
Privacy Statement
AFT EU B.V. (trading as “Aspire”)
This Privacy Statement explains how AFT EU B.V. collects, uses, shares and protects your personal data, and the rights you have under the EU General Data Protection Regulation (GDPR) and Dutch data protection law.
At a glance: how we handle your personal data
What we collect: information you give us when you apply for and use our services (such as identity documents and business and financial details), information generated when you use our platform and app, and information we receive from others (such as identity-verification, screening and credit-reference providers, and from people who send you or receive payments).
How we use it: to provide our payment and account services, verify your identity, prevent fraud and financial crime, meet our legal and regulatory obligations, improve our services, and – where permitted – send you relevant communications.
Our legal bases: performance of a contract, compliance with legal obligations, our legitimate interests, your consent, and, for special categories of data, substantial public interest or other GDPR conditions.
Who we share it with: companies in the Aspire group, service providers and partners that help us run our services, banking and payment partners, identity, screening and credit-reference providers, the people and businesses you transact with, and authorities where the law requires it.
International transfers: some of our group companies and providers are located outside the European Economic Area (for example in Singapore, India, the United States). Where this happens we put appropriate safeguards in place, such as Standard Contractual Clauses.
Your rights and contact: you have rights over your personal data, including access, rectification, erasure, restriction, portability, objection and withdrawal of consent. You can contact our Data Protection Officer at dpo-nl@aspireapp.com and you have the right to complain to the Dutch supervisory authority (Autoriteit Persoonsgegevens).
Privacy Statement
At a glance: how we handle your personal data
1. About us and how to contact us
2. Who this statement applies to and why you should read it
3. What personal data we collect
4. Where we collect your data from, including data not collected from you directly
5. Our legal bases for using your personal data
6. How we use your personal data and our legal bases
7. Automated processing and profiling
8. Special categories of data and criminal-offence data
9. Who we share your personal data with
10. International transfers of your personal data
11. How long we keep your personal data
12. Your rights
13. How to exercise your rights
14. Marketing and your choices
15. How we protect your personal data
16. Changes to this statement
17. Cookies
1. About us and how to contact us
AFT EU B.V. (“Aspire”, “we”, “us”, “our”) is the controller of the personal data we process when you apply for, or use, the products and services we provide. Aspire is an electronic money institution incorporated and registered in the Netherlands and authorised by De Nederlandsche Bank (DNB). Aspire is part of the wider Aspire group of companies. Where another Aspire group company or a partner is responsible for a particular product or service, we will tell you, and a separate or supplementary privacy notice may apply.
Our company details are:
Our Data Protection Officer (DPO)
We have appointed a Data Protection Officer who oversees how we handle personal data and acts as your point of contact for privacy matters. You can reach the DPO by email at dpo-nl@aspireapp.com or by writing to the DPO at our registered office address above.
The supervisory authority
The data protection supervisory authority for the Netherlands is the Autoriteit Persoonsgegevens (Dutch Data Protection Authority). If you have a concern about how we handle your personal data, we encourage you to contact us first so we can try to resolve it. You also have the right to lodge a complaint with the Autoriteit Persoonsgegevens at any time – see autoriteitpersoonsgegevens.nl, or by post to Autoriteit Persoonsgegevens, PO Box 93374, 2509 AJ The Hague, the Netherlands.
2. Who this statement applies to and why you should read it
This statement applies to personal data we process about:
- the businesses that hold or apply for an account with us (“Account Owners”), and the individuals connected to them whose data we process to meet our legal and regulatory obligations, such as directors, authorised users and signatories, cardholders, beneficial owners (UBOs) and other connected individuals;
- individuals who send payments to, or receive payments from, our customers (payment counterparties and beneficiaries);
- visitors to our website and users of our app and platform; and
- other people whose data we receive in connection with our services, for example through fraud-prevention, screening or due-diligence checks. This happens, for example, where we carry out sanctions, politically exposed person (PEP) or adverse-media screening; where fraud-prevention agencies share information with us about individuals linked to an application or transaction; or where an Account Owner provides us with documents or information that identify other people, such as shareholders, trustees, professional advisers or representatives
When we say “personal data” we mean any information relating to an identified or identifiable individual, for example, your name, contact details or payment card number, but also information such as your IP address or device identifiers where these can be linked to you. We collect your personal data when you use our website, our app and platform, and the services available through them. We may also receive personal data about you from other people and organisations – we explain this in section 4 and section 9.
This statement describes how we use personal data when we act as the data controller. For some limited processing we act on a customer's behalf as a processor, for example, for example, when you, as a customer upload personal data about your own employees, suppliers or clients (such as a receipt, invoice or payee record containing someone's details) to manage your records through the platform. There, you, as a customer, decide why the data is used and we act only on your instructions, so that processing is governed by the data-processing terms in our agreement with you as a customer, not by this statement.
Specific products, services or processes may have their own supplementary privacy notices or ‘just-in-time’ explanations. Wherever possible, we provide a brief, plain-language privacy explanation at the point of data collection (for example, in consent screens or collection forms) that identifies the specific lawful basis on which the data is being collected and the purpose for which it will be used.
3. What personal data we collect
The categories of personal data we collect and use are set out below.
4. Where we collect your data from, including data not collected from you directly
Where we receive your personal data indirectly, for example because you are a director, beneficial owner (UBO), authorised signatory or other individual connected to an Account Owner, or a payment counterparty, we may not always be able to provide this information to you directly. In line with the GDPR, this applies where doing so would be impossible or involve disproportionate effort (such as contacting large numbers of payment counterparties), where the data must remain confidential because of a legal obligation, or where notification could prejudice the prevention, detection or investigation of fraud or financial crime.
If none of these exceptions apply, we will tell you how we use your personal data within a reasonable time after we receive it, and at the latest within one month. If we use your data to contact you, or disclose it to someone else, before that month is up, we will tell you no later than the point at which we first contact you or make the disclosure. We will normally do this by providing you, or the Account Owner you are connected to, with a copy of or link to this statement, using the contact details we hold for you.
The categories of sources from which we obtain indirectly collected data include:
- credit-reference and financial crime prevention agencies;
- public registers, official databases and publicly available sources;
- banking, payment and other partners involved in processing your transactions; and
- our customers, who may provide data about their directors, UBOs, employees and payment counterparties.
5. Our legal bases for using your personal data
We must always have a valid legal basis to use your personal data. Depending on the activity, our legal basis is one or more of the following:
- Performance of a contract: we need certain personal data to provide our services to you and to take steps at your request before entering into a contract.
- Compliance with a legal obligation: we are required to collect and retain certain personal data, and to detect and prevent money laundering, terrorist financing and related financial crime, for example under anti-money laundering, counter-terrorist-financing, e-money, payment-services and tax laws.
- Legitimate interests: we process personal data where we (or a third party) have a legitimate interest, provided this is not overridden by your interests, rights and freedoms. We rely on legitimate interests for purposes including:
- preventing and detecting fraud and misuse of our services beyond what our legal obligations require, and keeping our services and customers secure;
- sharing data within the Aspire group to operate, secure and improve our services;
- analysing and improving our products, services and internal models;
- managing our business and risks, recovering debts, and establishing, exercising or defending legal claims; and
- sending relevant communications where permitted by law.
We carry out and document a Legitimate Interests Assessment (covering the purpose, necessity and balancing tests), before we rely on this basis for a processing activity, and keep a record of these assessments.
- Consent: where we ask for your consent to a specific use of your personal data. If consent is the legal basis for processing, you can withdraw your consent at any time (see section 12).
- Substantial public interest, legal claims and other GDPR conditions: for special categories of personal data and criminal-offence data, as explained in section 8.
We will not use your personal data for a new purpose that is incompatible with the purpose for which it was originally collected unless we have a lawful basis to do so. Where we intend to process your data for a different but compatible purpose (for example, regulatory reporting or financial-crime prevention), we will assess compatibility in line with the applicable laws.
Where we ask you for personal data in order to provide our services or to meet a legal obligation (for example identity, verification and due-diligence information), providing it is a contractual or legal requirement. If you do not provide it, we may be unable to open or to continue to operate your account, or to provide the relevant product or service
6. How we use your personal data and our legal bases
The table below explains the main ways we use your personal data and the legal bases we rely on.
7. Profiling
To run our services efficiently and to keep them secure, we use technology to analyse personal data and assess risks, for example, risk-scoring during onboarding (KYB/KYC), transaction monitoring and fraud detection. This may involve profiling.
Our onboarding and account decisions that produce legal or similarly significant effects (such as whether to open, restrict or close an account) are not based solely on automated processing: a member of our team reviews the relevant criteria and makes or confirms the decision. You have the right to express your view on any such decision and to ask for it to be reviewed by contacting us via the in-app chat or at support@aspireapp.com. Where, in future, we make a decision that produces legal or similarly significant effects about you based solely on automated processing, we will tell you, explain the logic involved and the significance and consequences for you, and give you the right to obtain human intervention, to express your point of view and to contest the decision.
8. Special categories of data and criminal-offence data
Special categories of data (biometrics).
As part of our identity-verification and fraud-prevention checks, our verification provider processes biometric data extracted from your identity documents and selfie/video to confirm that you are who you say you are. We process this special category of data on the basis of substantial public interest (preventing fraud and financial crime and meeting our regulatory obligations) and, where required, your explicit consent, and – where relevant – for the establishment, exercise or defence of legal claims.
Criminal-offence data.
In order to meet our legal and regulatory obligations, we may process information relating to criminal convictions, offences and related security measures, for example where adverse-media or due-diligence screening surfaces alleged or actual criminal conduct about you. We process this data only where authorised by law and subject to appropriate safeguards. Sanctions, watchlist and politically-exposed-person screening involve regulatory or political designations rather than criminal-offence data, and we carry these out under our legal obligations (see section 6).
9. Who we share your personal data with
We share your personal data only where necessary, and with appropriate safeguards in place. The specific recipients (or categories of recipients) for each processing activity are recorded in our Record of Processing Activities (ROPA) and, where relevant, disclosed at the point of collection. The categories of recipients are:
We do not sell your personal data.
10. International transfers of your personal data
We provide an international service and we are part of an international group. As a result, some of your personal data may be transferred to, or accessed from, countries outside the European Economic Area (EEA), including by group companies and service providers located in countries such as Singapore, India, the United States, Canada, Australia, Hong Kong, Japan, the Philippines, Thailand, Indonesia and Vietnam. Some of these countries are not covered by an EU adequacy decision.
Where we transfer personal data outside the EEA to a country that does not provide an equivalent level of protection, we put appropriate safeguards in place to protect it. For transfers from AFT EU B.V., these are principally the European Commission’s Standard Contractual Clauses (SCCs) – including under our intragroup data-sharing agreement – supported by transfer impact assessments and, where needed, supplementary technical, contractual and organisational measures (such as encryption, access controls and data minimisation). The competent supervisory authority for these transfers is the Autoriteit Persoonsgegevens. You can ask us for more information about the safeguards we use, or for a copy of the relevant clauses, by contacting our DPO at dpo-nl@aspireapp.com.
11. How long we keep your personal data
We keep your personal data only for as long as necessary for the purposes for which it was collected, including to meet our legal, regulatory, accounting and reporting obligations and to establish, exercise or defend legal claims.
Because we are a regulated financial-services provider, we are required to retain certain personal data for minimum periods set by anti-money laundering, e-money, payment-services and tax laws. For example, we retain transaction records for a minimum of five years from the date of the transaction, in line with applicable Dutch law, and identity-verification and due-diligence records for the periods required by anti-money laundering law (generally at least five years after our relationship with you ends). Where data is no longer required, we securely delete or anonymise it. Our internal retention schedule sets out the specific retention periods, and the criteria used to determine them, for each category of data.
12. Your rights
Under the GDPR you have the following rights in relation to your personal data:
13. How to exercise your rights
You can exercise your rights, or ask any privacy question, by contacting our Data Protection Officer at dpo-nl@aspireapp.com, or by writing to the DPO at AFT EU B.V., Strawinskylaan 1647, Tower Seven, 16th floor, 1077 XX Amsterdam, the Netherlands. For general queries you can also reach us via the in-app chat or at support@aspireapp.com. For security, we may need to verify your identity before we act on your request, and we may need proof of authority where someone makes a request on your behalf.
We will respond to requests within one month. We may extend this by up to two further months for complex or numerous requests and will let you know if we do. We will not normally charge a fee, but we may charge a reasonable fee or refuse to act where a request is manifestly unfounded or excessive.
If you are not satisfied with how we have handled your personal data or your request, you can lodge a complaint with the Autoriteit Persoonsgegevens: autoriteitpersoonsgegevens.nl, PO Box 93374, 2509 AJ The Hague, the Netherlands.
14. Marketing and your choices
Where permitted by law, we may send you information about our products and services that may be of interest to you. You can object to direct marketing, including related profiling, at any time – by using the unsubscribe link in our messages, adjusting your communication preferences, or contacting us at dpo-nl@aspireapp.com. We will not pass your details to third parties for their own marketing without your consent.
15. How we protect your personal data
We use appropriate technical and organisational measures to protect your personal data and to maintain its confidentiality, integrity and availability. These include encryption of data in transit and at rest, access controls based on least-privilege and need-to-know principles, multi-factor authentication, network security controls, continuous monitoring, and backup and disaster-recovery arrangements. Our staff receive data-protection and information-security training, and we assess the security of the providers we work with before sharing personal data with them. Our security controls are independently tested and certified (including under ISO 27001, PCI DSS and SOC 2).
16. Changes to this statement
We may update this statement from time to time. Where we make material changes, we will let you know by appropriate means, such as by email, through our app or platform, or on our website. The “effective date” at the top shows when this statement was last updated.
17. Cookies
We use cookies and similar technologies on our website and platform. For more information, please see our Cookies Policy.

