the source of funds for a payment order, and reason for payment.
We use pixels or web beacons in our direct marketing emails. These pixels track whether our email was delivered and opened, and whether links within the email were clicked. They also allow us to collect information such as your IP address, browser, email client type, and other similar details. We use this information to measure the performance of our email campaigns, and for analytics purposes.
Keeping to contracts and agreements between you and us, where the data is required to deliver the services specified in our contract with you.
Legitimate interests, where we want to:
⦁ Inform you of information, or products and services, relevant to our products or services that you already use).
⦁ Develop our products and services.
⦁ Be efficient about how we meet our legal and contractual duties.
⦁ Develop and improve how we deal with financial crime and meet our legal responsibilities.
Substantial public interest, where we process your personal data, or your sensitive personal data (sometimes known as special category personal data)
⦁ To adhere to government regulations or guidance, such as our obligation to prevent fraud
⦁ Support you if you are or become a vulnerable customer.
Legal obligations; in some cases, we have a legal responsibility to collect and store your personal data (for example, under anti-money laundering laws we must hold certain information about our customers).
Depending on the products or services you use, we may make automated decisions about you. This means that we may use technology that can evaluate your personal circumstances and other factors to predict risks or outcomes. This is sometimes known as profiling. We do this for the efficient running of our services and to ensure decisions are fair, consistent, and based on the right information.
Where we make an automated decision about you, you have the right to ask that a person manually reviews it. You can find out more about this in the What are my rights? Section below.
For example, we may make automated decisions about you that relate to:
Service registration for:
⦁ KYC, anti-money laundering and sanctions checks.
⦁ Identity and address checks.
Detecting fraud, in monitoring your transaction activity to detect fraud and financial crime.
Keeping to contracts and agreements between you and us, where the processing is required to deliver the services specified in our contract with you.
Legal obligations, where we have a legal responsibility to process your personal data (for example, under anti-money laundering laws).
Legitimate interests, where we want to develop and improve how we deal with financial crime and meet our legal responsibilities.
Credit checks are not required for any of our current services, and therefore we will not run credit checks on you.
If you sign up to our services, and where national laws allow, we’ll assume you want to be contacted by post, push notification, email and text message with information about our products, services, offers and promotions. Where national laws require us to get your consent to send marketing messages, we’ll do so in advance.
We use your personal data to personalise marketing messages about our products and services so they are more relevant and interesting to you (where allowed by law). This may include analysing how you use our services and your transactions.
You can object to profiling for direct marketing purposes. You can also adjust your preferences or tell us you don't want to receive direct marketing at any time (See 8. How do I exercise my rights?) specifying you object to profiling for direct marketing purposes. However, if you do not wish to receive personalised or general marketing communications via a particular channel, follow the unsubscribe instructions included in the communication.
If you do not want to receive personalised marketing messages, and opt out of receiving them, you will not receive any marketing communications. However, you may still receive generic information about our products and services in the MonRemit app.
We won't pass your details on to any external organisation for their marketing purposes without your permission. You can find out more in the Do you share my personal data with anyone else? Section below.
Consent, where we are required by law to collect your consent.
Legitimate interests, to send you marketing and to provide information relevant to your interests.
Your rights under UK and EU data protection law are outlined below. Your ability to exercise these rights will depend on several factors. If you attempt to exercise your rights, on occasion we will not be able to agree to your request. For example, if we have a legitimate reason or the right does not apply to the particular information we hold about you.
We provide this privacy notice to explain how we use your personal data.
If you ask, we’ll provide a copy of the personal data we hold about you. We can’t give you any personal data about other people, personal data which is linked to an ongoing criminal or fraud investigation, or personal data which is linked to settlement negotiations with you. We also won't provide you with any communication we've had with our legal advisers.
You can have incomplete or inaccurate personal data corrected. Before we update your file, we may need to check the accuracy of the new personal data you have provided.
You can ask us to delete your personal data if:
⦁ There's no good reason for us to continue using it.
⦁ You gave us consent (permission) to use your personal data and you have now withdrawn that consent.
⦁ You have objected to us using your personal data.
⦁ We have used your personal data unlawfully.
⦁ The law requires us to delete your personal data.
As a regulated financial services provider, we must keep certain customer personal data even when you ask us to delete it (we've explained this in more detail below). If you've closed your account, we may not be able to delete all personal data attributable to you because these regulatory responsibilities take priority. We’ll always let you know if we can't delete your personal data.
You can tell us to stop using your personal data, including profiling you, for marketing.
If our legal basis for using your personal data is 'legitimate interests' and you disagree with us using it, you can object.
However, if there is an overriding reason why we need to use your personal data, we will not accept your request.
If you object to us using personal data which we need to provide our services, we may need to close your account as we won’t be able to provide the services.
You can ask us to suspend using your personal data if:
⦁ You want us to investigate whether it’s accurate.
⦁ Our use of your personal data is unlawful, but you don’t want us to delete it.
⦁ We no longer need your personal data, but you want us to continue holding it for you in connection with a legal claim.
⦁ You have objected to us using your personal data (see above), but we need to check whether we have an overriding reason to use it.
As a regulated financial services provider, we must keep certain customer personal data even when you ask us to delete it (we've explained this in more detail below). If you've closed your account, we may not be able to delete all data attributable to you because these regulatory responsibilities take priority. We’ll always let you know if we can't delete your personal data.
If we can, and are allowed to do so under regulatory requirements, we’ll provide your personal data in a structured, commonly used, machine-readable format.
If you’ve given us consent to use your personal data, you can withdraw it at any time (See 8. How do I exercise my rights?).
(Please note, it is lawful for us to use the personal data up to the point you withdraw your permission.)
If we make an automated decision about you that significantly affects you, you can ask us to carry out a manual review of this decision.
To exercise any of your rights described in the previous section, you can send us an email to dataprotection@monremit.com or use the form at https://monremit.co.uk/data-and-account-management/.
For security reasons, we can't deal with your request if we’re not sure of your identity, so we may ask you for proof of ID.
If a third party exercises one of these rights on your behalf, we may need to ask for proof that they are authorised to act on your behalf.
When you exercise one of your rights, it may take us up to one month to respond to you or implement your changes.
We will usually not charge you a fee when you exercise your rights. However, law allows us to request a reasonable fee, or refuse to act on your request if it is unreasonably unfounded, excessive, or repetitive.
If you’re unhappy with how we’ve handled your request, you can complain to your local data protection authority. In the United Kingdom, this is the Information Commissioner’s Office (website).
When you initiate a payment, we’ll provide the recipient with your name alongside your payment. This is because, like all payment institutions, we’re required by law to include certain information with payments.
We normally share your personal data with the following suppliers.
So we may provide our services to you.
To help us provide our services to you. This may include banking partners, intermediaries, and international payment service providers.
To help us verify your identity so we can provide our services to you.
To help us improve our website or app.
Communications services providers
To help us send you emails, push notifications and text messages.
From time to time, we may work with other partners to offer you co-branded services or promotional offers, and we’ll share some of your personal data with those partners. We will always make sure you understand how we and our partners process your personal data for these purposes.
If you ask us to, we may share your personal data with other financial institutions. For example, if you make a payment by mistake, we may share your information with the beneficiary’s financial institution.
We also share your personal data with other financial institutions, financial services companies, insurance providers, government authorities, law enforcement authorities, tax authorities, companies and fraud prevention agencies to check your identity, investigate or protect against suspected fraud, keep anti-money laundering laws, or any other laws, and confirm that you’re eligible to use our products and services.
We may also need to share your personal data with other third-party organisations or authorities:
⦁ If we have to do so under any law or regulation.
⦁ If we sell our business or credit portfolio.
⦁ With criminal or fraud investigations.
⦁ To enforce our rights (and those of customers or others).
⦁ In connection with legal claims.
When we use social media for marketing purposes, your personal data (limited to only your name, email address) may be shared with the social media platforms so that they can check if you also hold an account with them. If you do, we may ask the advertising partner or social media provider to:
⦁ Use your personal data to send our adverts to you, because you might be interested in a new MonRemit product or service.
⦁ Not send you our adverts, because the marketing relates to a service that you already use, or where you have withdrawn consent (where applicable), or exercised your rights, for example, your right to restrict processing.
⦁ Send our adverts to people who have a similar profile to you (for example, if one of our services is particularly useful to people with similar interests to the ones on your social media profile, we may ask our advertising partner or social media partner to send our adverts for that service to those people).
An example of how we may use social media for marketing purposes is through Facebook’s ‘Custom Audience’ tool. Read more about these terms.
We may share your personal data with our advertising partners in the ways described above, but the personal data is hashed before we send it, and the advertising partner we share it with is only allowed to use that hashed personal data in the ways described above.
You can contact us at any time (See 8. How do I exercise my rights?) if you do not want us to share your personal data for advertising purposes. You can also manage your marketing preferences directly with any social media provider that you have an account with.
Where you direct us to share your personal data with a third party, we may do so. For example, you may authorise third parties to act on your behalf (such as a lawyer, accountant, or family member or guardian under a power of attorney). We may need to ask for proof that a third party has been authorised to act on your behalf.
As we provide an international service, we may need to transfer your personal data outside the United Kingdom or European Economic Area (EEA) to help us provide our services.
For example, if you make an international payment, we’ll send funds to banks (or other Account Servicing Payment Service Providers), or payment partners, outside the United Kingdom or EEA. We might also send your personal data outside the United Kingdom or EEA to keep to global legal and regulatory requirements, and to provide ongoing support services.
We may send your personal data outside the United Kingdom or EEA to:
⦁ Keep to global legal and regulatory requirements.
⦁ Provide ongoing support services.
⦁ Fraud prevention agencies or law enforcement authorities.
⦁ Enable us to provide you with the products or services you have requested.
If we transfer your personal data to another country that doesn’t offer a standard of data protection equivalent to the United Kingdom (or EEA if applicable), we will make sure that your personal data is sufficiently protected. For example, we’ll make sure that a contract with strict data protection safeguards is in place before we transfer your personal data. In some cases, you may be entitled to ask us for a copy of this contract.
If you would like more information, please contact us by sending an email to dataprotection@monremit.com.
We recognise the importance of protecting and managing your personal data. Any personal data we process will be treated with the utmost care and security. This section sets out some of the security measures we have in place.
We use a variety of organisational and technical measures to:
⦁ Maintain the confidentiality, availability and integrity of your personal data.
⦁ Make sure your personal data is not improperly used or disclosed.
We have detailed information security and data protection policies, which our employees are required to follow when they handle your personal data. Our employees receive data protection and information security training. Personal data is stored on secure computer systems with access management controls to limit physical, system, and information access to only authorised individuals.
Before we share your personal data with other companies, we perform due diligence, including assessment of:
⦁ The company’s legal status, its management, data processing locations, and related sub-outsourcing.
⦁ The security controls the company has in place to protect your personal data.
While we take all reasonable steps to ensure that your personal data will be kept secure from unauthorised access, we cannot guarantee it will be secure during input into our app or website by you. We use modern industry-standard encryption for communication between our app, website, and payment-processing services.
We will keep your personal data for as long as necessary to achieve the original purpose we collected it for, and in line with relevant laws.
We are required to keep certain personal data for specified time periods by KYC, anti-money laundering or payment services law.
We may keep your personal data for a longer period because of a potential or ongoing court claim, or for another legal reason.
If we change the way we use your personal data, we’ll update this notice and, if appropriate, let you know by email, or through our website.
