Who We Are
Reflow Zone UK Ltd ("Reflow", "we", "us", "our") is the data controller responsible for your personal data. We are a company registered in England and Wales under company number 11235853, with our registered office at 1 Canada Square, London, E14 5AB.
We are authorised and regulated by the Financial Conduct Authority (FCA) under the Payment Services Regulations 2017 (PSRs) as both an Account Information Service Provider (AISP) and a Payment Initiation Service Provider (PISP). Our FCA Firm Reference Number is 811078.
We are registered with the Information Commissioner's Office (ICO) as a data controller under registration number ZB898766.
We have appointed a Data Protection Officer (DPO) who can be contacted at dpo@reflowzone.io.
This policy applies to: visitors to our website (reflowzone.io), businesses and developers using our API platform, and end-users whose bank account data and payment instructions are processed through our services on behalf of our business customers.
Open Banking & Regulatory Context
Open banking allows regulated third-party providers (TPPs) like Reflow to access consumers' bank account data and initiate payments on their behalf, with their explicit consent, through secure APIs. This framework is governed in the UK by:
- The Payment Services Regulations 2017 (PSRs 2017) — implementing PSD2 into UK law and regulating AISP/PISP activity.
- The UK Open Banking Standard — operated by Open Banking Limited (OBL), which sets technical and security requirements for open banking in the UK.
- UK GDPR and the Data Protection Act 2018 — governing how personal data is collected, used, and protected.
- FCA Handbook (BCOBS, COBS, SYSC) — rules on customer protection, data management, and operational resilience.
When you (or your customers) connect a bank account through our platform, we act as a regulated TPP. We only access data or initiate payments with explicit, informed consent obtained through a compliant consent flow. You can withdraw consent at any time.
Important: Reflow never stores your online banking credentials (username, password, or OTP). We only ever receive a temporary access token from your bank via a secure OAuth 2.0 flow.
Data We Collect
The data we collect depends on whether you are a business customer (developer / company using our API) or an end-user (an individual whose bank account is connected via a Reflow-powered application).
3.1 Business Customers & Developers
- Identity data: full name, job title, company name, company registration number.
- Contact data: email address, telephone number, business address.
- Account data: login credentials (hashed), API keys, usage logs, billing information.
- Technical data: IP addresses, browser type and version, device identifiers, access logs, request/response metadata.
- Financial data: invoicing information, payment card details (processed by our PCI-DSS compliant payment processor; we do not store card numbers).
- Communications data: records of support tickets, emails, and chat messages.
3.2 End-Users (Open Banking Data)
When an end-user connects their bank account through a Reflow-powered application with their consent, we may process:
| Category | Examples | AISP / PISP |
|---|---|---|
| Account identifiers | Account number, sort code, IBAN, account name | Both |
| Balance data | Current balance, available balance, credit limit | AISP |
| Transaction data | Transaction amount, date/time, merchant name, category, reference | AISP |
| Identity data | Legal name, address (where provided by the bank) | AISP |
| Payment instruction data | Payee account, sort code, amount, reference, payment date | PISP |
| Consent metadata | Consent ID, timestamp, scope granted, expiry, withdrawal date | Both |
3.3 Website Visitors
- Usage data: pages visited, referral source, time on site, click events.
- Technical data: IP address, browser, device type, screen resolution.
- Contact form data: name, email, and message content when you contact us.
- Cookie data: see Section 10 for full details.
Special category data: We do not intentionally collect special category data (such as health, biometric, or political data). Transaction data may occasionally reveal such information (e.g. a payment to a medical provider). If so, it is processed only to the extent necessary to deliver our service and under appropriate safeguards.
How We Use Your Data
We use your personal data only for specific, legitimate purposes. We will never sell your personal data to third parties, nor use it for unsolicited marketing without your consent.
4.1 Open Banking Services
- Retrieving account information (balances, transactions) on behalf of a business customer with your consent (AISP).
- Initiating payment transactions from your bank account on your instruction (PISP).
- Verifying account ownership to prevent fraud and protect your financial interests.
- Generating enriched transaction data and financial insights for the business customer you have authorised.
- Processing and recording consent grants, amendments, and withdrawals.
4.2 Platform Operation & Security
- Authenticating and authorising access to our API and developer dashboard.
- Detecting, investigating, and preventing fraudulent or unauthorised transactions.
- Monitoring API usage for abuse, rate-limit enforcement, and billing.
- Maintaining audit logs for regulatory compliance and dispute resolution.
- Ensuring the security and integrity of our systems (ISO 27001 controls).
4.3 Regulatory & Legal Obligations
- Complying with FCA supervisory requirements under the PSRs 2017 and Open Banking Standard.
- Reporting to the FCA, ICO, or other competent authorities as required by law.
- Responding to lawful requests from law enforcement or courts.
- Maintaining records required under anti-money laundering (AML) and counter-terrorism financing (CTF) regulations.
- Handling complaints and exercising or defending legal claims.
4.4 Business Operations
- Creating and managing your account, processing payments, and invoicing.
- Providing customer and technical support.
- Sending transactional communications (service updates, security alerts, invoices).
- Sending marketing communications about Reflow products where you have opted in — you may opt out at any time.
- Conducting anonymised analytics to improve our platform and services.
Legal Basis for Processing
We rely on the following lawful bases under Article 6 UK GDPR:
| Processing Activity | Legal Basis |
|---|---|
| Accessing bank account data (AISP services) | Consent — explicit, granular consent obtained via PSD2-compliant consent flow (Art. 6(1)(a)) |
| Initiating payment transactions (PISP services) | Contract / Consent — necessary to perform the payment service you requested (Art. 6(1)(b) / (a)) |
| Business customer account management | Contract — necessary to perform our contract with you (Art. 6(1)(b)) |
| Fraud detection and security monitoring | Legitimate interests — protecting users and the integrity of our platform (Art. 6(1)(f)) |
| FCA regulatory reporting & AML checks | Legal obligation — required under PSRs 2017, MLR 2017, and FCA rules (Art. 6(1)(c)) |
| Audit log retention | Legal obligation / Legitimate interests — regulatory record-keeping and dispute resolution (Art. 6(1)(c)/(f)) |
| Marketing communications | Consent — where you have opted in (Art. 6(1)(a)); or Legitimate interests for existing business customers (Art. 6(1)(f)) |
| Website analytics (anonymised) | Legitimate interests — improving our services (Art. 6(1)(f)) |
Where we rely on legitimate interests, we have conducted a balancing test to confirm that our interests do not override your rights and freedoms. You may request a copy of these assessments from our DPO.
Where we rely on consent, you have the right to withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.
Data Sharing & Third Parties
We do not sell your personal data. We share data only where necessary to deliver our services, meet legal obligations, or with your explicit consent. Recipients include:
6.1 UK Banks & Financial Institutions
When you connect your bank account, we communicate with your bank via the Open Banking API. Your bank acts as an independent data controller for its own processing. We transmit only the minimum data required to execute your consent or payment instruction.
6.2 Business Customers (Our API Clients)
Where you are an end-user of a Reflow-powered application, we share your open banking data with the relevant business customer strictly within the scope of the consent you have granted. The business customer acts as a separate data controller for how they subsequently use that data. They must have their own privacy policy.
6.3 Open Banking Limited (OBL)
As a member of the Open Banking ecosystem, we may share limited technical and consent metadata with OBL for the purposes of dispute resolution, consent management, and regulatory oversight.
6.4 Sub-processors
We use the following categories of trusted sub-processors, all subject to written data processing agreements (DPAs) that meet UK GDPR requirements:
- Cloud infrastructure: secure hosting and storage of platform data.
- Payment processing: collection of subscription and invoicing payments (PCI-DSS Level 1 compliant).
- Identity verification / KYB: onboarding and anti-money laundering checks on business customers.
- Customer support tooling: management of support tickets and communications.
- Analytics & monitoring: anonymised or pseudonymised platform performance data.
- Email delivery: transactional and marketing email dispatch.
You may request the current list of named sub-processors by contacting our DPO.
6.5 Law Enforcement & Regulators
We may disclose personal data to the FCA, ICO, HMRC, the National Crime Agency, or other competent authorities where required by law, court order, or in connection with the prevention or investigation of crime, including financial crime.
6.6 Corporate Transactions
In the event of a merger, acquisition, or sale of all or part of our business, personal data may be transferred as part of that transaction. We will provide notice before data is subject to a different privacy policy.
International Transfers
We store and process all personal data within the United Kingdom and European Economic Area (EEA) by default. Our primary cloud infrastructure is located in UK data centres.
Certain sub-processors (such as support software vendors) may process data in countries outside the UK/EEA. In such cases, we ensure appropriate safeguards are in place, including:
- UK Adequacy Regulations — transfers to countries recognised by the UK Government as providing adequate protection.
- UK International Data Transfer Agreements (IDTAs) — standard contractual clauses approved by the ICO for international transfers from the UK.
- UK Addendum to EU SCCs — where applicable for transfers involving EU-originating data.
You may request further information about international transfers and the specific safeguards in place by contacting dpo@reflowzone.io.
Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including satisfying regulatory, legal, accounting, and reporting requirements.
| Data Category | Retention Period | Basis |
|---|---|---|
| Open banking consent records | 5 years from consent withdrawal or expiry | PSRs 2017 regulatory obligation |
| Payment transaction records | 6 years from transaction date | PSRs 2017 / AML Regulations / Limitation Act 1980 |
| Account data (AISP) | Duration of consent + 90 days | Consent scope; deleted on withdrawal |
| Business customer account data | Duration of contract + 6 years | Contract / Legal obligation |
| AML / KYB records | 5 years from end of business relationship | Money Laundering Regulations 2017 |
| Security audit logs | 12 months (active) + 5 years (archived) | FCA SYSC / ISO 27001 |
| Marketing consent records | 3 years from last interaction or withdrawal | PECR / Legitimate interests |
| Support communications | 2 years from closure of ticket | Legitimate interests |
| Website analytics (anonymised) | 26 months | Legitimate interests |
After the applicable retention period, personal data is securely deleted or irreversibly anonymised in accordance with our data disposal procedure.
Your Rights
Under UK GDPR, you have the following rights regarding your personal data. We will respond to all valid requests within one calendar month (with a possible extension of two further months for complex or numerous requests, with notice).
Request a copy of all personal data we hold about you (Subject Access Request).
Request correction of inaccurate or incomplete personal data we hold.
Request deletion of your personal data where it is no longer necessary, or where you withdraw consent. Note: certain data must be retained for regulatory purposes.
Request that we pause processing of your data in certain circumstances (e.g. while accuracy is contested).
Receive your data in a structured, machine-readable format and/or have it transferred to another controller — where processing is consent-based or contract-based.
Object to processing based on legitimate interests or for direct marketing purposes (absolute right for marketing).
Where we make solely automated decisions that have a legal or similarly significant effect, you have the right to request human review, express your point of view, and contest the decision.
To exercise any of these rights, please contact us at privacy@reflowzone.io or by post to our registered address. We may need to verify your identity before processing your request.
Open banking consent withdrawal: You can revoke an open banking consent at any time either through our platform, through the application you used to grant consent, or directly through your bank's open banking consent management portal.
Cookies
We use cookies and similar tracking technologies on our website. By using our site, you consent to our use of cookies in accordance with this section and our separate Cookie Policy.
| Type | Purpose | Retention |
|---|---|---|
| Strictly necessary | Authentication sessions, security tokens, load balancing, fraud prevention. Required to operate the service. | Session / up to 24 hours |
| Functional | Remembering your preferences (language, region, dashboard settings). | Up to 12 months |
| Analytics | Anonymised usage data to help us improve our website and platform (e.g. page views, journeys, error rates). | Up to 26 months |
| Marketing | Where you have consented, used to personalise content and measure the effectiveness of campaigns. | Up to 12 months |
You can manage or withdraw consent for non-essential cookies at any time via our cookie preference centre (available in the site footer) or by adjusting your browser settings. Please note that disabling certain cookies may affect the functionality of our website.
Our API platform does not use marketing cookies. Strictly necessary cookies are required for authentication and security.
Security
We implement robust technical and organisational security measures to protect your personal data against unauthorised access, loss, destruction, or alteration, in accordance with our obligations under UK GDPR Article 32 and FCA SYSC requirements.
- Encryption: all data is encrypted in transit (TLS 1.2+) and at rest (AES-256).
- Access controls: role-based access control (RBAC) with least-privilege principles; multi-factor authentication enforced for all staff.
- ISO 27001 certification: our information security management system is independently certified.
- Penetration testing: regular third-party penetration tests of our infrastructure and API.
- Incident response: a documented breach response plan; we will notify the ICO within 72 hours of becoming aware of a qualifying personal data breach, and affected individuals without undue delay where required.
- Credential security: we never store your bank login credentials. Authentication with your bank is handled via OAuth 2.0 through the Open Banking Secure Customer Authentication (SCA) flow.
- Supplier assurance: all sub-processors are assessed for security compliance before onboarding and subject to ongoing review.
Children
Our services are intended for use by individuals aged 18 years or older. We do not knowingly collect personal data from children under 18. If we become aware that we have inadvertently collected personal data from a child, we will take steps to delete it promptly.
If you believe a child has provided us with personal data without parental consent, please contact us at privacy@reflowzone.io.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. The date at the top of this page will always show when the policy was last revised.
Where we make material changes that affect how we process your personal data, we will notify you by:
- Displaying a prominent notice on our website and developer dashboard;
- Sending an email notification to registered business customers at least 30 days before the change takes effect; and
- Where the change requires fresh consent, presenting a new consent request before continuing to process your data.
Your continued use of our services after a policy update constitutes your acceptance of the revised policy (except where fresh consent is required).
Contact & Complaints
If you have any questions about this Privacy Policy or how we handle your personal data, please contact us:
Data Protection Officer
Reflow Zone UK Ltd
1 Canada Square
London, E14 5AB
Right to complain: You have the right to lodge a complaint with the Information Commissioner's Office (ICO) if you believe your personal data has been processed unlawfully. The ICO can be reached at ico.org.uk/make-a-complaint, by telephone on 0303 123 1113, or by post to Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF. We would, however, appreciate the opportunity to address your concerns before you contact the ICO, so please reach out to us first.
FCA complaints: Complaints relating to our regulated payment services (AISP/PISP activity) may also be referred to the Financial Conduct Authority at fca.org.uk or to the Financial Ombudsman Service at financial-ombudsman.org.uk / 0800 023 4567.