Privacy Policy
FinMechanica Corp. ("FinMechanica", "we", "us" or "our") respects your privacy and is committed to handling personal information responsibly, transparently and securely.
This Privacy Policy explains how we collect, use, disclose, retain and protect personal information when you visit https://fin-mechanica.com, apply for or use our products or services, communicate with us, or otherwise interact with us (collectively, the "Services").
This Policy does not apply to third-party websites, applications or services that have their own privacy notices. If we process personal information solely on behalf of a business customer, that customer is responsible for its processing instructions and privacy notice; requests concerning that information should generally be directed to that customer.
1. Who is responsible for your personal information
The organization responsible for the processing described in this Policy is:
Office 507, 5940 Macleod Trail SW, Suite 500
Calgary, Alberta, Canada T2H 2G4
Email: info@fin-mechanica.com
Website: https://fin-mechanica.com
2. Personal information we collect
"Personal information" means information about an identifiable individual, subject to the definitions and exclusions under applicable law. We collect only information reasonably required for identified purposes. Depending on your relationship with us and the Services you use, this may include:
- Identity information: name, date of birth, nationality, occupation, signature, government-issued identification details and copies, photograph, and identity-verification results.
- Contact information: residential or business address, email address and telephone number.
- Account and profile information: credentials, preferences, customer or reference numbers and account settings.
- Business and compliance information: employer, position, ownership and control information, source of funds or wealth, tax residency and identification numbers, expected activity, transaction purpose, sanctions and politically exposed person screening results, and information needed for customer due diligence, fraud prevention and regulatory compliance.
- Financial and transaction information: bank or payment account details, payment instrument information, beneficiary and counterparty details, transaction amount, currency, date, location, identifiers, instructions and history. Full payment-card data may be collected directly by an authorized payment provider rather than by us.
- Communications and support information: correspondence, enquiries, complaints, support records and, where notified or permitted by law, recordings of calls.
- Technical and usage information: IP address, device and browser type, operating system, language, time zone, identifiers, log data, pages viewed, referring and exit pages, timestamps, approximate location derived from IP address, and interactions with the Website or Services.
- Marketing and cookie information: communication preferences, consent records and information generated through cookies or similar technologies.
- Other information: information you choose to provide or that we are required or permitted by law to collect.
We do not ask you to provide a social insurance number unless it is reasonably required and permitted by law. Please do not send sensitive information unless we request it through an approved channel.
3. How we collect personal information
We may collect personal information:
- directly from you, including through applications, forms, transactions, correspondence and support interactions;
- automatically from your device when you use our Website or Services;
- from your employer, account administrator, authorized representative, beneficiary, counterparty or another person involved in a transaction;
- from banks, payment providers, financial institutions, payment networks and other participants involved in providing the Services;
- from identity-verification, fraud-prevention, sanctions-screening, credit-reference or compliance service providers, where permitted by law;
- from public records, government or regulatory sources, corporate registries and publicly available sources; and
- from business partners, referral sources and service providers.
If you give us another person's personal information, you must be authorized to do so and, where required, inform that person about this Policy.
4. Why we use personal information
We may use personal information to:
- assess applications, establish and administer relationships, authenticate users and provide, support and improve the Services;
- process and reconcile transactions and communicate with financial institutions, counterparties and service providers;
- verify identity and eligibility, conduct customer due diligence and enhanced due diligence, and understand ownership, control, source of funds and expected activity;
- detect, prevent and investigate fraud, money laundering, terrorist financing, sanctions evasion, cybersecurity incidents, misuse and other unlawful or prohibited activity;
- meet legal, regulatory, record-keeping, reporting, audit and risk-management obligations, including obligations applicable to a Canadian money services business;
- respond to enquiries, complaints, disputes, legal claims and requests to exercise privacy rights;
- maintain, monitor, secure, troubleshoot, analyze and develop our Website, systems and Services;
- communicate operational notices, service changes and security alerts;
- send marketing communications where permitted by law and manage your communication preferences;
- conduct internal reporting, business planning, audits, corporate transactions and professional-adviser reviews; and
- create aggregated or de-identified information that does not identify an individual, and use it for lawful business purposes.
We will not use personal information for a materially different purpose without providing notice and obtaining consent where required.
5. Authority and legal bases for processing
We collect, use and disclose personal information with valid consent or as otherwise permitted or required by applicable law. The form of consent may vary according to the sensitivity of the information and the reasonable expectations of the individual. You may withdraw consent, subject to legal or contractual restrictions and reasonable notice.
Where another legal framework requires us to identify a legal basis, including where the UK or European Economic Area data-protection laws apply, we rely as appropriate on:
- compliance with a legal obligation;
- performance of a contract or steps requested before entering into a contract;
- our legitimate interests or those of a third party, where those interests are not overridden by your rights and interests, including security, fraud prevention, service administration and business improvement;
- consent, including for certain marketing or optional cookies; and
- establishment, exercise or defence of legal claims or another basis permitted by law.
FinMechanica's legal and regulatory obligations may prevent us from providing certain Services or deleting certain information when consent is withdrawn.
6. Identity verification and biometric information
An identity-verification provider may ask you to take a photograph, video or liveness check and may compare it with your identification document. Depending on the technology and applicable law, this process may involve biometric information.
Before biometric information is collected, we or the provider will give any additional notice and obtain express consent where required. We limit its use to identity verification, fraud prevention, security and legal compliance, and require appropriate contractual and security safeguards. Where possible, FinMechanica receives a verification result rather than the underlying biometric template. Retention depends on the verification method, provider arrangements and legal requirements.
7. When we disclose personal information
We may disclose personal information, only as reasonably necessary, to:
- affiliates that support the purposes described in this Policy;
- banks, payment service providers, payment networks, financial institutions, beneficiaries, counterparties and other participants needed to process or investigate a transaction;
- identity-verification, sanctions-screening, fraud-prevention, cybersecurity, cloud-hosting, communications, analytics, customer-support and other service providers;
- insurers, auditors, lawyers, accountants and other professional advisers;
- regulators, courts, law-enforcement bodies, tax authorities and other public authorities where disclosure is required or permitted by law;
- a purchaser, investor, lender or adviser in connection with a proposed or completed financing, merger, acquisition, reorganization, insolvency or sale of all or part of our business, subject to appropriate confidentiality and lawful-use restrictions; and
- another person where you direct us or provide valid consent.
Service providers may process personal information only for the services they provide to us or as otherwise permitted by law and are required to protect it appropriately. We do not sell personal information for money. If applicable law gives a broader meaning to "sale" or "sharing", we will provide any legally required notice and choice.
8. Processing for business customers
Where FinMechanica processes personal information under the instructions of a business customer, that customer determines why and how the information is processed, and FinMechanica acts as its service provider or processor. We rely on the customer to have the required authority to provide the information to us. Individuals should review that customer's privacy notice and normally submit requests directly to it. We will assist the customer as required by contract and applicable law.
9. International and interprovincial processing
FinMechanica is based in Alberta, Canada. We and our service providers may process personal information in other Canadian provinces or in countries outside Canada. As a result, information may be subject to the laws of those jurisdictions and may be accessible to courts, law-enforcement or national-security authorities in accordance with local law.
We assess service providers and use contractual, organizational and technical measures appropriate to the sensitivity of the information. Where required for transfers from the European Economic Area, United Kingdom or another jurisdiction with transfer restrictions, we use a recognized transfer mechanism, such as an adequacy decision, approved standard contractual clauses or another lawful safeguard. You may contact us for further information about applicable safeguards.
10. Retention and deletion
We retain personal information only for as long as reasonably necessary for the purposes described in this Policy and to meet legal, regulatory, accounting, reporting, dispute-resolution and enforcement requirements.
Retention periods depend on the nature and sensitivity of the information, the Services involved, the risk of harm from unauthorized use or disclosure, and applicable legal requirements. Records subject to Canadian anti-money laundering and anti-terrorist financing requirements are generally retained for at least five years from the applicable event or record-creation date, although a longer period may apply where another law, legal hold, investigation or dispute requires it.
When information is no longer required, we securely delete, destroy or anonymize it in accordance with our retention procedures and applicable law. Residual copies may remain temporarily in protected backups until they are overwritten or deleted in the ordinary cycle.
11. Safeguards and security incidents
We use administrative, technical and physical safeguards appropriate to the sensitivity, amount, format and storage of personal information. These measures may include access controls, authentication, encryption in transit and where appropriate at rest, logging and monitoring, staff confidentiality and training, vendor due diligence, secure development and incident-response procedures.
No method of transmission or storage is completely secure. You are responsible for protecting your credentials and notifying us promptly if you suspect unauthorized access.
We investigate suspected privacy or security incidents and notify affected individuals, regulators or other parties when required by law. We also maintain records of breaches as required by applicable law.
12. Cookies and similar technologies
Our Website may use cookies, pixels, local storage and similar technologies to:
- operate and secure the Website and remember essential settings;
- understand Website performance and usage;
- remember preferences and improve functionality; and
- support communications or advertising, where used and permitted by law.
Where required, non-essential technologies are used only after you make a choice through our consent tool. You can change available choices through the Website's cookie settings and can control cookies through your browser. Blocking essential cookies may prevent parts of the Website from working. For details about the technologies actually deployed, their providers, purposes and durations, please see our Cookie Policy or cookie settings panel.
13. Marketing communications
We send commercial electronic messages only where permitted by applicable law. Where required, we obtain consent before sending them. You may unsubscribe using the link in a message or by contacting us. We may still send non-marketing communications necessary to administer your account, complete a transaction, provide a requested service, or address security or legal matters.
14. Automated processing
We may use rules, models and automated tools to support identity verification, fraud and financial-crime detection, transaction monitoring, security and risk assessment. These tools may flag activity for review or affect whether additional information is requested.
Where applicable law restricts a decision based solely on automated processing that produces legal or similarly significant effects, we will apply the required safeguards. These may include meaningful information about the decision, an opportunity to provide your point of view and a right to request human review or contest the decision. Unless we notify you otherwise, material adverse decisions are not made solely by an automated system without appropriate review.
15. Your privacy rights and choices
Depending on your location and applicable law, you may have the right to:
- request access to personal information we hold about you and information about how it has been used or disclosed;
- request correction of inaccurate or incomplete information;
- withdraw consent, subject to legal and contractual restrictions;
- object to or request restriction of certain processing;
- request deletion of information, subject to our legal retention obligations and lawful exceptions;
- request a portable copy of certain information in a structured, commonly used and machine-readable format;
- opt out of direct marketing;
- ask about the logic and safeguards used for certain automated decisions and request human review where applicable; and
- complain to an applicable privacy or data-protection authority.
To exercise a right, email info@fin-mechanica.com. Please describe your request clearly. We may need to verify your identity and authority before responding. We will respond within the period required by applicable law. Rights are not absolute; if we cannot fulfill a request in whole or in part, we will explain the reason where legally permitted.
Authorized agents may submit requests where permitted by law, subject to verification of their authority and the individual's identity. We will not discriminate against you for exercising a privacy right.
16. Children's privacy
The Services are intended for adults and are not directed to children. We do not knowingly collect personal information from children without authorization required by law. If you believe a child has provided personal information to us improperly, contact us so that we can investigate and take appropriate action.
17. Changes to this Policy
We may update this Policy to reflect changes in our practices, Services or legal obligations. We will post the revised version on our Website and change the effective date. If a change is material, we will provide additional notice or obtain consent where required by law. We encourage you to review this Policy periodically.
18. Questions and complaints
Questions, requests and complaints may be directed to our Privacy Officer:
Mail: Privacy Officer, FinMechanica Corp., Office 507, 5940 Macleod Trail SW, Suite 500, Calgary, Alberta, Canada T2H 2G4
We will investigate and respond to privacy complaints in accordance with applicable law. If you are not satisfied with our response, you may contact the Office of the Information and Privacy Commissioner of Alberta, the Office of the Privacy Commissioner of Canada, or another competent data-protection authority in your jurisdiction.
Fin-Mechanica