Privacy Policy
PRIVACY POLICY
Rolink Finance (“the Company”, “we”, “us” or “our”) is committed to safeguarding the privacy, confidentiality and security of personal information processed in connection with the provision of its Bureau de Change, Money Transfer, remittance, foreign currency exchange and related financial services.
This Privacy Policy sets out the basis upon which the Company collects, processes, uses, stores, retains and discloses personal information and should be read subject to all applicable data protection, financial services, anti-money laundering, counter-terrorist financing, counter-proliferation financing, sanctions, exchange control and other applicable laws and regulatory requirements.
1. Information We Collect
In the ordinary course of providing our services and discharging our statutory and regulatory obligations, the Company may collect and process the following categories of personal information:
- Personal Identity Data: Full legal name, date of birth, nationality, citizenship or residency status, identification numbers, photographs, signatures and information contained in government-issued identification documents, including national identity documents, passports, driver's licences and permits.
- Contact Information: Residential and/or business address, telephone number, email address and such other contact particulars as may reasonably be required for identification, verification or communication purposes.
- Financial and Transaction Data: Bank account and payment details, source of funds, source of wealth where applicable, transaction purpose, transaction amounts and currencies, transaction history, sender and beneficiary particulars and any other financial information reasonably required to process, verify, monitor or investigate a transaction.
- Technical and Usage Data: Where services are accessed electronically, the Company may collect IP addresses, browser and device information, security and access logs, cookies and other electronic identifiers necessary for system security, authentication, fraud prevention and administration.
The Company may obtain personal information directly from you or, where lawful and appropriate, from third parties, including financial institutions, payment service providers, public registers, competent authorities, identity verification providers and sanctions, adverse-media and politically exposed person screening databases.
2. How We Use Your Information
The Company shall process personal information only to the extent that such processing is lawful, necessary and proportionate to the provision of its services, the performance of contractual obligations, compliance with statutory or regulatory requirements, the protection of legitimate interests or, where applicable, pursuant to valid consent.
Personal information may be processed:
- To establish and verify identity and undertake Know Your Customer (KYC), Customer Due Diligence (CDD), Enhanced Due Diligence (EDD), beneficial ownership verification, sanctions screening and Politically Exposed Person (PEP) screening.
- To initiate, execute, settle, reconcile, monitor and maintain records of foreign currency exchange, money transfer, remittance and related transactions.
- To identify, assess, prevent, detect, investigate and, where required, report suspected money laundering, terrorist financing, proliferation financing, fraud, sanctions evasion or other unlawful or suspicious conduct.
- To comply with applicable legislation, regulatory directives, exchange control requirements, court orders, statutory reporting obligations and lawful requests or directions issued by competent authorities.
- To manage legal, operational, compliance and financial crime risk, maintain the integrity and security of our services, resolve disputes or complaints and communicate information material to the provision of our services.
Where processing is required by law or for the discharge of a statutory or regulatory obligation, such processing shall not be conditional upon consent and may continue notwithstanding the withdrawal or absence of consent.
3. Data Sharing and Disclosure
The Company does not sell, rent or otherwise commercially dispose of personal information. Personal information shall only be disclosed where such disclosure is necessary for the provision of services permitted or required by law, or reasonably necessary for the discharge of the Company's legal and regulatory obligations.
Accordingly, personal information may be disclosed to:
- Correspondent and settlement banks, payment processors, money transfer operators, financial institutions, agents, counterparties and other entities whose involvement is reasonably necessary for the execution or settlement of a transaction.
- Central banks, Financial Intelligence Units, exchange control authorities, law enforcement agencies, courts, tax authorities, regulators and other competent authorities where disclosure is required or authorised by law.
- Approved third-party service providers, including identity verification, screening, information technology, cybersecurity, hosting, audit, legal, compliance and professional advisers, subject to applicable confidentiality, security and data protection obligations.
Where the nature of a transaction necessitates the transfer or processing of personal information outside the jurisdiction in which it was collected, the Company shall take reasonable measures to ensure that such transfer is undertaken in accordance with applicable law and subject to appropriate safeguards.
4. Data Security
The Company shall implement and maintain appropriate technical, organisational, administrative and physical safeguards having regard to the nature and sensitivity of the personal information processed and the risks associated with such processing.
Such safeguards may include access controls, authentication measures, encryption where appropriate, secure information systems, segregation of access rights, cybersecurity controls, confidentiality obligations, monitoring arrangements, incident-response procedures and periodic review of information-security controls.
Notwithstanding the foregoing, no method of electronic transmission or information storage can be warranted as entirely secure. In the event of an actual or suspected personal data breach, the Company shall take reasonable steps to investigate, contain and remediate the breach and shall make such notifications to affected persons and/or competent authorities as may be required by applicable law.
5. Your Rights
Subject to applicable law and any lawful limitations or exemptions, a data subject may be entitled to request access to personal information held by the Company, require the rectification of inaccurate or incomplete information, object to or seek restriction of certain processing, withdraw consent where consent constitutes the lawful basis for processing, or request the deletion of personal information.
The exercise of such rights shall remain subject to the Company's overriding statutory, regulatory and legitimate record-keeping obligations. In particular, the Company may lawfully retain and continue to process information notwithstanding a request for deletion, restriction or objection where such retention or processing is necessary for compliance with AML/CFT/CPF requirements, sanctions obligations, exchange control requirements, regulatory reporting, legal proceedings, investigations, the establishment or defence of legal claims, or any other obligation imposed by law.
Personal information shall be retained for no longer than is necessary for the purposes for which it was collected, subject to any minimum retention period prescribed by applicable law or a competent regulatory authority. Upon expiry of the applicable retention period, and where no lawful basis for continued retention exists, the information shall be securely destroyed, deleted, anonymised or otherwise disposed of in accordance with the Company's records-management and information security requirements.
Contact Us
Any enquiry, complaint or request relating to this Privacy Policy, the processing of personal information or the exercise of data-subject rights should be directed to Rolink Finance at [support@rolink.com] or through such other official contact channels as the Company may designate from time to time.
The Company reserves the right to amend this Privacy Policy where reasonably necessary to reflect changes in applicable law, regulatory requirements, business operations, technology or processing activities. Any amendment shall take effect upon publication or on such later date as may be specified in the revised Privacy Policy.