How Long We Keep Your Personal Data
Date: April 2026
We retain personal data only for as long as is necessary for the purpose for which it was collected, and in accordance with our legal obligations.
Account and identity data (KYC/AML)
Minimum 5 years from the end of the business relationship.
Our lawful basis: FTRA 2013 (Uganda); AML Act 2006 as amended (Tanzania); Rwanda AML/CFT framework; UK Money Laundering Regulations 2017
Transaction records
Minimum 5 years from the date of the transaction.
Our lawful basis: AML/CFT legislation across applicable jurisdictions
Financial crime compliance records (SARs, EDD, PEP screening)
Minimum 5 years may be longer where required by regulatory guidance.
Our lawful basis: AML/CFT legislation; regulatory authority guidance
Biometric and identity verification data
Not retained beyond what is necessary for verification purposes. Maximum retention confirmed per KYC provider DPA.
Our lawful basis: DPPA 2019 s.20; PDPA 2022 s.22; UK GDPR Art.9 i.e. special category data minimisation
Device and usage data
12 months from collection, unless required for an ongoing security or fraud investigation.
Our lawful basis: Legitimate interests i.e. operational security
Customer communications and support data
2 years from the date of last contact.
Our lawful basis: Legitimate interests i.e. dispute resolution and service improvement
Marketing preferences and consent records
Duration of the relationship plus 2 years.
Our lawful basis: UK GDPR Art.7(1) i.e. accountability for consent
Legal proceedings / regulatory investigation data
Duration of proceedings plus a reasonable period thereafter, then securely deleted or anonymised.
Our lawful basis: Legal obligation and legitimate interests in defending legal claims
At the end of each applicable retention period, personal data is securely deleted or irreversibly anonymised.