Back to home

Privacy Policy

Last updated August 5, 2026

Effective date: August 5, 2026

1. Who we are

MX FINTECH INC., trading as EmbedBank("we", "us", "our"), provides embedded banking infrastructure — dedicated IBAN accounts, payment rail connectivity, foreign exchange, and compliance tooling — to fintechs, payment service providers (PSPs), and licensed financial institutions. This Privacy Policy explains what personal information we collect, why we collect it, how we use it, and how you can exercise your rights.

This policy applies to visitors of our website and to end-users of accounts opened through our platform by our clients. If you are an end-user, your relationship is primarily with the client that opened your account; this policy describes the personal information we process as their infrastructure provider.

2. Privacy Officer

Our designated Privacy Officer is responsible for data protection compliance. You can reach them at:

  • Email: [email protected]
  • Postal address: Privacy Officer, MX FINTECH INC., 44 Halstead Dr, Markham, ON L3R 7Z2, Canada

3. What personal information we collect

Depending on how you interact with us, we may collect:

  • Identity information — full legal name, date of birth, nationality, occupation, source of funds
  • Government-issued identification — passport, national ID card, driver's licence (as required for KYC)
  • Contact information — email address, phone number, mailing address
  • Financial information — account balances, transaction history, source and destination of funds, beneficiary details
  • Device and technical data — IP address, browser type, device identifiers, session logs
  • Communications — messages you send us, records of support interactions
  • Behavioural data — how you interact with our services (for fraud detection and service improvement)

4. Why we collect it and our legal basis

PurposeLegal basis
Verify identity and open / provision accountsLegal obligation (AML/KYC) + contractual necessity
Process and settle transactions you authorizeContractual necessity
Meet anti-money-laundering and counter-terrorism-financing reporting obligationsLegal obligation
Detect and prevent fraud, sanctions violations, and financial crimeLegitimate interest + legal obligation
Provide customer and integration supportContractual necessity
Send service-related notificationsContractual necessity
Send marketing communications (if opted in)Consent
Improve and secure our servicesLegitimate interest

5. How long we keep it

We retain records for the periods required by applicable law:

  • KYC records (identification documents, account-opening records): minimum 5 years after the account is closed
  • Transaction records: minimum 5 years after the transaction date
  • Compliance and reporting records: minimum 5 years
  • Support communications: kept while the matter is open and for a reasonable period afterwards, then deleted
  • Marketing consent records: until you withdraw consent

After the applicable retention period, we securely delete or anonymize your data.

6. Who we share your information with

We share personal information only when necessary and only with:

  • Identity-verification providers — to meet our KYC obligations
  • Banking and payments partners — to hold funds and settle transactions
  • Cloud and hosting providers — to run and back up the service
  • Regulators and law enforcement — where required by law
  • Professional advisors — auditors and lawyers, subject to confidentiality

We engage each of these under a written agreement that limits them to processing your information on our instructions. You can request the current list of the specific providers we use, and the countries they operate in, by emailing our Privacy Officer.

We do not sell your personal information.

7. International data transfers

We are established in Canada, so information you give us is processed there. Some of the providers above may process it in other countries; we will tell you which, on request. Wherever data is processed, we require comparable safeguards by contract, alongside technical security measures and the applicable regulatory framework. Data processed outside your own country may be subject to that country's laws, including lawful access requests.

8. How we protect your information

We use industry-standard safeguards, including:

  • Encryption in transit (TLS 1.2+) and at rest
  • Access controls — role-based, least privilege
  • Multi-factor authentication for staff accessing customer data
  • Monitoring and logging of privileged access
  • Regular security assessments and vulnerability testing

No system is perfectly secure, and we cannot guarantee absolute security.

9. Your rights

Subject to legal limitations (some regulated records cannot be deleted before their retention period ends), you have the right to:

  • Access the personal information we hold about you
  • Correct inaccurate information
  • Withdraw consent for uses based on consent (e.g., marketing)
  • Request deletion — where permitted by law
  • Complain to our Privacy Officer and, if unsatisfied, to the Office of the Privacy Commissioner of Canada, or to the supervisory authority competent for your jurisdiction

To exercise any of these rights, contact our Privacy Officer at the address above.

10. Cookies and tracking

We use cookies and similar technologies for:

  • Essential — a single session cookie that keeps you signed in (cannot be disabled)

We do not currently use functional, analytics, or advertising cookies, and we do not share data with ad networks. You can control cookies through your browser settings. See our Cookie Policy for detail.

11. Children

Our services are not directed at persons under 18, and we do not knowingly collect information from minors. If you believe a minor has provided us with personal information, please contact our Privacy Officer.

12. Breach notification

In the event of a personal data breach that creates a real risk of significant harm, we will notify affected individuals and report to the Office of the Privacy Commissioner of Canada, together with any other supervisory authority competent for your jurisdiction, as required by applicable data protection law.

13. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be announced with at least 30 days' notice where required by law.

14. Contact

  • Privacy Officer: [email protected]
  • General inquiries: [email protected]
  • Registered address: MX FINTECH INC., 44 Halstead Dr, Markham, ON L3R 7Z2, Canada
  • FinTRAC MSB registration: M23664081