Privacy Policy

At Triffin, we respect your privacy. This policy outlines how we collect, use, and protect your personal information when you visit our website or use our services.
last updated: 07.08.26

1. INTRODUCTION

This Privacy Policy is entered into between you and the relevant entity that provides the applicable Service (as defined and described in more detail in our Terms of Service which can be found here).

Run Viable Limited, trading as Triffin, company number 14275265, registered office Rise London, 41 Luke Street, London, England, EC2A 4DP, provides the platform, website, SaaS services, cash-flow tools, AI finance tools, workflow tools and related non-credit services unless otherwise stated.

Run Viable Limited (t/a Triffin) is an agent of Plaid Financial Ltd, an authorised payment institution regulated by the Financial Conduct Authority under the Payment Services Regulations 2017 (Firm Reference Number: 804718). Plaid provides you with regulated account information services through Triffin as its agent.

Triffin Capital Limited, company number 16268227, registered office 41 Luke Street, London, England, EC2A 4DP, provides or arranges certain credit, funding or finance-related products.

In this Privacy Policy, “Triffin”, “we”, “us” and “our” means the relevant entity providing the applicable Service. Unless expressly stated otherwise, each entity is responsible only for the Services it provides and is not liable for the obligations of another entity.

This Privacy Policy (“Privacy Policy”) sets out our approach to processing your Personal Data. We are committed to protecting and respecting your privacy and Personal Data in accordance with applicable data protection and privacy laws, including, where applicable, the UK General Data Protection Regulation, the Data Protection Act 2018, the EU General Data Protection Regulation, the Irish Data Protection Act 2018, the Privacy and Electronic Communications Regulations and applicable ePrivacy laws.

This Privacy Policy explains how we collect, process and keep your Personal Data safe. The Privacy Policy will tell you about your privacy rights, how the law protects you, and inform our employees and staff members of all their obligations and protocols when processing data.

Our Services are intended for business use. Our customers are businesses rather than individuals acting in a personal capacity. However, in providing the Services, we may process Personal Data relating to individuals connected with those businesses, including directors, officers, employees, contractors, consultants, shareholders, beneficial owners, authorised users, administrators, representatives, finance contacts, suppliers, customers, guarantors, applicants, prospects and other individuals whose Personal Data is provided to us or made available through the Services. 

Where you provide us with Personal Data about another individual (including your employees), or make such Personal Data available to us through the Services or connected accounts, you are responsible for ensuring that you have the right to do so and, where required, you have the relevant consent needed and that the relevant individual has been provided with appropriate privacy information about how their Personal Data may be shared with and used by us. 

“Personal Data” means any information relating to an identified or identifiable living individual. An individual may be identified directly or indirectly, including by reference to their name, identification number, location data, online identifier, contact details, role, account information, financial information, device information, or other information relating to their identity or circumstances.

Personal Data does not include information that relates only to a company, organisation or other legal entity and does not identify, or make it possible to identify, a living individual. For example, general business information about a company may not be Personal Data. However, business-related information may still be Personal Data where it relates to an identifiable individual.

Capitalised terms used but not defined in this Privacy Policy have the meanings given to them under the UK GDPR, such as “Controller,” “Joint Controller,” “Processor” and “Data Subject”.

We are not obliged by the GDPR to appoint a Data Protection Officer (DPO) and have not voluntarily appointed one at this time. Therefore, any inquiries about your Personal Data should be sent to us by email at [email protected] or by post to 41 Luke Street, London, EC2A 4DP, United Kingdom.

You have the right to make a complaint at any time to your applicable supervisory authority, which is the Information Commissioner’s Office for those subject to the UK GDPR, the UK supervisory authority for data protection issues, about our processing of your Personal Data. If you are located in Ireland or your Personal Data is subject to EU data protection law, you have the right to complain to the Irish Data Protection Commission or another relevant EU supervisory authority. We would, however, appreciate the chance to deal with your concerns before you approach the relevant supervisory authority, so please contact us in the first instance.

1.1 Relevant Data Controller in Your Case

We are the Data Controller responsible for the Personal Data we collect and process in connection with the Services, unless we tell you otherwise. However, in some circumstances, we may act as a Joint Controller with another organisation, such as a finance or credit provider, payment provider, account information service provider or other third-party provider involved in delivering or supporting the Services, including Froda AB, Plaid Financial Limited and Currency Cloud Limited where applicable. Where this applies, we and the relevant third party will each be responsible for complying with applicable data protection laws in respect of the Personal Data we process, and we may provide you with further information about the relevant controller arrangements where required.

In discharging our responsibilities as a Data Controller, and where applicable as a Joint Controller with another organisation, we have employees, staff members, contractors and other authorised personnel who may deal with your Personal Data on our behalf. Where required or appropriate, we may also use third-party service providers who process Personal Data on our behalf as “Processors.” 

The Data Controller, any Joint Controller where applicable, and our Processors have the following responsibilities:

  1. Ensure that all processing of Personal Data is governed by one of the legal bases laid out in the GDPR (see 2.3 below for more information);
  2. Ensure that Processors authorised to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality;
  3. Implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk associated with the processing of Personal Data;
  4. Obtain the prior specific or general authorisation of the Controller before engaging another Processor;
  5. Assist the Controller in the fulfilment of the Controller's obligation to respond to requests for exercising the Data Subject's rights;
  6. Make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in the GDPR and allow for and contribute to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller;
  7. Maintain a record of all categories of processing activities carried out on behalf of a Controller;
  8. Cooperate, on request, with the supervisory authority in the performance of its tasks;
  9. Ensure that any person acting under the authority of the Processor who has access to Personal Data does not process Personal Data except on instructions from the Controller; and
  10. Notify the Controller without undue delay after becoming aware of a Personal Data Breach.

2. LEGAL BASIS FOR DATA COLLECTION

2.1 From Whom We May Collect Personal Data

The individuals whose Personal Data we may collect and process include:

  1. Customers and/or prospective customers / applicants;
  2. Suppliers or other third parties such as those we have partnered with to provide regulated financial services or products; 
  3. Business contacts; 
  4. Affiliates; 
  5. Referral partners; 
  6. Marketing contacts;
  7. Our employees or prospective employees or applicants;
  8. Employees, directors, beneficial owners, shareholders, staff members, contractors, consultants, professional advisers, representatives or other individuals of our customers / applicants, suppliers, partners or affiliates; and
  9. Any other individuals with whom we have, may have, or need to manage a business relationship.

We may also receive Personal Data from third parties, including affiliates, referral partners, service providers, integration partners, financial partners, identity verification providers, open banking providers, marketing providers and other persons who provide information to us in connection with our Services.

We may collect Personal Data directly from you, from your employer or organisation, from users or administrators of your account, from affiliates or referral partners, from connected third-party services, from finance partners and/or affiliates, from open banking providers, from identity verification and compliance providers, from public registers, from credit reference or fraud prevention sources where applicable, from communications with you, from website and platform usage, and from publicly available sources (for example the Companies House). 

2.2 Types of Data / Privacy Policy Scope

We may collect, use, store and transfer different kinds of Personal Data about you depending on your relationship with us, the Services you use, and how you interact with us. The categories below describe the types of Personal Data we may collect where relevant, but not all categories will necessarily apply in every case: 

  1. Profile/Identity Data: This is data relating to your first name, last name, gender, date of birth.
  2. Contact Data: This is data relating to your phone number, addresses, email addresses, phone numbers.
  3. Marketing and Communications Data: This is your preferences in receiving marketing information and other information from us.
  4. Billing Data: This is information relating to your debit and credit card information such as the name attached to your payment details and your billing address.
  5. Financial Data: These are your banking details e.g. your account number and sort code.
  6. Transactional Data: This is information of details and records of all payments you have made for our Services or products.
  7. We do not intend to collect nor process any Special Categories of Personal Data about you (this includes details about your race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, information about your health, and genetic and biometric data). 
  8. In certain circumstances, including as part of our KYC, KYB, onboarding, financial crime, fraud prevention, sanctions screening, adverse media screening and ongoing compliance checks, we may collect or receive information relating to criminal convictions, offences, allegations or related adverse information, where this is relevant and permitted by applicable law and as part of our endeavour to provide our products in compliance with financial crimes laws.
  9. Business and role data: job title, employer, company, role, authority, user permissions, admin status and relationship to the customer.
  10. KYC/KYB and compliance data: ID documents and identity verification information including selfie checks where applicable, verification results, beneficial ownership, shareholder information, directorships, sanctions screening, PEP checks, adverse media, fraud indicators and onboarding outcomes.
  11. Connected account and integration data: bank account information, open banking data, transaction data, account balances, Shopify/e-commerce data, accounting platform data, sales data, payment processor data, platform permissions and integration tokens.
  12. Platform usage data: log-in data, user actions, audit logs, funding requests, payment requests, workflow activity, uploaded files, support messages and system events.
  13. Technical/device data: IP address, browser, device, location derived from IP, authentication logs, cookies, pixels and analytics identifiers.
  14. AI and analytics data: AI-generated summaries, classifications, forecasts, risk indicators, insights, extracted data and workflow recommendations.


2.3 The Legal Basis for Collecting That Data

There are a number of justifiable reasons under the GDPR that allow collection and processing of Personal Data. The main avenues we rely on are:

  1.  Consent: Certain situations allow us to collect your Personal Data, such as when you tick a box that confirms you are happy to receive email newsletters from us, or ‘opt in’ to a Service.
  2. Contractual Obligations: We may require certain information from you in order to fulfil our contractual obligations and provide you with the promised Service. 
  3. Legal Compliance: We’re required by law to collect and process certain types of data, such as fraudulent activity or other illegal actions.
  4. Legitimate Interest: We might need to collect certain information from you to be able to meet our legitimate interests - this covers aspects that can be reasonably expected as part of running our business, that will not have a material impact on your rights, freedom or interests. Examples could be your address, so that we know where to deliver something to, or your name, so that we have a record of who to contact moving forwards.


Legal Basis Overview

We may use your Personal Data for the purposes set out below. Depending on the circumstances, we may rely on more than one lawful basis for processing the same Personal Data.

Purpose Types of personal data that may be used Lawful basis
To create, manage and administer your account and provide access to the Services Identity data, contact data, business and role data, account and connected accounts data, technical data, usage data, financial data including information for underwriting purposes Performance of a contract; consent; legitimate interests in operating and administering our Services
To provide, operate, personalise, support and improve the Services, including our platform, dashboards, cash-flow tools, workflow tools and finance tools Identity data, contact data, business and role data, financial data, transactional data, connected account data, usage data, technical data Performance of a contract; consent; legitimate interests in providing and improving our Services
To provide customer support and respond to enquiries, complaints or requests Identity data, contact data, account data, communications data, usage data, transactional data (if the query is about a transaction), data about your third parties including suppliers Performance of a contract; consent; legitimate interests in responding to customers and improving our support
To carry out onboarding, KYC, KYB, sanctions screening, AML checks, fraud prevention, adverse media checks and ongoing compliance monitoring Identity data, contact data, business and role data, verification data, compliance data, financial data, transactional data, connected account data, criminal offence or adverse information where relevant and permitted by law Legal obligation; legitimate interests in preventing fraud, financial crime and misuse of the Services; substantial public interest where applicable
To assess, process, support or administer funding, credit, finance or related product workflows, including where we work with finance partners such as Froda AB, Currency Cloud Limited or other providers Identity data, contact data, business and role data, financial data, transactional data, connected account data, verification data, compliance data, funding request data Performance of a contract; consent; legitimate interests in providing and supporting finance-related services; legal obligation where applicable
To provide or support open financial, account information or connected account services, including where services are provided through partners such as Plaid Identity data, contact data, financial data, transactional data, connected account data, technical data, usage data Performance of a contract; consent where required; legitimate interests; legal obligation where applicable
To connect with, access data from, or support integrations with third-party platforms, including bank accounts, accounting systems, e-commerce platforms, payment processors, advertising platforms and other connected services Connected account data, financial data, transactional data, technical data, usage data, platform identifiers, access tokens, permissions and related metadata Performance of a contract; consent; legitimate interests in providing and improving the Services
To use AI-assisted tools, analytics, automation and machine learning to provide, support, monitor, personalise and improve the Services Usage data, technical data, connected account data, financial data, transactional data, AI Output data, analytics data and other relevant service data Performance of a contract; legitimate interests in providing, improving and securing the Services; consent where required
To send service communications, account notices, operational updates, legal notices, security alerts and other non-marketing communications Identity data, contact data, account data, communications data Performance of a contract; legal obligation; legitimate interests in keeping users informed about the Services
To send marketing communications, product updates, newsletters, event invitations or information about products and services that may be of interest Identity data, contact data, marketing and communications data, usage data Consent where required; legitimate interests where permitted by applicable marketing laws
To manage marketing preferences and opt-out requests Identity data, contact data, marketing and communications data Legal obligation; legitimate interests in respecting communication preferences
To protect the security, integrity and availability of our systems and Services, including through access controls, audit logs, monitoring, investigation and incident response Technical data, usage data, account data, security data, audit log data, transactional data Legal obligation; legitimate interests in securing our Services and preventing misuse
To prevent, detect, investigate and respond to fraud, unauthorised access, misuse, financial crime, sanctions risk, legal breaches or other harmful activity Identity data, contact data, business and role data, financial data, transactional data, connected account data, technical data, usage data, compliance data Legal obligation; legitimate interests in protecting our business, customers, partners and Services; public interest where applicable
To comply with legal, regulatory, tax, accounting, audit, reporting and record-keeping obligations Identity data, contact data, business and role data, financial data, transactional data, compliance data, account data, communications data Legal obligation; legitimate interests in maintaining appropriate business records
To establish, exercise or defend legal claims, enforce our agreements, manage disputes, respond to regulators or cooperate with law enforcement or public authorities Identity data, contact data, business and role data, financial data, transactional data, compliance data, communications data, technical data Legal obligation; legitimate interests in protecting our rights and complying with legal processes
To manage corporate transactions, restructuring, investment, financing, due diligence, sale of business or transfer of assets Identity data, contact data, business and role data, account data, financial data, transactional data, usage data and other relevant business records Legitimate interests in managing and developing our business; performance of a contract relating to corporate structure and funding arrangements

Where we rely on legitimate interests, we will consider and balance any potential impact on your rights and freedoms before processing your Personal Data. Where we rely on consent, you may withdraw your consent at any time, although this will not affect any processing carried out before consent was withdrawn. Where we need to process Personal Data to comply with a legal obligation or perform a contract, we may not be able to provide some or all of the Services if the required Personal Data is not provided.


3. HOW WE USE YOUR PERSONAL DATA

3.1 Our Connected Account Data Uses

We will use your Personal Data when the law allows us to in order for us to provide our Services or products to you.

Where you connect, authorise or enable access to a bank account, accounting system, e-commerce platform, payment processor, advertising platform or other third-party service, we may collect and process Personal Data and business data made available through that connection. This may include account information, transaction data, balances, sales data, order information, customer or supplier information, payment information, platform identifiers, access tokens, permissions, usage data and related metadata.

We use this information to provide, operate, support, personalise, monitor and improve the Services. The data available to us will depend on the third-party service connected, the permissions granted, and the Services you use.

Where connected-account data includes Personal Data relating to individuals other than you, you are responsible for ensuring that you have the necessary authority, permissions, and lawful basis, including consent where needed, to provide or make that data available to us.


3.2 Marketing and content updates

We may send you marketing communications where permitted by applicable law, including where you have consented to receive them or where we are otherwise permitted to contact you about our products and Services. You can opt out of marketing at any time by contacting us. We may still send you non-marketing Service, account, legal, security or administrative communications.

Our marketing emails may contain tracking technologies, such as pixels or links, that help us understand whether emails have been opened, whether links have been clicked and how users interact with our communications. Where required by applicable law, we will use these technologies only with appropriate consent or another permitted basis. 


3.3 Change of purpose

We will only use your Personal Data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose or we have a valid legal basis for processing the Personal Data. If you wish to get an explanation as to how the processing for the new purpose is compatible with the original purpose, please contact us. If we need to use your Personal Data for an unrelated purpose, we will notify you if required and we will explain the legal basis which allows us to do so. Please note that we may process your Personal Data without your knowledge or consent, in compliance with the above rules, where this is required or permitted by law.


4. USE OF DATA FOR AI, MACHINE LEARNING, MODEL IMPROVEMENT & EXTERNAL SERVICES

4.1 Purpose and Scope

In order to continuously enhance our Services, we may aggregate certain non-Personal Data collected from our clients. This processed data may be used to train, validate, and improve our AI & machine learning models, which in turn help us deliver more personalised and effective solutions to all customers. Furthermore, external services, such as 3rd party large language model providers are used to deliver our Services.

We may use AI-assisted and automation tools, machine learning models and automated systems to provide, support, monitor, secure and improve the Services. This may include data extraction, classification, summarisation, forecasting, workflow automation, risk indicators, financial crimes detection, customer support, product analytics and operational insights.

Where AI tools process Personal Data, we will do so in accordance with applicable data protection laws and this Privacy Policy. We will take reasonable steps to ensure that Personal Data is used only for appropriate business, service, security, compliance, product improvement and operational purposes.

Unless we tell you otherwise or agree otherwise, we do not permit third-party AI providers to use your Personal Data to train their general models.

These AI-assisted and automation tools may be used to support our internal processes, the provision of the Services, human review and operational decision-making, and where a decision produces legal or similarly significant effects for an individual, we will ensure that any automated decision-making is carried out only where permitted by applicable law and with appropriate safeguards.


4.2 Consent and Opt-Out

By using our Services, you expressly consent to the use of your data in line with this Privacy Policy and any other agreement we have in place with you, unless you have expressly opted out. Should you wish to opt out of such use of your Personal Data, please contact us (see section 12. CONTACT US for more information).

5. YOUR RIGHTS AND HOW YOU ARE PROTECTED BY US

5.1 Your legal rights

Under certain circumstances, you have the following rights under data protection laws in relation to your Personal Data:

  1. Right to be informed. You have a right to be informed about our purposes for processing your Personal Data, how long we store it for, and who it will be shared with. We have provided this information to you in this policy.
  2. Right of access. This enables you to receive a copy of the Personal Data we hold about you and to check that we are lawfully processing it (also known as a "data subject access request"). See section 5.2 below for more details on how you can make a data subject access request.
  3. Right to rectification. You have a right to request correction of the Personal Data that we hold about you. This enables you to have any incomplete or inaccurate data we hold about you corrected, though we may need to verify the accuracy of the new data you provide to us.
  4. Right to erasure. You have the right to ask us to delete or remove Personal Data where there is no good reason for us continuing to process it, where you have successfully exercised your right to object to processing (see below), where we may have processed your information unlawfully or where we are required to erase your Personal Data to comply with local law. Note, however, that we may not always be able to comply with your request of erasure for specific legal reasons which will be notified to you, if applicable, at the time of your request.
  5. Right to object. You can object to the processing of Personal Data we hold about you. This effectively allows you to stop or prevent us from processing your Personal Data. Note that this is not an absolute right and it only applies in certain circumstances, for example:
    1. Where we are processing your Personal Data for direct marketing purposes.
    2. Where we are relying on a legitimate interest (or those of a third party) and there is something about your particular situation which makes you want to object to processing on this ground as you feel it impacts on your fundamental rights and freedoms. In some cases, we may continue processing your data if we can demonstrate that we have compelling legitimate grounds to process your information which override your rights and freedoms.
  6. Right to restrict processing. You have the right to request the restriction or suppression of your Personal Data. Note that this is not an absolute right and it only applies in certain circumstances, for example:
    1. If you want us to establish the data's accuracy. 
    2. Where our use of the data is unlawful but you do not want us to erase it.
    3. Where you need us to hold the data even if we no longer require it as you need it to establish, exercise or defend legal claims.
    4. You have objected to our use of your data but we need to verify whether we have overriding legitimate grounds to use it.
  7. Right to data portability. You have the right to request the transfer of your Personal Data to you or to a third party. If you make such a request, we will provide to you, or a third party you have chosen, your Personal Data in a structured, commonly used, machine-readable format. Note that this right may only apply to information which you initially provided consent for us to use or where we used the information to perform a contract with you.

If you wish to make a request under any of these rights, please contact us (see section 12. CONTACT US for more information).

5.2 Your control over Our Limited’s use of your Personal Data and Data Subject Access Requests

You may request for us to delete your account at any time – this will remove your account page from our systems and our related software. We do not guarantee the ability to delete all stored data. If you would like us to delete /correct your Personal  Data, let us know and we will action your request as soon as practicable. In certain circumstances, you may be able to correct the Personal Data on your account / profile yourself. You can access information associated with your account by logging into your account you created with us.

Your account information will be protected by a password for your privacy and security. You need to prevent unauthorised access to your account and Personal Data by selecting and protecting your password appropriately and limiting access to your computer or device and by signing off after you have finished accessing your account.

You will not have to pay a fee to access your Personal Data (or to exercise any of the other rights). However, if your request is clearly unfounded, we could refuse to comply with your request where legally allowed to.

We may need to request specific information from you to help us confirm your identity and ensure you have the right to access your Personal Data (or to exercise any of your other rights). This is a security measure to ensure that Personal Data is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response.

If there is any action you cannot perform yourself, or if you have any other questions or concerns or would like to exercise any of the rights you have available to you, kindly contact us (see section 12. CONTACT US for more information).

5.3 How We protect customers' Personal Data

We are committed to keeping your Personal Data secure and protecting it from inappropriate disclosure. Personal Data is accessible only to authorised personnel and service providers who need access for business, service, support, compliance, security or operational purposes and who are subject to appropriate confidentiality and security obligations. If and when we use subcontractors to store your data, we will not relinquish control of your Personal Data or expose it to security risks that would not have arisen had the data remained in our possession. However, unfortunately no transmission of data over the internet is guaranteed to be completely secure. It may be possible for third parties not under the control of us to intercept or access transmissions or private communications unlawfully. While we strive to protect your Personal Data, we cannot ensure or warrant the security of any Personal Data you transmit to us. Any such transmission is done at your own risk. If you believe that your interaction with us is no longer secure, please contact us.

We maintain internal information security, access control, data protection, incident response and related policies and procedures designed to protect our systems and the Personal Data we process. We also use reputable third-party cloud, infrastructure, software and technology providers to support the delivery and security of our Services. Where appropriate, we assess these providers before use and, where available, consider their security assurances, certifications, audit reports or independent assurance materials, such as SOC 2 reports, ISO 27001 certifications or equivalent security documentation, to help us assess whether they maintain appropriate technical and organisational measures.


6. YOUR DATA AND THIRD PARTIES

6.1 Connected accounts, integrations and third-party platforms

Where you connect, authorise or enable access to a bank account, accounting system, e-commerce platform, payment processor, advertising platform or other third-party service, we may collect and process Personal Data and business data made available through that connection. This may include account information, transaction data, balances, sales data, order information, customer or supplier information, payment information, platform identifiers, access tokens, permissions, usage data and related metadata. The data available to us will depend on the third-party service connected, the permissions granted, and the Services you use and what data we require to provide the Services to you.

We use this information to provide, operate, support, personalise, monitor and improve the Services, including cash-flow tools, dashboards, workflow tools, finance tools, funding request workflows and underwriting, risk assessment, onboarding, compliance checks, fraud prevention, customer support, analytics and product development.

Where connected-account data includes Personal Data relating to individuals other than you, including your customers, suppliers, employees, contractors, representatives or other third parties, you are responsible for ensuring that you have the necessary authority, permissions and lawful basis to provide or make that data available to us.

We aim to avoid collecting or retaining unnecessary Personal Data from connected accounts and third-party platforms where it is not needed for the Services, compliance, security, support, analytics, product improvement or other legitimate business purposes.

6.2 Sharing your data with third parties

We may share Personal Data with third parties where this is necessary or appropriate for the purposes described in this Privacy Policy, where required by law, where permitted by applicable data protection laws, or where we have another lawful basis to do so.

The categories of third parties with whom we may share Personal Data include:

  • Service providers and technology partners who help us provide, operate, secure, support, monitor, improve or market the Services;
  • Financial services, funding, credit, payment, open banking, banking, e-money, foreign exchange or other product partners involved in providing, supporting or making available our products or Services;
  • Compliance, identity verification, KYC, KYB, sanctions screening, adverse media, fraud prevention, AML, risk-screening, debt collection and professional advisory providers;
  • Affiliates, introducers, referral partners, brokers, commercial partners and other business partners who refer customers to us or support our customer relationships;
  • Regulators, supervisory authorities, law enforcement agencies, courts, government bodies and other public authorities where required or permitted by law or where necessary to protect our rights, users, partners, business or Services;
  • Potential buyers, sellers, investors, lenders, funders, advisers or other third parties in connection with any actual or proposed merger, acquisition, investment, financing, restructuring, sale of business, sale of assets, transfer of rights or similar corporate transaction; and
  • Any other third party where you have authorised the sharing, where it is necessary to provide the Services, where it is necessary to enforce our agreements or policies, or where it is otherwise required or permitted by applicable law.

Where we share Personal Data with third-party service providers who process Personal Data on our behalf, we will take appropriate steps to ensure that they are subject to suitable contractual, confidentiality, security and data protection obligations. Where a third party acts as an independent Controller or Joint Controller, that third party will be responsible for its own processing of Personal Data in accordance with applicable data protection laws and, where relevant, its own privacy notice.

6.3 Third-Party Links

This website may include links to third-party websites, plug-ins and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy statements. When you leave our website, we encourage you to read the privacy policy of every website you visit.

6.4 Google Data Usage

We may access, use and store some Google data: Google Ads. We may connect with Google Ads and store access tokens within our database. We access Google Ads data on behalf of authenticated users, pulling in and saving down the latest spend and performance metrics for accounts and campaigns. No Personal Data is handled when doing this.

Our use and transfer to any other app of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements.

7. COOKIES AND SIMILAR TECHNOLOGIES

We use cookies and similar technologies on our website, the Triffin app and Services. Cookies are small text files that are placed on your device when you visit a website or use an online service. Similar technologies may include pixels, tags, scripts, software development kits, local storage, session storage, device identifiers and other tracking or storage technologies.

We use these technologies to operate, secure, monitor, improve and personalise our website, the Triffin app and Services, understand how users interact with us, remember user preferences, support account login and authentication, analyse performance, support marketing activities and improve our products and customer experience.

Cookies and similar technologies may collect or process information such as your IP address, device identifier, browser type, operating system, pages viewed, links clicked, time spent on pages, referring website, approximate location, log-in status, account activity, preferences, usage data, marketing interactions and other technical or usage information.

We may use the following types of cookies and similar technologies:

Where cookies or similar technologies involve the processing of Personal Data, we process that Personal Data in accordance with this Privacy Policy. Depending on the purpose, our lawful basis may include your consent, our legitimate interests in operating, securing and improving our website and Services, performance of a contract, or compliance with legal obligations. Where consent is required for the use of cookies or similar technologies, we will rely on consent for that use.


8. HOW LONG WE RETAIN YOUR DATA

The retention period may differ depending on the type of data and the reason we hold it. For example, we may retain onboarding, KYC, KYB, financial crime, transaction, contractual, accounting, tax, audit, complaint and legal records for longer periods where required or permitted by law, regulation, contractual obligations or our legitimate business interests.  We will only retain your Personal Data for as long as reasonably necessary to fulfil the purposes we collected it for and in line with our Record Retention Policy. We may retain your Personal Data for a longer period than usual in the event of a complaint or if we reasonably believe there is a prospect of litigation in respect to our relationship with you.

9. INTERNATIONAL TRANSFER OF DATA

We may transfer Personal Data outside the United Kingdom and/or European Economic Area where this is necessary for the provision of the Services, use of third-party providers, hosting, support, analytics, security, communications or business operations. Where we transfer Personal Data internationally, we will take steps designed to ensure that appropriate safeguards are in place, such as relying on an adequacy decision, the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, the EU Standard Contractual Clauses, or other safeguards permitted by applicable data protection laws. 

10. NOTIFICATION OF CHANGES AND ACCEPTANCE OF POLICY

By using the Services, you consent to the collection and use of data by us as set out in this Privacy Policy. Continued access or use of the Services will constitute your express acceptance of any modifications to this Privacy Policy.

11. INTERPRETATION

All uses of the word "including" mean "including but not limited to" and the enumerated examples are not intended to in any way limit the term which they serve to illustrate. Any email addresses set out in this policy may be used solely for the purpose for which they are stated to be provided. 

Our staff are not authorised to contract on behalf of us, waive rights or make representations (whether contractual or otherwise). If anything contained in an email from a Triffin address contradicts anything in this policy, our Terms or any official public announcement on our website, or is inconsistent with or amounts to a waiver of any our rights, our official Terms of Service, Agreement or this Privacy Policy will take preference. The only exception to this is genuine correspondence expressed to be from the Run Viable Limited (t/a Triffin) legal department.

12. CONTACT US

If you have any questions, or would like to exercise any of your rights you have at law, you may contact us at:

By email: [email protected]
By post: 41 Luke St, London, EC2A 4DP

If there is any conflict between this Privacy Policy and any individual agreement expressly signed between you and us, the signed agreement will take precedence to the extent of the conflict.

Do you have questions?
Reach out to our team and start a discussion.
Contact us
Contact us