Transfer Direct Ltd trading as Oqab Remittance

PRIVACY NOTICE
Effective date: July 15, 2026
Version: Draft 1.0 - for client and compliance-advisor approval
Company number: 12194165
ICO registration: ZB211737
FCA reference: 918589 - Small Payment Institution

This notice explains how we collect, use, share, transfer, and protect personal information when you visit our website, contact us, register as a customer, or use our money-remittance service.

1. Who we are
Transfer Direct Ltd, trading as Oqab Remittance, is the controller of the personal information described in this notice. This means that we decide why and how that information is used. You can contact us or our data-protection contact using the details below:
Transfer Direct Ltd, 37 Court Parade, East Lane, Wembley, Middlesex, England, HA0 3HS
Email: info@transferdirectltd.co.uk
Telephone: 020 8488 9777
Data-protection contact: Mr. Abdul Musawer Nasseri

2. Who this notice covers
This notice applies to:
  1. customers and prospective customers who send money through us;
  2. beneficiaries who receive or are intended to receive a transfer;
  3. people who contact us, make a complaint, visit our premises, or use our website or online services; and
  4. people connected with a transaction, including representatives, family members, source-of-funds providers, or other relevant third parties.
Our services are intended for senders aged 18 or older. We may process limited information about a beneficiary who is under 18 when this is necessary to complete a lawful transfer.

3. Personal information we collect
Depending on how you use our services, we may collect the following information:
CategoryExamples
Identity informationName, date of birth, nationality, signature, photograph, customer number, and copies or details of passports, driving licenses, immigration documents, or other identification.
Contact informationResidential address, email address, telephone number, and postcode.
Customer profile informationOccupation, employment status, income information, expected transaction activity, relationship to the beneficiary, purpose of the transfer, and customer-risk rating.
Transaction and financial informationTransfer amount, currency, exchange rate, fees, payment method, bank or sub-account details, transaction history, source of funds, source of wealth, affordability information, and supporting documents such as bank statements or payslips.
Beneficiary informationName, contact details, location, relationship to the sender, identification or payout information, and details needed to complete the transfer.
Compliance informationCDD and EDD records, sanctions and PEP screening results, adverse-media results, alerts, monitoring notes, internal or external suspicious-activity records, and reasons for accepting, holding, rejecting, or reporting a transaction.
CommunicationsEmails, letters, complaint records, call notes, and other communications with you.
Website and technical informationIP address, device and browser information, login and security records, pages viewed, cookie choices, and information submitted through online forms.
Premises and security informationCCTV images and incident records where applicable.
We may sometimes process special-category information, such as information that reveals political opinions through PEP screening, and information about alleged or proven criminal activity through fraud, sanctions, adverse-media, or AML checks. We process this information only where UK law permits it and where appropriate safeguards are in place.

4. How we collect personal information
We collect information:
  1. directly from you when you visit our office, contact us, complete a form, create or use an online service, provide identification, or make a transfer;
  2. from a sender who gives us beneficiary or other third-party information;
  3. from identity-verification, sanctions, PEP, fraud-prevention, and adverse-media providers;
  4. from a payment service provider, payout partners, banks, and other parties involved in processing or paying a transfer;
  5. from public sources, including government, regulatory, court, company, sanctions, and media records;
  6. from HMRC, the FCA, the NCA, OFSI, law-enforcement bodies, or other public authorities where permitted; and
  7. automatically through our website, security logs, cookies, and similar technologies.

5. Why we use personal information and our lawful bases
PurposeWhat we doLawful basis
Provide and manage remittance servicesRegister customers, process and pay transfers, communicate transaction status, provide receipts, manage refunds, and respond to service requests.Performance of a contract or steps taken at your request before entering a contract.
Meet AML, CTF, sanctions, and regulatory dutiesIdentify and verify customers, apply CDD or EDD, assess source of funds or wealth, screen customers and beneficiaries, monitor activity, investigate alerts, keep required records, and make required reports.Legal obligation. Where sensitive or criminal-offence information is involved, we also rely on the conditions permitted by UK data-protection law.
Prevent fraud and protect our serviceDetect identity fraud, account misuse, suspicious patterns, security incidents, and other unlawful activity.Legal obligation and our legitimate interests in protecting customers, the public, and our business.
Handle complaints and legal claimsInvestigate complaints, respond to disputes, cooperate with regulators, and establish, exercise, or defend legal claims.Contract, legal obligation, and legitimate interests.
Operate and improve our businessMaintain records, audit controls, train staff, manage systems, improve service quality, and prepare management information using the minimum information needed.Our legitimate interests in running a secure, effective, and compliant business.
Send marketingSend information about our services or offers where permitted.Consent, or another basis permitted by the Privacy and Electronic Communications Regulations. You may opt out at any time.
Operate our website and cookiesKeep the website secure, remember essential choices, understand use, and provide optional functions.Legitimate interests for strictly necessary security and service operation; consent for non-essential cookies where required.

6. AML and financial-crime use restrictions
Personal information obtained to meet the MLR 2017 is used only for preventing money laundering, terrorist financing, proliferation financing, sanctions breaches, fraud, and related financial crime, or for another purpose permitted by law. We do not use AML information for an unrelated purpose that is incompatible with those requirements.
We may be legally unable to tell you that we have made a suspicious-activity report, that an investigation is taking place, or that certain information has been shared with an authority. We may also need to limit or delay a response to an information-rights request where the law permits or requires this.

7. If you do not provide information
Some information is required by law or is needed to provide the requested transfer. If you do not provide accurate information or satisfactory documents, we may be unable to register you, process or pay a transfer, continue a business relationship, or respond fully to a request. We may also hold, reject, or cancel a transaction and consider whether a report is required.

8. Who we share information with
We may share the minimum information needed with:
  1. payment service providers and other settlement or intermediary service providers;
  2. Logar MSP and other licensed payout partners or correspondents involved in paying a beneficiary;
  3. identity-verification, sanctions, PEP, fraud-prevention, transaction-monitoring, and compliance service providers;
  4. banks, account providers, payment processors, technology, hosting, cloud, email, SMS, cybersecurity, and professional-service providers;
  5. HMRC, the FCA, the NCA or UKFIU, OFSI, the police, courts, tax authorities, and other regulators or public authorities where required or permitted;
  6. auditors, accountants, lawyers, insurers, and external compliance advisors; and
  7. a buyer, investor, or successor if our business or assets are sold or reorganized, subject to appropriate confidentiality and data-protection controls.
Some recipients act as our processors and may use information only on our documented instructions. Other recipients, such as regulators, law-enforcement bodies, banks, or overseas payout partners, may act as independent controllers under their own legal duties.

9. International transfers
To complete a remittance, we may need to send or make personal information available outside the United Kingdom, including to Afghanistan. This may include sender, beneficiary, transaction, compliance, and payout information.
Where the UK GDPR international-transfer rules apply, we use a permitted transfer mechanism. This may include UK adequacy regulations, an International Data Transfer Agreement or other approved safeguards together with a transfer-risk assessment, or a limited legal exception where the transfer is necessary to perform your money-transfer contract or a contract made in your interest. You may contact us for more information about the safeguard used for a particular transfer.

10. Screening, monitoring, and human review
We use systems to screen names against sanctions and PEP information and to identify unusual transaction patterns or other risk indicators. A system alert does not by itself mean that a person has done anything wrong. Alerts are referred for review by authorized staff or the MLRO.
We do not intend to make a decision that has a legal or similarly significant effect on you solely by automated means without the safeguards required by law. You may contact us if you believe a significant decision was made about you only by automated processing and you want an explanation or human review.

11. How long we keep information
RecordNormal retention approach
AML identification, CDD, EDD, and transaction recordsNormally five years from the end of the business relationship or, for an occasional transaction, five years from the transaction date, in line with the MLR 2017.
SARs, internal reports, sanctions alerts, and MLRO decisionsKept securely for the period required by law and the company's retention schedule, normally at least five years where connected with AML obligations.
Complaints, disputes, and legal recordsKept for the period needed to meet regulatory requirements and establish, exercise, or defend legal claims.
Website, security, and cookie recordsKept only for the period needed for security, service operation, consent records, analysis, or legal compliance.
Marketing recordsKept until you withdraw consent or opt out, plus a limited suppression record so we can respect your choice.
CCTVKept for a limited period unless an incident, investigation, insurance matter, or legal requirement requires longer retention.
When the applicable period ends, we securely delete or anonymize the information unless a law, court proceeding, regulatory requirement, or documented legal claim requires us to keep it longer.

12. Data security
We use appropriate technical and organizational measures designed to protect personal information from accidental loss, unauthorized access, misuse, alteration, or disclosure. These measures include access controls, individual user accounts, confidentiality requirements, secure record storage, system logging, staff training, backups, and incident-response procedures, where applicable. Access is limited to people who need the information for their work.
If a personal-data breach creates a risk that requires notification, we will notify the ICO and affected individuals as required by law.

13. Your data-protection rights
Depending on the circumstances and the lawful basis used, you may have the right to:
  1. ask for access to your personal information;
  2. ask us to correct inaccurate or incomplete information;
  3. ask us to erase information where there is no lawful reason to keep it;
  4. ask us to restrict how information is used;
  5. object to processing based on legitimate interests;
  6. receive certain information in a portable format;
  7. withdraw consent at any time where processing is based on consent; and
  8. ask for human review of a qualifying decision made solely by automated means.
Your right to object: You may object at any time to direct marketing. You may also object to processing based on legitimate interests because of your particular situation.
These rights are not absolute. For example, we may need to keep information or limit a response to comply with AML, sanctions, fraud-prevention, regulatory, or legal obligations. We will explain our decision unless the law prevents us from doing so.
To exercise a right, email info@transferdirectltd.co.uk or write to our registered address. We may ask for information to confirm your identity. We normally respond within the period required by data-protection law and do not charge a fee unless a request is manifestly unfounded, excessive, or repeated.

14. Marketing
We will send electronic marketing only where permitted. You can opt out at any time by using the unsubscribe method in the message or contacting us. Opting out of marketing does not stop service messages about an active or previous transaction, security, legal requirements, or changes to our service.

15. Cookies and similar technologies
Our website may use strictly necessary cookies for security, login, navigation, and requested services. These cookies do not normally require consent, but we still provide information about them.
We will not place analytics, functionality, advertising, social-media, or other non-essential cookies unless you have made an appropriate choice through our cookie banner or settings, where consent is required. You can change or withdraw your choice at any time through the cookie settings. The current cookie settings should identify each cookie, its provider, purpose, category, and duration.

16. Complaints
Please contact us first if you have a concern about how we use your information. We will review the matter and try to resolve it.
You also have the right to complain to the Information Commissioner's Office (ICO):
Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Telephone: 0303 123 1113
Website: https://ico.org.uk/make-a-complaint/

17. Changes to this notice
We review this notice regularly and when our services, systems, payment arrangements, suppliers, or legal requirements change. The current version and effective date will be published on our website. Where a change has a significant effect on how we use personal information, we will take reasonable steps to bring it to the attention of affected people.