Terms and Policies

Privacy Statement

Effective from
August 1, 2026

AFT EU B.V. (trading as “Aspire”)

This Privacy Statement explains how AFT EU B.V. collects, uses, shares and protects your personal data, and the rights you have under the EU General Data Protection Regulation (GDPR) and Dutch data protection law.

At a glance: how we handle your personal data

What we collect: information you give us when you apply for and use our services (such as identity documents and business and financial details), information generated when you use our platform and app, and information we receive from others (such as identity-verification, screening and credit-reference providers, and from people who send you or receive payments).

How we use it: to provide our payment and account services, verify your identity, prevent fraud and financial crime, meet our legal and regulatory obligations, improve our services, and – where permitted – send you relevant communications.

Our legal bases: performance of a contract, compliance with legal obligations, our legitimate interests, your consent, and, for special categories of data, substantial public interest or other GDPR conditions.

Who we share it with: companies in the Aspire group, service providers and partners that help us run our services, banking and payment partners, identity, screening and credit-reference providers, the people and businesses you transact with, and authorities where the law requires it.

International transfers: some of our group companies and providers are located outside the European Economic Area (for example in Singapore, India, the United States). Where this happens we put appropriate safeguards in place, such as Standard Contractual Clauses.

Your rights and contact: you have rights over your personal data, including access, rectification, erasure, restriction, portability, objection and withdrawal of consent. You can contact our Data Protection Officer at dpo-nl@aspireapp.com and you have the right to complain to the Dutch supervisory authority (Autoriteit Persoonsgegevens).

 

Privacy Statement

At a glance: how we handle your personal data

1. About us and how to contact us

2. Who this statement applies to and why you should read it

3. What personal data we collect

4. Where we collect your data from, including data not collected from you directly

5. Our legal bases for using your personal data

6. How we use your personal data and our legal bases

7. Automated processing and profiling

8. Special categories of data and criminal-offence data

9. Who we share your personal data with

10. International transfers of your personal data

11. How long we keep your personal data

12. Your rights

13. How to exercise your rights

14. Marketing and your choices

15. How we protect your personal data

16. Changes to this statement

17. Cookies

1. About us and how to contact us

AFT EU B.V. (“Aspire”, “we”, “us”, “our”) is the controller of the personal data we process when you apply for, or use, the products and services we provide. Aspire is an electronic money institution incorporated and registered in the Netherlands and authorised by De Nederlandsche Bank (DNB). Aspire is part of the wider Aspire group of companies. Where another Aspire group company or a partner is responsible for a particular product or service, we will tell you, and a separate or supplementary privacy notice may apply.

Our company details are:

Detail Information
Legal entity AFT EU B.V. (trading as “Aspire”)
Registered office Strawinskylaan 1647, Tower Seven, 16th floor, 1077 XX Amsterdam, the Netherlands
Chamber of Commerce (KvK) number 93225407
Regulatory status Authorised by De Nederlandsche Bank (DNB) as an electronic money institution (DNB relation number R197650)

Our Data Protection Officer (DPO)

We have appointed a Data Protection Officer who oversees how we handle personal data and acts as your point of contact for privacy matters. You can reach the DPO by email at dpo-nl@aspireapp.com or by writing to the DPO at our registered office address above.

The supervisory authority

The data protection supervisory authority for the Netherlands is the Autoriteit Persoonsgegevens (Dutch Data Protection Authority). If you have a concern about how we handle your personal data, we encourage you to contact us first so we can try to resolve it. You also have the right to lodge a complaint with the Autoriteit Persoonsgegevens at any time – see autoriteitpersoonsgegevens.nl, or by post to Autoriteit Persoonsgegevens, PO Box 93374, 2509 AJ The Hague, the Netherlands.

2. Who this statement applies to and why you should read it

This statement applies to personal data we process about:

  • the businesses that hold or apply for an account with us (“Account Owners”), and the individuals connected to them whose data we process to meet our legal and regulatory obligations, such as directors, authorised users and signatories, cardholders, beneficial owners (UBOs) and other connected individuals;
  • individuals who send payments to, or receive payments from, our customers (payment counterparties and beneficiaries);
  • visitors to our website and users of our app and platform; and
  • other people whose data we receive in connection with our services, for example through fraud-prevention, screening or due-diligence checks. This happens, for example, where we carry out sanctions, politically exposed person (PEP) or adverse-media screening; where fraud-prevention agencies share information with us about individuals linked to an application or transaction; or where an Account Owner provides us with documents or information that identify other people, such as shareholders, trustees, professional advisers or representatives

When we say “personal data” we mean any information relating to an identified or identifiable individual, for example, your name, contact details or payment card number, but also information such as your IP address or device identifiers where these can be linked to you. We collect your personal data when you use our website, our app and platform, and the services available through them. We may also receive personal data about you from other people and organisations – we explain this in section 4 and section 9.

This statement describes how we use personal data when we act as the data controller. For some limited processing we act on a customer's behalf as a processor, for example, for example, when you, as a customer upload personal data about your own employees, suppliers or clients (such as a receipt, invoice or payee record containing someone's details) to manage your records through the platform. There, you, as a customer, decide why the data is used and we act only on your instructions, so that processing is governed by the data-processing terms in our agreement with you as a customer, not by this statement.

Specific products, services or processes may have their own supplementary privacy notices or ‘just-in-time’ explanations. Wherever possible, we provide a brief, plain-language privacy explanation at the point of data collection (for example, in consent screens or collection forms) that identifies the specific lawful basis on which the data is being collected and the purpose for which it will be used.

3. What personal data we collect

The categories of personal data we collect and use are set out below.

Category Details
Information you give us

When you apply for or use our services, correspond with us, complete forms, or contact our support teams, we collect:

  • identity information: your name, date and place of birth, nationality, residential address and identification documents (such as passport or ID card);
  • contact information: email address and phone number;
  • business and role information: your position in the business, shareholding, and your status as a director, authorised representative or UBO;
  • financial and tax information: bank account and IBAN details, tax residency and tax identification numbers;
  • verification information: your image in photo or video form and facial-scan (biometric) data extracted from it for identity verification, and any other information needed to prove eligibility to use our services;
  • records of our communications with you, including emails, chat and call records.
Information about other people you provide Where you give us personal data about other individuals (for example joint signatories, directors, UBOs or payment counterparties), you confirm that you are entitled to share it and that you have brought this statement to their attention.
Information from your use of our services

When you use our website, app or platform we collect:

  • technical data: IP address, login data, device identifiers, browser type and version, time zone, operating system and platform;
  • usage data: information about your visits, the pages and features you use, and how you interact with them;
  • transaction data: details of payments into and out of your account, including date, time, amount, currency, exchange rate and counterparty details.
Information we infer or create We may create new data about you by analysing the information we hold, including risk scores (such as fraud or credit-risk indicators) and assessments based on your transactions and application details.
Information from others (indirect collection) We receive personal data from third parties such as credit-reference agencies, financial crime -prevention agencies, official registers and databases, banking and payment partners. See section 4.
Special categories and criminal-offence data In limited circumstances we process special categories of personal data (such as biometric data for identity verification). We also process information relating to criminal convictions and offences where this appears in adverse-media screening or other due-diligence sources. This can include publicly available reports of alleged or actual offences. Sanctions, watchlist and politically exposed person (PEP) screening does not generally involve criminal-offence data; we carry out those checks to meet our anti-money-laundering and counter-terrorist-financing obligations. See section 8.

4. Where we collect your data from, including data not collected from you directly

Where we receive your personal data indirectly, for example because you are a director, beneficial owner (UBO), authorised signatory or other individual connected to an Account Owner, or a payment counterparty, we may not always be able to provide this information to you directly. In line with the GDPR, this applies where doing so would be impossible or involve disproportionate effort (such as contacting large numbers of payment counterparties), where the data must remain confidential because of a legal obligation, or where notification could prejudice the prevention, detection or investigation of fraud or financial crime.

If none of these exceptions apply, we will tell you how we use your personal data within a reasonable time after we receive it, and at the latest within one month. If we use your data to contact you, or disclose it to someone else, before that month is up, we will tell you no later than the point at which we first contact you or make the disclosure. We will normally do this by providing you, or the Account Owner you are connected to, with a copy of or link to this statement, using the contact details we hold for you.

The categories of sources from which we obtain indirectly collected data include:

  • credit-reference and financial crime prevention agencies;
  • public registers, official databases and publicly available sources;
  • banking, payment and other partners involved in processing your transactions; and
  • our customers, who may provide data about their directors, UBOs, employees and payment counterparties.

5. Our legal bases for using your personal data

We must always have a valid legal basis to use your personal data. Depending on the activity, our legal basis is one or more of the following:

  • Performance of a contract: we need certain personal data to provide our services to you and to take steps at your request before entering into a contract.
  • Compliance with a legal obligation: we are required to collect and retain certain personal data,  and to detect and prevent money laundering, terrorist financing and related financial crime, for example under anti-money laundering, counter-terrorist-financing, e-money, payment-services and tax laws. 
  • Legitimate interests: we process personal data where we (or a third party) have a legitimate interest, provided this is not overridden by your interests, rights and freedoms. We rely on legitimate interests for purposes including:
  • preventing and detecting fraud and misuse of our services beyond what our legal obligations require, and keeping our services and customers secure;
  • sharing data within the Aspire group to operate, secure and improve our services;
  • analysing and improving our products, services and internal models;
  • managing our business and risks, recovering debts, and establishing, exercising or defending legal claims; and
  • sending relevant communications where permitted by law.

We carry out and document a Legitimate Interests Assessment (covering the purpose, necessity and balancing tests), before we rely on this basis for a processing activity, and keep a record of these assessments.

  • Consent: where we ask for your consent to a specific use of your personal data. If consent is the legal basis for processing, you can withdraw your consent at any time (see section 12).
  • Substantial public interest, legal claims and other GDPR conditions: for special categories of personal data and criminal-offence data, as explained in section 8.

We will not use your personal data for a new purpose that is incompatible with the purpose for which it was originally collected unless we have a lawful basis to do so. Where we intend to process your data for a different but compatible purpose (for example, regulatory reporting or financial-crime prevention), we will assess compatibility in line with the applicable laws. 

Where we ask you for personal data in order to provide our services or to meet a legal obligation (for example identity, verification and due-diligence information), providing it is a contractual or legal requirement. If you do not provide it, we may be unable to open or to continue to operate your account, or to provide the relevant product or service 

6. How we use your personal data and our legal bases

The table below explains the main ways we use your personal data and the legal bases we rely on.

7. Profiling

To run our services efficiently and to keep them secure, we use technology to analyse personal data and assess risks, for example, risk-scoring during onboarding (KYB/KYC), transaction monitoring and fraud detection. This may involve profiling.

Our onboarding and account decisions that produce legal or similarly significant effects (such as whether to open, restrict or close an account) are not based solely on automated processing: a member of our team reviews the relevant criteria and makes or confirms the decision. You have the right to express your view on any such decision and to ask for it to be reviewed by contacting us via the in-app chat or at support@aspireapp.com. Where, in future, we make a decision that produces legal or similarly significant effects about you based solely on automated processing, we will tell you, explain the logic involved and the significance and consequences for you, and give you the right to obtain human intervention, to express your point of view and to contest the decision.

8. Special categories of data and criminal-offence data

Special categories of data (biometrics).

As part of our identity-verification and fraud-prevention checks, our verification provider processes biometric data extracted from your identity documents and selfie/video to confirm that you are who you say you are. We process this special category of data on the basis of substantial public interest (preventing fraud and financial crime and meeting our regulatory obligations) and, where required, your explicit consent, and – where relevant – for the establishment, exercise or defence of legal claims.

Criminal-offence data.

In order to meet our legal and regulatory obligations, we may process information relating to criminal convictions, offences and related security measures, for example where adverse-media or due-diligence screening surfaces alleged or actual criminal conduct about you. We process this data only where authorised by law and subject to appropriate safeguards. Sanctions, watchlist and politically-exposed-person screening involve regulatory or political designations rather than criminal-offence data, and we carry these out under our legal obligations (see section 6).

9. Who we share your personal data with

We share your personal data only where necessary, and with appropriate safeguards in place. The specific recipients (or categories of recipients) for each processing activity are recorded in our Record of Processing Activities (ROPA) and, where relevant, disclosed at the point of collection. The categories of recipients are:

Recipient category Why we share your personal data
Aspire group companies We share personal data with other companies in the Aspire group for purposes including operating, securing and improving our services, onboarding, fraud and financial-crime prevention, group-level regulatory compliance and AML/KYC, risk management and internal audit, group financial consolidation and reporting, and corporate governance. This sharing takes place under an intragroup data-sharing agreement with appropriate safeguards. For certain group-level processing we act as joint controllers with other Aspire group companies; you can ask us for the essence of these arrangements.
Service providers (processors) Providers of IT, cloud hosting, identity verification, screening, payments, communications, analytics and customer-support services that help us run our services. They act on our documented instructions under written data-processing agreements.
Banking and payment partners and networks Banks, payment institutions, intermediaries and card/payment networks, to enable and process payments and provide our services.
Identity, screening and credit-reference providers To verify your identity, carry out due diligence, and screen against sanctions, watchlists and fraud databases.
People and businesses you transact with Where you send or receive payments, we share the information required by law to process the payment (such as name and account details) with the payer or payee and their providers.
Third-party providers (open banking) Where you authorise a third-party provider (TPP) under PSD2 to access your account information or initiate payments, we share the relevant data with that provider so it can act on your instructions.
Authorities and other third parties Regulators, supervisory authorities, law-enforcement and tax authorities, courts and other third parties, where required by law, to protect our rights, to prevent or detect crime, or in connection with legal claims or a business sale.

We do not sell your personal data.

10. International transfers of your personal data

We provide an international service and we are part of an international group. As a result, some of your personal data may be transferred to, or accessed from, countries outside the European Economic Area (EEA), including by group companies and service providers located in countries such as Singapore, India, the United States, Canada, Australia, Hong Kong, Japan, the Philippines, Thailand, Indonesia and Vietnam. Some of these countries are not covered by an EU adequacy decision.

Where we transfer personal data outside the EEA to a country that does not provide an equivalent level of protection, we put appropriate safeguards in place to protect it. For transfers from AFT EU B.V., these are principally the European Commission’s Standard Contractual Clauses (SCCs) – including under our intragroup data-sharing agreement – supported by transfer impact assessments and, where needed, supplementary technical, contractual and organisational measures (such as encryption, access controls and data minimisation). The competent supervisory authority for these transfers is the Autoriteit Persoonsgegevens. You can ask us for more information about the safeguards we use, or for a copy of the relevant clauses, by contacting our DPO at dpo-nl@aspireapp.com.

11. How long we keep your personal data

We keep your personal data only for as long as necessary for the purposes for which it was collected, including to meet our legal, regulatory, accounting and reporting obligations and to establish, exercise or defend legal claims.

Because we are a regulated financial-services provider, we are required to retain certain personal data for minimum periods set by anti-money laundering, e-money, payment-services and tax laws. For example, we retain transaction records for a minimum of five years from the date of the transaction, in line with applicable Dutch law, and identity-verification and due-diligence records for the periods required by anti-money laundering law (generally at least five years after our relationship with you ends). Where data is no longer required, we securely delete or anonymise it. Our internal retention schedule sets out the specific retention periods, and the criteria used to determine them, for each category of data.

12. Your rights

Under the GDPR you have the following rights in relation to your personal data:

Your right What it means
To be informed You have the right to be told how we collect and use your personal data, which is the purpose of this statement and any supplementary notices.
Access You can ask for a copy of the personal data we hold about you, and related information. We will respond within one month, which we may extend by up to two further months for complex requests, telling you why.
Rectification You can ask us to correct personal data that is inaccurate or incomplete. Where we have shared that data with others, we will inform them of the correction where possible.
Erasure You can ask us to delete your personal data in certain circumstances. We may not be able to do so where we are legally required to keep it (for example under anti-money laundering laws) or where we need it for legal claims; we will tell you if this is the case.
Restriction You can ask us to limit how we use your personal data in certain circumstances, for example while we check its accuracy or consider an objection. We will tell you before any restriction is lifted.
Data portability Where processing is based on consent or contract and carried out by automated means, you can ask us to provide the personal data you gave us in a structured, commonly used, machine-readable format, or to transmit it to another controller where technically feasible.
Objection You can object to processing based on our legitimate interests, and to processing for direct marketing (including related profiling) at any time. We will stop unless we have compelling legitimate grounds that override your interests, or we need the data for legal claims.
Withdraw consent Where we rely on your consent, you can withdraw it at any time. This does not affect the lawfulness of processing before withdrawal.
Human review of automated decisions Where we make a decision about you based solely on automated processing that produces legal or similarly significant effects, you can ask for human intervention, express your view and contest the decision (see section 7).
Notification to recipients Where you ask us to correct, erase or restrict your personal data, we will notify the third parties we have shared it with so they can do the same, unless this is impossible or involves disproportionate effort. If you ask, we will tell you who we have notified.
Complaint to the supervisory authority You have the right to lodge a complaint with the Autoriteit Persoonsgegevens (see section 1 and section 13).

13. How to exercise your rights

You can exercise your rights, or ask any privacy question, by contacting our Data Protection Officer at dpo-nl@aspireapp.com, or by writing to the DPO at AFT EU B.V., Strawinskylaan 1647, Tower Seven, 16th floor, 1077 XX Amsterdam, the Netherlands. For general queries you can also reach us via the in-app chat or at support@aspireapp.com. For security, we may need to verify your identity before we act on your request, and we may need proof of authority where someone makes a request on your behalf.

We will respond to requests within one month. We may extend this by up to two further months for complex or numerous requests and will let you know if we do. We will not normally charge a fee, but we may charge a reasonable fee or refuse to act where a request is manifestly unfounded or excessive.

If you are not satisfied with how we have handled your personal data or your request, you can lodge a complaint with the Autoriteit Persoonsgegevens: autoriteitpersoonsgegevens.nl, PO Box 93374, 2509 AJ The Hague, the Netherlands.

14. Marketing and your choices

Where permitted by law, we may send you information about our products and services that may be of interest to you. You can object to direct marketing, including related profiling, at any time – by using the unsubscribe link in our messages, adjusting your communication preferences, or contacting us at dpo-nl@aspireapp.com. We will not pass your details to third parties for their own marketing without your consent.

15. How we protect your personal data

We use appropriate technical and organisational measures to protect your personal data and to maintain its confidentiality, integrity and availability. These include encryption of data in transit and at rest, access controls based on least-privilege and need-to-know principles, multi-factor authentication, network security controls, continuous monitoring, and backup and disaster-recovery arrangements. Our staff receive data-protection and information-security training, and we assess the security of the providers we work with before sharing personal data with them. Our security controls are independently tested and certified (including under ISO 27001, PCI DSS and SOC 2).

16. Changes to this statement

We may update this statement from time to time. Where we make material changes, we will let you know by appropriate means, such as by email, through our app or platform, or on our website. The “effective date” at the top shows when this statement was last updated.

17. Cookies

We use cookies and similar technologies on our website and platform. For more information, please see our Cookies Policy.