EXTERNAL DOCUMENT 

CONTACTS PRIVACY NOTICE 

Version 4

March 2024

© Kroo Bank Ltd 1 of 7

EXTERNAL DOCUMENT 

First Issued: 19th May 2021 

Last updated: 5 March 2024

Introduction 

Kroo Bank Ltd ("we", "us", and "ours" or “Kroo”) respects your right to privacy. This Privacy Notice explains who we are, how we collect, share and use personal information relating to individuals who are our business contacts or who work for companies or other organisations that are business contacts. We refer to such individuals as “you”. 

This Privacy Notice is about you, and how you can exercise your privacy rights. If you have any questions or concerns about our use of your personal information (your data) please contact us using the contact details provided at the end of this Privacy Notice. 

What does Kroo do? 

Kroo is a company incorporated in England and Wales. It is authorised as a bank by the Prudential Regulation Authority and regulated by the Financial Conduct Authority and Prudential Regulation Authority (firm registration number 953772). 

Kroo is a bank offering current accounts, overdrafts, personal loans and other banking services. 

What personal information does Kroo collect and why? 

The personal information that we may collect about you broadly falls into the following categories: 

Information that you provide voluntarily 

Types of personal information Why we collect it

● Identification and contact details 

To establish and manage our relationship 

(name, address, telephone number and 

with our service providers, distributors and 

email address) 

other partners. We may also do due 

● Financial information (bank account 

diligence checks on key individuals in a 

details, payment card) if your business 

company or firm that we intend to do 

accounts are in your name 

business with. This includes checks on 

● Employment details (employer and job 

whether an individual is subject to any 

title) 

national or international sanctions, or is a 

politically exposed person (PEP). We may 

also carry out adverse media checks

© Kroo Bank Ltd 2 of 7

EXTERNAL DOCUMENT 

In addition we may correspond with you (electronically or otherwise) and that correspondence may contain personal data that we exchange in the ordinary course of business, such as to schedule meetings and calls and manage services we provide to you or your employer, or which you or your employer provide to us. If we ask you to provide any other personal information not described above, we will make clear to you at the time why we are asking for it and what we will do with it. 

If we ask you to provide any other personal information not described above, then the personal information we will ask you to provide, and the reasons why we ask you to provide it, will be made clear to you at the point we collect your personal information. 

Information that we obtain from third parties 

Types of personal information Why we collect it

From time to time we may receive personal 

To establish and manage our relationship 

information about you from third party 

with our service providers, distributors and 

sources (which may include your employer 

other partners. Also to carry out due 

or other suppliers or business partners). 

diligence checks (see above under 

We will only ask for such information if we 

“Information that you provide voluntarily”).

know you have consented to such 

disclosure or if the people or corporations 

making the disclosure are legally permitted 

or required to disclose your personal 

information to us. 

© Kroo Bank Ltd 3 of 7

EXTERNAL DOCUMENT 

Who do we share your personal information with? 

Categories of recipients Why we disclose it

Third party service providers and partners 

To establish and manage our relationship 

with our service providers, distributors and 

who provide data processing services to us, 

other partners.

or who otherwise process personal 

information for purposes that are described 

in this Privacy Notice or notified to you 

when we collect your personal information 

To any competent law enforcement body, 

Because we believe disclosure is necessary 

regulatory, government agency or other 

(i) as a matter of applicable law or 

third party. 

regulation - for example anti-money 

laundering laws , (ii) to exercise, establish 

or defend our legal rights, (iii) for fraud 

prevention purposes, (iv) to protect your 

vital interests or those of any other person. 

To a potential buyer (and its agents and 

To enable us to sell all or part of our 

advisers) in connection with any proposed 

business or to merge with another 

purchase, merger or acquisition of any part 

business.

of our business, provided that we inform the 

buyer it must use the personal information 

only for the purposes disclosed in this 

Privacy Notice. 

To any other person with your consent. Because we need to and you have consented.

What Kroo uses your personal information for 

In general, we will use the personal information we collect from you only for the purposes described in this Privacy Notice or for purposes that we explain to you at the time we collect your personal information. However, we may also use your personal information for other purposes that are not incompatible with the purposes we have disclosed to you (such as 

© Kroo Bank Ltd 4 of 7

EXTERNAL DOCUMENT 

archiving purposes in the public interest, scientific or historical research purposes, or statistical purposes) if and where this is permitted by applicable data protection laws. 

Legal basis for processing personal information 

Our legal basis for collecting and using the personal information described above will depend on the personal information concerned and the specific context in which we collect it. 

However, we will normally collect personal information from you only where we have your consent to do so, where we need the personal information to perform a contract with you or your employer, or where the processing is in our legitimate interests and not overridden by your data protection interests or fundamental rights and freedoms. In some cases, we may also have a legal obligation to collect personal information from you or from third parties (such as to carry out due diligence checks on you and your employer before we conduct business with you) or we may otherwise need the personal information to protect your vital interests or those of another person. 

Mostly, however, we process information about our business contacts for our legitimate business interests in the context of providing services to our customers or when receiving services from our service providers, or in the case of partners, for the purposes of collaboration or partnership. 

If we collect and use your personal information for anything other than our business interests, we will make this clear to you at the time. 

If you have questions about or need further information concerning the legal basis on which we collect and use your personal information, please contact us using the contact details provided at the end of this Privacy Notice. 

How does Kroo keep my personal information secure? 

We use appropriate technical and organisational measures to protect the personal information that we collect and process about you. The measures we use are designed to provide a level of security appropriate to the risk of processing your personal information. 

International data transfers 

Your personal information may be transferred to, and processed in, countries other than the country in which it was originally collected and other than the one in which you are resident. These countries may have data protection laws that are different to the laws of your country (and, in some cases, may not be as protective). 

© Kroo Bank Ltd 5 of 7

EXTERNAL DOCUMENT 

Specifically, our servers are hosted by AWS in Ireland. Our third party service providers and partners operate around the world. This means that when we collect your personal information we or our data processors may process it outside the UK or the European Economic Area (EEA).When we export your personal information to a different country, we will take steps to ensure that such data exports comply with applicable laws. 

Data retention 

We retain personal information we collect from you where we have an ongoing legitimate business need to do so (for example, to receive services from you or your employer, to provide services to our customers, to collaborate with our partners, or to comply with applicable legal, tax or accounting requirements. 

When we have no ongoing legitimate business need to process your personal information, we will either delete or anonymise it or, if this is not possible (for example, because your personal information has been stored in backup archives), then we will securely store your personal information and isolate it from any further processing until deletion is possible. 

Automated decision-making 

Automated decisions are decisions concerning you which are made automatically on the basis of a computer determination (using software algorithms), without human review. We do not use automated decision-making in our dealings with business contacts. 

Your data protection rights 

You have the following data protection rights: 

● If you wish to access, correct, update or request deletion of your personal information, you can do so at any time by contacting us using the contact details provided at the end of this Privacy Notice. 

● In addition, if you are a resident of the United Kingdom or the European Union, you can object to processing of your personal information, ask us to restrict processing of your personal information or request portability of your personal information. Again, you can exercise these rights by contacting us using the contact details at the end of this Privacy Notice. 

● You have the right to opt-out of marketing communications we send you at any time by contacting us using the contact details at the end of this Privacy Notice. 

● Similarly, if we have collected and processed your personal information with your consent, then you can withdraw your consent at any time. Withdrawing your consent will not affect the lawfulness of any processing we conducted prior to your 

© Kroo Bank Ltd 6 of 7

EXTERNAL DOCUMENT 

withdrawal, nor will it affect processing of your personal information conducted in reliance on lawful processing grounds other than consent. 

● You have the right to complain to a data protection authority about our collection and use of your personal information. For more information, please contact the UK’s Information Commissioner’s Office (ICO) www.ico.org.uk 

We respond to all requests we receive from individuals wishing to exercise their data protection rights in accordance with applicable data protection laws. 

Updates to this Privacy Notice 

We may update this Privacy Notice from time to time in response to changing legal, technical or business developments. When we update our Privacy Notice, we will take appropriate measures to inform you, consistent with the significance of the changes we make. We will obtain your consent to any material Privacy Notice changes if and where this is required by applicable data protection laws. 

You can see when this Privacy Notice was last updated by checking the date displayed at the top of this Privacy Notice. 

How to contact us 

If you have any questions or concerns about our use of your personal information, please contact our Data Protection Officer using the following details: dataprotection@Kroo.com. 

© Kroo Bank Ltd 7 of 7