Business FX and payouts for companies moving money across borders — faster settlement, better rates, and real support with Calen.Book a demo

Calen Privacy Policy

Last updated 28 August 2026

1. Our Relationship With You

Calen Payments Ltd, a company registered in England and Wales and also operating in Canada, and Calen Payments Inc, a corporation registered in the State of Delaware, USA, (together, "Calen", "we", "us", or "our") are the data controllers responsible for the personal data described in this policy. Depending on where you are based and which entity you deal with, one or both companies act as the controller of your personal data.

Calen provides an AI-native financial orchestration platform to businesses (each, a "Customer"). A Customer is a corporate entity, and corporate entities do not have personal data of their own. The individuals connected to a Customer do, and it is those individuals this policy is written for. Throughout this policy, "you" and "your" refer to the authorised dashboard users, corporate directors, founders, shareholders, and ultimate beneficial owners (UBOs) associated with a Customer, whose personal data we process in the course of onboarding, running, and monitoring that Customer's account.

If you interact with Calen in a different capacity, for example as a visitor to our website, an applicant for a role with us, or a supplier to our business, the sections of this policy that describe those specific activities apply to you as well. Where a Customer instructs us to process the personal data of its own end customers, such as payers in a payment flow, we do so as a processor acting on that Customer's instructions, and the relevant Customer's own privacy notice, not this policy, governs that processing.

2. Personal Data We Collect

We collect personal data through three operational intake pathways: data you give us directly, data we collect automatically as you use our platform, and data we receive from other sources. The table below sets out what we collect under each pathway and why.

PathwayWhat we collectWhy we collect it
Information you give usYour full name, business email address, phone number, and job title. Business registry documentation such as a certificate of incorporation and register of members. Shareholder and director validation logs. Proof of address. Biometric verification data, specifically a facial scan or selfie captured and matched against a government-issued identity document.To open and administer your Customer's account, to confirm who is legally authorised to instruct payments and manage the dashboard, and to complete the Know Your Business (KYB) and Anti-Money Laundering (AML) checks our regulators require of us.
Information collected automaticallyTechnical data including IP address, device identifiers, browser type and version, operating system, and indicators of VPN or proxy use. Platform usage data including click paths, scroll depth, active session length, and page response times.To keep the dashboard secure against unauthorised access, to diagnose and fix performance issues, and to understand how our product is used so we can improve it.
Information from other sourcesData received through API integrations with financial institutions you connect to Calen. Bank account and payment rail details for networks such as ACH, SEPA, and Fedwire. Screening results from fraud prevention agencies and sanctions watchlist providers. Records held by corporate intelligence and company registry databases.To move funds correctly and to the right recipient, to confirm the identity and standing of the individuals and entities we deal with, and to meet our legal duty to screen for financial crime risk before and during a business relationship.

3. Sensitive Personal Data and Biometric Processing

As part of onboarding, we ask certain individuals connected to a Customer, typically directors, founders, and UBOs, to complete an identity verification step that involves a facial scan or selfie. This image is processed dynamically through a verification API, which compares it against the photograph on a government-issued identity document to confirm that the person completing onboarding is who they claim to be.

We rely on this process to prevent corporate identity fraud, to satisfy our Know Your Business obligations under applicable law, including the UK Money Laundering Regulations 2017, the United States Bank Secrecy Act and associated FinCEN customer due diligence rules, and Canada's Proceeds of Crime (Money Laundering) and Terrorist Financing Act, and to comply more broadly with international anti-financial crime standards our banking and clearing partners require us to meet.

Biometric data is encrypted, access to it is restricted to the small number of systems and personnel who need it to perform this check, and it is processed only in jurisdictions where local law permits this type of processing for identity verification purposes. Where a jurisdiction imposes additional consent or notice requirements before biometric data may be collected, we obtain that consent or provide that notice before proceeding. Biometric data is retained only for as long as described in section 9 of this policy and is deleted once that period has passed.

4. How We Use Your Information

Data protection law requires us to have a valid legal basis for every way we use your personal data. We rely on five legal bases across our business.

Contractual necessity

We process personal data where doing so is necessary to open and administer a Customer's virtual multi-currency wallets, execute payment instructions, route transactions across the correct corridor, generate invoices, and otherwise deliver the services a Customer has signed up for.

Legal obligation

We process personal data where the law requires us to, including complying with anti-money laundering and counter-terrorist financing regulations, responding to lawful requests from regulators and law enforcement, and meeting our tax reporting duties.

Legitimate interests

We process personal data where it serves a legitimate business interest that is not overridden by your rights, such as improving our product and dashboard, securing our platform against misuse, and, where you have not opted out, sending relevant communications about our services to existing Customers.

Consent

Where the law requires it, we ask for your consent before processing your data, for example before sending you personalised marketing communications, before placing non-essential cookies on your device, or before collecting biometric data in a jurisdiction that requires explicit consent for that processing.

Substantial public interest

Under UK data protection law and comparable frameworks elsewhere, we may process personal data, including data that reveals potential unlawful conduct, where necessary for the prevention and detection of financial crime such as money laundering, terrorist financing, and payment fraud. We rely on this basis because the detection of that kind of harm serves a substantial public interest that extends beyond our own commercial interest as a business.

5. The Embedded Multi-Agent Workflow Exclusion

Calen's platform is built around embedded, autonomous software agents that automate a Customer's back-office finance work. These agents read unstructured inputs such as PDF invoices, extract line items and payment terms, calculate withholding tax liabilities across the jurisdictions a transaction touches, and write reconciled ledger entries directly into connected accounting systems such as Xero and QuickBooks.

This processing operates on a Customer's business and transactional data, such as invoice contents, amounts, currencies, and counterparties, rather than on data about you as an individual. The purpose is strictly back-office automation and ledger reconciliation. Our agents do not build behavioural profiles of you as a person, are not used to serve advertising, and do not make any decision that produces a legal or similarly significant effect concerning you as an individual. Where an automated process does affect you personally, such as a compliance flag on your account, that process is described separately in section 6.

Each agent is scoped to the specific fields it needs to complete its task, and every action an agent takes is logged so that it can be reviewed and audited by our engineering and compliance teams.

6. Profiling and Automated Decision Making

Calen uses automated processes for two purposes that can affect you directly: verifying whether a business is eligible to open or keep an account, and monitoring transaction flows on an ongoing basis for signs of suspicious activity.

Where one of these automated processes flags your account or a specific transaction, we will tell you that this has happened, unless we are legally prohibited from doing so, for example under anti-money laundering "tipping-off" rules that restrict what we can disclose while a matter is under investigation.

No automated flag results in a final decision on its own. Every flag is queued for review by a member of our human compliance team, who reassesses the underlying evidence, may request further information or documentation from you or your business, and then confirms or overturns the system's initial flag before we take any further action, such as restricting an account or filing a report with a financial intelligence unit where the law requires it. You can also ask us directly for a human review of an automated decision that concerns you by contacting our compliance desk at compliance@calen.finance.

7. How We Share Your Personal Data

We do not sell your personal data. We share it only with the categories of recipient below, and only to the extent needed for the purpose described.

  • Calen corporate group entities, meaning Calen Payments Ltd, Calen Payments Inc, and any group affiliate, for account administration and group-wide risk management.
  • Identity verification providers, who confirm the authenticity of government-issued identity documents and match them against biometric data collected during onboarding.
  • Sanctions and politically exposed person screening networks, who screen individuals and entities named on your account against global watchlists.
  • Know Your Business infrastructure and banking-as-a-service partners, including providers such as Conduit, who supply the underlying regulated account and payment rail infrastructure that moves your funds.
  • Tier-one depository and clearing bank affiliates, who hold safeguarded customer funds and execute the underlying wire, ACH, SEPA, and Fedwire transfers on our behalf.
  • Cloud storage and hosting providers, who store data on our behalf under contractual data processing terms that require them to protect it to our standard.
  • Tax compliance software nodes and connected accounting platforms, such as Xero and QuickBooks, which receive transaction data at your direction so our agents can post reconciled ledger entries.
  • Professional advisers, including our auditors, lawyers, and insurers, where necessary for them to advise us.
  • Law enforcement agencies, courts, and financial regulators, where we are legally compelled to disclose data or where disclosure is necessary to establish, exercise, or defend a legal claim.

8. International Data Transfers

Calen clears multi-currency payment lines across the United Kingdom, the United States, Canada, and a growing set of local corridors. Delivering that service means personal data will often need to cross international borders, for example when a UK-based team member's data is processed by our Delaware entity, or when a payment corridor routes through an intermediary bank based outside your home country.

Wherever we transfer personal data internationally, we put a recognised legal safeguard in place first. For transfers out of the European Economic Area, we rely on the European Commission's Standard Contractual Clauses. For transfers out of the United Kingdom, we rely on the UK International Data Transfer Addendum to those Standard Contractual Clauses. For transfers involving Canada, we rely on contractual protections consistent with the adequacy arrangements recognised under the Personal Information Protection and Electronic Documents Act. Where a transfer carries elevated risk, we complete a transfer impact assessment before it goes ahead, and we only transfer personal data to recipients who are bound by one of these safeguards or who are located in a jurisdiction recognised as offering an adequate level of protection.

9. Data Retention Parameters

We keep personal data only for as long as it is needed for the purposes set out in this policy. In most cases, that means we delete data shortly after the relationship it relates to ends.

As a regulated financial technology business, however, we are legally required to keep certain transactional and identity verification records for a set period after a Customer's account closes, regardless of whether the underlying relationship has ended. That period is typically between five and ten years, depending on the specific law that applies to the record. For example, UK money laundering regulations set a five-year minimum retention period, United States federal recordkeeping rules under the Bank Secrecy Act generally require five years, and records connected to a suspicious activity report may be retained for up to ten years where the law requires it.

Once the applicable statutory retention period has passed, the associated personal data is automatically purged from our systems, unless we are subject to a legal hold that requires us to preserve it for longer, for example because of ongoing litigation or an open regulatory inquiry.

10. How We Protect Your Data

We maintain a layered security programme designed to protect personal data at every stage of its lifecycle with us.

  • Electronic access controls: role-based access permissions, mandatory multi-factor authentication, and a least-privilege model that limits each employee and system to the specific data they need to do their job.
  • Database isolation: segregated storage environments for different categories of data, encryption of data at rest and in transit, and tokenisation of especially sensitive fields such as bank account numbers and biometric identifiers.
  • Employee information security training: mandatory data protection and security training for every employee at onboarding and on an annual refresher basis afterward, backed by confidentiality obligations written into every employment contract.
  • Third-party partner vetting: security questionnaires, review of penetration testing and audit evidence, and a signed data processing agreement before any vendor is permitted to process personal data on our behalf, with periodic reassessment for as long as that vendor relationship continues.

12. Corporate Regulatory Disclosures and Regional Footers

Calen is a global financial technology company and corporate software provider, not a licensed banking institution or depository clearer. The multi-currency virtual accounts, high-performance transactional payment rails, foreign exchange conversion corridors, and cross-border fund settlement services available through our digital dashboard are securely provisioned and cleared exclusively by our fully regulated, licensed partner financial institutions and their respective tier-one commercial banking networks.

Calen Payments Ltd is a corporate entity registered in England and Wales under the standard statutory regulations of Companies House. For our North American corporate operations and cross-border settlement channels, Calen Payments Ltd is officially registered with the Financial Transactions and Reports Analysis Centre of Canada as a Foreign Money Services Business. The company operates in strict compliance with federal anti-financial crime laws, is subject to the comprehensive regulatory oversight of the Retail Payment Activities Act, and is registered directly with the Bank of Canada as an authorized payment service provider.

Calen Payments Inc is a venture-backed enterprise corporation duly organized, validly existing, and in good standing under the corporate laws of the State of Delaware, United States. Calen Payments Inc is registered with the Financial Crimes Enforcement Network of the United States Department of the Treasury as a federal Money Services Business. In accordance with federal compliance architectures, Calen Payments Inc utilizes a strict regulatory reliance model, leveraging the comprehensive state-level money transmitter licenses and clearing capabilities held by our underlying banking infrastructure partners to execute all third-party state money movement workflows.

Calen does not maintain a sovereign banking charter or hold customer funds on its own corporate balance sheet. All client capital, operating cash reserves, and incoming business collection pools are held in isolated, designated safeguarding and custodial accounts managed entirely by our licensed network partners, ensuring absolute transparency, regulatory oversight, and complete financial security for the enterprises that rely on our platform.