This Privacy Policy explains how Mikupay ("we", "us", "our") collects, uses, shares and protects personal information in connection with our accounts and payment services, and the rights available to the individuals whose information we hold.
We act as a controller in respect of the personal information described here. Where we process information on behalf of a client — for example information about that client’s own customers — we act as a processor and do so in accordance with our agreement with that client.
1. Scope of this policy
This policy applies to information collected through our website and client portal, in the course of onboarding and administering an account, in processing transactions, and in our communications with you.
It does not apply to third-party websites or services that we do not control, including blockchain networks and third-party wallets.
2. Information we collect
2.1 Information you provide
- Identity information: name, date of birth, nationality, government identification details and document images.
- Contact information: email address, telephone number and postal address.
- Business information: entity name, registration details, place of business, nature of activity, and details of beneficial owners, directors and authorised signatories.
- Financial information: bank account details, source of funds and source of wealth information, and records supporting a transaction.
- Correspondence: messages, instructions and documents exchanged with us or with our support and compliance teams.
2.2 Information we collect automatically
- Technical information: IP address, device and browser characteristics, and language settings.
- Usage information: pages and features accessed, actions taken in the client portal, and session details.
- Security information: authentication events, session records and access logs.
2.3 Information from third parties
- Identity verification and screening providers, sanctions and politically exposed person lists, and adverse media sources.
- Banking and payment partners, in connection with the execution and reconciliation of transfers.
- Public registers and publicly available sources, where relevant to verification.
2.4 Information about blockchain transactions
Information relating to an on-chain transfer — including the destination address and transaction hash — is recorded on a public blockchain. It is inherently public, permanent and outside our control, and is not personal information that we are able to delete or amend.
3. Why we use information, and our lawful bases
We use personal information for the following purposes:
- Providing the services — opening and administering accounts, processing funding, conversions, withdrawals and card applications. Basis: performance of our contract with you.
- Verifying identity and meeting our regulatory obligations — client due diligence, screening, transaction monitoring, record keeping and reporting. Basis: compliance with legal obligations to which we are subject.
- Managing risk and protecting the platform — fraud prevention, security monitoring, and enforcement of our terms. Basis: our legitimate interests in protecting our business and our clients.
- Communicating with you — responding to enquiries, providing service notifications, and informing you of changes. Basis: performance of our contract, and our legitimate interests.
- Improving the services — understanding how the platform is used and diagnosing issues. Basis: our legitimate interests.
- Establishing or defending legal claims. Basis: our legitimate interests.
- Any purpose to which you have consented. Basis: consent, which you may withdraw at any time.
4. Identity verification and screening
As a provider of cross-border payment services involving digital assets, we are required to identify our clients and understand the nature and purpose of their activity. Verification is carried out by our compliance team on the basis of the information and documentation you provide, together with information obtained from verification and screening providers.
Verification and screening outcomes are recorded against your account, together with the reviewer, the date and the basis for the decision. You may be asked to provide additional or updated information at any point during the relationship, or in relation to a specific transaction.
5. How we share information
We do not sell personal information. We disclose it only as described below.
- Service providers: identity verification and screening, cloud hosting, communications and analytics providers, each engaged under contract and only for the purposes described in this policy.
- Banking and payment partners: as necessary to execute, reconcile, trace or recall a transfer, and to satisfy their own legal obligations.
- Professional advisers: auditors, legal advisers and insurers, where necessary and subject to duties of confidence.
- Regulators, law enforcement and courts: where we are required to disclose by law, by a competent authority, or in connection with legal proceedings.
- Corporate transactions: in connection with a merger, acquisition, reorganisation or sale of assets, subject to appropriate confidentiality.
- With your direction: where you ask us to share information with a third party.
6. International transfers
We may process and store information in jurisdictions other than the one in which you are located, including where our service providers operate. Where we transfer personal information internationally, we put in place appropriate safeguards and require our service providers to do the same.
7. How long we keep information
We retain information for as long as necessary for the purposes described in this policy, and in particular for as long as required by the record-keeping obligations that apply to us. Where we are required to retain records to evidence compliance with anti-money-laundering requirements, retention typically continues for the period prescribed by applicable law following the end of the relationship.
When information is no longer required, we delete it or render it anonymous. Information that we are obliged to retain is held securely and access is restricted.
8. How we protect information
We maintain administrative, technical and physical safeguards designed to protect personal information against unauthorised access, alteration, disclosure or destruction.
- Encryption of data in transit; access control on systems holding personal information.
- Role-based access, so that access is limited to personnel who require it for their function.
- A code sent to the account email address is required when signing in from an unfamiliar device, for both client and operational access.
- Logging of access to client records and of operational actions, retained for audit.
- Documentation stored outside publicly accessible directories and served only to authorised personnel.
- Review of our controls and of the safeguards applied by our service providers.
9. Your rights
Subject to applicable law and to the exemptions and limitations it provides, you may have the following rights in respect of your personal information:
- Access: to be told whether we hold information about you and to receive a copy of it.
- Rectification: to have inaccurate information corrected.
- Erasure: to have information deleted where there is no continuing lawful basis for holding it. This right is limited by the record-keeping obligations described in section 7.
- Restriction: to ask us to limit how we use information while a question about it is resolved.
- Objection: to object to processing carried out on the basis of our legitimate interests.
- Portability: to receive information you provided to us in a structured, commonly used format, where our processing is based on consent or contract and is carried out by automated means.
- Withdrawal of consent: where processing is based on consent, to withdraw it at any time without affecting processing already carried out.
10. Automated decision-making
We do not make decisions producing legal or similarly significant effects about you based solely on automated processing. Screening and monitoring tools assist our team by identifying activity for attention; the decisions that follow from that — including any decision to request further information, to delay a transaction, or to restrict an account — are made by a person.
Records of those decisions, including the reviewer and the basis for the outcome, are retained on the account.
12. Marketing
We may send you service and administrative communications that are necessary for the operation of your account. We will send marketing communications only where permitted by applicable law, and will provide a straightforward way to opt out. Opting out of marketing does not affect service and compliance communications.
13. Children
Our services are provided to businesses and to individuals acting in a professional capacity. They are not directed to children, and we do not knowingly collect information from them.
14. Changes to this policy
We may update this policy to reflect changes in our practices, in the services, or in applicable law. The date at the head of this page shows when it was last revised. Material changes will be notified to you before they take effect.
15. Contact and complaints
Questions about this policy, or requests to exercise your rights, should be sent to compliance@mikupay.com. We will respond within the period required by applicable law. If you are not satisfied with our response, you may be entitled to complain to the supervisory authority in your jurisdiction.
Version history
Only substantive changes are listed. Superseded versions are retained and are available on request.
- v1.017 September 2026First published version.
Questions about this document
Our compliance team can answer questions about this policy and can provide supporting documentation about Mikupay to counterparties and their advisers. The list of documents available on request is published on the disclosures page.
