NeoSign in

Privacy Policy

Last updated: 30 April 2026

This Privacy Policy explains how Noble Neo Ltd. ("Neo", "we", "our", "us") collects, uses, shares, and protects your personal data when you use our website, mobile app, and remittance services. We are the data controller for the personal data described below, registered with the UK Information Commissioner's Office (ICO) under registration number [ICO Reg].

1. Data we collect

  • Identity data: name, date of birth, nationality, government-issued ID details, photograph, biometric ID-verification data.
  • Contact data: email, phone, residential address.
  • Financial data: card details (tokenised), bank account details, source-of-funds evidence, transaction history, beneficiary details.
  • Compliance data: KYC documents, sanctions/PEP/adverse-media screening results, due diligence notes.
  • Technical data: IP address, device fingerprint, browser/OS, geolocation (approximate, derived from IP), pages viewed, login times.
  • Communications: support tickets, chat transcripts, feedback.

2. How we use your data and our lawful basis

We process your personal data on the following lawful bases under UK GDPR Article 6:

  • Performance of a contract (Art. 6(1)(b)) — to open your account, execute transactions, and provide customer support.
  • Legal obligation (Art. 6(1)(c)) — to comply with anti-money laundering (Money Laundering Regulations 2017), counter-terrorism financing, sanctions, FCA conduct rules, and tax reporting.
  • Legitimate interests (Art. 6(1)(f)) — to detect fraud, secure our systems, improve our services, and conduct internal analytics. Where we rely on legitimate interests we balance them against your rights and you may object.
  • Consent (Art. 6(1)(a)) — for marketing communications and non-essential cookies. You may withdraw consent at any time.

Identity documents and biometric ID-verification data are special-category data under Art. 9 and are processed under the "substantial public interest" condition (Schedule 1 Part 2 of the Data Protection Act 2018) for the prevention and detection of unlawful acts.

3. Who we share your data with

  • Payout partners and corresponding banks — to deliver funds to your beneficiary.
  • KYC and screening providers (e.g. GBG, Loqate, sanctions data vendors) — to verify your identity and screen transactions.
  • Card processors and Open Banking aggregators — to take payment from you.
  • Regulators and law enforcement — including the FCA, NCA, HMRC, and ICO when legally required.
  • Cloud and IT service providers — under written data-processing agreements.
  • Professional advisors — auditors, lawyers, insurers as needed.

We never sell your personal data. We do not use your data for advertising retargeting.

4. International transfers

Some of our partners and vendors are based outside the UK. When we transfer your data outside the UK we rely on UK adequacy regulations or, where there is no adequacy decision, on UK International Data Transfer Agreements (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, supplemented by transfer-impact assessments.

5. Retention

  • Account and transaction records: 5 years after account closure (MLR 2017 Reg 40 minimum).
  • KYC documents and screening results: 5 years after the end of the business relationship.
  • Audit logs of administrative actions: 7 years.
  • Support tickets: 3 years after closure.
  • Marketing data: until you withdraw consent.

6. Your rights

Under UK GDPR you have the right to:

  • Access your data (subject access request).
  • Have inaccurate data corrected.
  • Request erasure (subject to our legal-retention obligations).
  • Restrict or object to processing.
  • Receive your data in a portable format.
  • Withdraw consent for any processing based on consent.
  • Lodge a complaint with the ICO at ico.org.uk.

To exercise any right, email our Data Protection Officer at dpo@nobleneo.com. We aim to respond within one calendar month.

7. Security

We protect your data with industry-standard controls: TLS 1.2+ in transit, AES-256 at rest, encrypted database backups, role-based access control, mandatory multi-factor authentication for staff, intrusion detection, and regular penetration testing. We notify the ICO and affected users within 72 hours of any personal-data breach that is likely to result in a risk to your rights and freedoms, in line with UK GDPR Art. 33-34.

8. Cookies

We use a minimum set of cookies needed to keep you signed in (session cookie, CSRF token), to remember your preferences (e.g. remembered email), and to gather anonymised usage analytics. Non-essential cookies require your consent. See our cookie banner for granular controls.

9. Automated decisions

We use automated screening for sanctions, PEP status, and adverse media. A positive sanctions match will block a transaction automatically. You always have the right to request human review of an automated decision that has a legal or similarly significant effect on you.

10. Changes to this policy

We may update this policy from time to time. The "Last updated" date at the top reflects the most recent change. Material changes will be notified to you by email or in-app message at least one month in advance.

11. Contact

Data Protection Officer, Noble Neo Ltd., [Address]. Email: dpo@nobleneo.com.

Terms & ConditionsPrivacy Policy© 2026 Noble Neo Ltd.