Privacy Notice
1. Who we are
Regent Foreign Exchange Limited is a company registered in England and Wales with company number 07424083. Our registered office is 5–10 Bolton Street, London, W1J 8BA, United Kingdom.
Regent Foreign Exchange Limited is authorised by the Financial Conduct Authority as an Authorised Payment Institution under the Payment Services Regulations 2017. Our Financial Services Register number is 543156.
For the purposes of UK data protection law, Regent FE is usually the controller of the personal data described in this Privacy Notice. In limited circumstances, Regent FE may process personal data as a processor on behalf of another controller. Where that applies, the relevant controller’s privacy notice will also apply.
In this Privacy Notice, “Regent FE”, “we”, “us” and “our” mean Regent Foreign Exchange Limited. “You” means the individual whose personal data we process, including a customer, prospective customer, authorised user, signatory, director, officer, beneficial owner, employee or representative of a customer, payee, payer, beneficiary, website visitor or other person who interacts with us.
2. How to contact us
Questions about this Privacy Notice or about how we use personal data should be sent to:
| Contact route | Details |
| [email protected] | |
| Post | Compliance / Data Protection, Regent Foreign Exchange Limited, 5–10 Bolton Street, London, W1J 8BA, United Kingdom |
| Telephone | +44 (0)20 3750 0605 |
If Regent FE appoints a Data Protection Officer, the Data Protection Officer’s contact details will be made available on our website or otherwise notified to you. Until then, data protection queries should be sent to the Compliance contact above.
3. About this Privacy Notice
This Privacy Notice applies when you:
- use our website or online services;
- apply for, open or use a Regent FE account or payment service;
- enter into or perform a contract with us;
- act as an authorised user, administrator, signatory, director, officer, partner, trustee, beneficial owner, controller, employee or representative of a customer;
- send or receive funds through services provided by us;
- communicate with us by telephone, email, post, online portal, messaging service or any other channel;
- make a complaint, raise a fraud claim or contact us about a transaction; or
- apply for a role with us, attend an event or otherwise interact with Regent FE.
This Privacy Notice does not form part of any contract with you. It explains our use of personal data and your rights under applicable data protection law.
Our website and communications may contain links to third-party websites. Those third parties are responsible for their own privacy notices and practices.
4. Data protection law
This Privacy Notice is provided under applicable data protection and privacy laws, including the UK GDPR, the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations 2003. Where relevant, the EU GDPR may also apply to certain processing activities.
We also process certain personal data to comply with legal and regulatory obligations that apply to Regent FE, including the Payment Services Regulations 2017, financial crime, sanctions, anti-money laundering, counter-terrorist financing, fraud prevention, tax, accounting, record-keeping, regulatory reporting and complaints requirements.
5. Personal data we collect
The personal data we collect depends on your relationship with Regent FE and how you use our services. We may collect the following categories of personal data:
| Category | Examples |
| Identity Data | Name, title, date of birth, gender, nationality, residential status, national identifiers, passport, driving licence or identity document details, photographs or copies of identity documents, signature and identifiers used on our systems. |
| Contact Data | Residential address, business address, billing address, email address, telephone number and communication preferences. |
| Financial Data | Bank account details, payment account details, payment card details, source of funds, source of wealth, income, assets, liabilities, tax information, credit or affordability information where relevant. |
| Transaction Data | Details of payments to and from you, payees, beneficiaries, payment references, payment amounts, currencies, FX trades, fees, charges, account activity, statements, rejected or delayed payments and related correspondence. |
| Compliance Data | Know-your-customer information, beneficial ownership and control information, politically exposed person status, sanctions screening, adverse media, fraud-prevention checks, relationship to payees or beneficiaries, purpose of account or transaction, proof of funds, proof of wealth, tax residency, regulatory classifications and risk assessments. |
| Technical and Security Data | IP address, login data, device identifiers, browser type and version, time zone, location data, operating system, platform, security credentials, authentication records, portal activity, audit logs and information generated by security monitoring tools. |
| Usage and Profile Data | Information about how you use our website, portal and services, customer profile, preferences, feedback, survey responses, service history and communication history. |
| Marketing and Communications Data | Your marketing preferences, communication preferences and records of marketing messages sent to you and your responses. |
| Communications Data | Emails, letters, chat messages, call notes, recorded calls and other communications with us. |
| Special Category and Criminal Offence Data | We do not routinely seek special category data. We may process such data, or criminal offence data, where necessary for legal, regulatory, financial crime, fraud, sanctions, vulnerable-customer, complaints, legal claims or service-accessibility purposes and where permitted by law. |
6. How we collect personal data
We collect personal data from the following sources:
| Source | Examples |
| Directly from you | When you complete forms, apply for an account, provide onboarding information, give instructions, communicate with us, make a complaint, request support or use our services. |
| From your organisation or representatives | For example where a customer provides information about directors, officers, beneficial owners, authorised users, administrators, employees, agents, advisers, payees or beneficiaries. |
| Through our website, portal and systems | Through cookies, logs, authentication processes, device information, security monitoring and analytics. |
| From third parties and public sources | Identity verification providers, fraud prevention agencies, credit reference agencies, sanctions and PEP screening providers, Companies House, public registers, open-source information, recruitment agencies, professional advisers, banks, payment institutions, electronic money institutions, payment schemes, correspondents, processors, regulators, law enforcement and other public authorities. |
| From service providers and partners | Including providers used to support payments, FX, account infrastructure, customer due diligence, safeguarding arrangements, fraud prevention, operational delivery, customer support, IT hosting and data storage. |
7. Why we use personal data and our lawful bases
We only use personal data where we have a lawful basis to do so. More than one lawful basis may apply to a processing activity. The table below summarises the main purposes and lawful bases.
| Purpose | What this means | Lawful basis |
| Account applications and onboarding | To assess and process an application, verify identity, set up access, assess eligibility and decide whether to provide services. | Contract; legal obligation; legitimate interests; recognised legitimate interests where applicable. |
| KYC, AML, sanctions, fraud and financial crime controls | To carry out customer due diligence, enhanced due diligence, sanctions screening, PEP screening, transaction monitoring, fraud prevention and reporting to authorities. | Legal obligation; substantial public interest; legitimate interests; recognised legitimate interests where applicable. |
| Providing payment, account and FX services | To provide accounts, receive and execute payment instructions, process foreign exchange transactions, provide statements, manage limits, fees, charges and balances. | Contract; legal obligation; legitimate interests. |
| Customer communications and support | To communicate about your account, services, security, payments, complaints, fraud alerts, operational updates and changes to terms. | Contract; legal obligation; legitimate interests. |
| Security and service integrity | To operate secure systems, authenticate users, prevent unauthorised access, monitor misuse, investigate security incidents and maintain audit logs. | Legal obligation; legitimate interests; recognised legitimate interests where applicable. |
| Complaints, disputes and claims | To investigate and respond to complaints, APP scam claims, unauthorised-payment claims, legal claims, regulatory enquiries and disputes. | Legal obligation; contract; legitimate interests; legal claims. |
| Regulatory, tax, accounting and record-keeping | To comply with FCA, HMRC, Companies House, court, law enforcement, audit, accounting, tax, reporting and record-keeping obligations. | Legal obligation; legitimate interests; recognised legitimate interests where applicable. |
| Marketing and relationship management | To send service updates, regulatory updates, invitations, newsletters and information about products or services that may be relevant to you. | Consent where required by PECR; legitimate interests where permitted; contract for service communications. |
| Website, cookies and analytics | To operate the website, remember preferences, measure website performance, protect the site and understand usage. | Consent for non-essential cookies where required; legitimate interests for essential cookies, security and analytics where lawful. |
| Business administration and corporate transactions | To manage our business, suppliers, professional advisers, insurance, audits, restructuring, sale, transfer or merger of our business or assets. | Legitimate interests; legal obligation; contract. |
| Recruitment | To consider applications for employment, consultancy or other roles and to carry out recruitment checks. | Contract steps; legal obligation; legitimate interests; consent where required. |
8. Special category and criminal offence data
We only process special category personal data or criminal offence data where permitted by law and where necessary for a legitimate purpose. This may include financial crime prevention, sanctions compliance, fraud prevention, dealing with vulnerable-customer circumstances, handling complaints, making reasonable adjustments, legal claims, regulatory requirements or protecting the vital interests of an individual.
Where required, we rely on a condition under the Data Protection Act 2018, such as substantial public interest, preventing or detecting unlawful acts, regulatory requirements, safeguarding of individuals, legal claims or explicit consent. We maintain appropriate safeguards and policy documentation where required.
9. If you do not provide personal data
Where we need personal data to comply with law, perform a contract, complete customer due diligence or provide services, failure to provide that information may mean that we cannot open or maintain an account, execute a payment, process a transaction, provide a service, continue a relationship, respond to a request or meet our legal and regulatory obligations.
We may also refuse, suspend, restrict or close an account or service where required or permitted by law, regulation, our terms and conditions or our financial crime, sanctions, fraud, security or risk controls.
10. Automated checks, profiling and decision-making
We may use automated tools, profiling, risk rules and third-party screening systems to support identity verification, customer due diligence, sanctions and PEP screening, fraud prevention, transaction monitoring, security monitoring, credit or risk assessment and account or transaction controls.
These tools may help us decide whether to approve an account application, request further information, apply limits, delay or refuse a payment, suspend access, investigate activity or terminate a service.
Where we make a significant decision about you based solely on automated processing, we will provide information and safeguards required by applicable law. These may include the ability to obtain human intervention, make representations, challenge the decision or request an explanation, unless an exemption applies. We may not be able to provide services if we cannot complete checks required by law or regulation.
11. Who we share personal data with
We may share personal data where necessary for the purposes described in this Privacy Notice. Recipients may include:
| Recipient category | Examples |
| Regulated and financial service providers | Banks, payment institutions, electronic money institutions, payment schemes, correspondents, processors, safeguarding account providers, account infrastructure providers, FX providers and regulated third-party providers, including Currencycloud where relevant. |
| Customer due diligence and fraud providers | Identity verification providers, credit reference agencies, fraud prevention agencies, sanctions, PEP and adverse-media screening providers, transaction monitoring providers and investigative service providers. |
| Operational and technology providers | IT hosting, cloud, portal, communications, customer support, software, data storage, document management, email, telephony and cyber-security providers. |
| Professional advisers and insurers | Lawyers, auditors, accountants, consultants, insurers, brokers and other professional advisers. |
| Authorities and regulators | The FCA, HMRC, the ICO, law enforcement, courts, payment system operators, public authorities, ombudsman services, tax authorities and other regulators or competent authorities. |
| Group, business and transaction parties | Group companies, prospective buyers, sellers, funders, investors, lenders or transferees where we restructure, sell, transfer or merge all or part of our business or assets. |
| Your representatives and counterparties | Authorised users, administrators, directors, officers, employees, advisers, agents, payees, beneficiaries and other counterparties where necessary to provide services or comply with obligations. |
We do not sell your personal data.
12. International transfers
We may transfer personal data outside the United Kingdom where this is necessary to provide services, use service providers, operate systems, carry out checks or comply with legal and regulatory obligations.
Where we make a restricted transfer, we will use a transfer mechanism permitted under UK data protection law. This may include an adequacy regulation, the International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, binding corporate rules, another approved safeguard, or a lawful derogation where applicable.
You may contact us for further information about the safeguards used for international transfers, subject to confidentiality and security restrictions.
13. Data security
We use appropriate technical and organisational measures designed to protect personal data from accidental or unlawful destruction, loss, alteration, unauthorised disclosure or unauthorised access.
Access to personal data is limited to individuals and service providers who need it for legitimate business, legal, regulatory or operational purposes. Those individuals and providers are subject to confidentiality and security obligations.
We maintain procedures for handling suspected personal data breaches and will notify affected individuals, the ICO or other authorities where required by law.
14. Data retention
We keep personal data only for as long as necessary for the purposes for which it was collected, including to provide services, meet legal, regulatory, accounting, tax and reporting obligations, handle complaints, defend legal claims, prevent fraud and meet record-keeping requirements.
| Record type | Typical retention approach |
| Customer and account records | Normally at least seven years after account closure or the end of the customer relationship, unless a longer period is required or justified. |
| Declined applications | Normally five years from the decision, unless a longer period is required or justified. |
| Complaints, disputes, fraud claims and legal claims | Normally six years after the matter is closed, unless a longer period is required or justified. |
| Marketing records | Until you opt out or we no longer need the record, subject to suppression-list retention to respect opt-out requests. |
| Website cookies and analytics | In accordance with our cookie policy and cookie settings. |
| Recruitment records | In accordance with our recruitment retention schedule, unless a longer period is required or justified. |
Retention periods may be extended where required for legal, regulatory, financial crime, sanctions, fraud, complaint, audit, accounting, tax, investigation, litigation or enforcement purposes. We may also anonymise personal data so that it can no longer identify you and use the anonymised information for legitimate purposes.
15. Marketing communications
We may send you information about Regent FE services, regulatory updates, market updates, events or other information that may be relevant to you. We will comply with the UK GDPR, Data Protection Act 2018 and PECR when sending marketing communications.
Where consent is required, we will ask for consent. Where marketing is permitted on another lawful basis, we will only send marketing where lawful and fair to do so. You can opt out of marketing at any time by using the unsubscribe link in our emails or by contacting us.
Service messages, security alerts, regulatory notices, account communications and transactional communications are not marketing and may still be sent where necessary.
16. Cookies and similar technologies
Our website may use cookies and similar technologies. Some cookies are necessary for the website to work. Other cookies, such as analytics or marketing cookies, will only be used where we have a lawful basis and, where required, your consent.
Further information is available in our Cookie Policy: [insert cookie policy link]. You can manage cookies through our cookie banner, cookie preference centre or browser settings.
17. Your rights
Subject to conditions and exemptions under applicable law, you may have the following rights:
- access your personal data;
- correct incomplete or inaccurate personal data;
- request erasure of personal data;
- restrict processing of personal data;
- object to processing, including direct marketing;
- request portability of personal data;
- withdraw consent where processing is based on consent;
- challenge or request human review of significant automated decisions where applicable; and
- complain to the ICO.
You will not usually have to pay a fee to exercise your rights. We may charge a reasonable fee or refuse to comply where a request is manifestly unfounded, excessive or repetitive, or where another lawful basis for refusal applies.
We may ask for information to confirm your identity and to help us respond to your request. We will respond within the period required by law, usually within one month. Where permitted by law, we may extend the response period or pause the time for response while we wait for information reasonably needed from you.
18. Complaints about personal data
If you have a concern about how we use your personal data, please contact us first using the details in section 2 so that we can try to resolve it.
We will acknowledge data protection complaints within 30 days and respond without undue delay, in accordance with applicable data protection law.
You also have the right to complain to the Information Commissioner’s Office, the UK regulator for data protection.
| ICO contact route | Details |
| Website | www.ico.org.uk |
| Telephone | 0303 123 1113 |
| Post | Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF |
Complaints about Regent FE’s payment services are handled separately under our complaints process and, where eligible, may be referred to the Financial Ombudsman Service. This Privacy Notice deals with data protection complaints only.
19. Children
Our services are not directed at children under 18 and we do not knowingly provide payment services to children. If you believe that we have collected personal data about a child without appropriate authority, please contact us.
20. Changes to this Privacy Notice
We may update this Privacy Notice from time to time to reflect changes in our business, services, systems, legal or regulatory requirements. The latest version will be made available on our website or otherwise provided to you where appropriate.
Material changes will be communicated where required by law or where we consider this appropriate.