Privacy Policy
Last updated August 5, 2026
Effective date: August 5, 2026
1. Who we are
MX FINTECH INC., trading as EmbedBank("we", "us", "our"), provides embedded banking infrastructure — dedicated IBAN accounts, payment rail connectivity, foreign exchange, and compliance tooling — to fintechs, payment service providers (PSPs), and licensed financial institutions. This Privacy Policy explains what personal information we collect, why we collect it, how we use it, and how you can exercise your rights.
This policy applies to visitors of our website and to end-users of accounts opened through our platform by our clients. If you are an end-user, your relationship is primarily with the client that opened your account; this policy describes the personal information we process as their infrastructure provider.
2. Privacy Officer
Our designated Privacy Officer is responsible for data protection compliance. You can reach them at:
- Email: [email protected]
- Postal address: Privacy Officer, MX FINTECH INC., 44 Halstead Dr, Markham, ON L3R 7Z2, Canada
3. What personal information we collect
Depending on how you interact with us, we may collect:
- Identity information — full legal name, date of birth, nationality, occupation, source of funds
- Government-issued identification — passport, national ID card, driver's licence (as required for KYC)
- Contact information — email address, phone number, mailing address
- Financial information — account balances, transaction history, source and destination of funds, beneficiary details
- Device and technical data — IP address, browser type, device identifiers, session logs
- Communications — messages you send us, records of support interactions
- Behavioural data — how you interact with our services (for fraud detection and service improvement)
4. Why we collect it and our legal basis
| Purpose | Legal basis |
|---|---|
| Verify identity and open / provision accounts | Legal obligation (AML/KYC) + contractual necessity |
| Process and settle transactions you authorize | Contractual necessity |
| Meet anti-money-laundering and counter-terrorism-financing reporting obligations | Legal obligation |
| Detect and prevent fraud, sanctions violations, and financial crime | Legitimate interest + legal obligation |
| Provide customer and integration support | Contractual necessity |
| Send service-related notifications | Contractual necessity |
| Send marketing communications (if opted in) | Consent |
| Improve and secure our services | Legitimate interest |
5. How long we keep it
We retain records for the periods required by applicable law:
- KYC records (identification documents, account-opening records): minimum 5 years after the account is closed
- Transaction records: minimum 5 years after the transaction date
- Compliance and reporting records: minimum 5 years
- Support communications: kept while the matter is open and for a reasonable period afterwards, then deleted
- Marketing consent records: until you withdraw consent
After the applicable retention period, we securely delete or anonymize your data.
6. Who we share your information with
We share personal information only when necessary and only with:
- Identity-verification providers — to meet our KYC obligations
- Banking and payments partners — to hold funds and settle transactions
- Cloud and hosting providers — to run and back up the service
- Regulators and law enforcement — where required by law
- Professional advisors — auditors and lawyers, subject to confidentiality
We engage each of these under a written agreement that limits them to processing your information on our instructions. You can request the current list of the specific providers we use, and the countries they operate in, by emailing our Privacy Officer.
We do not sell your personal information.
7. International data transfers
We are established in Canada, so information you give us is processed there. Some of the providers above may process it in other countries; we will tell you which, on request. Wherever data is processed, we require comparable safeguards by contract, alongside technical security measures and the applicable regulatory framework. Data processed outside your own country may be subject to that country's laws, including lawful access requests.
8. How we protect your information
We use industry-standard safeguards, including:
- Encryption in transit (TLS 1.2+) and at rest
- Access controls — role-based, least privilege
- Multi-factor authentication for staff accessing customer data
- Monitoring and logging of privileged access
- Regular security assessments and vulnerability testing
No system is perfectly secure, and we cannot guarantee absolute security.
9. Your rights
Subject to legal limitations (some regulated records cannot be deleted before their retention period ends), you have the right to:
- Access the personal information we hold about you
- Correct inaccurate information
- Withdraw consent for uses based on consent (e.g., marketing)
- Request deletion — where permitted by law
- Complain to our Privacy Officer and, if unsatisfied, to the Office of the Privacy Commissioner of Canada, or to the supervisory authority competent for your jurisdiction
To exercise any of these rights, contact our Privacy Officer at the address above.
10. Cookies and tracking
We use cookies and similar technologies for:
- Essential — a single session cookie that keeps you signed in (cannot be disabled)
We do not currently use functional, analytics, or advertising cookies, and we do not share data with ad networks. You can control cookies through your browser settings. See our Cookie Policy for detail.
11. Children
Our services are not directed at persons under 18, and we do not knowingly collect information from minors. If you believe a minor has provided us with personal information, please contact our Privacy Officer.
12. Breach notification
In the event of a personal data breach that creates a real risk of significant harm, we will notify affected individuals and report to the Office of the Privacy Commissioner of Canada, together with any other supervisory authority competent for your jurisdiction, as required by applicable data protection law.
13. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be announced with at least 30 days' notice where required by law.
14. Contact
- Privacy Officer: [email protected]
- General inquiries: [email protected]
- Registered address: MX FINTECH INC., 44 Halstead Dr, Markham, ON L3R 7Z2, Canada
- FinTRAC MSB registration: M23664081