Calen Privacy Policy
Last updated 28 August 2026
1. Our Relationship With You
Calen Payments Ltd, a company registered in England and Wales and also operating in Canada, and Calen Payments Inc, a corporation registered in the State of Delaware, USA, (together, "Calen", "we", "us", or "our") are the data controllers responsible for the personal data described in this policy. Depending on where you are based and which entity you deal with, one or both companies act as the controller of your personal data.
Calen provides an AI-native financial orchestration platform to businesses (each, a "Customer"). A Customer is a corporate entity, and corporate entities do not have personal data of their own. The individuals connected to a Customer do, and it is those individuals this policy is written for. Throughout this policy, "you" and "your" refer to the authorised dashboard users, corporate directors, founders, shareholders, and ultimate beneficial owners (UBOs) associated with a Customer, whose personal data we process in the course of onboarding, running, and monitoring that Customer's account.
If you interact with Calen in a different capacity, for example as a visitor to our website, an applicant for a role with us, or a supplier to our business, the sections of this policy that describe those specific activities apply to you as well. Where a Customer instructs us to process the personal data of its own end customers, such as payers in a payment flow, we do so as a processor acting on that Customer's instructions, and the relevant Customer's own privacy notice, not this policy, governs that processing.
2. Personal Data We Collect
We collect personal data through three operational intake pathways: data you give us directly, data we collect automatically as you use our platform, and data we receive from other sources. The table below sets out what we collect under each pathway and why.
| Pathway | What we collect | Why we collect it |
|---|---|---|
| Information you give us | Your full name, business email address, phone number, and job title. Business registry documentation such as a certificate of incorporation and register of members. Shareholder and director validation logs. Proof of address. Biometric verification data, specifically a facial scan or selfie captured and matched against a government-issued identity document. | To open and administer your Customer's account, to confirm who is legally authorised to instruct payments and manage the dashboard, and to complete the Know Your Business (KYB) and Anti-Money Laundering (AML) checks our regulators require of us. |
| Information collected automatically | Technical data including IP address, device identifiers, browser type and version, operating system, and indicators of VPN or proxy use. Platform usage data including click paths, scroll depth, active session length, and page response times. | To keep the dashboard secure against unauthorised access, to diagnose and fix performance issues, and to understand how our product is used so we can improve it. |
| Information from other sources | Data received through API integrations with financial institutions you connect to Calen. Bank account and payment rail details for networks such as ACH, SEPA, and Fedwire. Screening results from fraud prevention agencies and sanctions watchlist providers. Records held by corporate intelligence and company registry databases. | To move funds correctly and to the right recipient, to confirm the identity and standing of the individuals and entities we deal with, and to meet our legal duty to screen for financial crime risk before and during a business relationship. |
3. Sensitive Personal Data and Biometric Processing
As part of onboarding, we ask certain individuals connected to a Customer, typically directors, founders, and UBOs, to complete an identity verification step that involves a facial scan or selfie. This image is processed dynamically through a verification API, which compares it against the photograph on a government-issued identity document to confirm that the person completing onboarding is who they claim to be.
We rely on this process to prevent corporate identity fraud, to satisfy our Know Your Business obligations under applicable law, including the UK Money Laundering Regulations 2017, the United States Bank Secrecy Act and associated FinCEN customer due diligence rules, and Canada's Proceeds of Crime (Money Laundering) and Terrorist Financing Act, and to comply more broadly with international anti-financial crime standards our banking and clearing partners require us to meet.
Biometric data is encrypted, access to it is restricted to the small number of systems and personnel who need it to perform this check, and it is processed only in jurisdictions where local law permits this type of processing for identity verification purposes. Where a jurisdiction imposes additional consent or notice requirements before biometric data may be collected, we obtain that consent or provide that notice before proceeding. Biometric data is retained only for as long as described in section 9 of this policy and is deleted once that period has passed.
4. How We Use Your Information
Data protection law requires us to have a valid legal basis for every way we use your personal data. We rely on five legal bases across our business.
Contractual necessity
We process personal data where doing so is necessary to open and administer a Customer's virtual multi-currency wallets, execute payment instructions, route transactions across the correct corridor, generate invoices, and otherwise deliver the services a Customer has signed up for.
Legal obligation
We process personal data where the law requires us to, including complying with anti-money laundering and counter-terrorist financing regulations, responding to lawful requests from regulators and law enforcement, and meeting our tax reporting duties.
Legitimate interests
We process personal data where it serves a legitimate business interest that is not overridden by your rights, such as improving our product and dashboard, securing our platform against misuse, and, where you have not opted out, sending relevant communications about our services to existing Customers.
Consent
Where the law requires it, we ask for your consent before processing your data, for example before sending you personalised marketing communications, before placing non-essential cookies on your device, or before collecting biometric data in a jurisdiction that requires explicit consent for that processing.
Substantial public interest
Under UK data protection law and comparable frameworks elsewhere, we may process personal data, including data that reveals potential unlawful conduct, where necessary for the prevention and detection of financial crime such as money laundering, terrorist financing, and payment fraud. We rely on this basis because the detection of that kind of harm serves a substantial public interest that extends beyond our own commercial interest as a business.
5. The Embedded Multi-Agent Workflow Exclusion
Calen's platform is built around embedded, autonomous software agents that automate a Customer's back-office finance work. These agents read unstructured inputs such as PDF invoices, extract line items and payment terms, calculate withholding tax liabilities across the jurisdictions a transaction touches, and write reconciled ledger entries directly into connected accounting systems such as Xero and QuickBooks.
This processing operates on a Customer's business and transactional data, such as invoice contents, amounts, currencies, and counterparties, rather than on data about you as an individual. The purpose is strictly back-office automation and ledger reconciliation. Our agents do not build behavioural profiles of you as a person, are not used to serve advertising, and do not make any decision that produces a legal or similarly significant effect concerning you as an individual. Where an automated process does affect you personally, such as a compliance flag on your account, that process is described separately in section 6.
Each agent is scoped to the specific fields it needs to complete its task, and every action an agent takes is logged so that it can be reviewed and audited by our engineering and compliance teams.
6. Profiling and Automated Decision Making
Calen uses automated processes for two purposes that can affect you directly: verifying whether a business is eligible to open or keep an account, and monitoring transaction flows on an ongoing basis for signs of suspicious activity.
Where one of these automated processes flags your account or a specific transaction, we will tell you that this has happened, unless we are legally prohibited from doing so, for example under anti-money laundering "tipping-off" rules that restrict what we can disclose while a matter is under investigation.
No automated flag results in a final decision on its own. Every flag is queued for review by a member of our human compliance team, who reassesses the underlying evidence, may request further information or documentation from you or your business, and then confirms or overturns the system's initial flag before we take any further action, such as restricting an account or filing a report with a financial intelligence unit where the law requires it. You can also ask us directly for a human review of an automated decision that concerns you by contacting our compliance desk at compliance@calen.finance.
8. International Data Transfers
Calen clears multi-currency payment lines across the United Kingdom, the United States, Canada, and a growing set of local corridors. Delivering that service means personal data will often need to cross international borders, for example when a UK-based team member's data is processed by our Delaware entity, or when a payment corridor routes through an intermediary bank based outside your home country.
Wherever we transfer personal data internationally, we put a recognised legal safeguard in place first. For transfers out of the European Economic Area, we rely on the European Commission's Standard Contractual Clauses. For transfers out of the United Kingdom, we rely on the UK International Data Transfer Addendum to those Standard Contractual Clauses. For transfers involving Canada, we rely on contractual protections consistent with the adequacy arrangements recognised under the Personal Information Protection and Electronic Documents Act. Where a transfer carries elevated risk, we complete a transfer impact assessment before it goes ahead, and we only transfer personal data to recipients who are bound by one of these safeguards or who are located in a jurisdiction recognised as offering an adequate level of protection.
9. Data Retention Parameters
We keep personal data only for as long as it is needed for the purposes set out in this policy. In most cases, that means we delete data shortly after the relationship it relates to ends.
As a regulated financial technology business, however, we are legally required to keep certain transactional and identity verification records for a set period after a Customer's account closes, regardless of whether the underlying relationship has ended. That period is typically between five and ten years, depending on the specific law that applies to the record. For example, UK money laundering regulations set a five-year minimum retention period, United States federal recordkeeping rules under the Bank Secrecy Act generally require five years, and records connected to a suspicious activity report may be retained for up to ten years where the law requires it.
Once the applicable statutory retention period has passed, the associated personal data is automatically purged from our systems, unless we are subject to a legal hold that requires us to preserve it for longer, for example because of ongoing litigation or an open regulatory inquiry.
10. How We Protect Your Data
We maintain a layered security programme designed to protect personal data at every stage of its lifecycle with us.
- Electronic access controls: role-based access permissions, mandatory multi-factor authentication, and a least-privilege model that limits each employee and system to the specific data they need to do their job.
- Database isolation: segregated storage environments for different categories of data, encryption of data at rest and in transit, and tokenisation of especially sensitive fields such as bank account numbers and biometric identifiers.
- Employee information security training: mandatory data protection and security training for every employee at onboarding and on an annual refresher basis afterward, backed by confidentiality obligations written into every employment contract.
- Third-party partner vetting: security questionnaires, review of penetration testing and audit evidence, and a signed data processing agreement before any vendor is permitted to process personal data on our behalf, with periodic reassessment for as long as that vendor relationship continues.
11. Your Legal Rights
Depending on where you live, you have some or all of the following rights over your personal data.
- The right to request a copy of the personal data we hold about you.
- The right to ask us to correct personal data that is inaccurate or incomplete.
- The right to object to processing that is based on our legitimate interests, including direct marketing.
- The right to request that we restrict how we use your personal data while a query about it is resolved.
- The right to request erasure of your personal data, noting that we may need to keep certain records regardless of this request where a financial recordkeeping law described in section 9 requires it.
- The right to receive certain personal data you have given us in a portable, machine-readable format.
- The right to withdraw consent at any time where our processing is based on consent, without affecting the lawfulness of processing carried out before that withdrawal.
- The right to lodge a complaint with your local data protection authority, such as the Information Commissioner's Office in the United Kingdom, the Office of the Privacy Commissioner of Canada, or the relevant state attorney general or the Federal Trade Commission in the United States.
To exercise any of these rights, contact our Data Protection Officer desk at dpo@calen.finance. We will respond within the timeframe required by applicable law.
12. Corporate Regulatory Disclosures and Regional Footers
Calen is a global financial technology company and corporate software provider, not a licensed banking institution or depository clearer. The multi-currency virtual accounts, high-performance transactional payment rails, foreign exchange conversion corridors, and cross-border fund settlement services available through our digital dashboard are securely provisioned and cleared exclusively by our fully regulated, licensed partner financial institutions and their respective tier-one commercial banking networks.
Calen Payments Ltd is a corporate entity registered in England and Wales under the standard statutory regulations of Companies House. For our North American corporate operations and cross-border settlement channels, Calen Payments Ltd is officially registered with the Financial Transactions and Reports Analysis Centre of Canada as a Foreign Money Services Business. The company operates in strict compliance with federal anti-financial crime laws, is subject to the comprehensive regulatory oversight of the Retail Payment Activities Act, and is registered directly with the Bank of Canada as an authorized payment service provider.
Calen Payments Inc is a venture-backed enterprise corporation duly organized, validly existing, and in good standing under the corporate laws of the State of Delaware, United States. Calen Payments Inc is registered with the Financial Crimes Enforcement Network of the United States Department of the Treasury as a federal Money Services Business. In accordance with federal compliance architectures, Calen Payments Inc utilizes a strict regulatory reliance model, leveraging the comprehensive state-level money transmitter licenses and clearing capabilities held by our underlying banking infrastructure partners to execute all third-party state money movement workflows.
Calen does not maintain a sovereign banking charter or hold customer funds on its own corporate balance sheet. All client capital, operating cash reserves, and incoming business collection pools are held in isolated, designated safeguarding and custodial accounts managed entirely by our licensed network partners, ensuring absolute transparency, regulatory oversight, and complete financial security for the enterprises that rely on our platform.