Aspora Bridge privacy policy
(Last updated on September 18, 2026)
Aspora Bridge gives you a single view of your finances across the countries where you hold money, and helps you complete an account and transfer setup without hunting through your inbox for paperwork. To do this, Aspora Bridge can – with your permission – connect to your Google account and read financial and identity documents in your Gmail. This Privacy Policy explains what personal information we collect through Aspora Bridge, why we collect it, how we use and share it, how long we keep it, and the rights you have over it. It is a single policy that applies wherever Aspora Bridge is offered.
If you connect your Google account, the section titled “Google User Data” governs how we handle information we receive from Google APIs. That section takes precedence over any other part of this policy in respect of Google user data.
1. About this policy and who we are
Aspora Bridge is provided on our mobile-only application, “Aspora” (the “App”), by the Aspora group of companies. This is a single privacy policy (the “Privacy Policy”) covering Aspora Bridge in every market where it is offered. The company responsible for your personal information (the “data controller”) depends on the country in which you use Aspora Bridge:
| Market | Controlling entity | Registered address |
|---|---|---|
| United Kingdom | Real Transfer Limited | Office 8, Merrion Business Centre, 58, Howard Street, Belfast, Northern Ireland, BT1 6PJ |
| United Arab Emirates | Vance Technologies Limited | 3rd Floor, 141-145 Curtain Road, London, EC2A 3BX |
| United States | Vance Money Services LLC | Office number 1236, 1000 N. West Street, Suite 1200, Wilmington, Delaware – 19801, United States of America |
| India | Aspora Technology Services Private Limited | 38, 1st floor, Aswini Layout, 2nd main, Egipura, Viveknagar (Bangalore), Bangalore, Bangalore South, Karnataka, India, 560047 |
You can reach our Data Protection Officer at dpo@aspora.com.
Throughout this policy, “Aspora”, “we”, “us” and “our” mean the controlling entity for your market. Aspora Bridge is available to anyone who chooses to sign in and connect their Google account; access is not limited to any particular type of customer. This Privacy Policy covers the Aspora Bridge net-worth view, the account- and transfer-onboarding help it provides, and the optional Google account connection described below.
This Privacy Policy applies to Aspora Bridge and to the personal information we handle through the App. Where you also use a regulated banking, e-money or remittance service, additional privacy terms provided at the point you take that service may apply; where they add detail specific to that service, they should be read together with this Privacy Policy.
2. Key terms we use
To keep this Privacy Policy readable, we use a few defined terms:
2.1 “Personal information” (also called personal data) means information that identifies you or that relates to an identifiable individual.
2.2 “Processing” means anything we do with personal information, for example collecting, storing, using, sharing, or deleting it.
2.3 “Data controller” means the entity that decides why and how personal information is processed. For Aspora Bridge, this is the entity identified for your market in section 1.
2.4 “Processor” or “service provider” means a third party that processes personal information on our behalf and on our instructions.
2.5 “Google user data” means information we receive from Google APIs when you connect your Google account, including the content of your Gmail that we read on a read-only basis.
2.6 “Special-category (sensitive) data” means data, such as information about your health, that is given additional protection under applicable law.
2.7 “Services” means the App, Aspora Bridge and the related features and services we provide.
2.8 “Applicable Google law” means Google API Services User Data Policy which will apply in this case to Aspora when we access your Gmail information. We are required to comply with this policy at all times.
2.9 “Applicable data-protection law” means the laws that apply to our processing of your personal information, including the the UK GDPR and the Data Protection Act 2018, each as amended by the Data (Use and Access) Act 2025, the UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (the “UAE PDPL”) and its implementing regulations, , the Indian and its implementing regulations, the Indian Digital Personal Data Protection Act, 2023 (the “DPDP Act”) and the rules made under it and the Digital Personal Data Protection Rules, 2025 made under it, and applicable United States federal and state privacy laws (including the California Consumer Privacy Act as amended by the California Privacy Rights Act (together, the “CCPA/CPRA”), and the Gramm-Leach-Bliley Act), in each case where applicable and any other privacy law that applies to you.
3. The information we collect
(a) Information you give us
We collect the information you provide when you create an account, complete identity and onboarding checks, add financial details, contact our support team, or otherwise use our Services. This includes:
3.1 Identity and contact data – name, date of birth, nationality, country of residence, email address, phone number and postal address.
3.2 Verification and KYC data – government-issued identity documents (such as passport, visa or PAN), address proof, and the results of identity, sanctions and anti-money-laundering checks.
3.3 Financial and account data – account and transaction details, holdings, balances and other financial information you enter or that we derive from documents you connect.
3.4 Communications – the content of your messages to us and our records of your interactions with our support team.
We do not ask you to provide special-category (sensitive) data through Aspora Bridge, and, as explained below, we do not use the Google connection to collect health-related documents. Because a mailbox is not organised by subject matter, the documents we read when you connect your Google account may nonetheless contain special-category data incidentally. We do not seek it, we do not extract or store it, and our classifier discards anything that falls outside the categories listed below. Where any special-category data is unavoidably processed in the course of that classification, we rely on your explicit consent and, where applicable, on the substantial public interest conditions in Part 2 of Schedule 1 to the Data Protection Act 2018, for which we maintain an appropriate policy document.
(a) Information from accounts you choose to connect
If you choose to connect your Google account, you grant Aspora permission to access your Gmail on a read-only basis (gmail.readonly) together with the basic identity scopes needed to establish and maintain the connection. We do not request access to any Google data we do not need, and we do not request scopes for features we have not yet built. This connection is entirely optional. We verify the access you actually grant rather than the access we request, so if you decline Gmail access, the feature does not proceed and no mail is read. Before you are taken to Google’s consent screen, we show you a separate in-App notice explaining what Aspora Bridge will read, why, and what we will and will not do with it, and we do not begin collecting anything until you have taken an affirmative action to accept it.
When the connection is active, we look only for financial documents that power features you can see in the App. The categories we look for, and the feature each one supports, are set out below.
| Category | Examples of documents | What it powers |
|---|---|---|
| Investments | Mutual fund Consolidated Account Statements (CAMS/KFintech), broker contract notes, demat holdings, NPS, PPF | Wealth view – portfolio holdings and asset allocation |
| Banking | Account statements (NRE/NRO India, UAE, UK), fixed-deposit advices | Wealth view – cash balances across countries; banking onboarding – proof of an existing account and address |
| Tax | TDS certificates, Form 16A, interest certificates | Wealth view – flagging recoverable NRO TDS and assembling documents needed at filing |
| Insurance | Life and general policy documents, premium receipts | Wealth view – protection cover shown alongside assets |
| Real estate | Property documents, rent receipts, rental income statements, property tax | Wealth view – property value and rental yield within net worth |
| Liabilities and bills | Loan statements, EMI schedules, credit card statements, utility bills | Wealth view – liabilities, so net worth reflects more than gross assets |
| Identity / KYC | Passport, visa, PAN, address proof – only where the required record is not one we already hold | Account and transfer onboarding – preparing documents you would otherwise find and upload manually when opening an account or setting up a transfer |
We do not use the Google connection to collect health-related documents such as medical bills, diagnostic reports or prescriptions. If we offer any feature that relies on such data in future, it will be introduced under a separate, explicit consent flow.
(b) Other people’s information in the documents you connect
The documents in your mailbox also contain information about other people – most obviously the name and email address of whoever sent a statement, invoice or certificate, and sometimes the details of a counterparty to a transaction. We do not seek that information out and we do not use it to build a profile of anyone. Where we process it, we do so because it is inseparable from the document you asked us to read, and we rely on our legitimate interests in providing the feature you have requested, to you. Because we have no relationship with those individuals and no practical means of contacting them, giving each of them a separate notice would involve disproportionate effort; this Privacy Policy is published so that any of them may contact us at dpo@aspora.com to exercise their rights. We have assessed this processing in a data protection impact assessment.
(c) Information we collect automatically
When you use our App we automatically collect:
3.5 Device and technical data – device identifiers, device type and operating system, App version, language settings and network information.
3.6 Usage data – the features you use, actions you take, screens you view, and the dates and times of your interactions.
3.7 Cookies and similar technologies – as described in the “Cookies and similar technologies” section below.
We use this information to operate, secure, personalise and improve our Services, to remember your preferences, and to detect and prevent fraud and abuse.
(a) Information we receive from other sources
We also receive personal information about you from:
3.8 identity-verification, sanctions- and fraud-screening providers, who help us meet our regulatory obligations;
3.9 your banks, financial institutions and other providers, where you connect an account or where information is shared to complete a transaction;
3.10 our group companies, where you use more than one Aspora service; and
3.11 publicly available sources and registers, where permitted by law.
4. How we use your information
We use your information to provide and improve our Services, to meet our legal and regulatory obligations, and to keep your account and our platform secure. The main purposes, and the legal bases we rely on where data-protection law requires one, are:
4.1 To provide your Aspora Bridge net-worth view – building your net worth across the countries where you hold money, from the financial documents you connect. Legal basis: your consent to connect your Google account, together with performance of our contract with you.
4.2 To help you open an account or set up a transfer – preparing and verifying the documents needed for onboarding and for regulatory checks such as source-of-funds. Legal basis: performance of our contract, and compliance with our legal obligations.
4.3 To meet legal, regulatory and anti-money-laundering obligations – including identity verification and record-keeping. Legal basis: compliance with a legal obligation.
4.4 To secure our Services and prevent fraud and abuse. Legal basis: our legitimate interests in protecting you, us and our platform.
4.5 To communicate with you about your account and to respond to your requests. Legal basis: performance of our contract and our legitimate interests.
4.6 To operate, test and improve the App – including troubleshooting, analytics and service development. Legal basis: our legitimate interests in running and improving our Services.
4.7 To keep records and respond to regulators, courts and authorities. Legal basis: compliance with a legal obligation.
Where we rely on your consent (for example, to connect your Google account), you can withdraw it at any time, as described in the “Consent and withdrawing consent” section. Where we rely on legitimate interests, we weigh those interests against your rights and only proceed where yours do not override them; you can ask us for more information about that assessment. Under the applicable data protection laws, we process your personal information on the equivalent lawful bases those laws provide, including your consent and the performance of a contract with you.
Where the Indian DPDP Act applies, we rely primarily on your consent and, where the DPDP Act permits, on certain legitimate uses. Where United States state privacy laws apply, the concept of a “legal basis” does not apply in the same way; we limit our use of your information to the purposes described in this Privacy Policy and honour the rights those laws give you.
Where the information we hold about you is subject to the Gramm-Leach-Bliley Act and Regulation P, the separate privacy notice we give you under that Act governs that information, and the State privacy laws described in this Privacy Policy do not apply to it. The supplemental notice for the United States below explains how the two fit together.
The purposes above apply to information from your Google account only to the extent described in the Google User Data section, which controls in the event of any conflict.
5. Google User Data
This section explains how we access, use, store, share and protect information we receive from Google APIs. It applies only if you choose to connect your Google account, and you can disconnect at any time.
(a) What we access and why
We request read-only access to your Gmail (gmail.readonly) and the basic identity scopes needed for the connection. We use this access solely to locate and read the categories of financial and identity documents described in section 3 (The information we collect), each of which powers a feature that is visible to you in the App. We do not read, index or retain any other mail. We use Google user data only to provide or improve user-facing features that are visible and prominent in the App, and we request the narrowest scopes that allow those features to work. We explain what Aspora Bridge will read, and why, at the point you connect your account, so that your choice is informed. Google’s own handling of your Google account and of the data held in it is governed by Google’s privacy policy and not by this Privacy Policy.
(b) What we store and what we process only once
We are deliberate about what leaves the processing stage and what is stored. The table below sets this out.
| Data | How we handle it | Retention |
|---|---|---|
| Raw messages and attachments | Held in a processing buffer only; never written to our long-term store | Deleted on extraction, with a hard time-to-live measured in hours |
| Extracted financial facts | Stored | Kept for the life of your account; deleted within 30 days of you disconnecting Gmail or deleting your account, subject to any retention the law requires |
| Gmail message ID and provenance | Stored | Kept for the life of your account. The source document is re-fetched from Gmail on demand and never kept. |
| Identity documents | Passed through to our KYC pipeline, then deleted from the Google connection | Zero retention in our Google system. The KYC pipeline holds them under statutory anti-money-laundering retention. |
| Google OAuth refresh token | Encrypted at rest in a dedicated secret store | Kept until you disconnect, at which point access is revoked at Google |
Two choices are worth calling out. First, we store the Gmail message ID, not the message. When you want to see the source document behind a figure, we re-fetch it from Gmail and show it to you without keeping a copy, so we never create a permanent copy of your mail. Second, identity documents pass through the system rather than living in it. Once a passport or address proof reaches our KYC pipeline it is held there under anti-money-laundering law; we keep no parallel copy in the Google connection, and we only ever fetch a document the KYC record tells us is missing.
(c) Limited Use
Aspora’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. The use of information received from Google Workspace scopes will adhere to the Google User Data Policy, including the Limited Use requirements. These commitments apply to the raw data we receive from those scopes and equally to any data we aggregate, anonymise or derive from it, and we require our employees, agents, contractors and successors to comply with them.
(d) Artificial intelligence and machine learning
We do not retain, use or transfer information received from Google Workspace APIs to develop, evaluate, fine-tune, train or improve generalised or non-personalised artificial-intelligence or machine-learning models, and we do not use it for serving ads. We do not create, train or improve any artificial-intelligence or machine-learning model using Google user data beyond your own personalised model for the feature you have asked for, and we do not pool your Google user data with that of other users for any model-development purpose.
(e) Third-party service providers and AI model providers
We engage, retain or might, as per requirement and business needs, employ, engage, contract with third party service professionals/providers to work on behalf of or with us, under agreements containing confidentiality obligations and in accordance with law, in relation to the services provided by us on Aspora Bridge. They may process this information only on our behalf, under contractual no-training and zero-retention terms, and we do not route your data to any provider outside that agreement.
To the extent that third parties process information collected from Google Workspace on our behalf (including third-party AI model providers), we only permit them to process this information on our behalf and to help us provide the Services. We do not disclose raw or derived Workspace API user data to third party AI services, including third-party AI model providers, for model training or secondary purposes.
(f) Uses we prohibit
We place strict limits on ourselves in respect of Google user data:
5.1 We do not transfer or sell Google user data to third parties such as advertising platforms, data brokers or information resellers.
5.2 We do not use, transfer or sell Google user data for serving advertisements, including retargeting, personalised or interest-based advertising.
5.3 We do not use, transfer or sell Google user data to determine credit-worthiness or for lending purposes.
5.4 We do not transfer Google user data at all except: to provide or improve the user-facing features described in this section, with your consent; for security purposes, such as investigating abuse; to comply with applicable law.
5.5 We do not use, transfer or sell Google user data for marketing, for market research, or to build products or insights for anyone other than you.
(a) When a person may access your Google data
Access to your Google data is automated by default. A member of our team may view it only in limited circumstances:
5.6 with your explicit and documented consent to view specific items;
5.7 to investigate a security incident or abuse;
5.8 where required by law; or
5.9 where the data has been aggregated and anonymised for internal operations.
Any such access is recorded in an access log under named, per-role identities, and any links generated to view content expire within minutes.
(a) Precedence
This section governs Google user data. Notwithstanding any other provision of this Privacy Policy, Google user data is used solely to provide the features described in this section. It is not used for marketing, is not shared with third parties in aggregated or anonymised form,is not shared with third parties other than the service providers described in this section, who process it only on our instructions and only to deliver those features, and is not used to determine credit-worthiness or for lending purposes. If any other part of this Privacy Policy would permit something this section prohibits, this section prevails.
(b) How to disconnect and delete your data
You can disconnect the Google connection at any time from within the App, and you can also review or revoke Aspora’s access from your Google account at myaccount.google.com/permissions. When you disconnect, we revoke our access at Google and delete the financial facts we extracted within 30 days, subject to any retention the law requires. To ask us to delete extracted data without disconnecting, contact us at dpo@aspora.com. Step-by-step instructions for disconnecting your Google account, and for asking us to delete the information we derived from it, are published in our Help Centre on the application. Identity documents that have already entered our KYC pipeline are held there under anti-money-laundering law and cannot be deleted on request until the statutory retention period has expired under applicable laws.
6. Consent and withdrawing consent
Where we rely on your consent to process your personal information – including your consent to connect your Google account, and your consent under the UAE PDPL where it applies – that consent is voluntary, specific and informed, and you can withdraw it at any time. You can withdraw consent by:
6.1 disconnecting your Google account from within the App or at myaccount.google.com/permissions;
6.2 changing the relevant permission in your device or App settings; or
6.3 contacting us at dpo@aspora.com.
Withdrawing consent does not affect the lawfulness of processing carried out before you withdrew it, and it does not affect processing we carry out on another lawful basis (for example, where we must keep certain records to meet legal or regulatory obligations). If you withdraw consent for the Google connection, the related features will stop working and we will delete the associated data as described in the Google User Data section.
7. How we share your information
We share personal information only where necessary to provide our Services, meet our legal obligations, or protect our platform. The categories of recipient are:
7.1 Group companies – other companies in the Aspora group, where they help provide the Services or where you use more than one Aspora service.
7.2 Service providers and processors – including third-party AI model providers, our cloud infrastructure and hosting providers, and providers of analytics, communications and customer-support tools. They act on our instructions under contract and may only use your information to provide services to us.
7.3 Identity-verification and anti-money-laundering partners – where we pass identity documents into our KYC pipeline to open accounts or complete regulated checks.
7.4 Banks, financial institutions and payment partners – where needed to provide a service you have asked for.
7.5 Regulators, law-enforcement and other authorities – where we are legally required or permitted to disclose information.
7.6 Professional advisers and, in a corporate transaction (such as a merger, acquisition or financing), prospective buyers or investors and their advisers, subject to appropriate confidentiality safeguards. Google user data will not be disclosed to a prospective buyer or investor. If we undergo a merger, acquisition or sale of assets, Google user data will be transferred only where permitted under the Google API Services User Data Policy and after obtaining your explicit prior consent.
We require everyone who processes personal information on our behalf to protect it, to use it only as we instruct, and to comply with applicable data-protection law.
We do not “sell” or “share” your personal information. We do not use it to serve advertising, and we do not use it to determine credit-worthiness or for lending purposes. These commitments apply to all of your information and, as set out above, are absolute in respect of Google user data.
8. Where we store and transfer your information
Our production systems currently store data in the United Kingdom. This means that information about you, including financial information relating to accounts you hold in India or elsewhere, may be processed outside your country of residence.
Where we transfer personal data across borders, we put in place the appropriate safeguards required by applicable law, which may include:
8.1 transfers to countries that the relevant authority has found to provide an adequate level of protection;
8.2 the UK International Data Transfer Agreement or Addendum, or the European Commission’s Standard Contractual Clauses, together with any additional measures needed; and
8.3 other lawful transfer mechanisms recognised under the UAE PDPL or other applicable law; and
8.4 for transfers involving India or the United States, the transfer mechanisms and safeguards recognised under the Indian DPDP Act or applicable United States law.
You can ask us for a copy of the safeguards that apply to transfers of your data using the contact details below.
Where personal data relating to India is subject to sectoral data-localisation requirements (for example, requirements set by the Reserve Bank of India for payment data), we comply with those requirements
9. How long we keep your information
We keep personal information only for as long as we need it for the purposes described in this policy, or for as long as the law requires us to. Account and transaction records are generally kept for the life of your account and for a statutory period afterwards to meet financial-services and anti-money-laundering obligations. When we no longer need your information, we securely delete or anonymise it.
The table below summarises how long we typically keep the main categories of information. Where a longer period is required by law, we keep the information for that longer period.
| Information | Typical retention |
|---|---|
| Account and profile data | For the life of your account, then up to 5 (five) year(s) |
| Transaction and KYC records | For the period required by anti-money-laundering and financial-services law – typically 5 (five) years after the end of our relationship |
| Raw Gmail messages and attachments | Deleted on extraction, within hours |
| Extracted financial facts | Life of your account; deleted within 30 days of disconnection or account deletion, subject to statutory retention |
| Identity documents (via Google connection) | Not retained in the Google connection; held in the KYC pipeline under statutory anti-money-laundering retention |
| Google OAuth refresh token | Until you disconnect |
| Support communications | Up to 5 (five) year(s) |
10. How we keep your information secure
We apply organisational and technical measures designed to protect your information, and the Google connection is subject to the independent annual security assessment that Google requires of applications using restricted scopes, carried out by a Google-designated assessor under the Cloud Application Security Assessment framework. These measures include:
10.1 Encryption at rest – including refresh tokens held in a dedicated secret store and documents held in object storage.
10.2 Encryption in transit – data moving between your device, the App and our systems is protected using industry-standard encryption.
10.3 Classification before storage – only information relevant to the features you use is written to our systems; anything out of scope is discarded rather than kept.
10.4 Access controls – access is limited to staff and providers who need it, under role-based controls and authentication, with no direct path to stored objects and a consent-to-view gate before any person can access your content.
10.5 Minimal logging – our pipeline and application logs never become a second copy of your mailbox; they carry job identifiers and counts, not email addresses or message content.
10.6 Automated deletion – a disconnect endpoint revokes access and triggers erasure, and scheduled processes enforce our retention periods at the infrastructure level.
10.7 Vendor due diligence – we assess the security and data-protection practices of the providers we use.
10.8 Key management – encryption keys and key material are held in a hardware security module or an equivalent key-management system.
10.9 Safeguards for automated document reading – content drawn from your mailbox is treated as untrusted input and is processed with controls designed to prevent prompt-injection and similar attacks against the models we use
10.10 Monitoring, testing and training – we monitor our systems for security events, review and test our controls, and require our staff to keep your information confidential and to complete data-protection and security training.
No system can be guaranteed to be completely secure. If you believe your account or your data is no longer secure, please contact us immediately at dpo@aspora.com.
11. Automated decision-making and profiling
Aspora Bridge uses automated processing to read and classify the documents you connect and to extract financial information from them. This helps us present your net-worth view and prepare your onboarding documents. The figures we show are informational, a person can review the results, and you remain in control of any decision you make.
We do not use your personal information – and in particular we do not use Google user data – to make solely automated decisions that produce legal or similarly significant effects about you, and we do not use it to determine credit-worthiness or for lending purposes. Where we are required to carry out automated checks for fraud-prevention or anti-money-laundering purposes, we do so under our legal obligations and apply appropriate safeguards, including the ability to request human review.
12. Marketing and communications
We may send you service messages that are necessary to provide the Services – for example security alerts, verification messages and important notices about your account. These are not marketing, and you cannot opt out of them while you hold an account.
Where the law requires your consent, we will only send you marketing about our products and services if you have agreed to receive it. You can opt out of marketing at any time using the unsubscribe link in the message, by changing your App or device settings, or by contacting us at dpo@aspora.com. We do not use Google user data for marketing.
13. Cookies and similar technologies
We and our providers use cookies and similar technologies (such as software development kits and device identifiers) to keep you signed in, remember your preferences, keep the App secure, measure how the App is used, and improve it. Some of these are necessary for the App to work; others are optional. Where the law requires your consent for non-essential cookies or similar technologies, we ask for it, and you can change your choices at any time in your App or device settings.
14. Your rights
Depending on where you live, you have rights over your personal information. Subject to the conditions and exceptions in applicable law, these include:
14.1 Access – to be told whether we process your personal information and to receive a copy of it.
14.2 Rectification – to have inaccurate or incomplete information corrected.
14.3 Erasure – to ask us to delete your information in certain circumstances.
14.4 Restriction – to ask us to limit how we use your information in certain circumstances.
14.5 Objection – to object to processing based on our legitimate interests, and to object to direct marketing at any time.
14.6 Portability – to receive certain information in a structured, commonly used, machine-readable format and to have it transferred to another controller where technically feasible.
14.7 Withdrawal of consent – to withdraw any consent you have given, including by disconnecting your Google account, as described above.
14.8 Rights in relation to automated decisions – not to be subject to solely automated decisions that produce legal or similarly significant effects, as described above.
If you are in the United Arab Emirates, you also have the rights provided under the UAE PDPL, including rights of access, correction, erasure and restriction, the right to object to processing, and the right to ask that the processing or cross-border transfer of your data be stopped, subject to that law. The supplemental notice for the United Arab Emirates below sets out these rights, and the bases on which we process your information, in more detail.
If you are in India, you also have the rights provided under the Indian DPDP Act, including the right to access a summary of the personal data we process about you and our processing activities, the right to correction, completion, updating and erasure of your personal data, the right to nominate another individual to exercise your rights in the event of your death or incapacity, and the right to a readily available means of grievance redressal. You can exercise these rights, and raise any grievance, with our Grievance Officer using the contact details in the “How to contact us and how to complain” section. The supplemental notice for India below sets out these rights, and the bases on which we process your information, in more detail.
If you are a United States resident, you may have rights under your state’s privacy laws (for example, the CCPA/CPRA in California). Subject to those laws, these include the right to know about and access the personal information we collect, the right to correct or delete it, the right to opt out of the “sharing” of personal information and of targeted advertising, the right to limit the use of sensitive personal information, and the right not to receive discriminatory treatment for exercising your rights. We do not sell your personal information, and we do not use Google user data for advertising. The supplemental notice for the United States below sets out these rights, and the bases on which we process your information, in more detail.
How to exercise your rights. You can exercise your rights by contacting us at dpo@aspora.com. We may need to verify your identity before we act on your request. We will respond within the timeframes required by applicable law and, in most cases, without charge; where a request is manifestly unfounded or excessive, we may charge a reasonable fee or decline to act, to the extent the law allows.
15. Supplemental notice for the United Kingdom
This section applies where we process your personal data as a controller under the UK GDPR and the Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025. It applies if you are in the United Kingdom, and also – wherever you are – where the processing is carried out in the context of the activities of our UK establishments, Real Transfer Limited and Vance Technologies Limited. Where it differs from the rest of this Privacy Policy, this section prevails.
(a) Legal bases for processing personal data
We process your personal data on one or more of the following legal bases:
15.1 Consent – including your consent to connect your Google account. Where our processing involves special-category data, we rely on your explicit consent.
15.2 Performance of a contract – where processing is necessary to enter into or perform a contract with you, including providing the Services.
15.3 Legal obligation – where processing is necessary for us to comply with a legal obligation, including our obligations under money-laundering, sanctions and financial-services law.
15.4 Legitimate interests – as set out in the section headed “How we use your information”, including securing the Services, preventing fraud and abuse, improving the App, and processing information about other people that appears in the documents you connect. We carry out a balancing assessment before relying on this basis and you may ask us for a summary of it.
15.5 Substantial public interest – where we process special-category data for the prevention or detection of unlawful acts, or in order to comply with regulatory requirements relating to unlawful acts and dishonesty, we rely on the conditions in Part 2 of Schedule 1 to the Data Protection Act 2018 and maintain the appropriate policy document that section 42 of that Act requires.
(a) Your rights
Subject to applicable law, you have the following rights in respect of your personal data.
15.6 Access your personal data and receive it in a portable form. We will carry out a reasonable and proportionate search.
15.7 Correct inaccurate or incomplete data, and have it completed or updated.
15.8 Delete your data, unless we are required to keep it by law.
15.9 Restrict or suppress processing where our processing is inappropriate.
15.10 Object to processing based on our legitimate interests, and object to direct marketing at any time – an absolute right.
15.11 Withdraw consent at any time, as easily as you gave it.
15.12 Challenge automated decisions. Where a significant decision about you is taken solely by automated means, you may be told about it, make representations, obtain human intervention and contest it.
You can exercise these rights by making a written request to dpo@aspora.com . Please note that we may ask you to provide us with additional information to confirm your identity, and the time we have to respond runs from the point at which we have what we need to identify you and the information you are asking about.
(a) Whether you have to provide your information
Some of the information we ask for is required by law – for example the identity information we must collect and verify under the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 – and some is required under our contract with you. If you do not provide it, we may be unable to open or maintain your account or to provide the Services. Connecting your Google account is entirely optional and is neither a statutory nor a contractual requirement; if you choose not to connect it, only the Aspora Bridge features that depend on it will be unavailable.
(b) Complaints
If you are unhappy with how we have handled your personal data, please tell us at dpo@aspora.com. We will acknowledge your complaint within 30 days and tell you the outcome without undue delay. You also have the right to complain to the Information Commissioner’s Office (ico.org.uk, 0303 123 1113, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF), and complaining to us first does not affect that right.
(c) International transfers
Where we transfer personal data out of the United Kingdom, we rely on UK adequacy regulations where they apply, and otherwise on appropriate safeguards – principally the Information Commissioner’s International Data Transfer Agreement, s – having first satisfied ourselves that the protection for your data would not be materially lower than it is under UK law. You can ask us for a copy of the safeguards we use.
16. Supplemental notice for the United Arab Emirates
This section provides additional detail for individuals in the United Arab Emirates, and applies where Aspora processes your personal data in its capacity as a Controller, in accordance with Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (the UAE PDPL).
(a) Legal bases for processing personal data
We process your personal data with your consent and, in the cases in which the UAE PDPL permits processing without consent, on those bases – in particular where processing is necessary for the performance of a contract to which you are a party or to take steps at your request before entering into one, to comply with obligations imposed on us by law, to establish, exercise or defend legal claims, or to protect the public interest.
(b) Your rights
Subject to applicable law, you have the following rights in respect of your personal data.
(a) Be informed of the types of personal data we process, the purposes, any automated decisions, the parties inside and outside the UAE with whom we share it, the retention and storage controls, the cross-border safeguards, and how to complain to the UAE Data Office.
(b) Request transfer of the personal data you gave us, in an organised, machine-readable form, and have it transmitted to another controller where technically feasible.
(c) Correct or erase your data – correction of inaccurate data without undue delay, and erasure where the data is no longer necessary, where you withdraw consent, or where processing was unlawful.
(d) Restrict processing where you contest accuracy, where you have objected pending verification, where processing breaches the agreed purposes, or where you need the data for legal claims.
(e) Stop processing carried out for direct marketing, including related profiling, or carried out in breach of Article 5 of the UAE PDPL.
(f) Withdraw consent at any time, without affecting the lawfulness of earlier processing.
You can exercise these rights by making a written request to dpo@aspora.com. We may ask you for additional information to confirm your identity. If you are not satisfied with our response, you may complain to the UAE Data Office.
(c) Cross-border transfers and breach notification
Your personal data is collected into, and processed in, our United Kingdom systems from the outset; we operate no separate system of record in the UAE. Where data is nonetheless transferred out of the UAE – for example where a UAE bank or partner sends us information to complete something you have asked for – we rely on the bases the UAE PDPL permits: necessity for our contract with you or a contract made in your interest, a contract obliging the recipient to apply UAE PDPL standards, or your explicit consent. The UAE Data Office has not yet published an adequacy list or approved standard contractual clauses; we will rely on those mechanisms if and when it does. Transfers out of the United Kingdom are dealt with in the supplemental notice for the United Kingdom above.
(d) Breach notification
If a personal data breach occurs that would prejudice the privacy, confidentiality or security of your personal data, we will notify the UAE Data Office immediately and will notify you where we are required to do so.
17. Supplemental notice for the United States
This section applies where we process personal information as a business or controller under United States State privacy laws, including the California Consumer Privacy Act as amended by the California Privacy Rights Act (the CCPA).
(a) How this section works with the Gramm-Leach-Bliley Act
Vance Money Services LLC is a financial institution for the purposes of the Gramm-Leach-Bliley Act (GLBA). Where the personal information we collect, process, disclose is subject to the GLBA and the regulations made under it, the separate GLBA privacy notice we give you when we establish our relationship with you – and, where required, annually thereafter – governs that information, and the State privacy rights described in this section do not apply to it. Those State privacy rights do apply to personal information that is not subject to the GLBA. Even where your personal information is subject to the GLBA, you may retain the rights and remedies provided by California Civil Code section 1798.150 for certain personal information security breaches.
(b) Sensitive personal information
Some information we handle is “sensitive personal information” under the CCPA and comparable State laws: your government identification numbers, your financial account information and – because we are not the intended recipient – the contents of the Gmail messages and attachments we read when you connect your Google account. We use it only to provide the goods and services you have asked for and for the other purposes the law permits, and not to infer characteristics about you. Because we use and disclose it for no other purpose, we do not provide a “Limit the Use of My Sensitive Personal Information” link; and because we do not sell or share personal information, we do not provide a “Do Not Sell or Share My Personal Information” link. We have no actual knowledge that we sell or share the personal information of consumers under 16 years of age.
(c) Your rights
Subject to applicable law, you have the following rights in respect of your personal data.
17.1 Access, in a portable format, the personal data we collect, use, disclose, share and sell about you, its sources, the purposes for which we collected it, and the categories of third parties to whom we disclose it.
17.2 Correct errors in your personal data.
17.3 Delete your personal data, unless we are required or permitted to keep it – for example to comply with anti-money-laundering record-keeping obligations.
17.4 Opt out of behavioural or targeted advertising, automated profiling and sales of personal data. We do none of these, and we honour opt-out preference signals such as Global Privacy Control where the law requires.
17.5 Limit our use and disclosure of your sensitive personal information to what is necessary to provide what you have asked for.
17.6 Opt out of automated decision-making technology that produces legal or similarly significant effects about you, and obtain meaningful information about how it works.
17.7 Not be treated differently for exercising these rights.
17.8 Appeal our decision on your request, where your State’s law provides an appeal – California’s does not – by writing to dpo@aspora.com. We will respond within 45 days and, if we deny the appeal, tell you how to contact your State Attorney General.
You can exercise these rights by contacting us at dpo@aspora.com or through the privacy centre in the App. We will verify your identity; you may use an authorised agent, and we may ask for proof of their authority. We retain each category of personal information for the periods set out under “How long we keep your information”, and never for longer than is reasonably necessary for the purposes we have disclosed.
18. Supplemental notice for India
This section applies where we process your personal data as a Data Fiduciary under the Digital Personal Data Protection Act, 2023 (the DPDP Act) and the Digital Personal Data Protection Rules, 2025, which are being brought into force in stages. We apply each provision from the date on which it takes effect.
18.1 Notice. This Privacy Policy, with the consent notice shown in the App, is intended as notice under Sections 5 and 6. It can be understood on its own, itemises the personal data we process and the purposes for which we process it, and is available in English and, on request, in any language specified in the Eighth Schedule to the Constitution of India.
18.2 Consent. We process on the basis of your consent and, where the DPDP Act permits, the certain legitimate uses in Section 7. The DPDP Act provides no “legitimate interests” basis and we rely on none in India.
18.3 Withdrawal. You may withdraw consent at any time, as easily as you gave it, by disconnecting your Google account in the App or at myaccount.google.com/permissions, by changing the relevant App or device setting, or by writing to dpo@aspora.com. Withdrawal does not affect earlier processing; we and our Data Processors will stop within a reasonable time unless the law requires otherwise.
18.4 Consent Managers. We may work with registered Consent Managers to manage and honour your consents.
18.5 Access (Section 11). You may request a summary of the personal data we process and of our processing activities, and the identities of the other Data Fiduciaries and Data Processors with whom we have shared it, with a description of what was shared. We may withhold the latter where the sharing was with an authorised Data Fiduciary for the prevention, detection or investigation of offences or cyber incidents.
18.6 Correction and erasure (Section 12). You may ask us to correct, complete, update or erase your personal data. We will erase it unless we need it for the specified purpose or to comply with a law, such as the record-keeping obligations under the Prevention of Money-Laundering Act, 2002.
18.7 Nomination (Section 14). You may nominate one or more individuals to exercise your rights in the event of your death or incapacity.
18.8 Children and guardianship (Section 9). Where we process the personal data of children, or of persons with disabilities who have a lawful guardian, we obtain verifiable consent from the parent or lawful guardian. We do not track or behaviourally monitor children or direct advertising at them.
18.9 Grievances (Section 13). Contact our Data Protection Officer at dpo@aspora.com. We respond within 30 days. You must use this mechanism before approaching the Data Protection Board of India.
18.10 Security and breach (Section 8). We apply reasonable security safeguards – encryption or tokenisation, access control, logging and monitoring, backups, and contractual obligations on our Data Processors – and will inform you and the Data Protection Board of India of a personal data breach without delay, giving the Board a detailed report within 72 hours of becoming aware of it.
18.11 Transfers (Section 16). We may transfer your personal data outside India, subject to any restriction the Central Government notifies and to the sectoral requirements that apply to us, including the Reserve Bank of India’s directions on the storage of payment system data.
19. If we experience a data breach
We maintain procedures to detect, investigate and respond to personal-data breaches. Where a breach is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority, and affected individuals, within the timeframes and in the manner required by applicable law.
20. Third-party links and services
Our App and our communications may contain links to third-party websites, services or content that we do not control, and Aspora Bridge relies on third-party services such as Google. This Privacy Policy does not apply to those third parties, and we are not responsible for their privacy practices. We encourage you to read their privacy notices.
21. Children’s data
Our Services are intended for adults. We do not knowingly provide our Services to, or collect personal information from, anyone under the age of 18. If you believe a child has provided us with personal information, please contact us so that we can remove it. Under the Indian DPDP Act, anyone under the age of 18 is a child; our Services are not directed to children, and we do not knowingly process children’s personal data without the consent of a parent or lawful guardian.
22. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our Services, our practices or the law. When we make changes, we will update the effective date at the top of this policy. Where the changes are material, we will give you reasonable notice through the App or by other appropriate means and, where the law requires, seek your consent. We encourage you to review this Privacy Policy periodically. If you do not agree with a change, you can stop using Aspora Bridge and, where relevant, disconnect your Google account and ask us to delete your data.
23. How to contact us and how to complain
If you have any questions, concerns or requests about this Privacy Policy or about how we handle your personal information, please contact our Data Protection Officer at dpo@aspora.com. We will acknowledge your complaint within 30 days and tell you the outcome without undue delay. You can also write to the controlling entity for your market at the registered address set out in section 1.
Complaining to us does not affect your right to complain to your data-protection authority, and if you are not satisfied with our response you may complain to:
23.1 United Kingdom – the Information Commissioner’s Office (ico.org.uk).
23.2 United Arab Emirates – the UAE Data Office, under the federal UAE Personal Data Protection Law, as applicable.
23.3 India – the Data Protection Board of India, once established under the DPDP Act.
23.4 United States – your State Attorney General, the Federal Trade Commission or, in California, the California Privacy Protection Agency, as applicable.
We would appreciate the chance to address your concerns directly before you approach a regulator.
