Skip to main content
Legal

Privacy Policy

The Vision Corporation Holdings Ltd (the "Bank", "we", "our"), registered in England & Wales (Company No. 16767315), is the controller of personal data processed through the Platform. This Policy explains what we collect, how we use it, who we share it with, how long we keep it and the rights available to you under the UK GDPR, the EU GDPR and the Swiss Federal Act on Data Protection.

Version
v2.0
Effective
15 January 2026
Last updated
15 January 2026
Reading time
~15 min
Jurisdictions
EEA, United Kingdom, Switzerland
Important

Notices you should read first.

Retention after closure

Some records — especially KYC documents and transaction history — must be kept for years after your account closes where AML and tax law require it.

Security notice

We will never ask you for your password, seed phrase, private keys, or one-time authentication codes. Any such request should be treated as fraudulent.

Automated decisions

Some checks (fraud, sanctions, KYT) are automated. You can request human review of decisions with legal or similarly significant effects on you.

Section

01

Introduction

The Vision Corporation Holdings Ltd (the "Bank", "we", "our"), a company incorporated in England & Wales (Company No. 16767315), is the controller of personal data processed through the Platform. This Privacy Policy explains what personal data we collect, how we use it, who we share it with, how long we keep it, and the rights available to you under the UK GDPR, the EU GDPR and the Swiss Federal Act on Data Protection (FADP).

Section

02

Scope of this Policy

This Policy applies to individuals who open, hold or attempt to open an Account, to authorised representatives of corporate Clients, to visitors of thevisionbank.io and its subdomains, and to anyone who communicates with us in relation to the Services. It does not cover third-party websites, wallets, exchanges or applications you access outside the Platform, even where linked from the Platform.

Section

03

Definitions

"Personal Data" means any information relating to an identified or identifiable natural person. "Processing" means any operation performed on Personal Data. "Controller" means the entity that determines the purposes and means of Processing. "Processor" means an entity that processes Personal Data on behalf of the Controller. Terms not defined here have the meaning given in the UK / EU GDPR or the Swiss FADP as applicable.

Section

04

Data Controller & Contact

The Data Controller is The Vision Corporation Holdings Ltd, registered office in London, England & Wales, Company No. 16767315. You can contact our Data Protection Officer at dpo@thevisionbank.io or write to the registered office marked for the attention of the Data Protection Officer.

Section

05

Categories of Personal Data

We collect only what is necessary to open and operate your Account, meet our legal obligations, keep you and other Clients safe, and improve the Services. The table below summarises the main categories and the primary reason each is collected; further detail is provided in the following sections.

Data
Why we collect it
Passport / national ID
Identity verification and KYC compliance
Residential address
AML compliance and jurisdiction eligibility
Selfie / liveness check
Confirming you are the identity holder
Wallet addresses
Recording on-chain deposits and withdrawals
Device fingerprint
Fraud prevention and account security
Login history
Detecting account compromise and unusual access
Transaction history
Regulatory reporting and account statements
Beneficiary details
Executing and monitoring fund transfers

Section

06

Identity Verification Data

To meet Know-Your-Customer, Know-Your-Business, and Customer Due Diligence obligations, we collect government-issued identification, proof of address, date and place of birth, nationality, tax residency, occupation, and, where applicable, beneficial-ownership declarations and corporate constitutional documents.

Where identity is confirmed via a selfie or short video, we process biometric data solely for the purpose of matching you to your identity document (liveness / face-match). Biometric data is not used for marketing, profiling or any purpose beyond identity verification and fraud prevention.

Sanctions, PEP and adverse-media screening produces additional Personal Data (screening hits, risk ratings, review notes) which we retain as required by AML law.

Section

07

Financial Information

In connection with the Services we process Fiat balances, IBANs and account details, incoming and outgoing SEPA / SWIFT / Faster Payments transfers, beneficiary information (name, address, bank, account number), card transactions and merchant metadata, exchange orders and executions, lending positions, earn positions, internal transfers between your accounts, and derived analytics such as running balances and portfolio history.

RelatedFees

Section

08

Blockchain Data

For Digital Asset Services we process supported wallet addresses (deposit and withdrawal), on-chain transaction hashes, amounts and counterparties, memo / destination-tag identifiers, network fees, and confirmation status. We use blockchain-analytics providers to produce KYT (Know-Your-Transaction) scores, risk bands, address-attribution data and screening outcomes.

Public blockchain transactions are by their nature transparent and pseudonymous; we cannot suppress or delete on-chain data.

Section

09

Device & Technical Information

When you use the Platform we automatically collect device fingerprints, IP address, approximate geolocation derived from IP, browser and operating-system identifiers, timezone, session identifiers, referrer URLs, page-view telemetry, error reports and performance metrics. We also process passkey / WebAuthn credential identifiers, TOTP metadata, and login history (successful and failed attempts) to keep your Account secure.

RelatedSecurity

Section

10

Communications

We keep records of support tickets, in-app messages, secure-chat threads with our compliance team, email correspondence, and any recorded telephone calls where recording is required by law or where you have been notified. These records are used to investigate and resolve issues, to meet legal obligations, and for training and quality-assurance purposes.

Section

11

Cookies & Tracking Technologies

We use cookies and similar technologies to authenticate sessions, remember preferences, understand usage, monitor reliability and — with your consent — measure marketing effectiveness. You can manage non-essential cookies at any time through the Cookie Preferences page or your browser settings.

Essential

Session, authentication, CSRF, load balancing. The site does not work without these.

Always on

Functional

Language, region, display currency, saved preferences.

You can opt out

Analytics

Aggregated usage statistics that help us improve the platform.

You can opt out

Performance

Error monitoring, latency and reliability telemetry.

You can opt out

Marketing

Attribution for campaigns, only where you have consented.

You can opt out

Section

12

How We Use Your Data

We rely on the following legal bases under the UK / EU GDPR and equivalent Swiss provisions:

  • Performance of a contract — to open and operate your Account, execute transactions, and provide the Services you request.
  • Compliance with a legal obligation — for AML, sanctions, tax, safeguarding, prudential and reporting obligations.
  • Legitimate interests — for fraud prevention, security monitoring, risk management, service improvement, and defending legal claims.
  • Consent — for optional marketing, non-essential cookies, and any processing where consent is the appropriate basis.
  • Vital interests — in the rare case where processing is needed to protect life or physical integrity.

Section

13

AML, Sanctions & Fraud Prevention

We monitor Accounts and transactions on a continuous basis to detect money laundering, terrorist financing, sanctions evasion, tax evasion, market abuse and fraud. Where required by law, suspicious activity is reported to the relevant Financial Intelligence Unit. This monitoring uses a combination of rules-based checks, blockchain analytics, sanctions and PEP screening, and human review.

RelatedAML Policy

Section

14

Automated Decision Making

Some checks are performed by automated systems, including fraud scoring, AML transaction monitoring, sanctions screening, KYT analysis, device-risk assessments and internal risk ratings. Where a decision produced solely by automated means has legal or similarly significant effects on you, you have the right to obtain human review, to express your point of view and to contest the decision.

Section

15

Marketing Preferences

You control whether you receive optional communications from us. You cannot opt out of security-critical alerts, regulatory notices, or transaction confirmations, because they are essential to the safe operation of your Account.

  • Optional: product announcements, marketing emails, educational newsletters, research and insights.
  • Optional: partner offers (only where you have explicitly opted in).
  • Always on: security alerts, device-verification codes, KYC / compliance requests, regulatory disclosures, transaction confirmations, statement notifications.

Section

16

Data Sharing & Third-Party Service Providers

We share Personal Data with a limited set of trusted providers, only to the extent necessary for the Services and under contractual obligations that require them to protect your data. Categories of recipient include banking partners and correspondent banks, qualified custodians and sub-custodians, card issuers and payment networks, KYC / KYB and identity-verification vendors, blockchain-analytics providers, cloud and infrastructure providers, email / SMS / notification providers, professional advisers (auditors, lawyers, tax advisers), and regulators, courts and law-enforcement authorities where required by law.

We do not sell your Personal Data.

Section

17

International Transfers

Some of our providers process Personal Data outside the UK, the EEA or Switzerland. Where this occurs, we protect your data by relying on adequacy decisions of the UK, EU or Swiss authorities, or by putting in place appropriate safeguards such as the UK International Data Transfer Agreement (IDTA), the EU Standard Contractual Clauses (SCCs), and where required a Transfer Risk Assessment. Copies of the relevant safeguards can be requested from the Data Protection Officer.

Section

18

Data Retention

We keep Personal Data only for as long as necessary for the purposes for which it was collected, including to meet legal, regulatory, tax, accounting and reporting requirements, and to defend against or bring legal claims. Typical retention periods are summarised below; the actual period depends on the specific record, your jurisdiction and applicable law.

Data type
Typical retention
Identity documents (KYC)
Up to 10 years after account closure (subject to applicable AML law)
Transaction records
Up to 10 years after the transaction (subject to applicable law)
Card / IBAN payment logs
Up to 7 years after the transaction
Support tickets & communications
Up to 6 years, longer if part of a dispute or investigation
Security & access logs
12 – 24 months, longer where required for investigations
Marketing consent records
For the duration of consent and 3 years after withdrawal
Closed-account balances (unclaimed)
Reported to unclaimed-property authorities where required by law

Section

19

Data Security

We apply technical and organisational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.

  • Encryption in transit (TLS 1.2+) and encryption at rest for stored Personal Data.
  • Multi-factor authentication, passkeys / WebAuthn and TOTP for account access.
  • Role-based access control with least-privilege principles and periodic access reviews.
  • Access logging, session monitoring, anomaly detection and 24/7 security alerting.
  • Regular penetration testing, third-party security audits and vulnerability management.
  • Infrastructure redundancy, backups and business-continuity planning.
  • Formal incident-response and breach-notification procedures.
  • Vendor security assessments, contractual data-protection commitments and ongoing monitoring.
RelatedSecurity

Section

20

Your Rights

Subject to applicable law, you have the following rights in respect of your Personal Data. We may need to verify your identity before responding, and some rights may be limited where we are required or permitted by law to retain data (for example AML records).

  • Access — obtain confirmation of whether we process your data and a copy of it.
  • Rectification — correct inaccurate or incomplete data.
  • Erasure — request deletion where the data is no longer needed and no legal obligation requires its retention.
  • Restriction — request that we temporarily limit processing while a query is investigated.
  • Portability — receive certain data you provided in a structured, machine-readable format.
  • Objection — object to processing based on legitimate interests or for direct marketing.
  • Withdraw consent — where processing is based on consent, without affecting prior lawful processing.
  • Complain to a supervisory authority — the ICO (UK), your local EEA Data Protection Authority, or the FDPIC (Switzerland).

Section

21

Children's Privacy

The Services are not intended for individuals under the age of 18 and we do not knowingly collect Personal Data from minors. If we become aware that we have collected Personal Data from a minor without appropriate parental or guardian consent, we will delete it.

Section

22

Regulatory Disclosures

We may be required to share Personal Data with tax authorities under FATCA, the Common Reporting Standard, DAC8 or similar frameworks, with Financial Intelligence Units when filing suspicious-activity reports, with regulators exercising supervisory or investigatory powers, and with law-enforcement authorities acting under valid legal process. Where we are legally permitted to notify you of such a disclosure, we will do so.

Section

23

Changes to This Policy

We may update this Privacy Policy to reflect changes in law, our practices, our providers or the Services. Material changes will be notified in-app or by email at least 30 days before they take effect, except where a shorter period is required by law. The version and effective date at the top of this page always reflect the current Policy.

Section

24

Contact Details

For privacy questions, data-subject requests, or complaints, use the contacts below. We aim to respond to rights requests within 30 days; complex requests may require an extension of up to two further months, in which case we will notify you.

Contact

Reach the right team.

Data Protection Officer
dpo@thevisionbank.io
Security Reporting
security@thevisionbank.io
Registered Office
London, England & Wales
Company Number
16767315
Business Hours
Monday – Friday, 09:00 – 18:00 GMT/BST
Target response
Within 30 days for rights requests (extendable by up to 2 months for complex cases)
Supervisory authority
ICO (UK), your local EEA DPA, or the FDPIC (Switzerland)

This document is informational and does not constitute legal advice. For clarifications, open a ticket from your Account or write to one of the addresses above.