Privacy Policy
Safeguarding your personal data is important to us.
This Privacy Policy explains how personal data is collected, used, and protected in accordance with applicable laws, including the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and relevant U.A.E laws and regulations (where applicable).
-
Data Controller:
Each company acts as a primary and independent data controller for the data it collects. -
General: Data Collected:
We may collect personal identification data, contact details, and transaction-related information. -
Lawful Basis:
Processing is carried out lawfully, including contract performance, legal obligations, and legitimate interests. -
Categories of Personal Data Collected:
- Identity data (name, date of birth, ID documents)
- Contact data (address, email, phone)
- Financial and transaction data
- Technical data (IP address, device, logs)
- KYC verification data (for identity confirmation before processing transactions)
-
Lawful Bases for Processing:
(Article 6 UK GDPR)- Performance of a contract
- Legitimate interests (fraud prevention, service improvement)
- Consent (where applicable)
- Explicit consent
- Legal compliance
- Contract necessity
-
Purpose of Processing:
- Customer onboarding and verification
- Fraud prevention and regulatory compliance
- Service provision
- Regulatory compliance
-
Special Category Data:
Where biometric or sensitive data is processed, it is strictly for identity verification and fraud prevention with appropriate safeguards. -
Purpose Limitation:
Data is collected only for specific, explicit purposes and not processed incompatibly. -
Data Minimisation:
Only necessary data is collected for onboarding, compliance, and service delivery. -
Accuracy:
We take reasonable steps to ensure data is accurate and up to date. -
Storage Limitation:
Data is retained only as long as necessary, typically up to 5 years. -
Data Security:
We implement technical and organizational measures such as encryption, access controls, and monitoring. -
International Transfers:
Data may be transferred between the UK and UAE with safeguards such as contractual clauses and risk assessments. -
Data Subject Rights:
Under UK GDPR:- Access data
- Rectify inaccuracies
- Request erasure
- Restrict processing
- Object to processing
- Data portability
- Access
- Correction
- Erasure
- Restrict processing
-
Automated Decision-Making:
Automated systems (e.g., KYC checks) may be used. Users can request human review. -
Complaints:
Users may contact:- UK Information Commissioner’s Office (ICO)
- UAE Data Office
-
Changes:
This policy may be updated periodically. -
Data Sharing:
Data may be shared with affiliated companies and service providers, including those outside the UK.
ANY DATA PROTECTION QUERIES?
PLEASE CONTACT US:
Email: info@pacificcorp.co.uk
