Privacy Policy
1. Introduction and Scope
1.1 This Privacy Policy (the “Policy”) describes how Switch Pay Limited (“Switch Pay”, “we”, “us” or “our”) collects, uses, shares, transfers, retains and otherwise processes personal data in connection with the Fuze Business platform, operated at www.business.fuze.finance (and any successor domain or associated application, the “Platform”) and the services made available through it (the “Services”).
1.2 Switch Pay is the principal data controller in respect of personal data processed through the Platform, save where this Policy or Applicable Law provides otherwise.
1.3 This Policy forms an integral part of the Fuze Business End-User Terms and Conditions (the “Terms”). Capitalised terms used but not defined in this Policy have the meanings given to them in the Terms.
1.4 This Policy applies to:
- (a) representatives, employees, officers, directors, and other Authorised Persons of the End-User;
- (b) ultimate beneficial owners and controlling persons of the End-User;
- (c) Beneficiaries and their representatives;
- (d) visitors to the Platform and to any website operated in connection with the Platform; and
- (e) any other individual whose personal data is processed by Switch Pay in connection with the Platform.
1.5 Switch Pay may amend this Policy from time to time in accordance with Clause 17 of the Terms.
2. Definitions
2.1 In this Policy:
- “Applicable Data Protection Law” means, as applicable to the processing in question: (a) the Personal Information Protection and Electronic Documents Act (Canada) (“PIPEDA”); (b) the Personal Information Protection Act (British Columbia) (“BC PIPA”); (c) Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data of the United Arab Emirates (the “UAE PDPL”); (d) the UK General Data Protection Regulation and the Data Protection Act 2018 (the “UK GDPR”); (e) Regulation (EU) 2016/679 (the “EU GDPR”); and (f) any other data protection, privacy or equivalent law applicable to Switch Pay or to the personal data being processed.
- “Group Entities” means the affiliated entities within the Fuze Finance group of companies, comprising, from time to time, the parent holding company, the UAE virtual assets service provider, the UAE payment services entity, the Canadian money services business, the Panama-incorporated crypto services entity, the group services and technology entity, and any other entity within the Fuze Finance group.
- “Personal Data” means any information relating to an identified or identifiable natural person.
- “Processing” (and its grammatical variants) means any operation or set of operations performed on Personal Data, whether by automated means or not, including collection, recording, organisation, structuring, storage, adaptation, retrieval, consultation, use, disclosure, dissemination, restriction, erasure or destruction.
- “Regulatory Authority” has the meaning given in the Terms.
3. Who We Are and How to Contact Us
3.1 Switch Pay Limited is a corporation duly organised and existing under the laws of the Business Corporations Act, SBC 2002, with incorporation number BC1481523, having its registered address at Unit 319, 2300-2850 Shaughnessy Street, Port Coquitlam, British Columbia, Canada, V3C 6K5.
3.2 Switch Pay is registered with the Financial Transactions and Reports Analysis Centre of Canada (FINTRAC) as a Money Services Business under registration number C100000220.
3.3 All privacy-related enquiries, requests and complaints should be directed to Switch Pay’s data protection mailbox at dpo@fuze.finance.
4. Personal Data We Collect
4.1 Switch Pay processes different categories of Personal Data depending on the individual’s relationship with the Platform. The categories set out below are indicative and not exhaustive.
4.2 Authorised Persons of the End-User (directors, officers, employees, and other representatives designated to act on behalf of the End-User on the Platform). We may collect:
- (a) identification data: full name, date of birth, nationality, country of residence, government-issued identification (passport, national identity card, driver’s licence), and photographic identification (including a live “selfie” for biometric identity verification);
- (b) contact data: business email address, business telephone number, business address;
- (c) role and authority data: position within the End-User, role assigned on the Platform (Admin, Maker, Checker, or otherwise), scope of authority, and evidence of authorisation;
- (d) authentication data: username, password (in encrypted form), multi-factor authentication factors, security questions and answers;
- (e) usage and technical data: IP address, device identifiers, browser type and version, operating system, log-in timestamps, geolocation data (approximate), Platform activity logs, and cookie identifiers; and
- (f) communications data: content and metadata of communications submitted through the Platform’s ticketing system, support channels, and email correspondence with Switch Pay.
4.3 Ultimate beneficial owners, directors, shareholders and controlling persons of the End-User. We may collect:
- (a) identification data: full name, date of birth, nationality, country of residence, government-issued identification, and ownership percentage or nature of control;
- (b) status data: politically exposed person (PEP) status, sanctions status, adverse media status; and
- (c) source of wealth and source of funds data: as required for know-your-business (“KYB”) and enhanced due diligence purposes.
4.4 Beneficiaries and their representatives. In respect of each Beneficiary designated in an Instruction, we may collect:
- (a) identification data: full name (of the Beneficiary and its representatives, if a legal entity), date of birth, address, and (where applicable) nationality and identification document details;
- (b) account and wallet data: bank account details, virtual asset wallet addresses, memo tags, destination tags, IBAN and equivalent identifiers, and payment references;
- (c) purpose and relationship data: purpose of Transaction, nature of the underlying commercial relationship between the End-User and the Beneficiary; and
- (d) information required under the Financial Action Task Force Travel Rule and equivalent Applicable Law.
4.5 Website visitors. We may collect:
- (a) technical data: IP address, device identifiers, browser type and version, operating system, referring and exit pages, date and time stamps, and clickstream data; and
- (b) cookie and similar-technology data, as described in the Cookie Policy.
4.6 Other individuals. We may process Personal Data of other individuals whose data is provided to Switch Pay in connection with the Platform, including individuals identified in supporting documents (corporate registers, licences, source of funds documentation, powers of attorney).
4.7 Sensitive Personal Data. Certain categories of Personal Data (including data revealing PEP status, criminal convictions and offences, and biometric data used for identity verification) may attract heightened protection under Applicable Data Protection Law. Switch Pay processes such data only where necessary for a lawful purpose set out in this Policy and in accordance with Applicable Data Protection Law.
5. How We Collect Personal Data
5.1 Switch Pay collects Personal Data:
- (a) directly from the individual, when Personal Data is submitted through the Platform, provided in the course of onboarding, or communicated in the course of interactions with Switch Pay;
- (b) from the End-User, in respect of Authorised Persons, ultimate beneficial owners, directors, Beneficiaries and other individuals whose Personal Data the End-User provides to Switch Pay in the course of onboarding or Transactions;
- (c) automatically, through the operation of the Platform, cookies, log files, and similar technologies (as described in the Cookie Policy);
- (d) from third parties and public sources, including identity verification providers, KYB and know-your-customer providers, sanctions and adverse media screening providers, blockchain analytics providers, credit reference and business information providers, corporate registries, government registries, public court and enforcement records, and publicly available online sources; and
- (e) from Third-Party Providers, including correspondent banks, payout partners, blockchain networks, virtual asset service providers, and other counterparties involved in the execution of Transactions.
5.2 Where the End-User provides Personal Data of any Authorised Person, ultimate beneficial owner, Beneficiary or other individual to Switch Pay, the End-User represents and warrants that: (a) it has provided all notices required by Applicable Data Protection Law to such individuals; and (b) it has obtained all consents and authorisations required to enable Switch Pay to Process such data in accordance with this Policy.
6. Purposes and Legal Bases for Processing
6.1 Switch Pay Processes Personal Data for the purposes set out in this Clause 6. The legal bases for Processing (which are described here for the assistance of individuals in jurisdictions where a legal basis framework applies) are indicated in respect of each purpose.
6.2 Onboarding, verification and account administration — to onboard the End-User, verify identity, conduct KYB and know-your-customer procedures, establish and maintain accounts, and manage Authorised Persons. Legal bases: consent; performance of a contract; compliance with a legal obligation.
6.3 Execution of Transactions and provision of Services — to receive, process, execute, settle, and record Instructions and Transactions, including FX conversion, on-ramp, off-ramp, crypto payment, and fiat funds transfer activities. Legal bases: performance of a contract; compliance with a legal obligation.
6.4 Anti-financial crime compliance — to conduct sanctions screening, transaction monitoring, adverse media screening, PEP screening, ultimate beneficial ownership verification, Travel Rule compliance, suspicious transaction and attempted transaction reporting, and fraud prevention. Legal bases: compliance with a legal obligation; legitimate interests (where recognised); public interest (where recognised).
6.5 Regulatory reporting and co-operation — to comply with, and to respond to requests from, FINTRAC and any other Regulatory Authority in any relevant jurisdiction. Legal basis: compliance with a legal obligation.
6.6 Security, integrity and fraud prevention — to protect the security and integrity of the Platform, prevent, detect and investigate unauthorised access, fraud, abuse and other unlawful activity, and to enforce this Policy and the Terms. Legal bases: legitimate interests; compliance with a legal obligation.
6.7 Communications and customer support — to communicate with individuals about the Platform, the Services, Transactions, complaints, and support requests. Legal bases: performance of a contract; legitimate interests.
6.8 Product improvement and analytics — to analyse, improve, personalise and develop the Platform and the Services, on an aggregated or de-identified basis to the extent practicable. Legal basis: legitimate interests.
6.9 Marketing communications — to send product updates, service announcements, industry insights and (where consent is provided) direct marketing communications. Legal bases: consent; legitimate interests (for existing customer product updates, where recognised).
6.10 Corporate transactions — to enable a due diligence, financing, acquisition, disposal, merger, restructuring, insolvency, or other corporate transaction involving Switch Pay. Legal basis: legitimate interests.
6.11 Legal claims and enforcement — to establish, exercise and defend legal claims, to enforce this Policy and the Terms, and to protect the rights, property and safety of Switch Pay, its personnel, its counterparties and third parties. Legal bases: legitimate interests; compliance with a legal obligation.
6.12 Retention and record-keeping — to retain Personal Data and Transaction records for the periods required by Applicable Law. Legal basis: compliance with a legal obligation.
7. Automated Decision-Making
7.1 Switch Pay uses automated systems and, in some cases, wholly automated decision-making (with or without human review) in relation to:
- (a) KYB, know-your-customer and identity verification (including biometric verification and document authentication);
- (b) sanctions and PEP screening;
- (c) transaction monitoring and fraud detection;
- (d) blockchain analytics and wallet risk scoring; and
- (e) risk-based decisions in relation to onboarding, Transaction execution, and continued access to the Services.
7.2 Automated decisions may result in Switch Pay refusing to onboard an End-User, refusing, delaying, holding, freezing or reversing a Transaction, imposing additional verification requirements, restricting access, or terminating the Terms.
7.3 Where an individual believes that an automated decision has been made in error or that the outcome of the decision is unfair, the individual may request human review by writing to dpo@fuze.finance. Switch Pay will consider each such request, but retains the discretion (in accordance with Applicable Law) to decline to disclose the reasons for a decision or the underlying screening data where disclosure would compromise Switch Pay’s anti-financial crime obligations, tipping-off restrictions, or the security and integrity of the Platform.
8. Who We Share Personal Data With
8.1 Switch Pay may share Personal Data with the following categories of recipient:
- (a) Group Entities — for shared onboarding, compliance, operational, treasury, technology, group-management and reporting functions across the Fuze Finance group, in each case subject to intra-group data sharing arrangements and Applicable Data Protection Law;
- (b) Identity verification, KYB and screening providers — for identity verification, biometric verification, document authentication, sanctions and adverse media screening, PEP screening, and ultimate beneficial ownership verification;
- (c) Blockchain analytics and on-chain intelligence providers — for wallet risk scoring, transaction attribution, sanctions screening on the blockchain, and Travel Rule compliance;
- (d) Correspondent banks, payment institutions, payout partners and card networks — for the execution and settlement of fiat Transactions;
- (e) Virtual asset service providers, exchanges, liquidity providers, custodians and wallet infrastructure providers — for the execution and settlement of Transactions involving Virtual Assets;
- (f) Cloud, hosting, security, and technology service providers — for the operation, hosting and security of the Platform;
- (g) Professional advisers — including legal, tax, accounting, audit, and insurance advisers, in each case under professional or contractual obligations of confidentiality;
- (h) Regulatory Authorities, law enforcement agencies, courts, tribunals and government agencies — where required or permitted by Applicable Law, or where Switch Pay considers disclosure necessary or appropriate for the purposes described in this Policy;
- (i) Counterparties to a corporate transaction — including prospective and actual purchasers, investors, financiers, and their advisers, in connection with a due diligence, financing, acquisition, disposal, merger, restructuring or insolvency process involving Switch Pay; and
- (j) Any other person with the individual’s consent, or as permitted by Applicable Data Protection Law.
8.2 Switch Pay does not sell Personal Data to any third party.
8.3 Third-party recipients that Process Personal Data on Switch Pay’s behalf are engaged under written contractual arrangements requiring them to Process Personal Data only in accordance with Switch Pay’s instructions and to implement appropriate technical and organisational measures.
9. Cross-Border Transfers
9.1 Switch Pay’s business is international in nature. Personal Data may be transferred to, and Processed in, jurisdictions outside the individual’s country of residence, including in particular:
- (a) Canada;
- (b) the United Arab Emirates (including transfers to Group Entities located in the UAE for shared operational and compliance functions);
- (c) the Republic of Panama;
- (d) other jurisdictions in which Group Entities are located from time to time; and
- (e) jurisdictions in which Third-Party Providers, correspondent banks, payout partners, and Regulatory Authorities are located.
9.2 The data protection laws of some of these jurisdictions may differ from, and may provide a lower level of protection than, the data protection laws of the individual’s country of residence.
9.3 Where Personal Data is transferred outside Canada, Switch Pay relies on the following mechanisms (as applicable):
- (a) the individual’s consent, informed by the disclosures in this Policy;
- (b) the necessity of the transfer for the performance of a contract between Switch Pay and the individual (or between Switch Pay and the End-User, where the individual is an Authorised Person or Beneficiary);
- (c) the necessity of the transfer for compliance with a legal obligation to which Switch Pay is subject; and
- (d) contractual safeguards imposed on the recipient (including, where the recipient is a Group Entity or a service provider, intra-group or contractual data protection provisions).
9.4 UAE PDPL transfers. In respect of transfers to the United Arab Emirates, Switch Pay relies on the mechanisms provided under Articles 22 and 23 of the UAE PDPL, including transfers under contractual safeguards binding the recipient to a comparable level of data protection.
9.5 EU and UK transfers. In respect of transfers from the European Economic Area or the United Kingdom to jurisdictions not the subject of an adequacy decision, Switch Pay relies on the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Agreement (or Addendum), as applicable, supplemented by any additional safeguards required by the exporting jurisdiction’s supervisory authority.
9.6 Copies of the relevant contractual safeguards may be requested by writing to dpo@fuze.finance, subject to redaction of commercially sensitive information.
10. Retention
10.1 Switch Pay retains Personal Data for as long as necessary for the purposes for which it was collected and to comply with Switch Pay’s obligations under Applicable Law.
10.2 The following minimum retention periods apply:
- (a) Transaction records, KYB records, source of funds records, screening records, and related Personal Data — a minimum of five (5) years from the date of the Transaction or the termination of the business relationship, as required by the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (Canada) and by equivalent Applicable Law (including, without limitation, the CBUAE AML/CFT Guidelines and the Federal Decree-Law No. 20 of 2018 on Anti-Money Laundering of the United Arab Emirates);
- (b) Records relating to closed or deactivated accounts — up to seven (7) years following closure, for the purposes of establishing, exercising or defending legal claims, resolving disputes, and enforcing this Policy and the Terms; and
- (c) Records subject to a longer statutory retention period, a legal hold, or a Regulatory Authority direction — the applicable period.
10.3 Following the expiry of the applicable retention period, Switch Pay will delete, destroy or irreversibly anonymise the Personal Data.
11. Security
11.1 Switch Pay implements appropriate technical and organisational measures to protect Personal Data against unauthorised or unlawful Processing and against accidental loss, destruction, damage, alteration or disclosure.
11.2 These measures include encryption in transit and at rest (as appropriate to the risk), access controls and role-based permissioning, network and endpoint security controls, monitoring and logging, personnel training, vendor security assessments, and incident response procedures.
11.3 No security measure can guarantee absolute security. The End-User and each individual is responsible for keeping Credentials secure and for notifying Switch Pay of any suspected compromise, in accordance with the Terms.
12. Your Rights
12.1 Subject to Applicable Data Protection Law and any conditions and exemptions available under it, individuals may have the following rights in relation to their Personal Data:
- (a) the right to be informed of the Processing of their Personal Data;
- (b) the right to access their Personal Data and to obtain a copy;
- (c) the right to correct inaccurate or incomplete Personal Data;
- (d) the right to request deletion of Personal Data;
- (e) the right to restrict or object to certain Processing;
- (f) the right to data portability;
- (g) the right to withdraw consent (where Processing is based on consent), without affecting the lawfulness of prior Processing;
- (h) the right to request human review of an automated decision, as described in Clause 7.3;
- (i) the right to lodge a complaint with a supervisory authority (as described in Clause 18); and
- (j) any additional rights available under Applicable Data Protection Law in the individual’s jurisdiction.
12.2 Requests to exercise these rights should be made to dpo@fuze.finance. Switch Pay will respond within the timeframe required by Applicable Data Protection Law.
12.3 Switch Pay may refuse or restrict a request where an exemption applies under Applicable Data Protection Law, including where compliance with the request would: (a) compromise Switch Pay’s obligations under anti-financial crime or sanctions law (including tipping-off restrictions); (b) compromise the security or integrity of the Platform; (c) breach an obligation of confidentiality owed to a third party; (d) prejudice legal claims, investigations, or the detection of fraud; or (e) contravene Applicable Law.
12.4 Switch Pay may require identity verification before responding to a request. Where a request relates to Personal Data of an individual other than the requester, Switch Pay may require evidence of the requester’s authority to act on behalf of that individual.
13. Marketing Communications
13.1 Switch Pay may send Platform updates, service announcements, transactional communications, and (where consent is provided or as otherwise permitted by Applicable Data Protection Law) direct marketing communications about the Services and other products of the Fuze Finance group.
13.2 Individuals may withdraw consent to direct marketing communications at any time by using the unsubscribe link in the communication or by writing to dpo@fuze.finance. Transactional and service communications (such as security notices, Transaction confirmations, and compliance-related notifications) cannot be opted out of while the End-User’s account remains active.
14. Cookies and Similar Technologies
14.1 Switch Pay uses cookies, pixels, tags, local storage, and similar technologies on the Platform. The categories of cookies used, the purposes for which they are used, and the controls available to individuals are set out in the Cookie Policy, which is incorporated into this Policy by reference.
15. Blockchain and On-Chain Data
15.1 Individuals should be aware that transactions on public blockchains are not anonymous and are recorded on a public, immutable ledger. Any person with access to the blockchain can view the transaction history, balances, and metadata associated with any given wallet address.
15.2 Personal Data disclosed by Switch Pay, an End-User, a Beneficiary, or any other party in connection with an on-chain transaction (including through Travel Rule messaging) may be correlated with on-chain data by third parties, including regulatory bodies, blockchain analytics providers, law enforcement agencies and any other party with the necessary tools.
15.3 Switch Pay uses blockchain analytics and on-chain intelligence tools to assess wallet risk, screen for sanctions and financial crime indicators, and comply with Applicable Law. On-chain data may be Processed, combined with off-chain Personal Data, and retained in accordance with this Policy.
15.4 Transactions on public blockchains are irreversible. Switch Pay cannot delete, alter, or amend on-chain records.
16. Children
16.1 The Platform is a business-to-business service and is not directed at, and must not be used by, natural persons under the age of eighteen (18). Switch Pay does not knowingly collect Personal Data of children. Where Switch Pay becomes aware that Personal Data of a child has been collected, it will delete such data promptly.
17. Breach Notification
17.1 Where a breach of security involving Personal Data occurs and Switch Pay determines that the breach creates a real risk of significant harm to affected individuals (or where notification is otherwise required by Applicable Data Protection Law), Switch Pay will:
- (a) notify the affected individuals in accordance with, and within the timeframes required by, Applicable Data Protection Law;
- (b) notify the Office of the Privacy Commissioner of Canada, and any other Regulatory Authority to which notification is required, in accordance with Applicable Data Protection Law; and
- (c) maintain records of the breach as required by Applicable Data Protection Law.
18. Complaints
18.1 Complaints about Switch Pay’s handling of Personal Data should be raised, in the first instance, by writing to dpo@fuze.finance. Switch Pay will investigate and respond within the timeframes required by Applicable Data Protection Law.
18.2 Individuals who remain dissatisfied with Switch Pay’s response may lodge a complaint with the applicable supervisory authority in their jurisdiction, including (as applicable):
- (a) the Office of the Privacy Commissioner of Canada (in respect of PIPEDA);
- (b) the Office of the Information and Privacy Commissioner for British Columbia (in respect of BC PIPA);
- (c) the UAE Data Office (in respect of the UAE PDPL);
- (d) the Information Commissioner’s Office in the United Kingdom (in respect of the UK GDPR); and
- (e) the competent supervisory authority in the individual’s Member State of the European Economic Area (in respect of the EU GDPR).
19. Changes to This Policy
19.1 Switch Pay may amend this Policy from time to time in accordance with Clause 17 of the Terms. Amendments will take effect on the date of publication on the Platform (or such later date as specified). The End-User’s and each individual’s continued use of the Platform following an amendment constitutes acceptance of the amended Policy.
19.2 Material amendments will be brought to the End-User’s attention through in-Platform notification, email, or another appropriate means.
20. Contact
20.1 All privacy-related enquiries, requests to exercise rights, complaints, and other communications relating to this Policy should be directed to:
Switch Pay Limited
Attention: Data Protection Mailbox
Unit 319, 2300-2850 Shaughnessy Street
Port Coquitlam, British Columbia, Canada, V3C 6K5
Email: dpo@fuze.finance
