Dated: December 2017
Privacy and the security of data are of paramount importance to all of us at TrueLayer. Please read this document carefully, and if you have any questions or queries about the contents, please email us at email@example.com
Our company is based at 40 Islington High Street, London N1 8XB, and our registration number with the Information Commissioners Officer - the regulator in charge of data protection and privacy - is ZA207054.
We are the data controller for the purposes of the personal data we collect via our website and for the performance of the services listed under the usages of your personal data, below (together, the “Services”).
Use of Our Site
When you use our website (the “Site”) we will not collect any personal data about you, except your IP address.
Use of our online Services
Collection of personal data
When you use our Services we will have access to your personal data that you submit to us and personal data held by Account Servicing Payment Service Providers (i.e. any payment service provider, such as a bank or a credit card issuer that maintains an online payment account on your behalf) (“ASPSPs”) (“Personal Data”) for the duration of the transmission.
Such Personal Data may include your date of birth, gender, account information, account balance, transactions, information on loans, insurance data and investments data. The manner in which we access, use, process and store your personal data for the provision of the Services is set out below.
Use of your personal data
Your Provider will direct you to use our Services which will include the following:
- We will provide you with a software tool (“Tool”) which you can use to transmit information (including personal data) relating to payment accounts (“Account Information”) that you hold with ASPSPs to your Provider.
- To use our Services you will need to provide the same identifying information that use to access the relevant payment accounts when you log in yourself (“Credentials”).
- The Tool will allow you to use your Credentials to retrieve such Account Information as you choose to transmit to the Provider. Schedule 1 [link] to the Terms of Service lists the information that you can elect to retrieve and transfer using the Tool.
You should check your Provider’s rules on data privacy. Once your Account Information (including any Personal Data) is transmitted through our software to a Provider, that Provider (and not TrueLayer) will become responsible for it.
Our Tool may merge or aggregate Account Information retrieved from a particular ASPSP with Account Information retrieved from other ASPSPs where you have instructed us to access and transmit such information.
Transfer of your personal data outside of the European Economic Area
The Legal basis for processing personal data
These are the following legal reasons for processing personal data:
- For the performance of a contract with You;
- For the purpose of furthering TrueLayer’s legitimate interests including providing better products, services, websites and applications, to operate our websites and applications.
When you provide us with your Credentials we will require your consent to use those Credentials to:
- retrieve your Account Information (including any Personal Data); and
- to provide such Account Information to the Providers which referred you to us.
Your Personal Data may be anonymised, so that it can no longer be used to identify you and used to improve the Service or the Tool or be part of a market study or analytics by us or a third party. On our website, we use Google Analytics or Mixpanel to process data in an anonymous form to provide us information about the use of our Site.
How do I withdraw my consent?
If after you provided your consent, you change your mind, you may withdraw your consent by contacting us at our address or at the email address set out in the contact information above.
Deletion of Personal Data
We will not keep your Personal Data for longer than necessary. We will delete your Personal Data as soon as it is no longer needed to provide the Services to you or upon termination of the Terms of Service.
We may share your Personal Data with selected third parties, including business partners, suppliers and sub-contractors that assist us in the provision of our Service to you. The third-party providers used by us will only collect, use and disclose your information as instructed by us to provide Services to you.
We may also disclose your Personal Data to other third parties in the event that:
- We reasonably consider that we are under a duty to disclose or share your Personal Data in order to comply with any legal obligation, or
- in order to enforce or apply our Terms of Service and other agreements; or
- to protect the rights, property, or safety of TrueLayer, our customers, or others.
Unfortunately, the transmission of information via the internet is not completely secure. We use industry-standard encryption methods to ensure the security of your Personal Data in accordance with applicable law and regulation but cannot guarantee the security of any data transmitted to a Provider using our Tool. Once we have received your information, we take reasonable precautions to ensure that it is not lost, misused, accessed, disclosed, altered or destroyed.
Our Services are not intended for use by anyone younger than 18 years old. Please do not use our Services if you are under 18.
Subject Access Requests
You have the right to ask us to provide any personal data we have collected about You, to You. Should You wish to do so, please email us at firstname.lastname@example.org to make a subject access request detailing:
- your name,
- your address,
- the details of your Provider, and
- the period of data you’d like access to.
Making a complaint to a supervisory authority
Should you be dissatisfied with the service we provide, You have the right to file a formal complaint to the Information Commissioner's Office at www.ico.org.uk.
Questions and Contact Information
If you would like to access, correct, amend or delete any personal information we have about you, register a complaint, or simply want more information about how we process your Personal Data, you can contact us at email@example.com or by mail at:Data Protection Officer TrueLayer c/o RocketSpace 40 Islington High Street London N1 8XB.