Scope and controller
This notice applies to visits, contact requests and initial eCEFA access applications. The final legal operating entity and data-controller details will be published before any regulated account or wallet service is activated.
Financial activation remains locked while controller, licence, representative and supervisory-authority details are incomplete.
Data we collect
- Contact details and the content of a message.
- Applicant type, country, intended use and consent records.
- Security and audit metadata needed to protect the service.
- No identity documents, biometrics, private keys or source-of-funds evidence are requested on the public website.
Purpose and legal basis
We use submitted data to respond, route an application, prevent abuse, preserve audit evidence and prepare requested pre-contractual steps. Consent is recorded where required. Legal-obligation and legitimate-interest bases are enabled only when the responsible entity and processing context have been confirmed.
Retention and deletion
The production retention schedule must be approved per record class and jurisdiction. Until then, the system uses minimisation and activation gates; it does not treat indefinite retention as a default.
Your rights
Depending on applicable law, you may request access, correction, deletion, restriction, portability or objection, and may complain to a competent supervisory authority. Account holders can use the authenticated Privacy Center; identity verification remains proportionate to the request.
Automated decisions and human review
Risk and monitoring tools may support a decision, but a materially affected account holder can request an explanation, express their position and obtain human reconsideration. A provider score cannot decide its own appeal.