Privacy Policy

Last updated: 22 June 2026

1. Introduction

Beya Finance ("BEYA", "we", "us", or "our") provides multi-currency accounts and cross-border payment services built on stablecoin rails. This Privacy Policy ("Policy") explains how we collect, use, store, share, and protect personal data when you:

  • Visit our website (www.beya.finance);
  • Create an account or use the BEYA app and services; or
  • Interact with us as a customer, prospective customer, recipient of a payment, partner, or supplier.

For the purposes of applicable data protection laws — including the UK General Data Protection Regulation (“UK GDPR”), the EU General Data Protection Regulation (“GDPR”), and other privacy laws that apply where you live — BEYA acts as a data controller, meaning we decide how and why your personal data is processed.

BEYA operates globally. Where your personal data is subject to the UK GDPR or EU GDPR, we process it in accordance with those regimes in addition to any local data protection laws that apply to you.

We may update this Policy from time to time. We will notify you of material changes (for example, by email or an in-app notice). Previous versions are available on request.

2. Scope of This Policy

This Policy applies to personal data relating to:

  • Account holders and prospective customers;
  • Recipients, senders, or beneficiaries of payments processed through BEYA;
  • Visitors to our website and users of our app; and
  • Business contacts, partners, and suppliers.

Nothing in this Policy limits any rights available to you under the data protection laws of your country of residence. Our services are intended for individuals aged 18 or over and are not directed at children.

3. Information We Collect

We collect and process the following categories of personal data.

3.1 Information you provide

  • Identity and contact details — name, date of birth, nationality, email, phone number, and residential address;
  • Verification information required for compliance — government-issued ID, proof of address, a selfie or liveness check, and, where relevant, source-of-funds information (as required under applicable KYC, anti-money-laundering, and sanctions laws);
  • Financial and transaction information — account balances, currencies held, transfers sent and received, payees and recipients, card activity, and savings or yield activity;
  • Communications — messages, support requests, and other correspondence with us.

3.2 Information we collect automatically

  • Device and connection data — IP address, device identifiers, browser type, and operating system;
  • Usage and log data — how you navigate and use our website and app, and access records relating to your account;
  • Data collected through cookies and similar technologies (see Section 11).

3.3 Information from third parties

  • Identity verification, sanctions screening, politically-exposed-person (PEP), watchlist, and fraud-prevention providers;
  • Banking, payment, and card-network partners involved in processing or settling your transactions;
  • Blockchain networks, where transaction data is recorded on public or distributed ledgers.

We process data received from third parties only for the purposes described in this Policy.

4. How We Use Personal Data

We use personal data to:

  • Provide, operate, and maintain your account and our services;
  • Verify your identity and onboard you (KYC);
  • Process, reconcile, and settle your transfers, payments, card spending, and savings or yield activity;
  • Comply with our legal and regulatory obligations, including financial-crime prevention;
  • Detect, prevent, and investigate fraud, misuse, and security incidents;
  • Communicate with you about your account, our services, and support requests;
  • Improve and develop our products, systems, and infrastructure;
  • Send you marketing communications where you have consented or where otherwise permitted by law (you can opt out at any time); and
  • Establish, exercise, or defend legal claims.

We use automated tools — such as transaction monitoring, risk scoring, and sanctions screening — to support these purposes. These systems assist our decision-making and are subject to human review and oversight. We do not make decisions based solely on automated processing that produce legal or similarly significant effects on you, except where permitted by applicable law.

6. Data Location and International Transfers

Because we operate globally and settle transactions on stablecoin rails, your personal data may be processed in countries other than the one you live in, including by our staff and service providers in different jurisdictions.

Where personal data originates from the European Economic Area or the United Kingdom and is transferred to a country without an adequacy decision, we put appropriate safeguards in place — such as Standard Contractual Clauses and the UK International Data Transfer Agreement — in accordance with Chapter V of the UK GDPR and EU GDPR. We remain accountable for personal data under our control wherever it is processed.

7. Sharing of Personal Data

We may share personal data with:

  • Banking, payment, and card-network partners (including Visa and Mastercard) involved in processing your transactions;
  • Stablecoin and blockchain infrastructure providers and network participants, where relevant to settlement;
  • Identity-verification, sanctions-screening, and fraud-prevention providers;
  • Professional advisers, including legal, audit, and accounting firms;
  • Regulators, law enforcement, and courts where legally required; and
  • Other companies in the BEYA group and service providers acting under confidentiality and data-protection obligations.

We do not sell your personal data, and we do not share it for third-party marketing purposes.

8. Data Security

We maintain technical and organisational measures designed to protect personal data against unauthorised access, loss, misuse, or alteration. These include access controls and role-based permissions, encryption of data in transit and at rest, monitoring and logging of system activity, and periodic security reviews. Access to personal data is restricted to personnel who need it for legitimate business purposes, and is supported by internal security policies, staff training, and incident-response procedures.

9. Data Retention

We keep personal data only for as long as necessary to provide our services, comply with our legal, regulatory, and accounting obligations, and resolve disputes or enforce our agreements.

Retention periods depend on the type of data and the applicable legal requirements. As a general guide, transaction records and KYC/anti-money-laundering documentation are typically retained for five (5) to seven (7) years after the end of our relationship with you, in line with applicable financial-services laws.

10. Your Rights

Subject to applicable law, you may have the right to:

  • Access the personal data we hold about you;
  • Request correction of inaccurate or incomplete data;
  • Request deletion of your data (subject to our legal and regulatory retention obligations);
  • Restrict or object to certain processing;
  • Withdraw consent where processing is based on consent;
  • Request portability of data you provided to us; and
  • Not be subject to decisions based solely on automated processing that produce legal or similarly significant effects, except as permitted by law.

Please note that some transaction information may be recorded on public or distributed blockchain networks. Because of the immutable nature of blockchain, this information cannot be modified or deleted once recorded. We limit on-chain data to pseudonymous or transactional identifiers wherever possible, and keep identifying information off-chain where it remains subject to deletion obligations.

Depending on where you live, you may also lodge a complaint with your local data protection supervisory authority. We encourage you to contact us first so we can address your concerns directly.

11. Cookies

Our website uses cookies and similar technologies to keep the site working, maintain security, and understand how the site is used. We use strictly necessary cookies (required for the site to function and stay secure) and analytical cookies (used to improve performance and your experience).

Where the law requires it, we ask for your consent before placing non-essential cookies. You can manage or withdraw your preferences at any time through your browser settings or any cookie-preference tool we make available.

12. Children

BEYA is intended for individuals aged 18 or over. We do not knowingly collect personal data from anyone under 18. If we learn that we have collected such data, we will delete it. If you believe a minor has provided us with personal data, please contact us.

13. Changes to This Policy

We may update this Policy from time to time to reflect changes in our services, technology, or legal obligations. When we make material changes, we will notify you by email or through an in-app notice, and we will update the “Last updated” date at the top of this page.

14. Contact Us

If you have questions about this Policy or wish to exercise your data protection rights, please contact us:

Beya Finance

Email: aymenberbache21@gmail.com

Registered office: 501 Folsom St, San Francisco, CA 94105