PRIVACY NOTICE


1. Important Information and Who We Are 

 

1.1 Purpose of this Privacy Notice 

BRAZA UK Ltd respects your privacy and is committed to protecting your personal data. This Privacy Notice explains, in a transparent manner, how we collect, use, share and protect your personal information when you use our services, visit our Website, or otherwise interact with us. 

This Privacy Notice is governed by the requirements of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. Where applicable to the processing of personal data relating to individuals in Brazil, this Privacy Notice also considers the requirements of the Brazilian General Data Protection Law (Lei Geral de Proteção de Dados – LGPD)

 

1.2 Age Requirement 

Our Website and the financial services provided by BRAZA UK Ltd are intended exclusively for individuals aged 18 or over

 

1.3 Data Controller 

BRAZA UK Ltd acts as the Data Controller for the personal data we process. This means that we are legally responsible for determining the purposes and means of processing your personal data within our organization. 

 

1.4 Data Protection Officer (DPO) 

To support our ongoing compliance obligations and ensure that your privacy rights are properly addressed, we have appointed a Data Protection Officer (DPO)

If you have any questions about this Privacy Notice or wish to exercise your data protection rights, you can contact our DPO using the following official channels: 

  • DPO Name: Filipe Ricetti 

  • Postal Address: 
    BRAZA UK Ltd
    Longcroft House
    2–4 Victoria Avenue
    Spitalfields
    London EC2M 4NS
    United Kingdom 

 

 

2. The Personal Data We Collect About You 

Personal data means any information that allows us to identify you or the beneficiary of your transaction, either directly or indirectly. In order to perform our contractual obligations and provide the services requested, the collection of certain information is necessary. 

We may collect, use, store and transfer different categories of personal data, which we have grouped as follows: 

 

2.1 Personal Identification and Contact Data 

Information required to identify you and/or the beneficiary of your transaction. This includes the collection of personally identifiable information (PII), such as full name, title, residential and/or business address, email address, telephone number, date of birth, gender, images, signatures, and passport or visa details (identity documents). 

 

2.2 Financial and Transactional Data 

Information required to process money transfers and provide our services, including bank account details and payment information relating to you and your transaction beneficiaries. 

 

2.3 Compliance and Financial Crime Prevention Data 

Additional information required by competent authorities or collected as part of our internal compliance procedures, in accordance with applicable legal obligations and global efforts to prevent money laundering, terrorist financing and other criminal activities. 

This may include information regarding your relationship with the transaction beneficiary, the specific purpose of the transfer, and supporting documentation relating to the Source of Funds (SoF)

 

2.4 Technical and Usage Data (Cookies) 

When you use our Website, we automatically collect certain information through cookies and similar technologies. This may include your IP address, browser type and version, time zone settings, operating system, pages visited, and interaction metrics with our platform (such as clicks and scrolling behavior). 

This information is collected to support Website security, ensure proper functionality and improve the user experience. 

 

2.5 Consequences of Failing to Provide Personal Data 

Where we are required to collect personal data by law (for example, under Anti-Money Laundering and Counter-Terrorist Financing regulations) or under the terms of a contract, and you fail or refuse to provide the required information, we may be unable to perform our contractual obligations or process your transaction. 

In such circumstances, we may be required to cancel or suspend the relevant product or service, and we will notify you at the appropriate time where permitted by applicable law. 

 

 

3. How We Use Your Personal Data (Lawful Bases and Data Sharing) 

We will only use your Personal Data within the limits permitted by applicable data protection laws. The processing of your information will be based on the following lawful bases: 

 

3.1 Performance of a Contract 

Where necessary to fulfil our contractual obligations with you, process your financial transactions, respond to your requests, or communicate with you regarding our services. 

For example, when you use our international payment services, your personal data may be shared with payment service providers responsible for processing and settling funds to the beneficiary in the destination country. 

 

3.2 Legal and Regulatory Obligations 

Where necessary to comply with specific legal and regulatory requirements applicable to our industry. 

To provide regulated financial services, we are required by law to perform appropriate levels of customer due diligence, risk assessments and ongoing monitoring. This may require us to disclose your personal data to competent regulatory authorities, law enforcement agencies or other authorized bodies, as well as request additional information from you to fulfil our compliance obligations. 

 

3.3 BRAZA UK Ltd’s Legitimate Interests 

Where applicable, we may process your personal data to improve the content, functionality and security of our Website and to enhance your experience with our services. 

This may include the use of IP addresses and aggregated or anonymized demographic information to analyze Website traffic, understand user behavior and maintain the security of our digital platforms. 

Where we rely on legitimate interests as a lawful basis for processing, we will ensure that our interests are balanced against your rights, freedoms and reasonable expectations, and that your fundamental rights are not overridden. 

 

3.4 Sharing Personal Data with Third Parties 

To operate our services effectively and meet our legal and regulatory obligations, we may share your personal data with the following categories of third parties: 

  • Service Providers and Partners: Compliance verification providers, financial service providers (such as banks and payment institutions), technology providers and credit reference agencies where applicable. 

  • Corporate Transactions: Third parties involved in potential or actual business transactions, including mergers, acquisitions, disposals, restructurings or transfers of business activities, subject to appropriate confidentiality and data protection safeguards. 

  • Legal and Regulatory Authorities: Law enforcement agencies, courts, regulators, governmental bodies or other competent authorities where required by law, regulation, legal process, or where we reasonably believe disclosure is necessary to prevent fraud, identity theft, financial crime or protect the rights, property and security of BRAZA UK Ltd, our customers or other individuals. 

 

 

4. Safeguarding of Funds 

 

Protecting our customers' funds is an absolute priority and a strict regulatory requirement. 

 

4.1 Segregation and Safeguarding of Funds 

All funds received from customers in exchange for electronic money are safeguarded in accordance with the requirements of the Electronic Money Regulations 2011

Customer funds are held separately from BRAZA UK Ltd’s own operational funds through appropriate safeguarding arrangements with authorized credit institutions or other permitted safeguarding methods. 

This means that customer funds are not used for the operational activities of BRAZA UK Ltd and remain protected through the applicable safeguarding framework. 

 

4.2 FSCS Protection Disclaimer (Important Notice) 

It is important that you understand that electronic money accounts are not equivalent to traditional bank deposit accounts. 

Accordingly, funds held with BRAZA UK Ltd are not covered by the Financial Services Compensation Scheme (FSCS)

The protection of your funds is provided exclusively through the safeguarding arrangements described in section 4.1, in accordance with the applicable electronic money regulations. 

 

5. Data Retention Policy (How Long Do We Keep Your Data?) 

 

5.1 General Retention Principle 

Personal Data is retained securely and only for as long as necessary to fulfil the purposes for which it was collected, provide the requested services, and comply with applicable legal, regulatory, accounting and reporting obligations. 

When determining the appropriate retention period, we consider the volume, nature and sensitivity of the data, the potential risk of unauthorized use or disclosure, and applicable legal and regulatory requirements. 

 

5.2 Legal and Regulatory Requirements (AML) 

To comply with our obligations relating to anti-money laundering, regulatory reporting and applicable tax and commercial legislation, BRAZA UK Ltd will retain your Personal Data and transaction records for a minimum period of five (5) years from the date of the relevant transaction or from the date on which our business relationship with you is formally terminated, whichever is later where required by applicable law. 

 

5.3 Customer Service and Relationship Management 

We will retain customer service information and correspondence (such as emails and communications records) for as long as we maintain an ongoing relationship with you. 

When our relationship with you ends and all services have been fully provided, your Personal Data will be securely deleted or anonymized, subject always to any legal, regulatory or compliance obligations requiring continued retention. 

 

 

6. Retention of Communications (Do We Archive Your Messages?) 

 

6.1 Communication Records 

Yes. If you contact us or provide correspondence, including emails, formal letters or other written communications, we will retain these records together with the other information associated with your account. 

 

6.2 Customer Service Communications 

We will also retain customer support records and service-related communications, as well as any other correspondence involving you, BRAZA UK Ltd, our partners and service providers. 

All such records will be retained and managed in accordance with our Data Retention Policy and applicable legal and regulatory requirements. 

 

 

7. Information Security (How We Protect Your Data) 

BRAZA UK Ltd is committed to maintaining the security and confidentiality of your Personal Data. We implement appropriate technical and organizational measures designed to protect your information against loss, misuse, alteration, unauthorized disclosure or unauthorized access. 

 

7.1 Infrastructure and Prevention 

We employ modern and secure technologies and regularly review and update our security controls as new and improved methods become available. 

Our data centers, as well as those operated by our trusted service providers, use advanced physical security measures designed to prevent unauthorized access, intrusion and compromise of facilities. 

 

7.2 Access Controls and Firewalls 

All Personal Data is stored within secure digital environments protected by firewalls and advanced security systems. Administrative access is strictly restricted based on the need-to-know principle and granted only to authorized personnel where required for legitimate business purposes. 

 

7.3 Staff Confidentiality and Awareness 

All BRAZA UK Ltd employees who have access to, or are involved in the processing of, Personal Data are contractually required to maintain strict confidentiality and comply with our established privacy and data protection standards. 

To ensure these standards are maintained and that employees remain aware of their data protection and compliance responsibilities, our staff receive mandatory and regular training. 

 

7.4 Limitation of Security Guarantee 

It is important to note that no information security system is completely secure or impenetrable. Therefore, while we apply industry-recognized security practices and appropriate safeguards to protect your privacy, we cannot guarantee the absolute and infallible security of your Personal Data. 

 

 

8. Your Data Protection Rights (UK GDPR) 

Under applicable data protection laws, including the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, and subject to appropriate verification of your identity, you have the following rights in relation to your Personal Data: 

  • Right to be Informed: The right to receive clear and transparent information about the collection and use of your Personal Data. We fulfil this requirement through this Privacy Notice and our Cookies Policy. 

  • Right of Access: The right to request access to the Personal Data we hold about you, including information about the purposes of processing, the categories of recipients, the applicable retention periods, and the existence of any automated decision-making. 

  • Right to Rectification: The right to request correction of incomplete or inaccurate Personal Data that we hold about you. We may need to verify the accuracy of any new information you provide before making changes. 

  • Right to Erasure: The right to request the deletion of your Personal Data where there is no longer a valid reason for us to continue processing it, including where the data is no longer necessary for the purposes for which it was collected, unless we are required to retain it to comply with legal obligations or for the establishment, exercise or defense of legal claims. 

  • Right to Object: The right to object to the processing of your Personal Data where we rely on our legitimate interests as the lawful basis for processing and you believe that your particular circumstances mean that such processing affects your fundamental rights and freedoms. 

You also have the right to object to the processing of your Personal Data for direct marketing purposes. 

  • Right to Restriction of Processing: The right to request that we restrict the processing of your Personal Data where you wish us to verify its accuracy, where you have objected to our use of your data and we need to determine whether we have overriding legitimate grounds to continue processing it, or in other circumstances provided for under applicable data protection laws. 

  • Right to Data Portability: The right, in certain circumstances and where technically feasible, to request the transfer of your Personal Data to another organization in a structured, commonly used and machine-readable format. 

 

 

9. Your Rights Under the LGPD (For Individuals in Brazil) 

The Brazilian General Data Protection Law (Lei Geral de Proteção de Dados Pessoais – LGPD, Law No. 13,709/2018) establishes the legal framework for the processing of personal data of individuals in Brazil, regardless of where the data controller is located. 

Where the LGPD applies, you have the following specific rights in relation to your Personal Data: 

  • Right to Confirmation and Access: The right to confirm whether your Personal Data is being processed and to access the Personal Data held about you. 

  • Right to Data Portability: The right to request the portability of your Personal Data to another service or product provider, subject to the protection of commercial and industrial secrets. 

  • Right to Rectification and Anonymization: The right to request the correction of inaccurate or incomplete Personal Data, as well as the anonymization, blocking or deletion of unnecessary, excessive or unlawfully processed data. 

  • Right to Deletion and Withdrawal of Consent: The right to request the deletion of Personal Data processed based on your consent, as well as the right to withdraw or revoke your consent at any time. 

  • Right to Information Regarding Data Sharing: The right to receive information about third parties with whom we share your Personal Data and the consequences of refusing to provide consent where consent is required as the lawful basis for processing. 

  • Right to Review Automated Decisions: The right to request a review of decisions made solely on the basis of automated processing that affect your interests. 

 

 

10. Privacy Complaints Procedure 

If you believe that we have failed to comply with our obligations under this Privacy Notice or applicable data protection laws, you have the right to submit a formal complaint. 

 

10.1 Internal Contact and Response Timeframes 

We encourage you to raise your concerns with us first by contacting our Data Protection Officer (DPO) at dpo@braza.uk

We will acknowledge receipt of your complaint within 10 days. Your complaint will be investigated thoroughly, and we will aim to provide a substantive response within one calendar month of receiving your complaint. 

If your complaint is particularly complex or requires additional time for investigation, we will inform you within the initial one-month period, explain the reasons for the delay, and confirm the revised timeframe. Any extension will not exceed a further two months, in accordance with applicable data protection legislation. 

 

10.2 Information Commissioner's Office (ICO) 

If you remain dissatisfied with our response or with the way we have handled your complaint, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the United Kingdom's independent supervisory authority for data protection. 

You can contact the ICO using the following details: 

  • Address: 
    Wycliffe House
    Water Lane
    Wilmslow
    Cheshire SK9 5AF
    United Kingdom 

  • Phone: 
    0303 123 1113
    01625 545 745 

 

 

11. Contact Us 

If you have any questions, concerns, or wish to exercise your rights under this Privacy Notice, please contact our dedicated privacy team: 

  • For the attention of: Data Protection Officer (DPO) – Filipe Ricetti 

  • Postal Address: 
    BRAZA UK Ltd
    Longcroft House
    2–4 Victoria Avenue
    London EC2M 4NS
    United Kingdom 

 

 

12. Updates to this Privacy Notice 

BRAZA UK Ltd reviews its policies and procedures against applicable legal and regulatory requirements at least annually. 

Where there are significant legislative or regulatory changes, we will promptly review and update this Privacy Notice to ensure ongoing compliance and the continued protection of your data protection rights. 

 




BRAZA UK LTD

Braza UK Ltd is authorised and regulated by the Financial Conduct Authority as an Electronic Money Institution under the Electronic Money Regulations 2011 (FRN 900901). Registered in England and Wales under company number 06397296.



© 2023

All rights reserved.


Contact

+44 (0) 203 206 1551


Registered office: Longcroft House, 2-4 Victoria Avenue London, EC2M 4NS United Kingdom. 

Customer funds are safeguarded in segregated accounts in accordance with the Electronic Money Regulations 2011. Electronic money accounts are not covered by the Financial Services Compensation Scheme (FSCS).