Effective date: 1 June 2025 · Last updated: 1 June 2025
app-myisb is committed to protecting your personal data and your right to privacy. This policy explains what data we collect, why we collect it, and your rights under applicable law including GDPR and CCPA.
1. Data We Collect
Identity & contact data: full name, email address, phone number, date of birth.
Financial data: bank account details, transaction history, payment card information.
KYC/AML data: government-issued ID, proof of address, biometric verification where required by law.
2. How We Use Your Data
To provide, operate, and improve app-myisb banking services and features.
To comply with legal and regulatory obligations, including anti-money-laundering (AML) and Know Your Customer (KYC) requirements.
To detect, prevent, and investigate fraud, security incidents, and unauthorised access.
To send service notifications, security alerts, and (with your consent) marketing communications.
3. Cookies & Tracking
We use essential cookies to keep you securely logged in and analytical cookies to understand how the app is used. You may manage non-essential cookies via your device or browser settings. Disabling essential cookies may affect service functionality.
4. Third-Party Sharing
Payment processors and card scheme operators (e.g., Visa, Mastercard) to execute transactions.
Identity verification and credit-reference agencies as required by law.
Cloud infrastructure providers operating under strict data-processing agreements.
We never sell your personal data to third parties for advertising purposes.
5. Your Rights (GDPR / CCPA)
Access: request a copy of the personal data we hold about you.
Rectification: ask us to correct inaccurate or incomplete data.
Erasure: request deletion of your data where no legal obligation requires retention.
Portability: receive your data in a structured, machine-readable format.
Opt-out (CCPA): California residents may opt out of any sale of personal information — we do not sell personal data.
Lodge a complaint with your supervisory authority at any time.
6. Data Retention
We retain personal and financial data for a minimum of 5 years after account closure to comply with financial-services regulations. Technical and analytical data is retained for up to 24 months. Data is securely deleted or anonymised once the applicable retention period expires.
7. Security
app-myisb employs AES-256 encryption at rest, TLS 1.3 in transit, multi-factor authentication, and regular third-party penetration testing. Access to personal data is restricted to authorised personnel on a strict need-to-know basis. In the event of a data breach, we will notify affected users and relevant authorities within 72 hours as required by GDPR.
8. Children's Privacy
app-myisb services are intended for individuals aged 18 and over. We do not knowingly collect personal data from children under 18. If we become aware that a child's data has been submitted, we will delete it promptly.
9. Changes to This Policy
We may update this Privacy Policy periodically to reflect changes in law or our practices. We will notify you of material changes via in-app notification or email at least 30 days before they take effect. Continued use of the app after the effective date constitutes acceptance of the updated policy.
10. Contact & Data Controller
Data Controller: app-myisb Financial Technologies Ltd.