1
Privacy Policy
Last updated: November 1, 2023
We at XNB Pty Ltd respect your privacy and is committed to protecting your personal data.
This privacy policy ("Policy") applies to the processing of personal data by XNB Pty Ltd, (collectively, "XNB", "we", "us",
"our") regarding the use of our services or products and the access of our website at www.xnb.com or our mobile
application (collectively, our "Services"). We will inform you as users of our Services in this Policy as to how we look
after your personal data and tell you about your privacy rights and how the law protects you.
We may update this Policy from time to time by posting amended versions including the effective date of the amended
version.
Our Services are not intended for minors below the age of 18 years ("Minors") and we do not knowingly collect data
relating to any Minors.
CONTENTS OF THIS POLICY
1. PURPOSE OF THIS PRIVACY POLICY
2. PERSONAL DATA WE COLLECT
3. HOW IS YOUR PERSONAL DATA COLLECTED?
4. HOW WE USE YOUR PERSONAL DATA
5. DISCLOSURES OF YOUR PERSONAL DATA
6. CROSS BORDER DATA TRANSFERS
7. DATA SECURITY
8. DATA RETENTION
9. YOUR LEGAL RIGHTS AND CHOICES
10. HOW TO CONTACT US
1 PURPOSE OF THIS PRIVACY POLICY
1.1 This Policy aims to give you information on how XNB collects and processes your personal data through
your use of our Services, including any data you may provide through our website or our mobile
application or other services when you sign up, register or continue using our Services.
1.2 It is important that you read this Policy together with any other privacy policy we may provide on specific
occasions when we are collecting or processing personal data about you so that you are fully aware of
how and why we are using your data. This Policy supplements other notices and privacy policies and is
not intended to override them.
1.3 This Policy is in accordance with Australian Privacy Principal on the Protection of Personal Data (the
'Data Protection Legislation').
2
Controller
1.4 We have appointed a data protection officer (DPO) who is responsible for overseeing questions in relation
to this Policy. If you have any questions about this privacy policy, including any requests to exercise your
legal rights, please contact the DPO using the details set out below.
1.5 If you have any questions about this Policy or our privacy practices, please contact our DPO at
info@xnb.com.
Changes to the privacy policy and your duty to inform us of changes
1.6 We keep our Policy under regular review. This version was last updated on November 1, 2023. Historic
versions can be obtained by contacting us via the contacts details set out in in 1.5.
1.7 It is important that the personal data we hold about you is accurate and current. Please keep us informed
if your personal data changes during your relationship with us.
Third-party links
1.8 This website may include links to third-party websites, plug-ins and applications. Clicking on those links
or enabling those connections may allow third parties to collect or share data about you. We do not control
these third-party websites and are not responsible for their privacy statements. When you leave our
website, we encourage you to read the privacy policy of every website you visit.
2 PERSONAL DATA WE COLLECT
2.1 Personal data means any data or information about an individual from which that person can be identified.
It does not include data or information where the identity has been removed, which is referred to as
anonymous data.
2.2 We may collect, use, store and transfer different kinds of personal data about you while you use our
Services, which we have grouped together as follows:
a) Identity Data includes full legal name (including first name, maiden name and last name), username
or similar identifier, title, date of birth, place of birth, nationality, government issued identification
document (such as passport, identification card), your live facial image for verification.
b) Contact Data includes residential address, proof of residential address such as utility bills, country of
residence, email address and telephone numbers.
c) Background Data includes your employment status, business type, political background, close
connections, geographical location/exposure, relationships with politically exposed persons, risk
assessment information, compliance assessment information, information provided by personal
referrals.
d) Financial Data includes description of source of funds, source of wealth and related documents, bank
account, payment card details, virtual currency accounts, stored value accounts.
e) Transaction Data includes details about payments to and from you and other details of products and
services you have subscribed from us.
f) Technical Data includes internet protocol (IP) address, your login data, browser type and version, time
zone setting and location, browser plug-in types and versions, operating system and platform, device
data, MAC address, and other technology on the devices you use to access this website.
3
g) Profile Data includes your username and password, requests and transaction history of our Services
made by you, your interests, preferences, feedback and any other responses you provide in your
communication with us including our customer support.
h) Usage Data includes information about how you use our Services.
i) Marketing and Communications Data includes your preferences in receiving marketing from us and
our third parties and your communication preferences.
2.3 We will collect your live facial image through us or our third party service providers for the purpose of
checking and verifying your identity for client on-boarding purposes. The foregoing may constitute
Sensitive Personal Data, which is defined as any data that directly or indirectly reveals an individual's
family, racial origin, political or philosophical opinions, religious beliefs, criminal records, biometric data,
or any data related to the health of the individual (including physical, psychological, mental, genetic or
sexual condition, health care services and health status).
We will only collect Sensitive Personal Data from you with your explicit consent and will only use such data for
the specified purpose in the table under 4.2 below.
2.4 If you fail to provide personal data
a. Where we need to collect personal data by law, or under the terms of a contract we have with
you, and you fail to provide that data when requested, we may not be able to perform the contract we have or
are trying to enter into with you (for example, to provide you with our Services). In this case, we may have to
cancel our Services you have with us but we will notify you if this is the case at the time.
3 HOW IS YOUR PERSONAL DATA COLLECTED?
3.1 We use different methods to collect data from and about you including through:
Direct interactions. You may give us your Identity, Contact and Financial Data by filling in forms or by
corresponding with us by email, phone, instant messaging through customer service, or post or otherwise.
Automated technologies or interactions. As you interact with our website or mobile application, we will
automatically collect Technical Data about your equipment, browsing actions and patterns. We collect this
personal data by using cookies, server logs and other similar technologies. We may also receive Technical
Data about you if you visit other websites employing our cookies.
Third parties or publicly available sources. We may receive personal data about you from various third
parties and public sources such as background check agencies, fraud and crime prevention agencies, third
party individuals, information on the internet available to the public.
4 HOW WE USE YOUR PERSONAL DATA
o Lawfulness of Processing
o
4.1 We will only use your personal data when the law allows us to. Most commonly, we will use your personal
data in the following circumstances:
b) Where it is necessary to perform the contract we are about to enter into or have entered into with you as a
party (such as providing the Services to you).
c) Where we have obtained your consent (in a clear, simple and unambiguous manner, obtained electronically
or in writing)
d) Where we need to comply with a legal obligation.
4
Purposes for which we will use your personal data
4.2 We have set out in the table below, a description of the purposes and lawfulness of processing your
personal data.
Purpose/ Activity
Type of Personal data
Lawfulness of Processing
Client on-boarding process:
Carrying out customer risk
assessment, client due diligence,
Anti-
Money Laundering ("AML")
checks and Know Your
Customers ("KYC") checks
1) Identity Data
2) Contact Data
3) Financial Data
4) Background Data
To assess the level of client due
diligence required and to carry out our
legal and regulatory obligations, such as
to assess and mitigate AML and financial
crime risks, as well as suitability and
appropriateness of certain products for
you.
To register you as our user/ new
customer
1) Identity Data
2) Contact Data
3) Financial Data
To enable us to register and sign you up
as our user and perform our contractual
obligations with you.
To process and perform our
Services for you
1) Identity Data,
2) Contact Data
3) Financial Data
4) Transaction Data
5) Technical Data
6) Profile Data
To provide you with your prescribed
Services and to perform our contractual
obligations with you.
To manage, process, collect,
transfer payments, fees, charges
for our Services
1) Identity Data
2) Contact Data
3) Financial Data
4) Transaction Data
5) Profile Data
As part of providing you our Services to
perform and complete the contractual
obligations.
To manage and prevent AML and
financial crime risks, to conduct
sanctions screening, fraud and
other background checks and to
prevent re-onboarding risks in the
future by compiling an internal
blacklist of rejected customers
1) Identity Data
2) Contact Data
3) Background Data
4) Financial Data
To prevent AML and financial crime risks
and to abide by legal obligations.
5
5) Technical Data
6) Transaction Data
To manage our relationship with
you which will include:
b.
Notifying you about
changes to our terms
or Policy;
Asking you to leave a review or
take a survey
1) Identity Data
2) Contact Data
3) Profile Data
4)
Marketing and
Communications Data
To provide you with updated information
on the Policy and to review the quality of
our services for review and
improvement. To perform our contractual
obligations and legal obligations
regarding data protection.
To deliver relevant website
content and advertisements to you
and measure or understand the
effectiveness of the advertising we
serve to you
1) Identity Data,
2) Contact Data
3) Profile Data
4) Usage Data
5)
Marketing and
Communications Data
To understand and study how our users
use our Services, to allow us to develop
the appropriate products and services
and grow our business and to inform
users of our marketing strategy with
consent, if required.
To use data analytics to improve
our
website, products/services,
marketing, customer relationships
and experiences
1) Technical Data
2) Usage Data
3) Profile Data
To analyse user information for providing
improved services and user experience
with consent, if required. .
To make suggestions and
recommendations to you about
our Services that may be of
interest to you
2) Identity Data
3) Contact Data
4) Technical Data
5) Usage Data
6) Profile Data
7)
Marketing and
Communications Data
To provide suggestions to users that
suits their interests. For development
and growth of our business. All with
consent, if required.
o Promotional offers from us
4.3 We may use your Identity, Contact, Technical, Usage and Profile Data to form a view on what we think
you may want or need, or what may be of interest to you. This is how we decide which products, services
and offers may be relevant for you ("Marketing Communications"). You will receive Marketing
Communications from us if you have provided explicit consent.
6
o Third-party marketing
4.4 We will get your explicit opt-in consent before we share your personal data with any third party for
marketing purposes.
o Opting out
4.5 You can ask us or third parties to stop sending you marketing messages at any time by clicking the opt-
out links on any marketing message sent to you or by contacting us at info@xnb.com any time.
4.6 Where you opt out of receiving these marketing messages, this will not apply to personal data provided
to us in connection with the use of our Services.
o Cookies
4.7 You can set your browser to refuse all or some browser cookies, or to alert you when websites set or
access cookies. If you disable or refuse cookies, please note that some parts of this website may become
inaccessible or not function properly.
o Change of purpose
4.8 We will only use your personal data for the purposes for which we collected it, unless we reasonably
consider that we need to use it for another reason and that reason is compatible with the original purpose.
If you wish to get an explanation as to how the processing for the new purpose is compatible with the
original purpose, please contact us. Otherwise, we will write to you to obtain your consent for processing
your personal data for the new purpose.
5 DISCLOSURES OF YOUR PERSONAL DATA
5.1 We may share your personal data with the parties set out below for the purposes set out in the table
under 4.2 above:
a) Third parties service providers, agents, subcontractors, associated companies, affiliates in order to
provide you with our Services;
b) Third party enforcement authorities, other judicial or governmental bodies as required by the law or
legal process or when it is necessary for such disclosure to protect the public interest (for example to
facilitate the investigation of suspected or actual illegal activities);
c) Other third parties with your consent; and
d) Third parties to whom we may choose to sell, transfer or merge parts of our business or our assets.
Alternatively, we may seek to acquire other businesses or merge with them. If a change happens to our
business, then the new owners may use your personal data in the same way as set out in this Policy.
5.2 Please be assured that we require all third parties to respect the security of your personal data and to
treat it in accordance with the law. We do not allow our third-party service providers to use your personal
data for their own purposes and only permit them to process your personal data for specified purposes
and in accordance with our instructions.
6 DATA SECURITY
6.1 We have put in place appropriate security measures to prevent your personal data from being accidentally
lost, used or accessed in an unauthorised way, altered or disclosed. In addition, we limit access to your
personal data to those employees, agents, contractors and other third parties who have a business need
7
to know. They will only process your personal data on our instructions and they are subject to a duty of
confidentiality.
6.2 We have put in place procedures to deal with any suspected personal data breach and will notify you and
any applicable regulator of a breach where we are legally required to do so.
7 DATA RETENTION
7.1 We will only retain your personal data for as long as reasonably necessary or appropriate to fulfil the
purposes we collected it for, including for the purposes of satisfying any legal, regulatory, tax, accounting
or reporting requirements. We may retain your personal data for a longer period in the event of a complaint
or if we reasonably believe there is a prospect of litigation in respect to our relationship with you.
7.2 To determine the appropriate retention period for personal data, we consider the amount, nature and
sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your
personal data, the purposes for which we process your personal data and whether we can achieve those
purposes through other means, and the applicable legal, regulatory, tax, accounting or other requirements.
7.3 Details of retention periods for different aspects of your personal data, please contact us at info@xnb.com.
7.4 In some circumstances, you can ask us to delete your data: see section 8 below for further information.
7.5 Under certain circumstances, we will anonymise your personal data (so that it can no longer be associated
with you) for research or statistical purposes, in which case the anonymous data will no longer be deemed
as personal data and we may use this information indefinitely without further notice to you.
8 YOUR LEGAL RIGHTS
8.1 Under certain circumstances, you have rights under data protection laws in relation to your personal data
as follows:-
(a) Request to obtain information regarding
(b) Request access to your personal data and information relating to the processing of it. This enables you
to receive a copy of the personal data we hold about you and to check that we are lawfully processing
it.
(c) Request correction of the personal data that we hold about you. This enables you to have any
incomplete or inaccurate data we hold about you corrected, though we may need to verify the accuracy
of the new data you provide to us.
(d) Request erasure of your personal data. This enables you to ask us to delete or remove personal data
where there is no good reason for us continuing to process it. You also have the right to ask us to delete
or remove your personal data where you have successfully exercised your right to object to processing
(see below), where we may have processed your information unlawfully or where we are required to
erase your personal data to comply with local law. Please note that we may not always be able to comply
with your request of erasure for specific legal reasons which will be notified to you, if applicable, at the
time of your request.
(e) Object to processing of your personal data where we are processing your personal data for direct
marketing purposes or for purposes of conducting surveys unless it is necessary for public interest. In
some cases, we may demonstrate that we have compelling legal basis to process your information.
8
(f) Request restriction of processing of your personal data. This enables you to ask us to suspend the
processing of your personal data in the following scenarios:
(i) If you want us to establish the data's accuracy.
(ii) If you are of the view that the processing of your personal data has exceeded the scope of the
agreed purposes.
(iii) Where our use of the data is unlawful.
(iv) Where you need us to hold the data even if we no longer require it as you need it to establish,
exercise or defend legal claims.
(v) You have objected to our use of your data but we need to verify whether we have overriding
legitimate grounds to use it.
(g) Request the transfer of your personal data to you or to a third party. We will provide to you, or a third
party you have chosen, your personal data in a structured, machine-readable format. Note that this right
only applies to automated information which you initially provided consent for us to use or where we
used the information to perform a contract with you.
(h) Withdraw consent at any time where we are relying on consent to process your personal data.
However, this will not affect the lawfulness of any processing carried out before you withdraw your
consent. If you withdraw your consent, we may not be able to provide certain products or services to
you. We will advise you if this is the case at the time you withdraw your consent.
How do you exercise your legal rights
8.2 You will not have to pay a fee to access your personal data (or to exercise any of the other rights).
However, we may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive.
Alternatively, we could refuse to comply with your request in these circumstances.
8.3 We may need to request specific information from you to help us confirm your identity and ensure your
right to access your personal data (or to exercise any of your other rights). This is a security measure to
ensure that personal data is not disclosed to any person who has no right to receive it. We may also
contact you to ask you for further information in relation to your request to speed up our response.
Time limit to respond
8.4 We try to respond to all legitimate requests within one month. Occasionally it could take us longer than a
month if your request is particularly complex or you have made a number of requests. In this case, we
will notify you and keep you updated.
9 HOW TO CONTACT US
9.1 If you have any questions or comments about this Policy or if you would like to exercise your rights
pursuant to section 8 of this Policy, you may contact us via the details set out below:-
Contact details:
Full name of legal entity: XNB Pty Ltd
Email address: info@xnb.com