Able Finance - Privacy Policy - Full Policy

September 12, 2026

Version 2.0 | Last updated 18 July 2026 | Applies to able.finance and the Able mobile and web applications.

Able Finance handles money, and money leaves a trail. This policy sets out exactly what we record about you, why each piece of it is necessary, who else sees it, and what you can ask us to do with it. Where we are required by law to keep or disclose something, we say so plainly rather than leaving it implied.

01. Who we are

In this policy, "Able", "we", "our" and "us" mean AKI HOLDINGS LIMITED, registered at DD-15-134-004-007, Level 15, WeWork Hub71, Al Khatem Tower under company number 33930.

Which Able Company Holds Your Data

Able operates through more than one company. The Able company that provides your account or card is the controller of your personal information for that product, and it is the company named in the terms and conditions you accepted. We tell you which one it is when you apply, and you can check it at any time in your account settings.

Our Partners

Parts of our service are delivered with regulated partners -- including our card issuing partner, whose cards are issued through channels in Singapore and Hong Kong depending on which card you hold, along with our banking and payment processing partners. Where a partner is a controller of your information in its own right, its own privacy notice applies alongside this one, and we identify that partner to you at the point it becomes relevant.

Notices That Sit Alongside This One

Some products and processes have their own notice with more detail -- for example our cookie policy, and the notices shown when you complete identity verification or apply for a specific product. We also show short, plain explanations inside the app at the moment you use a feature for the first time, so you can see what is being collected before you decide.

Language

We may publish this policy in languages other than English. If there is a conflict between versions, the English version is the one that applies.

02. Information we collect
Information You Give Us
  • Identity: full name, date of birth, place of birth, nationality, residential address, tax residency and tax identification number, and the identity document you upload -- its type, number, issuing country and expiry date.
  • Contact: email address, mobile number, and postal address for card delivery.
  • Biometric data: where identity verification requires it, your photo or short video, and the facial scan data derived from it, compared against your identity document to confirm you are the document holder.
  • Business details if you apply as a company: trading name, registration number, registered and operating addresses, ownership and control structure, directors and beneficial owners, and their identity information. We record the SIZE of each holding, not only who holds it, because sanctions rules require us to add holdings together -- several sanctioned parties each holding a minority can still put a company out of reach. For the same reason we ask whether any government or government body owns or controls part of the business.
  • Financial background: occupation or business activity, expected account activity, source of funds and, where relevant, source of wealth, plus the documents you provide to evidence them.
  • Correspondence: messages, support tickets, survey responses and documents you send us. We may record and monitor calls and in-app chats to keep accurate records, check instructions, resolve disputes, train our teams and improve service quality. We tell you at the start of a call when it is being recorded.
Information Your Account Activity Generates
  • Balances, top-ups, transfers and statements.
  • Card details held in protected form: the card reference, last four digits, expiry, status, and the limits and controls applied.
  • Transaction records -- amount, currency, date and time, merchant name, merchant category code, merchant country, the country and terminal where the card was used, exchange rate applied, counterparty name and account details, and whether the transaction was approved, declined, reversed or disputed.
  • Authentication and card-security events: failed verification attempts, PIN retry counts, freeze and unfreeze actions, device registrations and blocks applied.
  • Disputes, chargebacks and fraud claims, and the evidence gathered to resolve them.
Information Collected Automatically
  • IP address and the approximate location derived from it, device model and operating system, browser type and version, app version, language, time zone, mobile network information, and whether a VPN is in use.
  • A unique device identifier and device fingerprint used for security and fraud prevention.
  • Behavioural signals such as typing rhythm, scrolling and navigation patterns, used to tell a genuine session apart from an automated or hijacked one.
  • Log data: screens and pages viewed, features used, timestamps, referring pages, response times, crashes and errors.
  • Cookies and similar technologies, described in section 14.
Location

If you switch location services on, we use your device location to help confirm that a card transaction is happening where you are, which reduces false declines and helps detect fraud. You can turn this off at any time in your device or app settings, and doing so does not stop you using your account.

Information We Create About You

We also generate new information by analysing what we already hold. This includes your customer risk rating, fraud and transaction risk scores, spending and activity patterns used to spot anomalies, eligibility indicators showing which products we can offer you, and -- where you have not opted out -- segments used to make our communications relevant.

Information From Third Parties
  • Identity verification and document-authentication providers, including biometric comparison providers.
  • Sanctions, politically exposed person and adverse media screening providers.
  • Fraud prevention agencies, and credit reference agencies where we use them to confirm your identity and address. Where you apply for a product involving credit, we explain any additional checks before you apply.
  • Publicly available sources -- company registers, official databases, directories, media reports and public social media profiles -- used for enhanced due diligence, sanctions screening and fraud investigation.
  • Our card issuing partner, processors and the card networks, who return authorisation, settlement and dispute data to us.
  • Where a partner or reseller introduced you to Able, the onboarding information they pass to us.
  • Occasionally, other Able customers -- for example, where someone reports that a payment was sent in error or reports misuse of the service, and provides evidence.
We do not ask for special category data such as health, religious or political information. If a document you upload happens to reveal it -- a place of birth or a religious title on an identity page, for example -- we process only what is necessary to verify the document. Biometric data is special category data, and we handle it under the specific grounds set out in section 5.
03. Information about other people

Sometimes we have to ask you about someone else -- a joint account holder, a beneficial owner or director of your business, a person who sent you money, or a family member whose funds are involved in a transaction. We ask only because anti-money-laundering and sanctions rules require it.

If you give us personal information about another person, you confirm that you are entitled to do so and that you have shown them this policy. If you would rather we contacted them directly, tell us and we will.

04. How we use your information

Purpose: Opening your account
What This Involves: Verifying your identity, checking eligibility, and deciding whether we can offer you an account or card.

Purpose: Running the service
What This Involves: Processing top-ups, payments and card transactions, confirming payee details before a transfer leaves, producing statements, issuing and replacing cards, and applying account limits and controls.

Purpose: Financial crime prevention
What This Involves: Screening, ongoing monitoring, investigation and reporting, as described in section 6.

Purpose: Fraud and security
What This Involves: Detecting unusual activity, protecting accounts from unauthorised access, authenticating you, and investigating suspected fraud or misuse.

Purpose: Support and disputes
What This Involves: Answering questions, handling complaints, and pursuing chargebacks and dispute claims on your behalf.

Purpose: Spending insights
What This Involves: Showing you where your money goes, categorising transactions, and flagging activity you may want to check.

Purpose: Improving the product
What This Involves: Understanding how features are used, fixing faults, testing improvements, and developing and testing the models described in section 7.

Purpose: Protecting our business
What This Involves: Managing risk, recovering amounts you owe us including any negative balance, enforcing our terms, defending legal claims, and dealing with harmful or unlawful use of the service.

Purpose: Legal and regulatory
What This Involves: Meeting obligations to regulators, tax authorities, courts, card networks and our partner institutions.

Purpose: Marketing
What This Involves: Sending product news and offers in line with your choices -- see section 10.

05. Legal basis for processing

Where data protection law such as the UK and EU GDPR applies to you, we rely on the following grounds:

Ground: Performance of a contract
When We Rely On It: Opening and operating your account, processing your payments, and providing support.

Ground: Legal obligation
When We Rely On It: Identity verification, record keeping, sanctions screening, transaction monitoring, suspicious activity reporting and tax reporting. Where United States law reaches our activity this includes the Bank Secrecy Act, Title III of the USA PATRIOT Act and the regulations made under them; the card networks require the same standards of us by contract, so these obligations reach us through two routes at once.

Ground: Legitimate interests
When We Rely On It: Fraud prevention, network and information security, product improvement, debt recovery, managing risk across our business, and direct marketing to existing customers where the law permits. We balance these against your rights, and you may object -- see section 17.

Ground: Substantial public interest
When We Rely On It: Processing biometric data to verify identity, and processing limited special category or criminal-offence data where anti-money-laundering, sanctions or fraud prevention law requires it.

Ground: Vital interests
When We Rely On It: Rare cases where using your information is necessary to protect someone's life -- for example, sharing details with emergency services when we have reason to believe there is an immediate risk to you or another person.

Ground: Consent
When We Rely On It: Optional marketing, non-essential cookies, location services, and biometric checks where your jurisdiction requires separate consent. Some countries -- mainland China among them -- require consent to be given separately for particular uses, and require that it expressly covers sending your information abroad. Where that applies we ask for it in those terms rather than relying on a single blanket permission. You can withdraw consent at any time, and doing so does not affect processing that already took place.

06. Identity, sanctions and financial crime checks

We are required to know who our customers are and to monitor how accounts are used. This is not optional for us, and it is the reason for much of what we collect.

  • Customer due diligence. We verify your identity and, for business accounts, the identity of owners and controllers, before the account is fully enabled. Card network rules allow some card products to be issued without identifying the holder. We do not use them: every Able account and card is held by an identified person, and we do not offer anonymous products.
  • Enhanced due diligence. Where your profile, country of residence, industry or activity presents higher risk, we ask for more information -- typically about source of funds or source of wealth -- and the account may stay limited until we receive it.
  • Screening. Names, dates of birth, nationalities and related details are screened against sanctions lists, politically exposed person data and adverse media, at onboarding and on an ongoing basis. The sanctions lists include those published by the United States (the Specially Designated Nationals list and the Consolidated list), the European Union (its restrictive measures lists) and the United Nations (the Security Council Consolidated list), together with any local list that applies to you. Ongoing means exactly that: we re-screen as the lists change, not only when you join.
  • Sectoral sanctions. Some sanctions programmes restrict particular kinds of dealing rather than barring a person outright. Where one applies, we may be able to continue serving you but only within the limits that programme sets, and we will tell you what we can and cannot do.
  • Who else gets screened. The rules reach beyond our own customers. We must also screen our service providers, agents and any programme manager working on our behalf, so screening data is generated about people who are not our customers at all.
  • Restricted jurisdictions. We cannot open accounts or issue cards to residents or nationals of certain countries and regions, and transactions connected to some countries, currencies or merchant categories are blocked. These lists come from sanctions authorities, our regulators, our partner institutions and the card networks, and they change.
  • The card lists work in two tiers, and the difference matters to you. For some nationalities a card application is refused and transactions are declined as well. For others the application is refused but transactions on any account you already hold continue to process normally. The two cards we issue carry different lists, so a nationality may be refused on one card and accepted on the other. If a restriction applies to you we will tell you which of these situations you are in, so far as we are lawfully able to.
  • Activity that damages a card network's reputation. Separately from anything unlawful, the card networks prohibit activity that in their opinion damages their reputation, their brands or the integrity of their systems -- whether or not any other rule covers it, and including activity we only facilitate rather than carry out ourselves. Because that judgement belongs to the network rather than to us, we may have to restrict or close an account on that basis even where nothing illegal has happened.
  • Ongoing monitoring. Transactions are monitored for patterns that suggest fraud, money laundering, terrorist financing or misuse of a card, including unusual velocity, sudden cross-border activity, repeated failures, card testing and refund manipulation. Card network rules also require us to watch money arriving from cryptocurrency exchanges, transfers used to fund other accounts or instruments, and cash-out activity, so those patterns receive particular attention.
  • Reporting to the card networks. If screening produces a confirmed sanctions match, network rules require us to disable your access, tell the network promptly, and give it details of the steps we took. So a confirmed match is disclosed beyond us and beyond the authorities.
  • Reporting. Where we are required to report a suspicion to the authorities, we will do so. The law may prohibit us from telling you that a report has been made, or from explaining why an account was restricted.
To keep our controls effective, we cannot publish every detail of how they work -- explaining a rule precisely would help people evade it. We will always tell you as much as we lawfully can about a decision that affects you.
07. Automated decisions, profiling and AI

Some decisions are made by our systems without a person reviewing them first, because payments happen in seconds. These include:

  • Approving or declining a card authorisation.
  • Assigning your account a risk rating that affects limits and the level of checking applied.
  • Deciding whether you are eligible for a product or feature.
  • Temporarily freezing a card, restricting an account, or closing it, where we detect fraud, financial crime or a breach of our terms.
  • Flagging activity for review by our risk and compliance team.
How We Use Artificial Intelligence

We use statistical models, machine learning and -- in some places -- generative AI. Specifically:

  • Fraud and financial crime models that score transactions and behaviour in real time.
  • Transaction categorisation that turns merchant data into readable spending insights.
  • Support tooling that drafts or suggests replies, summarises your case history, and routes your query. A person remains accountable for the answer you receive on anything material.
  • Content selection for in-app messages and marketing, where you have not opted out.
  • Model development and testing, using your data to build, train, test and check our models for accuracy and fairness. We use pseudonymised or aggregated data for this wherever it is workable.

We do not use your personal information to train third-party general-purpose AI models, and our suppliers are contractually barred from using it to train theirs.

Your Right To A Human

Where an automated decision has a legal or similarly significant effect on you, you can ask for it to be reviewed by a person, explain your circumstances, and contest the outcome. Write to us at the address in section 21.

08. Cards, payments and the people at the other end

When you pay with an Able card, the transaction is processed through our card issuing partner, its processor and the relevant card network before it reaches the merchant's bank. Each of them receives the data needed to authorise, clear and settle the payment -- including the card reference, amount, currency, merchant details and location. Those parties act as controllers under their own rules and privacy notices. Cards can be used wherever the relevant card network is accepted, subject to the country, currency and merchant-category restrictions in section 6.

What The Card Network Does With Your Data

The card network is not simply processing payment data on our instructions. Under its own rules it is also a controller in its own right, and it uses the data it receives for its own purposes -- accounting, auditing and billing; fraud, financial crime and risk management; defending itself against claims and litigation; deciding disputes; developing and improving its products; internal research, reporting and analysis; turning data into anonymised form to build data-analytics products; and meeting its own legal obligations.

We cannot switch that off on your behalf. It is a condition of being able to issue cards at all, and it applies to every card issued on that network by any institution, not only to us.

If We Fail To Settle

Card network rules provide that if we fail to meet a settlement obligation, the network may satisfy it in our place. If it does, it becomes entitled to the records behind that debt -- including the name and address of each cardholder involved -- and we must hand them over promptly. It may also refuse to authorise transactions while it protects its position.

This has not happened and we do not expect it to. We set it out because the obligation is real, it would involve your information, and in that situation the network's settlement rules take priority over the data-protection terms in its own rulebook.

Sending And Receiving Money

When you send a transfer, payment rules require us to include certain details about you -- typically your name and account identifier -- so the receiving institution can process it. When someone pays you, we give the sender confirmation of the account details, which may include your name. This is standard across all payment institutions and is not something either of us can opt out of.

Confirmation Of Payee

Before a transfer leaves your account, we may check the name you entered against the name on the destination account and tell you whether it matches. This protects you from misdirected payments and from impersonation scams.

Payments Sent By Mistake

If money reaches your account in error, we may share your details with the sending institution or the sender so the payment can be recovered. If you send money in error, we will ask the receiving institution to do the same for you.

Wallets

Where you add a card to a mobile wallet, the wallet provider processes the data needed to create and manage that token. We store full card numbers only in protected, tokenised form, and our staff cannot retrieve them.

09. Linked accounts and open banking

If you connect an account you hold at another institution, we receive the data you authorise -- typically balances, transactions and account details -- and use it only for the purpose you connected it for. Your permission lasts until you withdraw it, and you can disconnect a linked account at any time in your settings. Where another provider connects to your Able account with your permission, we share the data that permission covers, and you can withdraw it the same way.

10. Marketing and your choices

Where the law allows us to market to existing customers, we will send you news about Able products by email, push notification and in-app message unless you tell us not to. Where the law requires your consent first, we ask for it before sending anything.

We personalise these messages using how you use the service, so they are relevant rather than generic. You can object to that profiling separately from objecting to the marketing itself.

To stop marketing, use the privacy settings in the app, click unsubscribe in any email, or write to us. Two things to know: opting out does not stop service messages -- security alerts, statement notices, terms changes and scam warnings, which we have to send you -- and you may still see general product information inside the app.

We do not pass your details to other organisations for their own marketing without your permission.

11. Who we share information with

We do not sell your personal information. We share it only where it is needed to deliver the service, meet a legal duty, or protect against fraud:

  • Other Able companies -- to provide the service, protect customers and systems from fraud, let you move between Able products without repeating onboarding, and develop our products.
  • Regulated partners -- our card issuing partner, banking partners and payment processors, and the card networks.
  • The people and businesses you pay, and who pay you -- as described in section 8.
  • Joint account holders -- where you hold an account jointly, each holder can see the account's transactions and balances.
  • Verification and screening providers -- identity, document, biometric, sanctions, PEP and adverse media providers.
  • Fraud prevention agencies and other financial institutions -- to check identity and investigate suspected fraud.
  • Technology suppliers -- cloud hosting, data storage, communications, customer support tooling and analytics, acting on our instructions under written contracts. A supplier may in turn engage its own sub-contractors to process your information; our sanctions, politically exposed person and adverse media screening, for example, is delivered by one provider working through another. We remain responsible to you for the whole chain, and each link is bound to the same standard.
  • Card networks exercising their audit rights -- a network may require an examination or audit of us, at our expense and by people of its choosing, to confirm we are meeting its rules. That can include access to customer records. It applies regardless of any examination our regulators already carry out, and we may not obstruct it.
  • Debt collection agencies -- where you owe us money and have not responded to us.
  • Professional advisers -- auditors, lawyers and insurers, bound by confidentiality.
  • Authorities -- regulators, financial intelligence units, tax authorities, law enforcement and courts, where we are required or permitted to disclose. This includes emergency services where we believe someone's life is at risk.
  • Advertising and social platforms -- for campaign measurement and audience matching, we may share a limited, hashed identifier such as your email address. Platforms may use it only for the purpose we specify. You can opt out in your privacy settings.
  • Corporate transactions -- a buyer or investor in connection with a merger, acquisition, restructuring or portfolio sale, under confidentiality obligations. We will tell you if this affects who controls your data.
  • Anyone you authorise -- a lawyer, accountant, attorney or family member acting for you. We will ask for proof of their authority.
A consequence worth knowing. If we or a fraud prevention agency record that you present a fraud or money laundering risk, that record may be visible to other organisations. It can lead to other companies refusing you services, financing or employment, and those agencies may keep the record for several years. If you believe such a record is wrong, contact us and we will investigate.

We vet every company before sharing personal information with it, assess the controls it has in place, and bind it contractually to use the data only for the purpose we specify. We require every third party with whom we share your personal information -- including the partners, suppliers and any parent, subsidiary or related entities described above -- to provide the same or equal protection of your personal information as set out in this policy.

12. Anonymous and aggregated information

We combine data across many customers to produce statistics -- spending trends, product usage, forecasting and regulatory reporting. Once combined, the result cannot be linked back to you as an individual, and we may share it internally or with third parties. Anonymised data is no longer personal information, so the rights in section 17 do not apply to it.

13. Where your data is stored and transferred

Able operates across several regions, and our partners and suppliers do too. Your information may be stored or accessed in countries other than the one you live in. Our primary hosting is in the United Arab Emirates. International payments necessarily involve sending data to institutions in the destination country.

Because our hosting is in the United Arab Emirates, the ADGM Data Protection Regulations 2021 apply to our processing alongside any law that applies where you live. Where our data-protection duties and our anti-money-laundering duties pull against each other -- deletion against record-keeping, for instance -- the financial crime obligations take precedence, because we are not permitted to delete what the law requires us to keep.

Card payments are international by design. The card network, our issuing partner and their processors move authorisation, clearing and settlement data across borders under their own transfer rules, and several countries -- mainland China and Brazil among them -- impose additional conditions and their own liability rules on those transfers. We cannot route a card payment around this; it is how the network functions.

Wherever your information is handled, we protect it to the standard set out in this policy. Where the law of your country restricts sending personal information abroad, we only do so using a lawful transfer method -- for example, sending it to a country the relevant authority has approved, or putting a contract in place that binds the recipient to protect your data to the same standard. You can ask us which method applies to you by writing to us.

14. Cookies, pixels and tracking

Type: Strictly necessary
What It Does: Keeps you signed in, protects sessions, balances load and blocks abuse. These cannot be switched off.

Type: Preferences
What It Does: Remembers language, currency display and interface choices.

Type: Analytics
What It Does: Tells us which pages and features are used, and where people get stuck. Set only with your consent where consent is required.

Type: Marketing
What It Does: Measures campaign performance and limits repeat advertising. Off unless you opt in.

Our marketing emails contain small tracking pixels that tell us whether the email was delivered, opened and clicked, along with your IP address, browser and email client type. We use this to measure campaign performance. Turning off marketing emails turns this off too.

You can change your choices at any time through the cookie settings link in our footer, and through your browser controls. Blocking necessary cookies will stop parts of the service from working.

15. How we protect your information

We apply technical and organisational measures appropriate to the sensitivity of financial data:

  • Encryption of data in transit over TLS, and encryption of stored data.
  • Tokenisation of card numbers, and restricted handling of identity and biometric documents.
  • Role-based access control, least-privilege access, and logging of access to customer records.
  • Multi-factor authentication for our systems, and step-up verification for sensitive actions on your account.
  • Segregated environments, vulnerability management, independent testing and continuous monitoring.
  • Staff vetting, confidentiality obligations and mandatory data protection and financial crime training.
  • Compliance with the Payment Card Industry Data Security Standard across the card programme, and a contractual requirement that our suppliers meet the same standard.
  • A documented incident response process, including notification to regulators and to affected people where a breach requires it. Our partners and the card networks are required to tell us without undue delay if personal data they hold about you is breached, and to help us meet our own obligations -- notifying authorities and you, and giving you a route to protect yourself.

No system can be made immune to every risk, and we do not claim otherwise -- data can also be intercepted on its way to us, which is outside our control.

What We Need From You
  • Keep your password, PIN and one-time codes to yourself. Anyone who has them can reach your money and your data.
  • Able will never ask you for a password, PIN or one-time code by phone, email or message. If someone does, it is not us -- end the contact and report it in the app.
  • Turn on every authentication option we offer, and tell us immediately if you think someone else has access.
  • Do not post account details or personal information on public channels, including our social media pages.
16. How long we keep your information

Category: Identity and due diligence records
Retention Period: Ten years, counted from the later of the transaction completing, the relationship ending, or the account closing.

Category: Transaction and card records
Retention Period: Ten years, counted the same way.

Category: Financial crime investigations and reports
Retention Period: For the period set by the relevant law, which may exceed the periods above.

Category: Support correspondence, call recordings and complaints
Retention Period: Up to six years after the matter is closed.

Category: Applications we declined
Retention Period: Kept for a limited period to record the decision and prevent repeat or fraudulent applications, then deleted.

Category: Biometric data
Retention Period: Deleted or irreversibly anonymised once verification is complete and any legally required record of the check has been made.

Category: Website and analytics data
Retention Period: Typically up to 24 months, or less where you withdraw consent.

Why Ten Years

United Arab Emirates law sets a minimum of five years for these records, and the ADGM rules that apply to part of our business set six. Our own group standard is ten, and where two standards apply we follow the stricter one -- so ten years is what we hold you to and what we hold ourselves to. We would rather tell you the real number than quote a legal minimum we do not actually operate to.

A legal hold -- issued when there is an investigation, a claim or a regulatory request -- suspends deletion immediately, across our systems and our partners', and overrides every period in this table until it is lifted.

These periods are ours. The card networks, our issuing partner and our screening providers each hold their own copy of the data they received and keep it on their own schedules, which we do not set. Their rules require them to keep it no longer than their purposes need, and then to delete, anonymise or return it -- but the timing is theirs rather than ours, and deleting your data from our systems does not by itself remove it from theirs.

We may keep information longer where it is needed for an ongoing or potential legal claim, an investigation, or a regulatory request. Fraud prevention agencies set their own retention periods, which can run to several years. When a period ends, we delete the information or anonymise it so it can no longer identify you.

17. Your rights

Right: Be informed
What It Means In Practice: To know how we use your information -- through this policy, the notices that sit alongside it, and the explanations shown in the app.

Right: Access
What It Means In Practice: A copy of the personal information we hold about you. We cannot give you information about other people, anything tied to an ongoing fraud or criminal investigation, or our legal advice.

Right: Correction
What It Means In Practice: To have inaccurate or incomplete information fixed. We may need to verify the new details first.

Right: Deletion
What It Means In Practice: To have information erased where there is no longer a good reason to hold it. As a regulated firm we must keep certain records even after your account closes, and we will always tell you when that applies.

Right: Portability
What It Means In Practice: A copy of the data you gave us, in a structured, machine-readable format.

Right: Restriction
What It Means In Practice: To have us pause our use of your information while we check its accuracy, or while we consider an objection you have raised.

Right: Objection
What It Means In Practice: To object to processing based on legitimate interests, including profiling. If we have an overriding reason we will say so -- and if the objection concerns data we need to run your account, we may have to close it.

Right: Withdraw consent
What It Means In Practice: At any time, for anything based on consent, without affecting what was lawful before.

Right: Human review
What It Means In Practice: Of a significant automated decision, with the chance to explain your position and contest the outcome.

Right: Opt out of marketing
What It Means In Practice: Through app settings, the unsubscribe link, or by telling us.

Right: Complain
What It Means In Practice: To us first, and to your data protection authority if our answer does not satisfy you.

Whether a right applies depends on where you live, the information involved, and why we hold it. We will tell you which of these applies to your request rather than declining without explanation.

18. How to exercise your rights
  • Use the privacy settings in the app, or email privacy@able.finance.
  • You can request deletion of your account directly in the app, from your account settings. As a regulated firm we must keep certain records even after your account closes -- we will delete what we are not required to keep, and tell you what we must retain and for how long.
  • We will ask you to prove your identity before we act, because acting on a request from the wrong person would be the worse outcome.
  • If someone is acting for you, we will ask for proof of their authority.
  • We respond within one month, and will tell you if a complex request needs longer.
  • There is normally no charge. The law allows us to charge a reasonable fee, or decline, if a request is clearly unfounded or excessive -- we would explain why first.
19. Age requirement

Able's services are for adults. We do not offer accounts or cards to anyone under 18, and we do not knowingly collect information from children. If you believe a minor has given us personal information, contact us and we will delete it, subject to any record-keeping obligation that applies. If we ever offer a product for under-18s, it will have its own notice written for that audience, and a parent or guardian will approve the account.

20. Changes to this policy

We update this policy when our services, partners or legal obligations change. The "last updated" date at the top shows the current version. If a change materially affects how we use your information, we will notify you by email or in the app before it takes effect, and where the law requires it we will ask for your consent.

21. Contact and complaints

For any question about this policy, or to exercise a right:

  • Email: admin@able.finance
  • Data Protection Officer: Mohamed Tayel, tayel@able.finance
  • Post: AKI Holdings Limited, DD-15-134-004-007, Level 15, WeWork Hub71, Al Khatem Tower

If you are not satisfied with our response, you can complain to the data protection authority in your country.