Last Updated: March 21, 2026

Privacy Policy

At PaySwiift, we take your privacy seriously. This policy describes how we collect, use, and protect your personal information.

Effective Date: January 1, 2024
GDPR & CCPA Compliant

Your Privacy Matters

This Privacy Policy explains how PaySwiift ("Bank", "We", "Us", "Our") collects, uses, discloses, and protects your information when you use our banking services, website, and mobile applications. We are committed to protecting your privacy in accordance with applicable data protection laws, including GDPR, CCPA, and other relevant regulations.

1

Information We Collect

1.1. Personal Information: When you open an account or use our services, we collect:

• Full name, date of birth, and government-issued ID information;

• Contact information (email address, phone number, physical address);

• Social Security Number, Tax Identification Number, or equivalent;

• Employment information, occupation, and source of funds;

• Financial information including income, assets, and transaction history;

• Biometric data (fingerprints, facial recognition) for authentication;

• Signature and voice recordings for verification purposes;

• Device information, IP addresses, and login credentials.

1.2. Account Information: We collect and maintain:

• Account numbers, balances, and transaction history;

• Beneficiary and payee information;

• Card details and usage patterns;

• Loan applications and credit history;

• Investment preferences and portfolio information;

• Communication records with our support team.

1.3. Technical Information: When you use our website or app, we automatically collect:

• IP address, browser type, and operating system;

• Device identifiers and mobile network information;

• Cookies, tracking pixels, and similar technologies;

• Pages visited, time spent, and navigation patterns;

• App crashes, performance data, and error logs.

1.4. Verification Information: To comply with KYC/AML regulations, we collect:

• Government-issued ID documents (passport, driver's license, national ID);

• Proof of address (utility bills, bank statements, lease agreements);

• Source of funds documentation (pay stubs, tax returns, business financials);

• Beneficial ownership information for business accounts;

• Politically Exposed Person (PEP) status and sanctions screening results.

1.5. Biometric Information: With your consent, we may collect:

• Fingerprint data for device authentication;

• Facial recognition data for identity verification;

• Voice patterns for telephone banking authentication;

• Behavioral biometrics (typing patterns, mouse movements).

1.6. Location Information: We may collect:

• GPS coordinates from your mobile device (with permission);

• IP-based location approximation;

• Transaction locations from card usage;

• Branch visit locations.

2

How We Use Your Information

2.1. Service Delivery: We use your information to:

• Process transactions and maintain your account(s);

• Verify your identity and prevent fraud;

• Provide customer support and respond to inquiries;

• Send account notifications, alerts, and statements;

• Process loan applications and credit decisions;

• Calculate and apply fees, interest, and charges.

2.2. Compliance and Legal Obligations: We use your information to:

• Comply with KYC (Know Your Customer) requirements;

• Perform AML (Anti-Money Laundering) checks and monitoring;

• Screen against sanctions lists and watchlists;

• Report suspicious activities to regulatory authorities;

• Respond to court orders, subpoenas, and legal requests;

• Maintain records as required by law (typically 5-7 years).

2.3. Security and Fraud Prevention: We use your information to:

• Monitor for unauthorized access and suspicious activity;

• Detect and prevent fraudulent transactions;

• Authenticate your identity during login and transactions;

• Maintain audit logs and security records;

• Investigate security incidents and breaches.

2.4. Improvement and Development: We use your information to:

• Analyze usage patterns and improve our services;

• Develop new features and products;

• Personalize your experience and offers;

• Conduct research and analytics;

• Test and optimize system performance.

2.5. Marketing and Communications: With your consent, we may:

• Send promotional offers and product recommendations;

• Notify you about new features or services;

• Conduct customer satisfaction surveys;

• Provide personalized financial insights;

• Share information about partners and affiliates.

2.6. Automated Decision-Making: We may use automated processes for:

• Credit scoring and loan eligibility decisions;

• Fraud detection and transaction monitoring;

• Risk assessment and account reviews;

• Personalized offers and recommendations.

3

Information Sharing and Disclosure

Important: We do not sell your personal information to third parties. We only share information as necessary to provide our services and comply with legal obligations.

3.1. Service Providers: We share information with:

• Payment processors and card networks (Visa, Mastercard, etc.);

• Banking partners and correspondent banks;

• Identity verification and KYC service providers;

• Cloud storage and data processing services;

• Customer support and communication platforms;

• Analytics and business intelligence tools;

• Marketing and advertising partners (with consent).

3.2. Regulatory and Legal Disclosures: We may disclose information to:

• Financial intelligence units and anti-money laundering authorities;

• Law enforcement agencies and courts;

• Tax authorities (IRS, HMRC, etc.);

• Banking regulators and supervisory bodies;

• Consumer protection agencies;

• In response to valid subpoenas, warrants, or court orders.

3.3. Business Transfers: In the event of:

• Merger, acquisition, or corporate reorganization;

• Sale of assets or business units;

• Bankruptcy or insolvency proceedings;

• Your information may be transferred to the successor entity.

3.4. Affiliates and Partners: We may share information with:

• Subsidiaries and affiliated companies;

• Strategic partners offering integrated services;

• Co-branded product partners;

• With your explicit consent or at your direction.

3.5. International Data Transfers: Your information may be transferred to:

• Countries where our service providers operate;

• Jurisdictions with different data protection laws;

• We implement Standard Contractual Clauses and safeguards;

• We ensure adequate protection through binding corporate rules.

4

Data Security Measures

4.1. Technical Safeguards: We implement industry-standard security measures including:

• 256-bit AES encryption for data at rest;

• TLS 1.3 encryption for data in transit;

• Multi-factor authentication for account access;

• Biometric authentication options (fingerprint, facial recognition);

• Automated session timeout after 30 minutes of inactivity;

• Rate limiting and brute force protection (max 5 attempts);

• Account lockout for 30 minutes after failed attempts;

• Password expiration every 90 days;

• Minimum password length of 8 characters.

4.2. Organizational Safeguards: We maintain:

• Strict access controls and need-to-know basis;

• Regular security training for all employees;

• Background checks for personnel handling sensitive data;

• Confidentiality agreements and data handling policies;

• Regular security audits and penetration testing;

• Incident response and breach notification procedures.

4.3. Physical Safeguards: We protect physical access through:

• Secure data centers with 24/7 monitoring;

• Biometric access controls to server facilities;

• Surveillance systems and security personnel;

• Secure disposal of physical records.

4.4. Security Monitoring: We continuously monitor for:

• Unauthorized access attempts and suspicious activities;

• Malware, ransomware, and cyber threats;

• Data breaches and information leaks;

• Compliance with security policies and standards.

5

Your Privacy Rights

GDPR Rights (EU Residents)

  • • Right to access
  • • Right to rectification
  • • Right to erasure
  • • Right to restrict processing
  • • Right to data portability
  • • Right to object

CCPA Rights (California Residents)

  • • Right to know
  • • Right to delete
  • • Right to opt-out
  • • Right to non-discrimination
  • • Right to correct
  • • Right to limit use

5.1. Access and Portability: You have the right to:

• Request a copy of your personal information;

• Receive data in a structured, machine-readable format;

• Request transfer to another service provider;

• Obtain information about how your data is processed.

5.2. Correction and Deletion: You have the right to:

• Request correction of inaccurate or incomplete data;

• Request deletion of your personal information;

• Withdraw consent for processing (where consent is the basis);

• Note: Legal retention requirements may limit deletion rights.

5.3. Objection and Restriction: You have the right to:

• Object to processing for direct marketing;

• Restrict processing during dispute or investigation;

• Opt-out of automated decision-making;

• Challenge profiling activities.

5.4. How to Exercise Your Rights: To exercise your privacy rights:

• Submit a request through your account settings;

• Email us at contact@payquin.com;

• Call us at +1-800-123-4567;

• Write to us at 123 Banking Street, Financial District;

• We will respond within 30 days (as required by law).

5.5. Verification Process: To protect your privacy:

• We may require identity verification before processing requests;

• We may request additional information to confirm your identity;

• Authorized agents may act on your behalf with proper documentation;

• We will notify you of any extensions or limitations.

6

Cookies and Tracking Technologies

6.1. Types of Cookies We Use:

Essential Cookies: Required for website functionality, authentication, and security. Cannot be disabled.

Functional Cookies: Remember your preferences, language, and settings.

Analytics Cookies: Help us understand how visitors use our site and improve performance.

Marketing Cookies: Track your browsing habits to deliver relevant advertisements.

Third-Party Cookies: Set by partners for integrated services and social media features.

6.2. Cookie Duration: We use:

• Session cookies (expire when you close your browser);

• Persistent cookies (remain for up to 2 years);

• First-party cookies (set by our domain);

• Third-party cookies (set by our partners).

6.3. Managing Cookies: You can control cookies through:

• Browser settings (block, delete, or disable cookies);

• Our cookie consent manager (available on first visit);

• Opt-out tools like YourOnlineChoices or Network Advertising Initiative;

• Note: Disabling essential cookies may affect website functionality.

6.4. Tracking Technologies: We also use:

• Web beacons, pixels, and tags;

• Local storage and session storage;

• Device fingerprinting technologies;

• SDKs in mobile applications.

7

Data Retention and Deletion

7.1. Retention Periods: We retain your information for:

• Active accounts: Duration of account relationship + 7 years;

• Transaction records: 7 years (regulatory requirement);

• KYC documentation: 5 years after account closure;

• Login records: 2 years;

• Marketing preferences: Until consent withdrawn;

• Cookie data: As specified in cookie policy.

7.2. Account Closure: When you close your account:

• Transactional capabilities are immediately suspended;

• Remaining balance is returned (less fees);

• Personal information is flagged for deletion;

• Legal and regulatory holds may apply;

• Some information may be retained for fraud prevention.

7.3. Data Deletion: After retention periods expire:

• Personal information is securely deleted;

• Backups are purged or anonymized;

• Aggregated, anonymized data may be retained for analytics;

• Deletion certificates are available upon request.

7.4. Legal Holds: We may retain information beyond standard periods:

• During active litigation or investigations;

• To comply with court orders or legal obligations;

• For unresolved disputes or claims;

• As required by bankruptcy or insolvency proceedings.

8

Contact Us and Complaints

Data Protection Officer

Email: dpo@payquin.com

Phone: +1-800-123-4567

Privacy Team

Email: contact@payquin.com

Hours: Mon-Fri: 9AM-5PM EST

8.1. Privacy Questions: For privacy-related inquiries:

Email: contact@payquin.com

Phone: +1-800-123-4567

Address: 123 Banking Street, Financial District

Hours: Mon-Fri: 9AM-5PM EST

8.2. Filing a Complaint: If you believe we have violated your privacy rights:

• Contact our Privacy Team first - we will respond within 30 days;

• If unsatisfied, you may file a complaint with your local data protection authority;

• For EU residents: Your local Data Protection Authority;

• For UK residents: Information Commissioner's Office (ICO);

• For California residents: California Attorney General.

8.3. Supervisory Authority Contact:

Information Commissioner's Office

Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

Tel: +44 303 123 1113

Website: www.ico.org.uk

9

Policy Updates and Changes

9.1. Policy Changes: We may update this Privacy Policy to reflect:

• Changes in our data practices or services;

• New legal or regulatory requirements;

• Industry standards and best practices;

• Feedback from customers and regulators.

9.2. Notification of Changes: We will notify you of material changes through:

• Email to your registered address;

• Notice in your account dashboard;

• Pop-up notification on our website/app;

• Push notifications (with your consent).

9.3. Version History:

• Version 4.2 - January 1, 2024 (Current)

• Version 4.1 - October 15, 2023

• Version 4.0 - July 1, 2023

• Version 3.0 - January 1, 2023

9.4. Continued Use: Your continued use of our services after changes constitutes acceptance of the updated policy. If you do not agree, you may close your account.

Our Commitment to Your Privacy

At PaySwiift, we are committed to protecting your privacy and being transparent about our data practices. We regularly review and update our privacy policy to ensure compliance with evolving regulations and industry standards.

GDPR Compliant
CCPA Compliant
PCI DSS Level 1

Questions About Your Privacy?

Our privacy team is available to address any concerns.

Version 1.0.0 | Last Updated: March 21, 2026 | PaySwiift is a registered financial institution