Privacy Policy

This Privacy Policy explains how UAB MoneyBeat (“MoneyBeat”, “we”, “us”, “our”) collects, uses, stores, and shares personal data when you use our website, mobile app, dashboard, and related services (together, the “Services”). We process personal data in accordance with the EU General Data Protection Regulation (GDPR) and applicable Lithuanian data protection laws.

.1) Who is the controller

Controller: UAB MoneyBeat
Company code: 306008398
Registered address: Giedraičių g. 39, R53, LT-09302 Vilnius
Email: privacy@moneybeat.eu
Support: support@moneybeat.eu

2) What personal data we collect

We collect personal data only to the extent necessary to provide the Services, operate securely, and meet legal/compliance obligations.

2.1 Data you provide to us

Account & profile data: name, date of birth, nationality/citizenship (where required), address, email, phone number.
Verification data (KYC/KYB): identity document details, document copies, selfie/liveness checks (where used), proof of address, business registration information (for business users), UBO/ownership and control information (where required), and related verification results/status.
Customer support & communications: messages, emails, call records (if applicable), complaint details, and information you provide during support.
Payment-related data for fees (if applicable): limited information needed to process platform fees (note: payment card data is typically handled by payment providers, not stored by MoneyBeat in full).

2.2 Data generated when you use the Services

Transactional & operational data: account identifiers (e.g., IBAN or equivalent where available), payment/transfer details (such as beneficiary name, IBAN, amount, reference), timestamps, and status information.
Security and technical data: device identifiers, IP address, login history, session logs, browser/app details, and security events.

2.3 Cookies and similar technologies

We use cookies and similar tools to operate the website/app, enhance functionality, measure performance, and improve user experience. For details, see our Cookie Policy: https://moneybeat.eu/cookies-policy.

3) Why we use your data (purposes)
We use personal data for the following purposes:
Provide the Services (create and manage your account, enable core features such as SEPA transfers where available, provide statements/history, deliver support).
Verify identity and manage risk (KYC/KYB, fraud prevention, security monitoring, account protection).
Comply with legal obligations (including AML/CTF requirements, sanctions screening, record-keeping obligations, and responding to lawful requests).
Customer support and communication (respond to requests, handle disputes/complaints, send service updates and important notices).
Improve and maintain our Services (testing, troubleshooting, analytics, service monitoring, and product development).
Marketing (optional) (only where permitted and/or where you have provided consent; you can opt out anytime).

4) Legal bases for processing
We process personal data on one or more of the following legal bases under the GDPR:
Contract: to provide the Services and perform our obligations to you.
Legal obligation: to meet compliance requirements and respond to lawful requests.
Legitimate interests: to operate a secure platform, prevent fraud, improve Services, and maintain service quality (balanced against your rights).
Consent: for optional marketing and certain cookies/analytics where required. You may withdraw consent at any time.

5) Who we share your data with

We may share personal data with the following categories of recipients, only as necessary:

5.1 Service providers (processors)

IT hosting and infrastructure, analytics (where enabled), customer support tools, email/SMS delivery providers, security providers, and other vendors that help us operate the Services under appropriate contractual safeguards.

5.2 Financial and verification partners

To provide neobanking and payment-related features (including SEPA processing where available) and to perform verification/compliance steps, we may share data with:
identity verification providers,
compliance screening providers,
payment and banking partners involved in account and transfer processing,
card program partners (if card features are available).

5.3 Authorities and legal requests

We may disclose data where required by law, regulation, court order, or lawful request by competent authorities.

5.4 Professional advisers and business transfers

We may share limited data with auditors, lawyers, consultants, or in connection with a merger, acquisition, restructuring, or sale of assets (subject to appropriate protections).
We do not sell your personal data.

6) International transfers (outside the EEA)

Your data is generally processed in the EEA. If we or our service providers transfer data outside the EEA, we use appropriate safeguards, such as:
transfers to countries recognized as providing an adequate level of protection, and/or
Standard Contractual Clauses (SCCs) and supplementary measures where required.

7) How long we keep your data (retention)

We keep personal data only as long as needed for the purposes described in this Policy, including:
while your account is active and for a reasonable period after closure,
longer where required to comply with legal obligations (including AML/CTF record-keeping),
as necessary to resolve disputes, enforce agreements, and maintain security/audit records.
Retention periods may vary depending on the data type and legal requirements.

8) How we protect your data

We use organizational and technical measures designed to protect personal data, such as:
access controls and least-privilege permissions,
encryption in transit and, where appropriate, encryption at rest,
monitoring, logging, and security alerting,
internal policies and staff confidentiality obligations.
No system is 100% secure, but we work to maintain strong protections and respond quickly to risks.

9) Your GDPR rights

Depending on the circumstances, you may have the right to:
access your data,
correct inaccurate data,
request deletion,
restrict processing,
object to processing (including certain legitimate-interest processing),
data portability,
withdraw consent (where processing is based on consent),
lodge a complaint with your supervisory authority (in Lithuania, the State Data Protection Inspectorate – VDAI) or your local EU authority.
To exercise your rights, contact: privacy@moneybeat.eu

10) Children

Our Services are not intended for children. If you are under the age required to lawfully use our Services in your country, you must not use the Services. If we learn we have collected personal data from a child unlawfully, we will take steps to delete it.

11) Changes to this Policy

We may update this Policy from time to time. We will post the updated version in the Services and may notify you by email or in-app notice where appropriate. The “Last updated” date shows when changes were made.