Legal

Personal Customer Privacy Notice

Effective from 18 February 2026Version Number: 4.0

Previous version available on request

Translations

Available languages and regional versions

Privacy content is being localised across supported markets. The versions below are shown as placeholders for now and can be connected to dedicated translated notices later.

German / DeutschComing soonFrench / FrançaisComing soonPortuguese / PortuguêsComing soonChinese / 中文Coming soonHebrew / עִברִיתComing soonBahasa IndonesiaComing soonJapanese / 日本語Coming soonTurkish / TürkçeComing soonMalay / MelayuComing soonSpanish / EspañolComing soonThaiComing soon

1. Data controller

In this notice, "we", "our", and "us" refer to the relevant WiseVault company that provides your service. That company acts as the data controller for the personal data processed in connection with the relevant product, account, or customer relationship.

Where different entities provide different services, the applicable entity can be referenced in onboarding materials, contractual documents, or service-specific appendices.

2. Personal data we collect about you

2.1 Information you give us

This can include profile details, personal identifiers, contact information, financial information, identity documents, communications with support, vulnerability-related information, source-of-funds or source-of-wealth details, and guardian or child-related information where a service requires it.

2.2 Information collected from use of services

This can include transaction data, device and browser information, permitted geolocation signals, website and app usage data, behavioural biometrics, and information stored on your device or made available through device permissions such as contacts where you choose to enable them.

2.3 Information from other sources

We may receive information from financial institutions, connected persons, fraud prevention agencies, government or sanctions databases, analytics and advertising providers, and public sources that help us verify identity, assess risk, and provide services safely.

2.4 Information from social networks

If you use social login or interact with WiseVault on social platforms, we may receive profile data made available by that service, information about those interactions, or public social information used for customer support, marketing, or due diligence where lawful.

3. Ways we use your information

WiseVault uses personal data to open and maintain customer relationships, move money safely, support customers, improve products, detect fraud, and comply with financial regulation.

3.1 Legal bases

Contract necessity

We use personal data when it is necessary to open accounts, move money, maintain services, and fulfil the contract we have with you.

Legal obligation

Financial services providers must process certain data to comply with anti-money laundering, fraud prevention, sanctions, tax, accounting, and regulatory rules.

Legitimate interests

We may use personal data to improve products, defend legal claims, secure systems, and operate the service responsibly where those interests are not overridden by your rights.

Consent

In some cases we rely on consent, such as optional marketing, certain cookies, or device permissions. You can withdraw consent where applicable.

Substantial public interest

Some processing, such as anti-fraud measures and certain financial crime controls, may be required in the substantial public interest under applicable law.

3.2 Purposes for using personal data

Eligibility, verification, and KYC checks

Legal obligation, contract necessity, substantial public interest

Provide products and services

Contract necessity

Customer support and service quality

Contract necessity, legitimate interests

Discoverability and account connections

Contract necessity, legitimate interests, consent where required

Account safety and fraud prevention

Legal obligation, legitimate interests, substantial public interest

Regulatory compliance and legal enforcement

Legal obligation, substantial public interest

Marketing and analytics

Legitimate interests, consent where required

Maintaining and improving services

Legitimate interests

Supporting vulnerable customers

Substantial public interest, legal obligation, contract necessity

4. How we share your personal data

01

Other WiseVault group companies

We may share information across the WiseVault group so services can be delivered consistently, safely, and with the right operational support.

02

Banks and financial institutions

Payment networks, correspondent banks, safeguarding banks, and other institutions may receive data needed to process transactions and maintain accounts.

03

Service providers and partners

We use carefully selected vendors for hosting, verification, analytics, support tooling, communications, and operational services under contractual safeguards.

04

Beneficiaries and counterparties

When you send money or use connected services, relevant details may be shared with beneficiaries, merchants, or counterparties so the transaction can be completed.

05

Regulators, law enforcement, and fraud prevention agencies

We may share data where required by law, court order, regulation, or where necessary to prevent fraud, financial crime, or misuse of services.

06

Debt recovery, insolvency, or business transfer related parties

We may share information with advisers, auditors, insolvency practitioners, or acquiring entities in the context of lawful recovery, restructuring, or a sale of business assets.

07

Programme partners and discoverability features

Certain partner products or account-linking features may require limited sharing so connected services and customer discovery features function correctly.

08

With your consent

Where a disclosure is optional and not otherwise necessary, we may ask for your consent before sharing specific information.

5. International data transfers

WiseVault operates across markets and may transfer personal data internationally when services, support, fraud prevention, or infrastructure require it. Where local laws restrict transfers, we use lawful mechanisms such as adequacy decisions, standard contractual clauses, the UK addendum, or other recognised safeguards.

6. Profiling and automated decision making

We may personalise product flows or communications using account context, service usage, and relevant preferences.
Automated checks may be used for eligibility, fraud detection, sanctions screening, suspicious behaviour monitoring, and security controls.
These checks can affect account access, transfer release, verification requirements, or whether a product feature is available.
You can request more information and, where applicable, human review of significant automated decisions.

7. Cookies

WiseVault uses cookies, pixels, web beacons, and similar technologies to support security, remember preferences, measure performance, and improve products and communications.

View Cookie Policy

8. Data retention

We keep personal data only for as long as necessary for the purposes explained in this notice, including legal, regulatory, fraud prevention, accounting, and dispute-handling requirements. Financial institutions often need to retain information after an account is closed, commonly for five to ten years depending on the applicable law. Data is deleted or anonymised when no longer required.

9. How we protect your personal information

Encrypted communications in transit

Encryption at rest where appropriate

Secure infrastructure, patching, and hardening

Monitoring for malicious activity and suspicious behaviour

Responsible disclosure and vulnerability management

Access controls, staff training, and least-privilege practices

Physical, technical, and organisational safeguards

Independent audits and control frameworks where applicable

10. Your rights

Request a copy of your personal data

You can ask for access to the personal information WiseVault holds about you.

How to exercise it: Contact privacy@wise.com or use in-product support where available.

Request correction

You can ask us to correct inaccurate or incomplete personal information.

How to exercise it: Update your profile directly where possible or contact support.

Request deletion

You can ask us to erase certain information, subject to legal and regulatory retention duties.

How to exercise it: Submit a privacy request for deletion review.

Withdraw consent

Where we rely on consent, you can withdraw it at any time without affecting earlier lawful processing.

How to exercise it: Change preferences or contact privacy support.

Stop direct marketing

You can opt out of marketing communications and related profiling used for direct marketing.

How to exercise it: Use unsubscribe links or update communication settings.

Request human review of automated decisions

You can ask for more information and human review where an automated decision significantly affects you.

How to exercise it: Raise the request through privacy or support channels.

Object to processing based on legitimate interests

You can object when we rely on legitimate interests, including some analytics or product improvement uses.

How to exercise it: Explain the concern so we can assess the request.

Ask us to suspend processing

You can request restriction of processing in certain circumstances while a concern is reviewed.

How to exercise it: Submit a privacy request describing the relevant issue.

Request transfer of your data

You can ask for certain data in a portable format where applicable by law.

How to exercise it: Request portability support through privacy@wise.com.

11. Changes to our Privacy Notice

This notice may be revised for legal, operational, product, or best-practice reasons. If changes are significant, we will communicate them through appropriate channels such as the app, website, or direct communications where required by law.

12. Contact

If you have privacy questions, comments, or requests, contact privacy@wise.com. If you are not satisfied with how a concern is handled, you may also have the right to complain to a supervisory authority or relevant data protection authority.

Country specific provisions

These region-specific sections highlight disclosures or rights that can apply in addition to the main notice. Expand the panels below for the most relevant local provisions.

EEA (European Economic Area) - disclosure of your personal dataMore

Where EEA data protection law applies, WiseVault provides the disclosures required by the GDPR, including the categories of recipients that may receive your data, the legal bases relied on, and the safeguards used for restricted transfers.

If you need more information about a specific transfer or recipient category, you can contact privacy@wise.com and request further details where legally permitted.

California residents - your rightsMore

California residents may have rights to know, access, correct, delete, and limit certain uses of personal information under applicable California privacy laws.

WiseVault does not sell personal information in the ordinary meaning of the term. Where California law treats certain ad-tech sharing as sharing for cross-context behavioural advertising, California residents can exercise available opt-out rights through the methods we provide.

India - Data we collect about you and ways we use your informationMore

Where Indian privacy law applies, WiseVault may provide additional notices covering categories of data processed, lawful grounds or legitimate uses, complaint and grievance processes, and retention expectations.

Services or data uses that are specific to India can be highlighted separately where local law requires a distinct notice or consent flow.

Japan - To whom we disclose your personal dataMore

Where Japanese privacy law applies, WiseVault may disclose the categories of jointly used data, the scope of joint users, management responsibility, and cross-border transfer arrangements in accordance with local requirements.

If you need more detail about overseas transfers or recipient categories relevant to Japan, please contact privacy@wise.com.

UK anti-fraud agency specific provisionsMore

WiseVault may share information with fraud prevention agencies and use the information they provide to help verify identities, prevent financial crime, recover debt, and manage fraud risk.

If false or inaccurate information is provided and fraud is identified, details may be passed to fraud prevention agencies and law enforcement in line with UK legal requirements.

Provisions specific to Wise Pago Mexico, S.A. de C.V., Institucion de Fondos de Pago ElectronicoMore

Where services are provided by the relevant Mexican entity, WiseVault may provide local transparency wording that explains processing purposes, transfer categories, rights-exercise methods, and local regulator-facing notices required under Mexican law.

Any Mexico-specific rights or disclosures can be expanded in a dedicated local annex as product availability evolves.