Privacy Policy

Dated: February 2019

Overview

Privacy and the security of data are of paramount importance to all of us at TrueLayer. Please read this document carefully, and if you have any questions or queries about the contents, please email us at privacy@truelayer.com

In this Privacy Policy, TrueLayer will sometimes be referred to as ‘we’, ‘us’, or ‘our’. Additionally, there are references to “You”. In these instances, “You” may be a visitor to our site, or a user of our Services (“Provider”), or a customer of a Provider (“End User”).

Our company is based at 1 Hardwick Street, London, EC1R 4RB , and our registration number with the Information Commissioner's Office (“ICO”) - the regulator in charge of data protection and privacy - is ZA207054.

We are the data controller for the purposes of the personal data we collect via our website and for the performance of the services listed under the usages of your personal data, below (together, the “Services”).

Personal Data

Collection of your personal data

When you use our Services we will have access to your personal data that you submit to us and personal data held by Account Servicing Payment Service Providers (i.e. any payment service provider, such as a bank or a credit card issuer that maintains an online payment account on your behalf) (“ASPSPs”) (“Personal Data”) for the duration of the transmission.

Such Personal Data may include your date of birth, gender, account information, account balance, transactions, information on loans, insurance data and investments data. The manner in which we access, use, process and store your personal data for the provision of the Services is set out below.

When you use our website (the “Site”) we will collect browser information, including your IP address. We will also store some cookies (see our Cookies section below for more details).

Use of your personal data

Your Provider will direct you to use our Services which will include the following:

  • We will provide you with a software tool (“Tool”) which you can use to transmit information (including personal data) relating to payment accounts (“Account Information”) that you hold with ASPSPs to your Provider, and for Payment Initiation, which you can use to consent to and authorise a payment as specified by your Provider; this may require that your Provider sends us your bank account details;
  • To use our Services you may need to provide the same identifying information that you use to login to your online bank account to access your relevant payment accounts with your bank (“Credentials”).
  • The Tool may allow you to use your Credentials to retrieve such Account Information as you choose to transmit to the Provider. Schedule 1 to the Terms of Service ists the information that you can elect to retrieve and transfer using the Tool.

You should check your Provider’s rules on data privacy. If your Account Information (including any Personal Data) is transmitted from a Provider to us, or through our software to a Provider, that Provider (and not TrueLayer) is responsible for it.

Our Tool may merge or aggregate Account Information retrieved from your Provider, or a particular ASPSP with Account Information retrieved from other ASPSPs where you or your Provider have instructed us to access and transmit such information.

When you have signed up on TrueLayer’s website for marketing purposes we will use your email address to contact you in relation to products, events and service-related matters, where you have provided your consent to do so.

Retention of your personal data

We will not retain your information for any longer than we think is necessary. Information that we collect will be retained for as long as needed in order to:

  • fulfil the purposes outlined in the ‘Use of your personal data’ section above;
  • in line with our legitimate interest;
  • or for a period specifically required by applicable regulations or laws, such as retaining the information for regulatory reporting purposes.

When determining the relevant retention periods, we consider factors including:

  • our contractual obligations and rights in relation to the information involved;
  • legal obligation(s) under applicable law to retain data for a certain period of time;
  • statute of limitations under applicable law(s);
  • our legitimate interests where we have carried out balancing tests (see section on 'How we use your personal information' above);
  • fraud and risk management;
  • (potential) disputes; and
  • guidelines issued by relevant data protection authorities.

Otherwise, we securely erase your information where we no longer require your information for the purposes collected.

Deletion of Personal Data

We will not keep your Personal Data for longer than necessary. We will delete your Personal Data:

  • as soon as it is no longer needed to provide the Services to you;
  • upon termination of the Terms of Service; and / or
  • if You withdraw Your consent, and Your consent is necessary for us to retain the data.

Disclosure

We may share your Personal Data with selected third parties, including business partners, suppliers and sub-contractors that assist us in the provision of our Service to you. The third-party providers used by us will only collect, use and disclose your information as instructed by us to provide Services to you.

We may also disclose your Personal Data to other third parties in the event that:

  • We reasonably consider that we are under a duty to disclose or share your Personal Data in order to comply with any legal obligation, or
  • in order to enforce or apply our Terms of Service and other agreements; or
  • to protect the rights, property, or safety of TrueLayer, our customers, or others.

Transfer of your personal data outside of the European Economic Area

The data that we collect from you will not be transferred to, or stored outside the European Economic Area ("EEA"). We will take reasonable steps to ensure that your Account Information (including any Personal Data) is handled securely and in accordance with this Privacy Policy.

The Legal basis for processing personal data

These are our legal reasons for processing your personal data:

  • For the performance of a contract with You or Your Provider;
  • For the purpose of furthering TrueLayer’s legitimate interests including providing better products, services, websites and applications, to operate our websites and applications.
  • With your consent to provide you with updates of TrueLayers, products, events and service-related matters.

Security

We use industry-standard encryption methods to ensure the security of your Personal Data in accordance with applicable law and regulation but cannot guarantee the security of any data transmitted to a Provider using our Tool. Once we have received your information, we take reasonable precautions to ensure that it is not lost, misused, accessed, disclosed, altered or destroyed. If you have reason to believe that your Personal Data is no longer secure (for example if you feel that the security of your Personal Data has been compromised then please contact us immediately).

Cookies

When you browse the Site, we automatically receive your computer’s internet protocol (IP) address. We collect data about how you interact with our website through the use of cookies. A cookie is a small file of letters and numbers that we store on your browser or the hard drive of your computer, if you agree. Cookies contain information that is transferred to your computer's hard drive.

Our Site uses cookies to distinguish you from other users of our website. It helps us to remember your preferences. When you visit our Site, Cookies allow us to keep track of how many times you’ve visited us, how long you’ve visited us for and what you’ve done whilst you’ve been on our Site.

We use cookies to enhance your online experience of our Site and to better understand how our Site is used. Cookies help to ensure that what you see online is more relevant to you and your interests, based on information you’ve previously entered on our Site. The length of time the cookie is stored depends on that cookie, but this can vary from between a few minutes to up to two years.

Cookies never store any of your banking details.

We use the following types of cookies:

  • ‘Session cookies’ which exist only while your browser is open. These cookies let us see where you’ve spent time on our Site and which part of the Site is the most or least effective. These are deleted automatically once you close your browser; and
  • ‘Persistent cookies’ which survive after your browser is closed. They can be used by the site to recognise your computer or mobile device when you open your browser and browse the Internet again.
  • ‘Third Party cookies’ these are cookies set by a domain other than our Site or a third party. These work by sharing your browser identification with that third party (like Facebook, Google), so that they can show you ads on their sites.

Here is a list of TrueLayer’s cookies that we may use; the list is not exhaustive and we’ve listed them here so that you could opt out of the cookies if you choose to.

Cookie name Purpose Session or Persistent Cookies
__session Technical Persistent
accepted_cookies Technical + Tracking Persistent
tl.session Technical + Tracking Persistent

The third parties that we allow to set cookies on our Site are listed below. The list is not exhaustive and we’ve listed them here so that you could opt out of the cookies if you choose to.

These are for user management and for analytical purposes. These Third parties may set their own cookies to provide advertising:

Cookie name Purpose Cookie Policy Opt out
Google Used for analytics and service improvements Please click here Please click here
Mixpanel Used for analytics and service improvements Please click here Please click here
Auth0 Used for user management and login Please click here Please contact: compliance@auth0.com
Intercom Used for customer messaging Please click here Please click here
Cloudflare Used for performance and security Please click here Please click here
Segment Used for analytics Please click here Please contact: privacy@segment.com

You can find more information about how to manage and remove cookies (including how to opt-out) at www.allaboutcookies.org/manage-cookies/ or by visiting the website relevant to the browser you are using. Below we have provided links to some of the most popular browser websites:

  • Google Chrome
  • Mozilla Firefox
  • Microsoft Internet Explorer
  • Apple Safari

You can block cookies by activating the setting on your browser that allows you to refuse the setting of all or some cookies. However, if you use your browser settings to block all cookies (including essential cookies for the provision of our Service) you may not be able to access all or parts of our site.

Minors

Our Services are not intended for use by anyone younger than 18 years old. Please do not use our Services if you are under 18.

Your Rights

Subject Access Requests

You have the right to ask us to provide any personal data we have collected about You, to You. Should You wish to do so, please email us at privacy@truelayer.com to make a subject access request detailing:

  • your name,
  • your address,
  • the details of your Provider, and
  • the period of data you’d like access to.

Making a complaint to a supervisory authority

Should you be dissatisfied with the service we provide, You have the right to file a formal complaint to the Information Commissioner's Office at www.ico.org.uk.

Object to Direct Marketing

You have the right to ask us at any time to stop processing your Personal Data for direct marketing at any time. We provide for the right for you to unsubscribe from any of our marketing material at any time.

The Right to be Forgotten

If after you provided your consent, you change your mind, you may withdraw your consent by contacting us at our address or at the email address set out in the contact information above.

Changes to this Privacy Policy

Any changes we make to our Privacy Policy in the future will be posted on this page and, where appropriate, notified to you by e-mail. Please check back frequently to see any updates or changes to our privacy policy.

Questions and Contact Information

If you would like to access, correct, amend or delete any personal information we have about you, register a complaint, or simply want more information about how we process your Personal Data, you can contact us at privacy@truelayer.com or by mail at:

Data Protection Officer, TrueLayer, 1 Hardwick Street, London EC1R 4RB.

Do you have a question? Contact us at legal@truelayer.com