Privacy policy
Privacy Policy / EEA Residents
1. Introduction
1.1 This policy applies to MiFinity Malta Ltd and to the companies that are part of the MiFinity Group (MiFinity UK Limited, MiFinity Payments Limited (Ireland), MiFinity Canada Limited, Concentric Data Services Limited (Ireland) and Concentric Data Services Limited (Malta)). The reference to MiFinity (including “we”, “us” or “our”) includes the above company and all relevant group companies.
1.2 This policy applies to personal data we collect about: a) visitors to our website; and
b) people who do business with us or register for our services.
1.3 Please read this Privacy Policy carefully to understand our views and practices regarding your personal data, how we use it and how we will process it. If you do not agree with this Privacy Policy, please do not use our services.
2. The personal data we collect about you
When you do business with us or register for our service we may collect the following personal data from you:
a) your full name, residential address, email address, residence, nationality, IP address, mobile number, date of birth and bank or payment card details and any proof of your identity and/or address that we may request;
b) details of any transactions you carry out through our website and/or mobile application of the fulfilment of your requests;
c) details of any bank account (including, but not limited to: account holder, account name, account number, sort code, online banking PIN, Transaction Authentication Number “TAN” and password, available balance and transaction history of your bank account,);
d) details of any credit, debit or other card used by you for transactions;
e) your participation in any promotion sponsored by us;
f) correspondence that you send us;
g) calls that we make to you or you make to us;
h) surveys that you complete;
i) personal data collected through cookies – please see Section 6 below for more details;
and
j) your IP address, log-in times, operating system and browser type.
2.1 In order to fulfil our legal obligations to prevent fraud and money laundering, we will obtain information about you from third party agencies, including your financial history, county court judgements and bankruptcies, from credit reference and fraud prevention agencies when you open an account with MiFinity and at any time when it is necessary to prevent fraud and minimise our financial risks.
3. Representation
3.1 If you appoint a representative to act on your behalf, we would require from the representative:
a) Proof that you have given your representative authority to exercise your data protection rights, or make a complaint on your behalf; and
b) proof of identity of the representative.
You need to confirm that the representative can receive on your behalf any data protection notices, and give consent to the transfer of your personal data abroad.
4. How we will use the personal data about you
4.1 We use personal data held about you in the following ways:
a) to operate and administer your account and to provide the services that you have requested;
b) to carry out your instructions to make and receive payments and undertake transactions using our services, including verifying that you have sufficient funds in your nominated bank account to make such payments;
c) to allow you to participate in the interactive features of our website;
d) to notify you about changes to our service(s)/this website;
e) to improve our internal training programs;
f) to comply with financial services regulations including retention of financial information and transactions;
g) for financial and identity checks, fraud prevention and detection checks, anti-money laundering and credit checks;
h) for customer service, including answering questions and responding to feedback and complaints;
i) to enhance the security of our services
j) to ensure that content on our website is presented in the most effective manner for you and for your computer; and
k) for research, statistical analysis and behavioural analysis.
5. Marketing
5.1 We may also wish to provide you with information about the special features of our website or any other service we think may be of interest to you. If you would rather not receive this information, please send an email message to [email protected]. If you agreed to MiFinity providing you with marketing information, and now wish to opt out or decide to opt out at a later date, you can do this by sending an email to [email protected].
6. Cookies and other information-gathering technologies
6.1 Our website uses third party cookies. Cookies are text files placed on your computer to collect standard Internet log information and visitor behaviour information. These
cookies allow us to distinguish you from other users of the website. Furthermore it helps us to provide you with a good experience when you browse our website and allows us to improve our website.
7. How we protect your personal data
7.1 We have put in place the following security procedures and technical and organisational measures to safeguard your personal data:
a) access to your account is controlled by a password unique to you;
b) we store your personal data on secure servers; and
c) we automatically encrypt your personal data in transit from your computer to ours.
7.2 We have implemented measures designed to secure your personal data from accidental loss and from unauthorised access, use, alteration and disclosure. The safety and security of your personal data is also dependent upon you. If we have given you (or if you have chosen) a password or access code for access to certain parts of our website/portal or mobile applications and similar, you are responsible for keeping this password and/or access code confidential. You must not share your password and/or
access code with anyone. You must ensure that there is no unauthorised use of your password and access code. MiFinity will act upon instructions and information received from any person that enters your user ID and password, therefore you are fully responsible for all use and any actions that may take place during such use of your account.
7.3 You must promptly notify MiFinity of any personal data you have provided to us which has changed.
7.4 The transmission of personal data via the internet is not completely secure. Although we will do our best to protect your personal data, we cannot guarantee the security of your personal data transmitted to our site, unless you are communicating with us through a secure channel that we have provided. Once we have received your personal data, we will use strict procedures and security features to try to prevent unauthorised access.
7.5 If you are concerned that any of your login details have been compromised, you can change them at any time once you are logged on, but you should always also immediately contact MiFinity Client Services. and tell us why you think your login details have been compromised.
8. Retention of personal data
8.1 The periods for which we retain your personal data are determined based on the nature and type of personal data, our service and the country in which they are provided as well as any applicable local legal or regulatory requirements.
8.2 If you use our services, we will retain your personal data as long as necessary to provide you with the services of your choice and any linked legitimate business purpose. That would generally mean we retain your personal data for as long as you are our customer and for a required period of time afterwards based on our legal obligations.
8.3 When our relationship with you ends, we still need to retain certain elements of your personal data for 5 years, or such greater period as mandated by the Authorities.
8.4 We might also continue marketing and sending you direct marketing, subject to local laws and where you have not objected the receipt of to such marketing material.
9. Disclosure of personal data
9.1 We may disclose your personal data to our group companies, which means our subsidiaries and any subsidiaries of our shareholder(s) and/or any companies which provide outsourced services to us, who are based in different countries within the EEA and the rest of the World.
9.2 Disclosure of your personal data may be necessary in order to fulfil your request, process your payment details, provide support services and monitor fraudulent activities.
9.3 When sending money to a person who you wish to pay, we will pass on certain details to the recipient. Depending on the requirements of that other person and the type of payment involved, we may send other personal data such as your name, address and country of residence if the recipients request such data from us in order to improve the payment process, to reconcile payments with the commercial transaction or to conduct
their own anti-fraud and anti-money laundering checks.
9.4 When you open an account, at intervals of up to every 3 months and at any other time it is necessary to do so to protect our financial interests and prevent money-laundering or fraud, we share certain information about you and your account with us, which may include financial history and transactions as part of our normal business operations with our banks, payment facilitator partners, credit/debit card processing services, identity verification service providers and credit reference agencies in order to limit our exposure to fraud and other criminal activities and to manage our financial risk. When conducting identification or fraud prevention checks, the relevant parties may retain a record of our query along with your personal data and may share this personal data with other fraud prevention agencies.
9.5 We will share your personal data with third parties only in the ways that are described in this Privacy Policy. We do not sell your personal data to third parties. We may also disclose your personal data to:
a) a prospective buyer of our business or a buyer of a substantial number of the shares in our business, if MiFinity is involved in a merger, acquisition, or sale of all or a portion of its assets, you will be notified via email and/or a prominent notice on our website of any change in ownership or uses of your personal data, as well as any choices you may have regarding your personal data;
b) Law Enforcement, the Maltese Financial Services Authority (MFSA), the Financial Intelligence Analysis Unit (FIAU) and any other law enforcement body, regulatory body or court if we are obliged or required by law to disclose or share your personal data , or to protect the rights, property, or safety of ourselves or our group companies, our customers, or others; and
c) third parties we may occasionally use to provide you with the services that you have requested.
Such third parties will not use your personal data for any other purpose other than for what it was intended for.
10. Overseas transfers
10.1 The personal data you provide may be transferred to countries outside the European Economic Area (EEA) that do not have similar protections in place regarding your data and restrictions on its use as set out in this policy. However, we will take measures to ensure adequate protections are in place to ensure the security of your personal data.
11. Your Rights
11.1 In order to access to your personal data, you have the right to request a copy of the personal data that we hold about you. If you would like a copy of some or all of your personal data, please send an email to [email protected] or send a letter to : MiFinity Malta Limited, Level 3 (SUITE 2507), Tower Business Center, Tower Streer, Swatar, Birkirkara, Malta. We may make a small charge for this service.
11.2 Correction of personal data – is to ensure that your personal data is accurate and up to date. If any of the personal data that you have provided to MiFinity changes, for example if you change your email address, residential address or name, please let us know the correct details by sending an email to [email protected]. You may also ask us to correct and/or remove personal data you think is inaccurate.
11.3 Right to withdraw consent – in cases where you gave your consent to process your personal data, you have the right to withdraw such consent. It is important to know that by withdrawing your consent MiFinity may have to terminate the relationship with you if the given personal data is required for the provision of the services.
11.4 Right of erasure (also known as ‘right to be forgotten’) – You can request either verbally via our Client Services or in writing to [email protected] for us to erase your personal data where there is no compelling reason to continue processing. This right only applies in certain circumstances; it is not absolute right.
11.5 Right to data portability – This right allows you to obtain your personal data that you have provided to us in a format which enables you to transfer such personal data to another organisation. You may have the right to have your personal data transferred by us directly to the other organisation, if this is technically feasible.
11.6 Right to restrict processing of personal data – You have the right in certain circumstances to request that we suspend our processing of your personal data. Where we suspend our processing of your personal data, we will still be permitted to store it, but any other processing of this personal data will require your consent, subject to certain exemptions.
11.7 Right to object to processing of personal data – You have the right to object to our use of your personal data which is processed on the basis of our legitimate interests. However, we may continue to process your personal data, despite your objection, where there are compelling legitimate grounds to do so or we need to process your personal data in connection with any legal claims.
12. Monitoring of the Communication
12.1 We may monitor and record communications with you (such as telephone conversations and emails) for the purpose of quality assurance, training, fraud prevention and compliance with our legal obligations.
13. Communicating with you
13.1 We may contact you by email to the primary email address registered on your account with MiFinity and/or by telephone to the contact number(s) you have provided when registering for your account with MiFinity. You can change your primary email address and/or contact number at any time.
13.2 You may also receive system-generated transactional emails such as confirmation of uploads, notification of receipt of payments, notification of password changes, etc. which are necessary for the proper operation and administration of your account.
13.3 Phishing is the name given to attempts to steal personal data and financial account details from a website user. “Phishers” use fake or “spoof” emails to lead users to counterfeit websites where the user is tricked into entering their personal details, such as credit card numbers, user names and passwords. WE WILL NEVER SEND EMAILS ASKING YOU FOR SUCH DETAILS AND OUR STAFF WILL NEVER ASK YOU FOR YOUR PASSWORD. If you do receive such an email or are asked for your password by anyone claiming to work for us, please forward the email or report the incident to our Data Protection Officer at [email protected] or by contacting MiFinity Client Services.
14. Your consent
14.1 By submitting your personal data you consent to the use of that personal data as set out in this policy.
15. Changes to Privacy Policy
15.1 We keep our Privacy Policy under regular review. If we change our Privacy Policy, we will post the changes on this page, and place notices on other pages of the website, so that you may be aware of the personal data we collect and how we use it at all times. We reserve the right to make changes to our Privacy Policy at any time, without notice, where such change is required by applicable legislation.
16. Links to other websites
16.1 Our website contains links to other websites. This Privacy Policy applies to this website and our mobile applications, so when you access links to other websites you should read their own privacy policies.
17. Filing a Compliant
17.1 If you are not satisfied with how we manage your personal data, you have a right to make a complaint. Please email your complaint to the Data Protection Officer at [email protected], if you feel that your complaint has not been dealt with to your satisfaction you can contact Office of the Information and Data Protection Commissioner (IDPC) or depending on your location then your local Data Protection Authority.