€18.4M recovered in 2025 · 1,200+ cases closed · ISO 27001 secure

Privacy Policy

Version 3.0 · Last updated: 18 June 2026 · Compliant with Regulation (EU) 2016/679 (GDPR), Directive 2002/58/EC (ePrivacy), Regulation (EU) 2022/1925 (DMA), Regulation (EU) 2022/2065 (DSA) and Directive (EU) 2015/849 as amended (AMLD).

At a glance. We collect only what we need to recover your funds and meet our legal duties. We never sell your data, never use it for cross-context behavioural advertising, and never use solely automated decisions with legal effect. You can access, correct, export, restrict or delete your data from Account or by emailing privacy@unblockfunds.com. You may complain to your national data-protection authority at any time.

1. Controller, joint controllers and DPO

The data controller is UnblockFunds Ltd, 12 St Stephen's Green, Dublin 2, D02 XY12, Ireland (company no. 738291; VAT IE3829174L). Our Data Protection Officer can be reached at dpo@unblockfunds.com or by post at "Data Protection Officer" at the same address.

Where we partner with an independent law firm or expert under a joint-controller arrangement (Article 26 GDPR), the essence of that arrangement is disclosed to you in the engagement letter and a copy is available on request. Where you entrust us with personal data of third parties (for example data subjects appearing in your dispute file), we act as a processor on your behalf under the Data Processing Addendum (DPA) incorporated into your engagement letter.

2. Scope of this policy

This policy applies to all processing of personal data carried out by UnblockFunds in connection with our website, the Service, our customer support, marketing communications, recruitment, and our offices. Where a specific product or campaign has its own privacy notice, that notice supplements (not replaces) this one.

3. Personal data we collect

3.1 Data you give us

  • Identity & account: name, email, phone, password hash, profile preferences, language, time zone.
  • Business: legal entity name, trading name, registration number, registered address, beneficial owners, ID documents, proof of address.
  • Case: payment processor name, MID, amounts held, freeze/reserve dates, correspondence, statements, contracts, screenshots, chargeback evidence, banking metadata.
  • Financial: invoicing details, IBAN for recovered funds, VAT number, tax residency.
  • Communications: messages exchanged with specialists, support tickets, call recordings (where you have consented or been notified), meeting notes.

3.2 Data collected automatically

  • Device & log: IP address, browser and OS, timestamps, pages visited, referrer, error logs.
  • Security: sign-in attempts, MFA events, device fingerprints used to detect account take-over, audit trail of sensitive actions (e.g. document downloads, payout changes).
  • Product analytics: aggregated, privacy-preserving usage metrics (no cross-site tracking).

3.3 Data from third parties

  • Identity verification providers (KYC/AML checks under AMLD).
  • Public registers (company houses, beneficial-owner registers, court registers).
  • Sanctions, PEP and adverse-media screening providers.
  • Your payment processor, acquiring bank or correspondent bank, where you authorise disclosure.
  • Counterparty law firms and courts in the context of formal proceedings.

4. Purposes and lawful bases

PurposeLawful basis (GDPR Art. 6)Notes
Create and operate your account(b) ContractNecessary to provide the Service you signed up for.
Progress your recovery case(b) Contract / (c) Legal obligationIncludes case correspondence, expert input, court submissions.
KYC, AML, sanctions screening(c) Legal obligationUnder AMLD as transposed in Ireland.
Invoicing, accounting, tax(c) Legal obligationIrish Revenue, VAT Directive, country-specific e-invoicing.
Service security, fraud prevention(f) Legitimate interestSecuring the platform against abuse and account take-over.
Service improvement, analytics(f) Legitimate interestAggregated, pseudonymised where possible.
Customer support and quality(b) Contract / (f) Legitimate interestIncludes review of tickets and (notified) call recordings.
Product news and marketing(a) Consent / (f) soft opt-inYou can withdraw at any time; soft opt-in applies only to similar products to existing customers.
Establishing, exercising, defending legal claims(f) Legitimate interest / (c) Legal obligationIncludes Art. 9(2)(f) basis for special-category data.
Corporate transactions (M&A, due diligence)(f) Legitimate interestLimited to what is necessary, under NDA.

Where we rely on legitimate interests, we have performed a Legitimate Interests Assessment (LIA) and can share a summary on request. You may object at any time on grounds relating to your particular situation (Art. 21 GDPR).

5. Special-category and criminal-conviction data

We do not knowingly seek special-category data (Art. 9 GDPR) or criminal-conviction data (Art. 10 GDPR). Where a case file unavoidably contains such data — for example, allegations of fraud against a counterparty — we process it only insofar as necessary for the establishment, exercise or defence of legal claims (Art. 9(2)(f)) or where we are subject to a clear legal obligation. Such data is access-restricted, encrypted at rest, and logged.

6. Who we share data with

  • Assigned recovery specialists and partner law firms working on your case (under written confidentiality and professional rules).
  • Counterparties — payment processors, acquiring banks, card schemes, regulators, courts — where necessary to progress your case.
  • Processors bound by Art. 28 GDPR contracts: cloud hosting, database, email delivery, identity verification, error monitoring, customer-support tooling, payment providers. The current list is in section 7.
  • Professional advisers (auditors, lawyers, insurers) under confidentiality.
  • Authorities where legally required (court order, AML/CFT, tax, sanctions enforcement).
  • A successor in a merger, acquisition or asset sale, subject to equivalent protections and notice to you.

We never sell your personal data and do not use it for cross-context behavioural advertising.

7. Sub-processors

The principal categories of sub-processors we use today are:

CategoryPurposePrimary region
Cloud platform & databaseApplication hosting, document storageEU (Ireland / Frankfurt)
CDN & DDoS protectionEdge delivery and securityGlobal (EU edge preferred)
Identity verification (KYC)Document and liveness checksEU
Email deliveryTransactional and notification emailEU / US (DPF certified)
Error monitoringDiagnose and fix bugsEU
Payment processorsCharging, refunds, payoutsEU / UK
Customer support toolingTickets, messaging, knowledge baseEU
Analytics (privacy-preserving)Aggregated product usageEU

A current, named list with locations and safeguards is available from the DPO. We will give you at least 30 days' prior notice (by email and in-app) of any intended addition or replacement of a sub-processor, giving you the opportunity to object on reasonable grounds.

8. International transfers

Your data is primarily stored in the EU/EEA. Where a processor or sub-processor is located outside the EEA, transfers are protected by one or more of the safeguards permitted by Chapter V GDPR:

  • An EU adequacy decision (e.g. UK, Switzerland, Japan, Republic of Korea, EU–US Data Privacy Framework where the recipient is certified).
  • The European Commission's Standard Contractual Clauses (Decision 2021/914) with supplementary technical, contractual and organisational measures informed by a Transfer Impact Assessment (TIA).
  • Binding Corporate Rules or another mechanism permitted by Chapter V GDPR.

A copy of the safeguards (with commercial information redacted) is available from the DPO on request.

9. Retention schedule

CategoryRetention periodReason
Account dataLife of account + 12 monthsWind-down and audit.
Case files6 years after closureLimitation periods + AMLD record-keeping.
KYC documents5 years after end of business relationshipAMLD (extendable to 10 years).
Invoices and tax records7 yearsIrish Revenue requirements.
Marketing consentsUntil withdrawn (+ suppression record)Proof of consent / suppression.
Security and access logs12 monthsIncident response, audit.
Call recordings (where used)6 monthsQuality and dispute resolution.
Cookies (strictly necessary)Session / up to 12 monthsSession continuity, security.

After these periods, data is deleted or irreversibly anonymised. Backups are rotated on a fixed cycle and overwritten in due course.

10. Security measures

We apply technical and organisational measures appropriate to the risk (Art. 32 GDPR), including:

  • TLS 1.2+ in transit; AES-256 at rest for the database and document storage.
  • Role-based access control, principle of least privilege, just-in-time elevation, full audit logging.
  • Multi-factor authentication (MFA) required for all staff and offered to all customers.
  • Private document storage with short-lived signed URLs; documents are never indexed by search engines.
  • Network segmentation, web application firewall, automated dependency and vulnerability scanning.
  • Quarterly penetration testing by an independent third party; annual disaster-recovery exercise; daily encrypted off-site backups with a recovery-point objective of 24 hours and a recovery-time objective of 8 hours.
  • Vendor due diligence and ongoing monitoring under Art. 28 contracts.
  • Mandatory privacy and security training for all staff at onboarding and at least annually thereafter.
  • Confidentiality obligations that survive end of employment.

11. Personal data breach handling

We maintain a documented incident-response process. Confirmed personal-data breaches are notified to the lead supervisory authority within 72 hours where required (Art. 33 GDPR), and affected data subjects are informed without undue delay where the breach is likely to result in a high risk to their rights and freedoms (Art. 34 GDPR). All incidents are recorded internally and reviewed to prevent recurrence.

12. Your rights and how to exercise them

Under the GDPR you have the right to:

  • Access your data and obtain a copy (Art. 15).
  • Rectify inaccurate or incomplete data (Art. 16).
  • Erasure ("right to be forgotten") (Art. 17), subject to legal-retention exceptions.
  • Restrict processing (Art. 18).
  • Portability — receive your data in a structured, commonly used, machine-readable format and transmit it to another controller (Art. 20).
  • Object to processing based on legitimate interests, including profiling (Art. 21).
  • Withdraw consent at any time, without affecting prior lawful processing (Art. 7(3)).
  • Not be subject to a solely automated decision producing legal or similarly significant effects (Art. 22). We do not make such decisions about you.
  • Be informed about processing (Arts. 13–14) — this policy is the principal vehicle.

Exercise any right from Account or by emailing privacy@unblockfunds.com. We respond within one month of receiving a complete request, extendable by two months for complex requests (Art. 12(3)). Identity verification may be required to protect your data. Requests are free of charge unless manifestly unfounded or excessive.

13. Automated decisions and profiling

We do not make decisions producing legal or similarly significant effects on you based solely on automated processing. Where we use automation to triage new cases or flag suspicious activity, a human reviewer takes the final decision and you have the right to obtain human intervention, express your point of view, and contest the outcome.

14. Cookies and similar technologies

We use strictly necessary cookies and local storage to keep you signed in, balance load, persist your accessibility preferences, and protect against CSRF and session fixation. These do not require consent under Article 5(3) of the ePrivacy Directive. We do not use advertising, profiling, or cross-site tracking cookies.

If we introduce optional analytics or marketing cookies in future, they will be loaded only after your opt-in consent through a banner, refusal will be as easy as acceptance, and you will be able to withdraw consent at any time from a persistent settings link in the footer.

15. Marketing communications

We send product news and similar marketing only with your consent or, where permitted by Article 13(2) of the ePrivacy Directive (the so-called "soft opt-in"), to existing customers about similar products, with a clear unsubscribe link in every message and in your Account → Notifications settings. Transactional and case-related communications (security alerts, invoices, case updates) are sent on the basis of contract performance and our legal obligations and are not marketing.

16. Children

The Service is intended for businesses and the adults representing them. It is not directed at children under 16 and we do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact the DPO and we will delete it.

17. Complaints to a supervisory authority

You may lodge a complaint with a supervisory authority — in particular in your EU Member State of habitual residence, place of work, or place of the alleged infringement (Art. 77 GDPR). Our lead supervisory authority is the Irish Data Protection Commission (dataprotection.ie, 21 Fitzwilliam Square South, Dublin 2). We would, however, appreciate the chance to address your concern first via dpo@unblockfunds.com.

18. Changes to this policy

We will notify you of material changes by email and in-app at least 30 days in advance. Minor clarifications and editorial corrections may be made without prior notice but will be reflected in the version number and "Last updated" date above. Older versions are available from the DPO.

19. Contact

General privacy queries: privacy@unblockfunds.com
Data Protection Officer: dpo@unblockfunds.com
Security disclosures: security@unblockfunds.com
Postal: Data Protection Officer, UnblockFunds Ltd, 12 St Stephen's Green, Dublin 2, D02 XY12, Ireland.

© 2026 UnblockFunds Ltd. All rights reserved.