Version 3.0 · Last updated: 18 June 2026 · Compliant with Regulation (EU) 2016/679 (GDPR), Directive 2002/58/EC (ePrivacy), Regulation (EU) 2022/1925 (DMA), Regulation (EU) 2022/2065 (DSA) and Directive (EU) 2015/849 as amended (AMLD).
At a glance. We collect only what we need to recover your funds and meet our legal duties. We never sell your data, never use it for cross-context behavioural advertising, and never use solely automated decisions with legal effect. You can access, correct, export, restrict or delete your data from Account or by emailing privacy@unblockfunds.com. You may complain to your national data-protection authority at any time.
The data controller is UnblockFunds Ltd, 12 St Stephen's Green, Dublin 2, D02 XY12, Ireland (company no. 738291; VAT IE3829174L). Our Data Protection Officer can be reached at dpo@unblockfunds.com or by post at "Data Protection Officer" at the same address.
Where we partner with an independent law firm or expert under a joint-controller arrangement (Article 26 GDPR), the essence of that arrangement is disclosed to you in the engagement letter and a copy is available on request. Where you entrust us with personal data of third parties (for example data subjects appearing in your dispute file), we act as a processor on your behalf under the Data Processing Addendum (DPA) incorporated into your engagement letter.
This policy applies to all processing of personal data carried out by UnblockFunds in connection with our website, the Service, our customer support, marketing communications, recruitment, and our offices. Where a specific product or campaign has its own privacy notice, that notice supplements (not replaces) this one.
| Purpose | Lawful basis (GDPR Art. 6) | Notes |
|---|---|---|
| Create and operate your account | (b) Contract | Necessary to provide the Service you signed up for. |
| Progress your recovery case | (b) Contract / (c) Legal obligation | Includes case correspondence, expert input, court submissions. |
| KYC, AML, sanctions screening | (c) Legal obligation | Under AMLD as transposed in Ireland. |
| Invoicing, accounting, tax | (c) Legal obligation | Irish Revenue, VAT Directive, country-specific e-invoicing. |
| Service security, fraud prevention | (f) Legitimate interest | Securing the platform against abuse and account take-over. |
| Service improvement, analytics | (f) Legitimate interest | Aggregated, pseudonymised where possible. |
| Customer support and quality | (b) Contract / (f) Legitimate interest | Includes review of tickets and (notified) call recordings. |
| Product news and marketing | (a) Consent / (f) soft opt-in | You can withdraw at any time; soft opt-in applies only to similar products to existing customers. |
| Establishing, exercising, defending legal claims | (f) Legitimate interest / (c) Legal obligation | Includes Art. 9(2)(f) basis for special-category data. |
| Corporate transactions (M&A, due diligence) | (f) Legitimate interest | Limited to what is necessary, under NDA. |
Where we rely on legitimate interests, we have performed a Legitimate Interests Assessment (LIA) and can share a summary on request. You may object at any time on grounds relating to your particular situation (Art. 21 GDPR).
We do not knowingly seek special-category data (Art. 9 GDPR) or criminal-conviction data (Art. 10 GDPR). Where a case file unavoidably contains such data — for example, allegations of fraud against a counterparty — we process it only insofar as necessary for the establishment, exercise or defence of legal claims (Art. 9(2)(f)) or where we are subject to a clear legal obligation. Such data is access-restricted, encrypted at rest, and logged.
We never sell your personal data and do not use it for cross-context behavioural advertising.
The principal categories of sub-processors we use today are:
| Category | Purpose | Primary region |
|---|---|---|
| Cloud platform & database | Application hosting, document storage | EU (Ireland / Frankfurt) |
| CDN & DDoS protection | Edge delivery and security | Global (EU edge preferred) |
| Identity verification (KYC) | Document and liveness checks | EU |
| Email delivery | Transactional and notification email | EU / US (DPF certified) |
| Error monitoring | Diagnose and fix bugs | EU |
| Payment processors | Charging, refunds, payouts | EU / UK |
| Customer support tooling | Tickets, messaging, knowledge base | EU |
| Analytics (privacy-preserving) | Aggregated product usage | EU |
A current, named list with locations and safeguards is available from the DPO. We will give you at least 30 days' prior notice (by email and in-app) of any intended addition or replacement of a sub-processor, giving you the opportunity to object on reasonable grounds.
Your data is primarily stored in the EU/EEA. Where a processor or sub-processor is located outside the EEA, transfers are protected by one or more of the safeguards permitted by Chapter V GDPR:
A copy of the safeguards (with commercial information redacted) is available from the DPO on request.
| Category | Retention period | Reason |
|---|---|---|
| Account data | Life of account + 12 months | Wind-down and audit. |
| Case files | 6 years after closure | Limitation periods + AMLD record-keeping. |
| KYC documents | 5 years after end of business relationship | AMLD (extendable to 10 years). |
| Invoices and tax records | 7 years | Irish Revenue requirements. |
| Marketing consents | Until withdrawn (+ suppression record) | Proof of consent / suppression. |
| Security and access logs | 12 months | Incident response, audit. |
| Call recordings (where used) | 6 months | Quality and dispute resolution. |
| Cookies (strictly necessary) | Session / up to 12 months | Session continuity, security. |
After these periods, data is deleted or irreversibly anonymised. Backups are rotated on a fixed cycle and overwritten in due course.
We apply technical and organisational measures appropriate to the risk (Art. 32 GDPR), including:
We maintain a documented incident-response process. Confirmed personal-data breaches are notified to the lead supervisory authority within 72 hours where required (Art. 33 GDPR), and affected data subjects are informed without undue delay where the breach is likely to result in a high risk to their rights and freedoms (Art. 34 GDPR). All incidents are recorded internally and reviewed to prevent recurrence.
Under the GDPR you have the right to:
Exercise any right from Account or by emailing privacy@unblockfunds.com. We respond within one month of receiving a complete request, extendable by two months for complex requests (Art. 12(3)). Identity verification may be required to protect your data. Requests are free of charge unless manifestly unfounded or excessive.
We do not make decisions producing legal or similarly significant effects on you based solely on automated processing. Where we use automation to triage new cases or flag suspicious activity, a human reviewer takes the final decision and you have the right to obtain human intervention, express your point of view, and contest the outcome.
We use strictly necessary cookies and local storage to keep you signed in, balance load, persist your accessibility preferences, and protect against CSRF and session fixation. These do not require consent under Article 5(3) of the ePrivacy Directive. We do not use advertising, profiling, or cross-site tracking cookies.
If we introduce optional analytics or marketing cookies in future, they will be loaded only after your opt-in consent through a banner, refusal will be as easy as acceptance, and you will be able to withdraw consent at any time from a persistent settings link in the footer.
We send product news and similar marketing only with your consent or, where permitted by Article 13(2) of the ePrivacy Directive (the so-called "soft opt-in"), to existing customers about similar products, with a clear unsubscribe link in every message and in your Account → Notifications settings. Transactional and case-related communications (security alerts, invoices, case updates) are sent on the basis of contract performance and our legal obligations and are not marketing.
The Service is intended for businesses and the adults representing them. It is not directed at children under 16 and we do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact the DPO and we will delete it.
You may lodge a complaint with a supervisory authority — in particular in your EU Member State of habitual residence, place of work, or place of the alleged infringement (Art. 77 GDPR). Our lead supervisory authority is the Irish Data Protection Commission (dataprotection.ie, 21 Fitzwilliam Square South, Dublin 2). We would, however, appreciate the chance to address your concern first via dpo@unblockfunds.com.
We will notify you of material changes by email and in-app at least 30 days in advance. Minor clarifications and editorial corrections may be made without prior notice but will be reflected in the version number and "Last updated" date above. Older versions are available from the DPO.
General privacy queries: privacy@unblockfunds.com
Data Protection Officer: dpo@unblockfunds.com
Security disclosures: security@unblockfunds.com
Postal: Data Protection Officer, UnblockFunds Ltd, 12 St Stephen's Green, Dublin 2, D02 XY12, Ireland.
© 2026 UnblockFunds Ltd. All rights reserved.