This notice explains how we collect and use your personal data. The UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 apply to our merchants in the United Kingdom.
Who this notice covers
Our services are aimed at businesses. This notice is for the individuals behind the businesses we work with. It covers directors, legal representatives, beneficial owners, authorised signatories, and the commercial, finance and support contacts we deal with. We process their data where they act in a professional or business capacity.
Where a merchant is a corporate entity, the company itself is not a data subject and only data about the individuals behind it is personal data. Where a merchant trades as a sole trader, business data is also personal data.
Buyers who use Mondu as a payment method at a merchant’s checkout are covered by a separate notice, available at https://www.mondu.ai/en-gb/gdpr-notification-for-buyers/.
Responsible entity
Mondu GmbH (Unter den Linden 16, 10117 Berlin, Germany) is an independent controller for the platform service agreement and the commercial relationship. This covers merchant onboarding, the creditworthiness assessment, and commercial correspondence and support.
Mondu UK Ltd (Cannon Place, 78 Cannon Street, EC4N 6AF London, United Kingdom) purchases receivables from merchants in the United Kingdom. It is an independent controller for the receivables purchase, for merchant billing and invoicing, and for the customer due diligence, identity and beneficial ownership verification, screening and ongoing monitoring required of it under the Money Laundering Regulations 2017. It is registered with the Financial Conduct Authority under those Regulations and supervised by it for anti-money laundering purposes.
The two companies disclose your data to each other where a purpose requires it. Mondu GmbH carries out the customer due diligence checks as Mondu UK Ltd’s processor and on its instructions.
You can contact us at contact@mondu.ai. We will coordinate your request with the relevant controller.
Data we process
a) For the fulfilment of contractual obligations (Art. 6(1)(b) UK GDPR)
We collect the personal data needed to prepare and perform the platform service agreement and to communicate with you about our services. Alongside your company data and ownership structure, this includes the name, address, e-mail address, telephone number, date of birth, place of birth and tax identification number of your management and owners. Without this data we cannot conclude the contract.
We process billing contact details and account information to issue and collect invoices for our platform services. We retain executed contracts, contractual documents and the records of our commercial correspondence with you, including support interactions and any disputes or complaints.
b) To protect our legitimate interests (Art. 6(1)(f) UK GDPR)
Where necessary, we process your data beyond the performance of the contract to safeguard Mondu’s legitimate interests. This includes handling your enquiries and establishing, exercising or defending legal claims.
Before we enter into the platform service agreement we assess the creditworthiness and default risk of your business. Our interest is in avoiding credit losses and in extending credit responsibly. To do this we may consult a credit reference or business information agency, using your company data together with the contact details of a representative.
Our employees use generative AI tools in their day-to-day work, for example to draft, summarise, analyse or translate. Where a document or message containing your data is handled in this way, we rely on our legitimate interest in efficient business operations.
c) For compliance with legal obligations (Art. 6(1)(c) UK GDPR)
We process identification and ownership information about your management and beneficial owners. This includes their identification and contact details, date and place of birth, tax identification number, proof of identity documents, and information about ownership and control. We process it to meet our obligations under UK anti-money laundering, counter-terrorist financing and sanctions law, in particular the Money Laundering Regulations 2017, the Proceeds of Crime Act 2002 and the Sanctions and Anti-Money Laundering Act 2018. Those obligations cover customer due diligence, sanctions and politically exposed person screening, ongoing monitoring, record keeping, and reporting suspicious activity to the National Crime Agency. Any personal data we receive from you under these obligations will be processed only for the purposes of preventing money laundering, terrorist financing or proliferation financing, or as otherwise permitted by the Money Laundering Regulations 2017.
We verify identity documents and ownership information with the support of a specialist identity verification provider.
We re-screen representatives and beneficial owners periodically throughout the business relationship and monitor for changes in ownership structure and sanctions exposure. Re-screening is risk-based and may also be triggered by a change in your profile or ownership.
We process correspondence and identity data to receive, verify and answer requests to exercise data protection rights.
If you do not provide the data required for these checks we may be unable to enter into or maintain our business relationship.
Automated decision-making
We do not take decisions about you that are based solely on automated processing and produce legal effects concerning you or similarly significantly affect you. A person makes the creditworthiness assessment. The identity and document checks required for anti-money laundering purposes run by automated means, and a person reviews their outcome before any decision on your business relationship is taken.
Sources of data
Most of the data we hold about you is provided by you or by your colleagues at the merchant. We also receive personal data from the following sources:
- Credit reference and business information agencies, providing information on the financial standing and payment history of your business.
- Public commercial registers and registers of beneficial ownership and control, providing ownership and control information.
- Publicly available sanctions lists, politically exposed person databases and adverse media sources, used in our screening checks.
- Our identity verification provider, providing the results of document and identity checks.
Data deletion
If there is no legal retention period, the data will be deleted as soon as storage is no longer necessary or the legitimate interest in storage has expired. We keep the documents and information obtained for customer due diligence for five years from the end of the business relationship, as required by regulation 40 of the Money Laundering Regulations 2017. Accounting, tax and commercial records are kept for the periods set by the statutory retention obligations that apply to them.
Recipients of your data
We share your data with the following recipients to the extent necessary to provide our services and to meet legal obligations:
- Cloud hosting and infrastructure providers.
- Customer relationship management, workflow and customer support platforms.
- Identity verification, KYC, AML and sanctions screening providers.
- Credit reference and business information agencies.
- Accounting, billing and invoicing providers.
- Contract lifecycle management, electronic signature, document archiving and secure destruction providers.
- Generative AI providers supporting our employees’ day-to-day work.
- Other Mondu group companies, which process your data on our instructions.
- Competent authorities, where we are required to report or disclose.
Service providers act on our instructions as processors under a data processing agreement. Where a recipient determines the purposes of its own processing, it acts as an independent controller under its own privacy notice.
Credit reference agencies
We obtain business and risk information about your company from Dun and Bradstreet B.V. (Netherlands). To obtain a report we disclose the identifiers needed to locate your business, together with the name and business contact details of a representative where required. Dun and Bradstreet acts as an independent controller. Further information and your rights are available here.
Identity verification
We use an identity verification service provider to carry out the identity and document checks required under anti-money laundering law. This involves processing a copy of your identity document and, where applicable, a facial image compared against that document by automated means. Comparing a facial image against an identity document produces biometric data. We process that data on grounds of substantial public interest under Art. 9(2)(g) UK GDPR, read with paragraph 10 of Schedule 1 to the Data Protection Act 2018, which covers processing necessary for the prevention or detection of an unlawful act. Our obligations under the Money Laundering Regulations 2017 are why we carry the checks out. Biometric data is not retained beyond the period necessary to complete the verification.
Generative AI tooling
The generative AI tools our employees use are Gemini, provided by Google Cloud Emea Ltd., and Claude, provided by Anthropic Ireland, Limited. Both act as processors on our instructions and neither is permitted to use your data to train its models. Both host their processing in the United States. The transfer to Google relies on the UK Extension to the EU-US Data Privacy Framework. Anthropic holds no Data Privacy Framework certification, so the transfer to it relies on the UK Addendum to the Standard Contractual Clauses.
International transfers
Some recipients process data outside the United Kingdom. Several of the platforms we use for customer relationship management, customer support and invoicing are established in the United States. Where data leaves the United Kingdom we rely on UK adequacy regulations where they apply. Otherwise we rely on appropriate safeguards, being an International Data Transfer Agreement or the UK Addendum to the Standard Contractual Clauses, with supplementary measures where required. You can obtain a copy of the transfer agreement from dataprotection@mondu.ai.
Your data protection rights
You have the following rights over your personal data:
-
Access: You can ask what personal data we hold about you and obtain a copy of it.
-
Rectification: You can ask us to correct data that is inaccurate and to complete data that is incomplete.
-
Erasure: You can ask us to delete your data. A legitimate reason must exist, and no rule requiring us to retain the data must apply.
-
Restriction: You can ask us to restrict our processing of your data. A legitimate ground must exist.
-
Portability: In certain cases you can receive your data in a structured, commonly used and machine-readable format, or ask us to transmit it to a third party.
-
Objection: You can object to processing we carry out on the basis of our legitimate interests, on grounds relating to your particular situation.
Every data subject has the right to file a complaint with a supervisory authority if they believe that the processing of data concerning them violates data protection law. In the United Kingdom this is the Information Commissioner’s Office.
Our Data Protection Officer
Our Data Protection Officer will be happy to provide you with more information about data protection under the following contact details:
Name: Fraser Blakeway
Email: dataprotection@mondu.ai
Address: Mondu Financial Services B.V., Attn: Fraser Blakeway, Herengracht 168, 1016 BP Amsterdam, Netherlands