About this Policy
This Privacy Policy (the “Policy”) explains how AlicoRemit (“we”, “our”, “us”) collects, uses, shares and protects your personal data when you use our services, our website (www.alicoremit.co.uk) or our mobile application, and the lawful bases on which we do so.
It also explains your rights under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 (DPA 2018).
This Policy should be read together with our Cookie Policy and our User Agreement & Transaction Terms. Where we use capitalised terms such as Profile, Services, Account or Transaction, these have the same meaning as in our User Agreement unless we define them differently here.
Who we are
We are Alico (UK) Limited, trading as AlicoRemit, a company registered in England and Wales with company number 4402104, registered office 383a Green Street, London, E13 9AU, United Kingdom.
For the purposes of UK data protection law, Alico (UK) Limited is the data controller of your personal data.
We are authorised and regulated by the Financial Conduct Authority (FCA) (firm reference number 535954) and registered with the Information Commissioner’s Office (ICO) (registration number Z1510612).
You can contact us about this Policy or any privacy matter at:
- Email — privacy@alicoremit.co.uk
- Post — Data Protection Lead, Alico (UK) Limited, 383a Green Street, London, E13 9AU, United Kingdom
What personal data we collect
The personal data we collect depends on how you interact with us. When we say “personal data” we mean any information relating to an identified or identifiable individual. We may collect the following categories:
- Basic identifying information — your full name (including any aliases), residential address, email address, telephone number, date of birth, nationality, gender, occupation, and any customer reference we generate to identify you in our systems.
- Government-issued identification and records — passport, driving licence, national identity card or similar, a photograph or recording of you alongside your identity document, proof of address (e.g. utility bill or bank statement), tax reference numbers, and evidence of source of funds (e.g. a bank statement or payslip).
- Payment and financial information — bank account details, payment-confirmation data, and payment references (see How payments are processed below).
- Transaction information — records of your transfers, the unique transaction reference, recipient details, your relationship to the recipient, purpose of the transfer, transfer amounts and frequency, and payment history.
- Recipient information — the full name, address and contact details of the person you are sending money to, and, depending on the payout method, their bank or mobile-wallet details.
- Special category and criminal-offence data — biometric data used for identity verification (a facial-match check), and information relating to actual or suspected criminal offences generated through our anti-money laundering, sanctions and fraud screening (see Why we process special category and criminal-offence data below).
- Technical and device information — IP address, device identifiers, hardware and software details, operating system, browser type, and, where you enable it, location data.
- Usage information — how you interact with our website, app and communications, including logs and analytics.
- Communications information — records of your correspondence with us, including emails, chat and call recordings (for example, where we record customer-service calls for quality and compliance purposes).
- Marketing and consent information — your marketing and communication preferences and consents.
How we collect your personal data
We collect personal data:
- Directly from you — when you register, create a Profile, make a Transaction, complete identity verification, contact us, or respond to surveys.
- Automatically — through cookies and similar technologies when you use our website or app (see our Cookie Policy).
- From third parties — including our identity-verification provider, payment providers, fraud-prevention agencies, sanctions and politically-exposed-person screening providers, credit reference agencies, and publicly available sources and registers.
How payments are processed
AlicoRemit does not collect or store your full card number or security code. When you pay for a Transaction, payment is processed within the secure environment of our regulated payment providers, which process card payments and open-banking/bank-to-bank payments.
Following a card payment, we receive and retain limited payment-confirmation data — a payment token, the last four digits of your card, the card type and the expiry date — for reconciliation, refunds and fraud-prevention purposes. For open-banking payments, we receive confirmation of payment together with the payer’s name and a payment reference.
How we use your personal data
We use your personal data to:
- Provide our Services — set up and manage your Account, process and settle Transactions, and provide customer support.
- Meet our legal and regulatory obligations — customer due diligence (KYC), anti-money laundering and counter-terrorist-financing checks, sanctions screening, fraud prevention, record-keeping, and reporting to regulators and authorities.
- Protect against financial crime and fraud — monitor, detect, investigate and prevent fraudulent, illegal or prohibited activity, and protect the security of your Account and our systems.
- Manage and improve our business — analytics, service improvement, training, audit and record-keeping.
- Communicate with you — including service messages and, where you have consented, marketing.
Our lawful basis for processing
We only process your personal data where the law allows. The list below sets out the lawful basis on which we rely for each category. Where more than one basis is listed, more than one may apply depending on the circumstances.
- Basic identifying information — Art. 6(1)(c) legal obligation (Money Laundering Regulations 2017); Art. 6(1)(b) performance of our contract with you; Art. 6(1)(f) legitimate interests (preventing fraud, managing and improving our business).
- Government-issued identification and records — Art. 6(1)(c) legal obligation (customer due diligence under MLR 2017); Art. 6(1)(b) performance of our contract with you.
- Payment and financial information — Art. 6(1)(b) performance of our contract with you; Art. 6(1)(c) legal obligation; Art. 6(1)(f) legitimate interests (collecting payment, preventing fraud).
- Transaction information — Art. 6(1)(b) performance of our contract; Art. 6(1)(c) legal obligation (transaction monitoring and record-keeping).
- Recipient information — Art. 6(1)(b) performance of our contract with you; Art. 6(1)(c) legal obligation.
- Special category data (biometric) — Art. 9(2)(g) substantial public interest, with a basis in DPA 2018, Schedule 1, Part 2 (see below); where required, processed on the basis of Art. 9(2)(a) explicit consent.
- Criminal-offence data (AML / sanctions / fraud) — Art. 10 UK GDPR, processed under DPA 2018, Schedule 1, Part 2 conditions (preventing or detecting unlawful acts; regulatory requirements; preventing fraud).
- Technical, device and usage information — Art. 6(1)(f) legitimate interests (security, service operation and improvement).
- Communications information — Art. 6(1)(b) performance of our contract; Art. 6(1)(c) legal obligation; Art. 6(1)(f) legitimate interests (quality and training).
- Marketing and consent information — Art. 6(1)(a) consent (and, for electronic marketing, the Privacy and Electronic Communications Regulations 2003).
Where we rely on legitimate interests, we have carried out a balancing assessment to ensure our interests are not overridden by your interests, rights and freedoms. You may ask us for further information about that assessment.
Why we process special category and criminal-offence data
To meet our obligations to prevent money laundering, terrorist financing and fraud, we process special category data (biometric data used to verify your identity) and criminal-offence data (information arising from sanctions, politically-exposed-person and adverse-media screening, and from suspicious-activity investigations).
Identity verification, including biometric facial-matching, is carried out on our behalf by a specialist identity-verification provider within their secure environment; we receive the result of the check rather than the underlying biometric template. Sanctions, politically-exposed-person, adverse-media and credit-reference screening is carried out using specialist screening and credit-reference providers.
We rely on the substantial public interest basis in Article 9(2)(g) UK GDPR, met by the conditions in Schedule 1, Part 2 of the DPA 2018 — in particular preventing or detecting unlawful acts, complying with regulatory requirements relating to unlawful acts and dishonesty, and preventing fraud. Where a condition requires it, we obtain your explicit consent before processing biometric data.
As required by Schedule 1, Part 4 of the DPA 2018, we maintain an Appropriate Policy Document governing this processing. This is an internal governance document and is available to the ICO on request.
Who we share your personal data with
We share personal data only where necessary, with:
- Service providers and processors acting on our instructions — our identity-verification provider; our card and open-banking payment providers; our screening and credit-reference providers; and our IT, cloud-hosting and customer-communications providers.
- Our payout network and payout partners — we share recipient/beneficiary data with our cross-border payout network and its local payout partners (banks, mobile-wallet providers and cash-payout agents), so that funds can be delivered to your recipient.
- Fraud-prevention, sanctions and screening agencies, and credit reference agencies — used for verification and financial-crime checks.
- Regulators, authorities and law enforcement — including the FCA, HMRC, the National Crime Agency, the courts, the police and the ICO — where we are required or permitted to disclose.
- Professional advisers — including auditors, insurers, lawyers and accountants.
- Acquirers or successors — if we are involved in a merger, acquisition, financing or transfer of our business or assets, we may disclose personal data to the parties involved, subject to appropriate safeguards.
A current list of the specific providers (sub-processors) we use is available on request.
We never sell your personal data.
Automated decisions and profiling
We use automated systems to verify your identity, screen Transactions and detect fraud and financial crime. These processes may automatically reject a Transaction, block a suspected unauthorised login, or restrict or close an Account.
Where a decision producing a legal or similarly significant effect is taken solely by automated means, you have the right to request human review, to express your point of view, and to contest the decision, save where an exemption applies (for example, where disclosure would prejudice the prevention or detection of crime). To request a review, contact us at privacy@alicoremit.co.uk.
Transferring personal data internationally
As a UK business we primarily process your data in the UK. Because remittance involves paying funds to recipients abroad, some of your data — and your recipient’s data — will be transferred to our payout network and payout partners outside the UK. Some of these providers are located in, or have group operations in, countries outside the UK, including the United States, and the local partners that disburse funds are based in the destination countries.
Whenever we transfer personal data outside the UK, we ensure an appropriate safeguard is in place, which may be:
- a transfer to a country covered by UK adequacy regulations; or
- the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses; or
- another lawful safeguard recognised under UK data protection law.
You may request details of the specific safeguard applied to a transfer by contacting us.
How long we retain your data
We retain your personal data only for as long as necessary for the purposes for which it was collected, including to meet our legal, regulatory and accounting obligations.
As a firm regulated for anti-money laundering purposes, we are required by Regulation 40 of the Money Laundering Regulations 2017 to retain customer due-diligence records and transaction records for five (5) years following the end of our business relationship with you or the date of an occasional transaction. We will not retain data beyond this period unless we are required to do so by law or to establish, exercise or defend legal claims.
When determining retention periods we consider the amount, nature and sensitivity of the data, the potential risk of harm from unauthorised use or disclosure, the purposes of processing, and our legal and regulatory obligations.
Your privacy rights
Under UK GDPR you have the right to:
- Access — request a copy of the personal data we hold about you.
- Rectification — ask us to correct inaccurate or incomplete data.
- Erasure — ask us to delete your data, subject to our legal obligation to retain certain records (see How long we retain your data).
- Restriction — ask us to limit how we process your data in certain circumstances.
- Objection — object to processing based on our legitimate interests.
- Portability — request transfer of certain data to you or another provider.
- Withdraw consent — where our processing is based on consent, withdraw it at any time (this does not affect processing already carried out).
To exercise any of these rights, contact us at privacy@alicoremit.co.uk. We will respond within one month. We may need to verify your identity before acting on a request. We do not usually charge a fee, but may charge a reasonable fee, or decline to act, where a request is manifestly unfounded or excessive.
Please note that some rights are qualified — for example, we cannot delete records we are legally required to keep, and we may be unable to stop processing necessary to meet our legal obligations.
Cookies
We use cookies and similar technologies on our website and app. Strictly necessary cookies are used to operate our Services; non-essential cookies (such as analytics and marketing) are used only with your consent, in line with the Privacy and Electronic Communications Regulations 2003 (PECR). Full details of the cookies we use, and how to manage your preferences, are set out in our separate Cookie Policy.
Marketing
Where you have consented, we may send you marketing by email, SMS and app notification — including newsletters, promotional offers, referral schemes and rate alerts — in line with PECR. You can withdraw your consent at any time by using the “unsubscribe” link in any marketing message or by updating your preferences in your Account. If you opt out, we will retain a minimal record (such as your email address) on a suppression list so that we can honour your choice. Service and security messages relating to your Account and Transactions are not marketing and will continue to be sent.
How we protect your data
We use industry-standard technical and organisational measures, including:
- encryption of data in transit and at rest;
- access controls limiting access to a need-to-know basis, with authentication;
- ongoing security monitoring, reviews and audits.
You are responsible for keeping your login credentials confidential. No method of transmission or storage is completely secure, so while we take all reasonable steps to protect your information, we cannot guarantee absolute security.
Links to third-party websites
Our website and app may contain links to third-party sites and services whose privacy practices differ from ours. This Policy does not cover those third parties, and we are not responsible for their practices. We encourage you to read the privacy policy of any site or service you visit.
Children
Our Services are not intended for anyone under 18. We do not knowingly collect personal data from children. If we discover that someone under 18 has registered, we will close the Account.
Language and translations
This Policy is drafted in English. Where we provide translations, the English version prevails in the event of any inconsistency.
Changes to this Policy
We may update this Policy from time to time. We will post the updated version on our website with a new “last updated” date and, where the changes are significant, notify you directly. Please review this Policy periodically.
Contact and complaints
If you have any questions or complaints about this Policy or how we handle your personal data, contact us:
- Email — privacy@alicoremit.co.uk
- Post — Data Protection Lead, Alico (UK) Limited, 383a Green Street, London, E13 9AU, United Kingdom
If you are not satisfied with our response, you have the right to complain to the Information Commissioner’s Office (ICO):
- Website — www.ico.org.uk
- Helpline — 0303 123 1113
Alico (UK) Limited, trading as AlicoRemit, is authorised and regulated by the Financial Conduct Authority (FRN 535954) and registered with the Information Commissioner’s Office (Z1510612).