Privacy Policy
Your data, in plain terms
Last updated 1 July 2026. Written to be read, not to be defensible. Where the law forces a technical phrase, we explain it.
Nordhaven Bank plc is the data controller for the personal information described here. This summary explains what we collect, why, how long we keep it and what you can ask us to do about it.
What we collect
- Identity and contact data — name, date of birth, address, nationality, identity document images and the selfie used for liveness checking.
- Financial data — balances, transactions, counterparties, card authorisations and credit information from licensed reference agencies.
- Technical data — device identifiers, IP addresses, session logs and behavioural signals used solely for fraud prevention.
- Support data — call recordings, chat transcripts and correspondence.
Why we hold it
To operate your account (contract), to meet anti-money-laundering, fraud and reporting obligations (legal obligation), to keep the bank secure (legitimate interests) and, only where you have opted in, to send marketing (consent). We do not sell personal data, and we do not share it with advertisers.
Automated decisions
Credit and fraud decisions may be automated. You always have the right to a human review, and any declined application receives written reasoning that explains what drove the outcome.
How long we keep it
Account and transaction records are retained for six years after your relationship with us ends, as required by financial regulation. Call recordings are kept for twelve months. Marketing preferences are kept until you change them.
Who we share it with
Payment schemes and correspondent banks to execute your instructions, identity and credit reference agencies, regulators and law enforcement where legally required, and vetted processors under contract. Transfers outside the UK or EEA rely on approved safeguards.
Your rights
- Access a copy of the data we hold, free, within one month.
- Correct anything inaccurate.
- Erase data we no longer have a legal reason to keep.
- Object to processing based on legitimate interests.
- Port your data to another provider in a machine-readable format.
- Withdraw marketing consent at any time, in one tap.
Cookies
We use strictly necessary cookies for sign-in and security. Analytics are aggregated and first-party, with no third-party advertising trackers on any Nordhaven page.
Contacting the DPO
Email dpo@nordhavenbank.example or write to the Data Protection Officer at 12 Cheapside House, London EC2V 6AA. You may also complain to the Information Commissioner's Office, though we would rather resolve it with you first.

