Privacy Policy
1. Introduction
Seapoint Finance Ltd operates seapoint.co as a financial technology platform based in Dublin. This policy covers three entities:
- Seapoint Finance Limited — Ireland, company #767570, address: 6 Mount Street Upper, Dublin 2, D02 VF44
- Seapoint Finance UK Limited — England & Wales, company #16138873, registration #ZB874525
- Seapoint Finance UK Investments Limited — England & Wales, company #16419896, registration #ZB895698
Regulatory arrangements include appointments with Modulr FS Limited, Modulr Finance BV, Yapily Connect Ltd, and WealthKernel Limited through various financial authorities.
This policy explains our data collection, usage, protection, and sharing practices, and your individual rights. We collect your name, contact details, and financial data to provide services and meet regulatory obligations. Contact dpo@seapoint.co for questions.
2. Definitions
- Agreement: Terms of Service and Schedules
- App: Web application providing Services
- Data Controller/Processor: Entities determining or executing data processing
- GDPR/UK GDPR: Applicable data protection regulations
- KYC: Know Your Customer verification requirement
- Personal Data: Information relating to identifiable persons
3. What Data We Collect About You
User Types
Users may be:
- Account Representatives
- Authorised Users
- Beneficial Owners or Directors
- Customers of account holders
Information You Provide
- Personal details (name, date of birth, nationality)
- Contact information (email, phone, address)
- Identity data (ID documents, selfies, biometric data from photos/videos)
- Business role data
- Company-related data (shareholder/director details, tax info)
- Financial data (bank accounts, payment cards)
Information From Your Company
- Business contact details and role
- Employment details if using payroll features
Information From Service Usage
- Transaction data (dates, amounts, recipient details, merchant info)
- Usage patterns
- Card transaction data
Information From Your Device
- Technical data (IP address, device ID, browser info)
- Behavioural data (page visits, clicks, response times)
- Location data (if enabled)
Information From Third Parties
- Regulatory sources (credit agencies, fraud prevention agencies, public records)
- Financial partners (banks, payment providers, Open Banking services)
- Public sources (media, directories, social media)
4. Why We Use Your Data
Processing purposes include:
- Fulfilling service obligations under the Agreement
- Regulatory compliance (KYC, anti-money laundering)
- Service notifications
- Safety and security assurance
- Service administration and improvement
- Advertising effectiveness measurement
- Customer analysis for business development
- Data combination from multiple sources
Declining to provide requested data may prevent service delivery.
5. Legal Basis for Using Your Data
Processing relies on:
- Consent: For marketing materials (withdrawable anytime)
- Contract Performance: Service provision and support
- Legal Obligations: Anti-money laundering compliance
- Legitimate Interest: Fraud prevention, IT security, business development (with interest assessment ensuring user rights aren’t overridden)
6. Sharing Data
Data sharing is minimised and anonymised where possible. Recipients include:
Public Authorities
- Financial regulators
- Tax authorities
- Act as independent controllers when legally required
Service Providers
- Financial market participation facilitators
- Data delivery providers
- IT infrastructure maintainers
- Regulatory obligation fulfilment partners
- Act as processors under company instructions
International Transfers
- EEA–UK transfers use EU–UK adequacy decision
- Other regions use Standard Contractual Clauses (SCCs) or other safeguards
- Details available at dpo@seapoint.co
Anonymised Data
Aggregated demographics shared with partners for service improvement and marketing.
7. Where We Store Your Data
Data is stored in Irish databases, hosted internally or by service providers. Protection mechanisms include encryption, access controls, and regular security audits. External transfers follow Section 6 protocols.
8. How Long We Keep Your Data
General Retention: Minimum 5 years after business relationship ends (per EU AML Directive 2015/849 and UK Money Laundering Regulations 2017).
Exceptions: Extended retention if required by law, legal proceedings, investigations, or legitimate interest. Shorter periods for non-regulatory data (e.g., marketing data deleted upon consent withdrawal).
Unneeded data is deleted in compliance with applicable laws.
9. Your Data Protection Rights
Under GDPR and UK GDPR, you have the right to:
- Access: Request data holdings (subject to regulatory limits)
- Rectification: Update inaccurate information
- Erasure/Restriction: Request deletion or limited use (may retain for legal reasons)
- Portability: Receive data in machine-readable format or transfer to another controller (for consent/contract-based data)
- Objection: Challenge processing based on legitimate interest
- Withdrawal: Stop consent-based processing anytime via email or unsubscribe (may limit Services)
Exercise rights by contacting dpo@seapoint.co.
10. Requesting Deletion of Data
Email dpo@seapoint.co for deletion, restriction, or data details. Response deadline is one month from request receipt. Regulatory requirements (e.g., AML laws) may prevent deletion — explanations will be provided. Deletion may restrict Services.
11. Complaints
Initial contact: complaints@seapoint.co
If unresolved, escalate to:
UK
Information Commissioner’s Office (ICO)
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Helpline: 0303 123 1113
Website: ico.org.uk/make-a-complaint
EEA
Data Protection Commission (DPC)
21 Fitzwilliam Square South, Dublin 2, D02 RD28, Ireland
Website: dataprotection.ie
Local EEA authorities are also available. Judicial remedy may also be sought.
12. Applicable Law and Jurisdiction
- Seapoint Finance Limited: Governed by Irish law; Irish courts handle disputes
- Seapoint Finance UK Limited: Governed by UK law; UK courts handle disputes
This doesn’t affect rights to lodge supervisory authority complaints.
13. Changes to This Policy
Updates are posted here with significant changes notified via email. Review periodically.
Annex 1: Personal Data Processing Details
| Personal Data | Purpose | Source | Legal Basis |
|---|---|---|---|
| Name, phone, DOB, ID number, age | Regulatory compliance; Agreement party identification | You, public databases | Legal obligations (Art. 6(1)(c)); Contract (Art. 6(1)(b)) |
| Email, address, IP, supporting docs | Contact; regulatory purposes | You | Contract (Art. 6(1)(b)); Legal obligations (Art. 6(1)(c)) |
| Bank details, tax info, citizenship, employment, source of wealth, ID data | Client understanding; regulatory compliance | You | Legitimate interest (Art. 6(1)(f)); Legal obligations (Art. 6(1)(c)) |
| Usage data (frequency, features used) | Service improvement; marketing; regulatory compliance | You | Legitimate interest (Art. 6(1)(f)); Legal obligations (Art. 6(1)(c)) |
| Marketing data (email, citizenship) | Marketing materials; regulatory compliance | You | Consent (Art. 6(1)(a)); Legal obligations (Art. 6(1)(c)) |
| Financial data (payment info, investments) | Service provision; platform improvement | You, service providers | Contract (Art. 6(1)(b)); Legitimate interest (Art. 6(1)(f)) |
| Service info (onboarding state) | Service provision; educational content; regulatory compliance | You | Legitimate interest (Art. 6(1)(f)); Legal obligations (Art. 6(1)(c)) |
| Company rep contact info | Service introduction; regulatory compliance | Public data | Legitimate interest (Art. 6(1)(f)); Legal obligations (Art. 6(1)(c)) |
| Customer support communications | Service provision | You | Contract (Art. 6(1)(b)) |
| Security data (access logs) | Service security | You, public databases | Legitimate interest (Art. 6(1)(f)) |
Note: Services are not intended for individuals under 18.