Legal
FTFT Pay – Global Privacy Policy
FTFT Finance UK Limited, trading as FTFT Pay, gives businesses a simple and secure way to send and receive payments, move money across borders and manage their accounts.
Last updated: September 2026
About This Policy
FTFT Finance UK Limited ("FTFT", "we", "us" or "our") takes the protection of personal information seriously. This Global Privacy Policy (the "Policy") sets out what Personal Data we collect, why we collect it, who we share it with and how we keep it safe. It applies whenever you deal with us, whether you are a customer, a potential customer, a contact at a business we work with, a job applicant or a visitor to our website or app.
This Policy also explains when we act as a Data Controller and when we act as a Processor. Additional rules that apply in particular countries are set out in the Appendices at the end.
By visiting our website, using our app or Services, or otherwise dealing with us, you accept that this Policy applies to that interaction.
Company details
FTFT Finance UK Limited
Horizon House, 136B Darkes Lane, Potters Bar, London, EN6 2AF
Website: ftftpay.com
Key Terms
The capitalised words below have the following meanings wherever they appear in this Policy.
- Anonymisation: changing Personal Data so that nobody can be identified from it, directly or indirectly. Information that has been Anonymised is no longer Personal Data.
- Applicable Law: any law, regulation, rule or binding requirement of a government, regulator or supervisory body that has authority over FTFT or over how Personal Data is Processed, in any country where we operate or provide Services, as amended or replaced from time to time.
- Business Day: any day except a Saturday, Sunday or public holiday on which banks in the relevant country are open.
- Consent: a clear, informed, specific and freely given indication (for example, ticking a box or making a statement) that you agree to your Personal Data being Processed, where local law requires this.
- Cookies: small text files, identifiers or pieces of code that store information on your device or track online activity.
- Data Controller: the organisation that decides why and how Personal Data is Processed.
- Data Protection Officer: the person appointed by FTFT to oversee our compliance with data protection law and to act as a point of contact for individuals and Supervisory Authorities.
- EEA: the European Economic Area, being the EU member states together with Iceland, Liechtenstein and Norway.
- EU: the European Union and its member states.
- EU GDPR: Regulation (EU) 2016/679, the General Data Protection Regulation that governs the Processing of Personal Data in the EEA.
- Independent Controller: a separate organisation that decides for itself why and how it Processes Personal Data, and which is responsible for its own compliance.
- Personal Data: any information about a person who is identified or can be identified.
- Process (and Processing / Processed): anything done with Personal Data, including collecting, using, storing, sharing, transferring or deleting it.
- Processor: an organisation that Processes Personal Data on behalf of a Data Controller and only on that Controller's written instructions.
- Pseudonymisation: Processing Personal Data so it can only be linked back to an individual using extra information that is held separately and securely.
- Sensitive Personal Data: categories of Personal Data that receive extra legal protection, such as biometric data, health information, racial or ethnic origin, or political opinions.
- Services: the payment services, accounts, products and platforms made available by FTFT.
- Supervisory Authority: an independent public body responsible for enforcing data protection law in a particular country.
- UK GDPR: the UK's retained version of the General Data Protection Regulation, read together with the Data Protection Act 2018.
Who This Policy Covers
This Policy applies to all Personal Data that we Process in the course of running our business, including information about:
- Customers: people who use our Services directly, and individuals connected to the businesses we serve;
- Prospects and marketing contacts: people we may approach, directly or through third parties, about our Services, including through referral schemes;
- Business contacts: staff and representatives of banks, payment networks, suppliers, partners and other organisations we deal with;
- Job applicants: people who apply for a role with us;
- Website and app users: people who visit our website or use our app, including information gathered through Cookies and similar tools; and
- Anyone else: any other individual whose Personal Data we handle in the course of our business, even if they do not fall into one of the groups above. In limited cases this may involve Sensitive Personal Data, as explained later in this Policy.
This Policy applies wherever we operate or Process Personal Data, including the United Kingdom, the EU/EEA, the United States, Canada, Brazil, the United Arab Emirates, Singapore, India and Australia. If any part of this Policy conflicts with local law, local law will apply in that country.
When We Act as Controller and When We Act as Processor
As a Data Controller: we are the Data Controller when we decide the purposes and methods of Processing, as described in Section 6.
As a Processor: we act as a Processor when we handle Personal Data for another organisation, following its written instructions and the terms of our contract with it. For example, this happens when we:
- use Personal Data supplied by a business customer (such as details of its own customers or payees) purely to deliver the Services it has asked for; or
- store transaction records, customer lists or similar information for a client without using it for our own purposes.
Whenever we act as a Processor, we will:
- keep the information confidential and make sure our staff and subcontractors do the same;
- protect it with suitable technical and organisational security measures;
- help the Data Controller meet its own obligations, as our contract or Applicable Law requires;
- return or delete the information at the end of the Services, as the Data Controller chooses; and
- only use subcontractors who are contractually bound to equivalent security standards, and get the Data Controller's approval first where this is required.
Our Processing may involve sending Personal Data to other countries. Where the law requires it, we put suitable protections in place, such as adequacy decisions, standard contractual clauses or other lawful transfer tools, chosen to suit the country and the type of data involved (see Section 10).
In every case, we handle Personal Data lawfully, fairly and openly, keep it only for as long as we need it under our retention schedule, and protect it with appropriate security measures.
The Personal Data We Collect
We obtain Personal Data directly from you, from your use of our Services, from third parties (such as our payment partners, identity verification providers and people who refer you to us) and from public sources (such as company registers and social media). What we collect depends on how you deal with us, but may include:
- Identity and contact details: name, address, email address, telephone number, date of birth and official identity documents (used for identity verification, Know Your Customer and anti-money laundering checks), plus professional details such as your job title, employer and work contact details;
- Financial and transaction information: account details, balances, payment history, details of payers and payees, billing information and other records relating to the Services;
- Security and login information: identity documents, photographs or other biometric checks (with your explicit Consent where the law requires it), usernames, passwords and authentication tokens;
- Device and usage information: IP address, device identifiers, browser and operating system type, system logs and details of how you use our website and app, including information collected through Cookies (see Section 8);
- Marketing and preference information: your marketing choices, opt-in and opt-out records, how you interact with our campaigns, and limited information from social media or advertising platforms, depending on your settings on those platforms;
- Customer service information: your enquiries, complaints and feedback, and recordings or transcripts of calls and chats (with notice or Consent where the law requires it);
- Referral information: referral codes and the minimum details about people you refer that we need to run the referral scheme, with notice given to those people;
- Recruitment information: CVs, employment history, qualifications, interview notes, background checks (where lawful) and information from recruiters or professional networking sites. All key hiring decisions are reviewed by a person. In some countries we may also collect limited information about your family (for example, whether a partner or children need visa sponsorship, or for benefit eligibility). See Section 6; and
- Sensitive Personal Data: occasionally, we may Process Sensitive Personal Data, such as biometric data used to confirm your identity, or information about racial or ethnic origin that appears on an identity document. We only do this where it is necessary for a specific purpose, with appropriate protections and Consent.
We will give you extra information or ask for Consent where the law requires. Not every category applies to every person, and we only collect what is relevant and needed for the purposes in this Policy. Some of this information may be transferred to other countries in line with Applicable Law and the protections described in Sections 4 and 10.
Why We Use Personal Data
We use Personal Data to run our business and to meet our legal duties. Our main purposes are set out below.
Delivering our Services This covers opening and verifying accounts, carrying out payments, managing accounts, supporting customers, preventing fraud and meeting our legal and regulatory duties. Our Services may be provided through our own platforms or, where allowed, through systems run by partners or other third parties, such as integrated technology, hosted checkout pages, white-label products or other embedded services. We also use Personal Data to manage our relationships with business customers and their staff, partner banks, payment networks, suppliers and other partners. Where appropriate and permitted, and in line with your choices, we may tailor your experience (for example, by remembering your settings or pointing you to relevant features).
Improving our Services We use information to improve existing features, build new products, make our services easier to use, run our operations more efficiently and carry out market research and analysis. Wherever we can, we use Anonymised or Pseudonymised data for this.
Marketing and growing our business We promote our Services and keep in touch with existing and potential customers and partners, either directly or through trusted third parties. To do this we may collect professional contact details from public or third-party sources and gather information from our website, app and Services (including through Cookies) to support outreach, targeted advertising and analysis.
When you give us your details through our website, landing pages, event sign-ups or contact forms, we will tell you how we plan to use them and, where the law requires it, ask for your Consent through a clear action such as ticking a box. We may contact you by phone, email or professional networking messages, or reach you through advertising networks and social media platforms, including remarketing and custom audience campaigns.
You can stop receiving marketing at any time by clicking the unsubscribe link in any marketing email or by contacting us. Once you do, we will stop using your Personal Data for marketing and personalisation, although we may still send you important service or operational messages. We respect "Do Not Call" requests and any choices you make using platform tools, and you can also manage your advertising settings directly with platforms such as Google, Meta and LinkedIn. All of our marketing complies with Applicable Law (see Section 7).
Recruitment We use applications and assessments to decide whether candidates are suitable for a role. This may involve reviewing CVs, holding interviews, running skills tests (sometimes through specialist providers) and, where lawful, carrying out background or reference checks with your knowledge or Consent. We may keep your application for up to 12 months in case another suitable role comes up, unless you ask us to delete it sooner and the law allows this. Any equal opportunities or diversity information is kept apart from hiring decisions and used only in aggregate for monitoring and compliance. Candidate information is kept confidential and only seen by people involved in the recruitment process.
Referral schemes We run referral schemes involving the person making the referral and the person being referred, sometimes with the help of approved service providers. If we contact someone who has been referred, we will tell them where we got their details from and follow the relevant marketing rules. We only share what is necessary, usually just the referrer's name so the referred person knows who recommended them. Taking part is optional, and you can ask us to stop using your details at any time. If you do, we will add you to a suppression list so you are not contacted again, keeping only what we need for fraud prevention or under the scheme's terms.
Meeting our legal duties We carry out Know Your Customer (KYC), Know Your Business (KYB), anti-money laundering (AML) and sanctions checks, including through trusted third-party providers. These checks may use automated tools and, where the law requires, human review. We may also share information with Supervisory Authorities, law enforcement agencies and other authorities when we are legally required to.
Automated systems and artificial intelligence We may use Personal Data in automated systems, including artificial intelligence and machine learning, to provide, improve and protect our Services. This includes spotting and stopping fraud, meeting compliance requirements, improving the user experience and building new features. We may also use Personal Data for other related purposes, such as improving how we deliver the Services and the overall quality of what we offer. Where possible we use Anonymised or Pseudonymised data, and we apply the safeguards required by Applicable Law, such as risk assessments and access limits, to protect your rights.
Other business purposes We also use Personal Data to carry out audits and financial reporting, enforce our terms, prevent misuse of our Services, protect our legal rights, test and fix our systems and meet our reporting duties to Supervisory Authorities, industry bodies and other authorities. This includes dealing with disputes, chargebacks and legal claims (such as debt recovery and court or regulatory proceedings). We may keep some Personal Data for tax, accounting, payment network or similar reasons.
Extra protection for sensitive and financial information Sensitive Personal Data (such as biometric identifiers, health information or information about children) receives extra protection. We only Process it where necessary and lawful, and we apply additional measures such as encryption, access controls and strict limits on how it is used. Financial information, such as bank and card details, is also protected with enhanced security, including encryption and restricted access.
Some of these activities may involve sending Personal Data to other countries (see Sections 4 and 10).
Our Legal Grounds for Processing
Where data protection law (for example, the UK GDPR or EU GDPR) requires us to have a legal ground for Processing, we will identify and rely on one. In countries where this is not formally required, we still apply the same standards set out in this Policy. The main grounds we rely on are:
Legal ground
When we rely on it
Examples Performing a contract To: provide our Services or meet our contractual commitments to you or your employer.Opening an account, making payments and providing the Services agreed.
Legal obligation To: meet duties placed on us by financial services, data protection and other laws and regulators.KYC, KYB, AML and sanctions checks; keeping records for audit, tax and financial reporting; complying with payment services and e-money rules; responding to lawful and proportionate requests from Supervisory Authorities and other authorities.
Legitimate interests: Where Processing is needed for our business and your rights do not outweigh our interests. We record our assessment of this balance.Preventing fraud, sending marketing (with the option to opt out), improving and securing our Services, and some automated decision-making (such as fraud detection or security monitoring), with safeguards including transparency, human review and the right to challenge decisions (see Section 14).
Consent: Where you have a real choice and agree to the Processing. You can withdraw Consent at any time, but this does not affect Processing that has already taken place.Marketing to people who are not customers, some Cookies and biometric checks in certain countries.
Vital interests: Only in rare cases, to protect someone's life or physical safety. Sharing information with emergency services where someone is in immediate danger.
Sending Personal Data to Other Countries
As we operate internationally and work with partners around the world, your Personal Data may be transferred to, or accessed from, countries other than your own. For example, if you are in the EEA, your information may be sent to the UK, the United States, Asia or other locations where our partners and support teams operate. When you send or receive money internationally, we may also need to share information with payment partners, correspondent banks or regulators in the receiving country, either because the law requires it or because it is needed to complete the payment.
If the receiving country offers a lower level of protection than your own, we use suitable safeguards, such as:
- Adequacy decisions: where the relevant authority (for example, the UK government or the European Commission) has confirmed that a country protects Personal Data adequately, we may rely on that decision;
- Standard Contractual Clauses and the UK International Data Transfer Addendum: where there is no adequacy decision, we use these approved contract terms to require the recipient to protect Personal Data to UK and EU GDPR standards. We also carry out transfer risk assessments and, where needed, apply extra technical and organisational measures such as encryption or Pseudonymisation; and
- Other legal grounds: in limited cases, we may rely on specific exceptions allowed by data protection law, including where:
- you have given your explicit Consent after being told about the risks and have a real choice;
- the transfer is needed to carry out a contract you have asked for (such as sending an international payment);
- the transfer is needed to bring, pursue or defend legal claims;
- the transfer is needed to protect someone's life or safety; or
- another limited ground recognised by Applicable Law applies.
Whenever we transfer Personal Data to a third party, such as a service provider or financial partner, we require suitable protections, including contractual commitments and technical safeguards, as Applicable Law requires. Where the recipient is an Independent Controller, its own privacy notice will apply. We keep legal developments under review and update our safeguards as needed.
Personal Data is most commonly transferred to the United Kingdom, EU/EEA countries, the United States, Canada, Singapore, the United Arab Emirates and other countries where FTFT, Sokin or our key service providers and partners operate.
Keeping Personal Data Secure
Protecting your Personal Data is a priority for us. We run a security programme that combines technical, organisational and physical measures to guard against unauthorised access, loss or misuse. These include:
- Organisational measures: regular privacy training for staff, confidentiality commitments, access to Personal Data only on a need-to-know basis, and careful checks on suppliers before we use them;
- Technical measures: encryption of data in transit and at rest, strict access controls including multi-factor authentication, firewalls, regular vulnerability testing and monitoring, and secure software development practices;
- Physical measures: restricted access to our premises, secure storage of records, and safe disposal of equipment and media that are no longer needed; and
- Supplier oversight: assessing key suppliers before we engage them and at regular intervals afterwards to make sure they maintain suitable security.
We also carry out regular risk assessments, penetration tests and audits, and our security programme is designed to follow recognised international standards for information security and payment data protection, and to meet Applicable Law.
No system for sending or storing information can ever be completely secure. If a Personal Data breach occurs that puts your rights or freedoms at risk, we will tell you and the relevant regulators as the law requires.
How you can help: keeping your information safe is a shared effort. If you have an FTFT account, please use a strong password that you do not use elsewhere, keep your login details private and watch out for phishing attempts. We will never ask for your password by email or phone. If you notice anything suspicious, please contact us straight away.
How Long We Keep Personal Data
We keep Personal Data only for as long as we need it to provide our Services and for the purposes described in this Policy, including supporting customers, processing payments, meeting our legal and regulatory duties and running our business (for example, audits, marketing and corporate transactions). Financial services and anti-money laundering laws generally require us to keep certain records for at least five years, and some legal duties require longer. Where no legal requirement applies, we keep information for the shortest period that meets our business needs. In practice:
- Transaction information: identity and financial records are kept in line with financial services and AML rules;
- Active accounts: information is kept while your account is open and for a period after it closes, as required by Applicable Law (such as tax or AML rules) or to protect our legal position (for example, in a dispute);
- Marketing information: kept until you opt out or after a period of inactivity. If you opt out, we keep your contact details on a suppression list so we can respect your choice;
- Recruitment information: kept for up to 12 months after you apply, unless the law requires or allows otherwise, you ask us to delete it sooner, or you agree to a longer period; and
- Website and Cookie information: Cookies stay on your device for their set lifetime or until you delete them.
Special rules also apply in some cases:
- Legal holds: we may keep Personal Data for longer if it is needed for legal claims, regulatory compliance or fraud prevention;
- Backups: when we delete Personal Data, we remove it from our live systems. It may stay in secure backups for a limited time in line with our internal policies, but those backups are kept separate and are only used for security and integrity purposes; and
- Deletion and Anonymisation: once we no longer need Personal Data and are not legally required to keep it, we securely delete it or permanently Anonymise it.
If you ask us to delete your Personal Data, we will do so unless a legal or regulatory duty requires us to keep it. In that case, we will remove it from active use until it can be securely deleted.
Your Rights
You have rights over your Personal Data, and we have processes in place to help you use them. The exact rights available depend on the law where you live, but generally include the right to:
- Access and portability: find out whether we hold your Personal Data and get a copy in a secure, commonly used, machine-readable format. Where applicable, you can also ask us to send it to another organisation;
- Correction: ask us to correct or complete Personal Data that is wrong or incomplete;
- Deletion: ask us to delete your Personal Data if we no longer need it, if you withdraw your Consent or if the law requires deletion. Sometimes we must keep certain records by law (for example, financial or AML records). In that case, we will restrict access and securely delete the data once the retention period ends;
- Restriction: in some situations, ask us to pause Processing your Personal Data (for example, while we check whether it is accurate);
- Objection: object to us using your Personal Data where we rely on legitimate interests. You can always object to direct marketing;
- Withdrawal of Consent: withdraw your Consent at any time where we rely on it (for example, for marketing). This does not affect Processing before you withdrew it;
- Automated decisions: not be subject to a decision made purely by automated means (including profiling) that has legal or similarly significant effects on you, unless an exception applies (for example, where it is needed for a contract, required by law or based on your explicit Consent with safeguards). Where this right applies, you can ask for a person to review the decision, give your point of view and challenge the outcome; and
- Complaints: we would like the chance to resolve any concern first, so please contact us. If you are still not satisfied, you can complain to your Supervisory Authority (see Appendix 9).
We will reply within the time allowed by law (for example, one month under the GDPR, or 45 days under US laws), extending this where necessary and permitted. Most requests are free. If a request is clearly unfounded, excessive or repetitive, we may charge a reasonable fee or, in rare cases, refuse it, and we will always explain why.
Sometimes we may be unable to fully meet your request because of legal or regulatory requirements (for example, we may have to keep certain records or remove information about other people). If so, we will tell you what we cannot do and why.
Some rights can be managed directly by you:
- Update your details or password: in your account settings;
- Stop marketing: using the unsubscribe link in any marketing email; and
- Access or download certain information: through your account tools, or by contacting us if these are not available.
You can use your rights at any time by contacting us using the details in Appendix 9.
Automated Decisions and Profiling
We use automated tools to help keep our Services secure, efficient and compliant, including for fraud prevention, security monitoring, personalisation and recruitment.
- Automated decision-making means a decision made without human involvement that could significantly affect you, such as blocking a payment.
- Profiling means analysing Personal Data to assess behaviour or preferences, such as fraud risk or interest in particular products.
Where we use artificial intelligence or machine learning, we explain what Personal Data is used, why, and how we manage the risks. We avoid fully automated decisions with significant effects unless the law allows them, and we always apply safeguards, including human review where required. In particular:
- Fraud and compliance checks: automated tools help us detect suspicious activity such as fraud or money laundering. They may temporarily block or flag an action, but where the system is under our control, a member of our team reviews alerts before anything permanent happens to your account. Our payments partner, partner banks or payment networks may also run their own fraud and compliance controls, which can lead to payments being blocked for reasons outside our control;
- Personalisation and marketing: we may look at how you use our Services to improve your experience or send you relevant messages. This profiling is limited, does not have significant effects on you, and you can opt out of marketing at any time. Where the law allows, you can also object to certain profiling; and
- Recruitment: automated tools may help us sort applications, but every hiring decision involves a person. If you think automation has treated your application unfairly, please contact us and you can ask for a human review.
Where the law gives you the right not to be subject to solely automated decisions (including profiling) with significant effects, we respect that right. You can:
- object to profiling or automated decision-making that significantly affects you;
- opt out of marketing-related profiling and personalised advertising at any time; and
- ask us to explain an automated decision, have a person review it or challenge it.
We regularly review and improve our automated tools, including checking for bias and errors, to keep them fair, accurate and transparent. If we introduce new Services involving automated decisions or profiling, we will make sure they comply with Applicable Law and update this Policy.
Children's Data
Our Services are designed for business and professional use and are not aimed at anyone under 18 (or the age of digital Consent in your country, usually between 13 and 16). We do not knowingly Process Personal Data about children. If we find that a child has given us Personal Data without the required Consent, we will delete it as the law requires. If you are a parent or guardian and believe your child has given us Personal Data, please contact us using the details in Appendix 9. We will verify the request where needed and delete the information promptly, within 30 days or any shorter period required by law.
Links to Other Websites and Services
Our Services may link to, or connect with, websites, apps or platforms run by other organisations. Those organisations have their own privacy policies, and we are not responsible for how they handle Personal Data. Please read their policies before giving them any of your information.
Updates to This Policy
We may change this Policy from time to time to reflect changes in how we work, the technology we use, our legal obligations or for other operational reasons. The "Last updated" date at the top shows when it was last revised. If we make a significant change to how we handle Personal Data, we will let you know in an appropriate way (for example, by email, in-app message or as the law requires). For minor changes, we will publish the updated Policy with a new "Last updated" date.
Contact Us
If you have any questions or concerns about this Policy or how we handle your Personal Data, please see Appendix 9, which sets out how to reach our Data Protection Officer and how to contact the relevant Supervisory Authority.
Country-Specific Information
The Appendices below form part of this Policy and give extra information for people living in particular countries. If an Appendix conflicts with the main Policy, the Appendix will apply for people in that country.
In each country listed, FTFT Finance UK Limited is the Data Controller for the Processing described in this Policy, unless we tell you otherwise. Sokin, as our payments partner, may act as an Independent Controller for Personal Data it Processes to provide the regulated elements of the Services.
Appendix 1: United Kingdom and EU/EEA
This Appendix applies where Processing is governed by the UK GDPR (for people in the UK) or the EU GDPR (for people in the EEA).
Data Controller: FTFT Finance UK Limited is the Data Controller for people in the UK and the EEA. Certain regulated parts of the Services are provided in partnership with Sokin, which may be a Data Controller in its own right for the Personal Data it Processes to deliver those Services. If you are not sure which organisation is responsible for your Personal Data, please contact us first. More information about the other Independent Controllers we share data with is in Section 9.
Legal grounds: where data protection law requires a legal ground for Processing, we rely on those set out in Section 7. Where we Process Sensitive Personal Data (for example, biometric data for identity checks or AML compliance), we rely on your explicit Consent or another ground permitted by the UK or EU GDPR. We always identify and record the correct legal ground before we start Processing and apply the safeguards in this Policy.
Your rights: you have the rights under the UK and EU GDPR described in Section 13. Our contact details are in Appendix 9. You can also complain to a Supervisory Authority, such as the UK Information Commissioner's Office (ICO) or a Supervisory Authority in the EU (a list is published by the European Data Protection Board).
Response times: we will respond to requests under Section 13 without undue delay and in any event within one month. If your request is complex or you have made several requests, we may extend this by up to two further months. If so, we will tell you within the first month and explain why.
International transfers: if we send your Personal Data outside the UK or EEA, we use safeguards such as adequacy decisions, the EU Standard Contractual Clauses, the UK International Data Transfer Agreement or Addendum, and suitable technical and organisational measures (such as encryption and supplier checks), in line with Applicable Law. More details are available on request, subject to confidentiality and security.
Breaches: if a Personal Data breach occurs, we will notify the relevant Supervisory Authority within 72 hours where required, and tell you without undue delay if the breach is likely to pose a high risk to your rights and freedoms.
Contact: see Appendix 9.
Appendix 2: Singapore
This Appendix applies where Processing is governed by Singapore's Personal Data Protection Act 2012 ("PDPA").
Data Controller: FTFT Finance UK Limited.
Legal grounds: our starting point is to ask for your Consent before we collect, use or disclose your Personal Data, unless a legal exception applies. You can withdraw Consent at any time, although this may affect our ability to provide the Services. We will not use or disclose your Personal Data for purposes beyond those we have told you about, unless you agree or the PDPA allows it.
We may also Process Personal Data without Consent where the PDPA permits, for example to meet legal or regulatory duties, for investigations, in emergencies or where the information is publicly available.
In some situations, the PDPA allows us to treat you as having given Consent ("deemed Consent"), for example where:
- the Personal Data is reasonably needed to carry out a contract with you;
- you have provided the Personal Data voluntarily; or
- we have told you about a new purpose, given you the chance to opt out, and you have not done so.
We explain why we collect and use Personal Data at or before the time we collect it, mainly through this Policy and, where required by law or appropriate for a particular activity, in a separate notice. If we want to use your Personal Data for a significantly different purpose not described here, we will ask for your Consent or rely on another lawful ground.
Do Not Call: we follow the PDPA's marketing rules, including the Do Not Call (DNC) Registry, and will not make marketing calls or send marketing texts to registered numbers without Consent or a valid exemption.
Response times: we will respond to requests under Section 13 as soon as reasonably possible and usually within 30 days. If we cannot meet that timeframe, we will write to you explaining why and when you can expect a reply. You can also ask how your Personal Data has been used or disclosed by us over the past year.
International transfers: if we send your Personal Data outside Singapore, we make sure it is protected to a standard comparable to the PDPA.
Security and retention: we protect Personal Data with suitable technical and organisational measures and stop keeping it when it is no longer needed, unless the law requires otherwise. We also take reasonable steps to make sure Personal Data is accurate and complete if it is likely to be used to make a decision about you or passed to another organisation.
Contact: see Appendix 9.
Appendix 3: United States
This Appendix applies where Processing is governed by US federal and state privacy laws, including the California Consumer Privacy Act as amended by the California Privacy Rights Act (together, the "CCPA"), and other state laws (such as those in Virginia, Colorado, Connecticut and Utah).
Data Controller: FTFT Finance UK Limited.
Our approach: in line with US state privacy laws, including the CCPA, we are open about how we collect, use and share Personal Data, respect your rights under Section 13 and maintain reasonable safeguards to protect your information.
California residents (CCPA): you have the right to:
- know what categories of Personal Data we collect, why we use them and what categories of third parties we share them with;
- opt out of the "sharing" of your Personal Data for cross-context behavioural advertising. We do not sell your Personal Data. If any of our activities count as "sharing" under the CCPA (such as certain advertising technologies), we will give you a way to opt out;
- limit the use and disclosure of your Sensitive Personal Data (such as financial or health information), except where we only use it for essential purposes like fraud prevention or legal compliance; and
- not be treated less favourably (for example, by being refused Services or charged different prices) because you have used your privacy rights.
Other states: people in other US states (including Virginia, Colorado, Connecticut and Utah) may have similar rights under their own laws, and we respect those rights where they apply. For consistency, we offer the same rights and controls to everyone in the US, including the right to opt out of targeted advertising, the sale or sharing of Personal Data and, where relevant, certain profiling. We also give notice and ask for Consent where required before Processing Sensitive Personal Data or carrying out profiling that has legal or similarly significant effects (see Section 14).
Response times: we will confirm receipt of requests under Section 13 within 10 Business Days and give a full response within 45 days. We may extend this by a further 45 days where reasonably necessary, in which case we will tell you within the first 45 days and explain why.
Security and breaches: we maintain an information security programme with suitable technical and organisational measures and require our service providers to maintain reasonable safeguards too. We will notify you of Personal Data breaches where the law requires.
Contact: see Appendix 9.
Appendix 4: Canada
This Appendix applies where Processing is governed by Canadian privacy law, including the federal Personal Information Protection and Electronic Documents Act ("PIPEDA"), similar provincial laws in Quebec, Alberta and British Columbia, and any new or updated Canadian privacy laws that apply to us.
Data Controller: FTFT Finance UK Limited.
Legal grounds: we only collect, use or disclose Personal Data for purposes that a reasonable person would consider appropriate, taking into account the type of information, how it is collected and your relationship with us. We generally obtain your knowledge and Consent first, unless an exception applies (for example, for investigations, legal or regulatory requirements, or emergencies). Consent may be express or implied, depending on how sensitive the information is and what you would reasonably expect.
International transfers: if we send your Personal Data outside Canada (for example, to the UK, US or EU/EEA), it may be subject to the laws of those countries. We remain responsible for your Personal Data and use contractual and technical safeguards to protect it to a standard comparable to Canadian law.
Your rights: in addition to the rights in Section 13, you can ask how your Personal Data has been used and disclosed. These rights are subject to certain exceptions under Canadian law (for example, where disclosure would reveal information about another person or legally privileged information).
Response times: we will usually respond to requests under Section 13 within 30 days. If we need more time, we will tell you within that period and explain why. If we refuse a request, we will explain our reasons and tell you about your right to challenge the decision, including by contacting the Office of the Privacy Commissioner of Canada or a provincial commissioner.
Marketing: we comply with Canada's Anti-Spam Legislation (CASL). We only send commercial electronic messages where we have Consent or a lawful exemption. You can unsubscribe or withdraw Consent at any time, and we will act on your request within 10 Business Days.
Security and retention: we protect Personal Data with suitable technical and organisational measures and only keep it for as long as needed for the purposes described above, unless the law requires a longer period. When it is no longer needed, we securely delete, Anonymise or archive it.
Contact: see Appendix 9.
Appendix 5: Brazil
This Appendix applies where Processing is governed by Brazil's General Data Protection Law (Lei Geral de Proteção de Dados Pessoais, Law No. 13.709/2018) ("LGPD").
Data Controller: FTFT Finance UK Limited.
Legal grounds: as the LGPD allows, we rely on the legal grounds set out in Section 7, in particular performing a contract, meeting legal obligations, Consent and legitimate interests, as relevant. We only Process Sensitive Personal Data with your explicit Consent or where an LGPD exception applies (for example, fraud prevention, legal or regulatory compliance, protecting life or physical safety, or public health).
Your rights: in addition to the rights in Section 13, you can ask us to:
- confirm whether we Process your Personal Data;
- Anonymise, block or delete Personal Data that is unnecessary, excessive or Processed unlawfully;
- tell you which public and private organisations we share your Personal Data with; and
- review decisions made solely by automated Processing that affect your interests. Where automated decisions significantly affect you, we apply safeguards including human review and transparency, as described in Section 14.
Response times: we will respond to requests under Section 13 within 15 days of receiving them, as the LGPD requires.
International transfers: if your Personal Data is sent outside Brazil, including to the United Kingdom, the United States, Canada, the EU, Australia, Singapore or India, we protect it in line with the LGPD. This may involve adequacy decisions, standard contractual clauses approved by the ANPD or other contractual safeguards offering comparable protection.
Security and breaches: we protect Personal Data with suitable technical and organisational measures. If a security incident is likely to cause you significant risk or harm, we will notify the Brazilian National Data Protection Authority (Autoridade Nacional de Proteção de Dados, "ANPD") and affected individuals, as the LGPD requires.
Contact: our Data Protection Officer (the "Encarregado") is responsible for Personal Data matters and can be contacted using the details in Appendix 9.
Appendix 6: United Arab Emirates
This Appendix applies where Processing is governed by UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data ("PDPL") and, where relevant, free zone laws such as the DIFC Data Protection Law No. 5 of 2020 ("DIFC") and the ADGM Data Protection Regulations 2021 ("ADGM").
Data Controller: FTFT Finance UK Limited.
Legal grounds: under the PDPL, Consent is the main ground for Processing, with limited legal exceptions. Under DIFC and ADGM law, other grounds such as performing a contract, legal obligation and legitimate interests may also apply.
Your rights: you have the rights described in Section 13, subject to certain exceptions (for example, where giving access would reveal someone else's information, where regulatory duties prevent deletion or where disclosure could harm an investigation).
Response times: we will respond to requests under Section 13 within one month of receipt, unless UAE law allows a longer period. If we need more time, we will tell you within the first month and explain why.
International transfers: if we send your Personal Data outside the UAE (for example, to the UK, EU or other countries where we or our partners operate), we protect it to a standard consistent with UAE law, using safeguards such as recognised adequacy decisions, contractual clauses and additional measures like encryption and supplier checks.
Security and breaches: we protect Personal Data with suitable technical and organisational measures. Where DIFC or ADGM law requires, we will notify the relevant regulator within 72 hours of becoming aware of a reportable breach.
Contact: see Appendix 9.
Appendix 7: Australia
This Appendix applies where Processing is governed by the Australian Privacy Principles ("APPs") under the Privacy Act 1988 (Cth) and related regulations.
Data Controller: FTFT Finance UK Limited.
Legal grounds: Australian law does not require a specific legal ground for Processing, but we only collect, use and disclose Personal Data where the APPs allow it, and we comply with the APPs. We obtain Consent where the law requires it.
Your rights: you have the rights described in Section 13, as adapted under the Privacy Act 1988, including the right to access and correct your Personal Data, subject to applicable exceptions.
Response times: we will respond to access or correction requests under Section 13 within a reasonable time, generally within 30 days. If we refuse a request, we will explain our reasons in writing and tell you how to complain, including to the Office of the Australian Information Commissioner ("OAIC").
Direct marketing: we comply with APP 7 and the Spam Act 2003 (Cth). Where required, we tell you where we obtained the Personal Data used for marketing, and every marketing message includes a clear, free way to opt out. We will not use Sensitive Personal Data for marketing without your Consent.
International transfers: if we send your Personal Data outside Australia, we take reasonable steps to make sure the overseas recipient handles it in line with the APPs, for example through contractual terms, supplier checks and security measures such as encryption. We remain accountable for your Personal Data while it is under our control.
Security and breaches: we protect Personal Data with suitable technical and organisational measures. If a breach is likely to cause serious harm, we will notify the OAIC and affected individuals as soon as practicable under the Notifiable Data Breaches scheme.
Contact: see Appendix 9.
Appendix 8: India
This Appendix applies where Processing is governed by the Digital Personal Data Protection Act, 2023 ("DPDPA") once it is in force and, until then, the relevant parts of the Information Technology Act, 2000 and its data protection and security rules, together with any later or additional privacy rules.
Data Controller: FTFT Finance UK Limited.
Legal grounds: we rely on the legal grounds in Section 7 where relevant. Under the DPDPA, Consent, supported by a clear notice, is the main ground for Processing. The DPDPA also requires us to delete Personal Data once its purpose has been served, unless the law requires us to keep it.
Your rights: the DPDPA does not currently include a right to data portability. Your rights include access, correction, deletion and having your complaints addressed. Until detailed rules are published, we will handle access and correction requests in line with current Indian law and good practice.
Response times: we will respond to requests under Section 13 within the period set by the DPDPA and its rules once they are in force. Until then, we will generally respond within 30 days.
Aadhaar and Sensitive Personal Data: we do not collect or Process Aadhaar numbers, biometric identifiers or related Aadhaar information unless the law requires it (for example, for KYC). Where it is legally required, we will ask for your Consent and use the information only for that purpose, in line with Applicable Law.
International transfers: if we send your Personal Data outside India, we use contractual and technical safeguards to protect it appropriately. Where Indian law restricts cross-border transfers, we comply with those restrictions.
Security and breaches: we protect Personal Data with suitable technical and organisational measures. If a breach occurs, we will notify the Data Protection Board of India and affected individuals as soon as possible and within any timeframe set by Indian law.
Grievances: our Data Protection Officer also acts as our Grievance Officer and handles any concerns or complaints about your Personal Data. You can contact them using the details in Appendix 9. We will acknowledge and respond within the timeframes set by Indian law.
Appendix 9: Contact Details
If you have any questions, concerns or requests about this Policy or how we handle your Personal Data, or you want to use any of your privacy rights, please contact our Data Protection Officer.
Data Protection Officer (all countries) Email: support@ftftpay.com Post: Data Protection Officer, FTFT Finance UK Limited, Horizon House, 136B Darkes Lane, Potters Bar, London, EN6 2AF, United Kingdom
We will respond within the time required by Applicable Law (for example, usually one month under the GDPR, or sooner where local law requires). For security reasons, we may need to confirm your identity before acting on your request.
Supervisory Authorities: if you are unhappy with our response, you can contact the Supervisory Authority in your country. In the UK, this is the Information Commissioner's Office (ico.org.uk). Contact details for other Supervisory Authorities are available on their official websites.
General enquiries: for questions that are not about privacy (for example, about your account or the Services), please email support@ftftpay.comFTFT Pay – Global Privacy Policy
Last updated: September 2026
FTFT Finance UK Limited, trading as FTFT Pay, gives businesses a simple and secure way to send and receive payments, move money across borders and manage their accounts.
See all FTFT Pay policies on the policies index, or read our regulatory information.