Privacy Policy | Equals Europe
Last updated: September 2026
At equals we take your privacy seriously. This policy explains what personal data we collect about you, why we collect it, the lawful bases on which we rely, how long we keep it, who we share it with, where it is transferred, and the rights you have under data protection law. It is written to meet the transparency requirements of the EU General Data Protection Regulation (GDPR) and the Belgian Data Protection Act of 30 July 2018.
1. Who we are and how to contact us
Equals is part of the Equals group of companies. In Belgium and the European Economic Area (EEA), our services are provided by Equals Money Europe SA, a payments institution incorporated under the laws of Belgium (enterprise number 0849.185.510) and supervised by the National Bank of Belgium, with its registered office at Avenue Louise 231, 1050 Brussels, Belgium.
Equals Money Europe SA is the controller of the personal data described in this policy. In this policy, “we”, “us” and “equals” mean Equals Money Europe SA. “Controller”, “processor”, “personal data”, “processing” and “data subject” have the meanings given to them in the GDPR.
Contacting our Data Protection Officer (DPO). Our DPO can be contacted in writing at Data Protection Officer, Equals Money Europe SA, Avenue Louise 231, 1050 Brussels, Belgium, or by email at privacy@equalsmoney.com. The DPO is the appropriate point of contact for any questions about this policy, to exercise your rights, or to raise a concern about how your personal data is handled.
2. What personal data we collect
Most personal data is collected directly from you, typically during the application process and while you use our products. We may collect the following categories of personal data:
- Identity data: title, full name, date of birth, nationality, gender (where relevant for identity checks), photograph or video used for identity verification, and signature.
- Contact data: current and previous address, email address, mobile and home telephone numbers.
- Financial and transactional data: bank account details, card details, transaction history, balances, and payment instructions.
- Identification documents: passport, identity card, residence permit, utility bills, or other documents used to verify your identity under anti-money laundering law.
- Profile and usage data: your login credentials, account preferences, language preference, and information about how you use our website, app and services (including IP address, device information and pages visited).
- Marketing and communications data: your preferences for receiving marketing from us and your communication preferences.
- Special category data: we do not routinely process special category data, such as data revealing racial or ethnic origin, religious beliefs, or health. To verify your identity, we use facial-recognition technology that compares a photograph or video of you against your identity document. Because this uniquely identifies you, it involves biometric data, which is a special category of personal data. We carry out this check to verify your identity reliably and to prevent identity fraud, money laundering and other financial crime, as we are required to do under anti-money laundering law. Our lawful basis for this processing is compliance with a legal obligation. The additional condition we rely on for the biometric data is that the processing is necessary for reasons of substantial public interest, on the basis of Belgian law, in particular the Law of 18 September 2017 and the Belgian Data Protection Act of 30 July 2018. Where you choose to give us other special category data that is not required for these purposes (for example, accessibility information), we rely on your explicit consent. Information you must provide. Some of the information we ask for is needed to meet our legal obligations or to enter into and perform a contract with you – for example, the identity information we must collect under anti-money laundering law. If you do not provide it, we may not be able to open or continue your account or provide the services you have asked for.
Third-party data. If you provide us with personal data about another person (for example, additional directors, shareholders, beneficial owners or cardholders), you confirm that you have the authority to share their data with us and that you have shared this privacy policy with them.
3. Where we obtain your personal data
We collect personal data from the following sources:
- Directly from you when you complete an application, contact us, use our website or app, or otherwise interact with us.
- From a partner or platform where you access our services through that business rather than directly with us.
- From identity verification agencies who carry out checks on our behalf or whose databases we consult.
- From fraud prevention agencies.
- From sanctions, politically exposed person (PEP) and adverse media screening providers used to meet our financial crime obligations.
- From publicly available sources, including public registers such as the Crossroads Bank for Enterprises (KBO/BCE), the Belgian Official Gazette, and the register of beneficial owners (UBO register).
- From your employer or business where you are a cardholder on a corporate account.
- From banking and payment partners, card schemes and merchants in connection with transactions you make.
Where we use identity verification agencies, we do so only to confirm your identity. This is an identity check and is not an assessment of your creditworthiness.
4. How and why we use your personal data, and our lawful bases
Under data protection law, we must have a lawful basis for each purpose for which we process your personal data. This section describes our purposes and the lawful basis we rely on for each.
4.1 To perform our contract with you
We process your personal data because it is necessary to enter into or perform a contract with you, including to:
- take steps at your request before entering into a contract;
- decide whether to enter into a contract with you;
- set up, manage, administer and close your account;
- execute payments, transfers and other transactions you instruct;
- issue and manage cards and related services;
- keep our records of you up to date;
- provide customer support.
4.2 To comply with our legal obligations
We process your personal data because we are required to do so by law, including to:
- verify your identity and the identity of beneficial owners, directors and authorised representatives, as required by the Belgian Law of 18 September 2017 on the prevention of money laundering and terrorist financing and on the restriction of the use of cash (the “AML Law”);
- screen against sanctions, PEP and adverse media lists;
- monitor transactions and report suspicious transactions to the Belgian Financial Intelligence Processing Unit (CTIF-CFI);
- respond to requests from regulators, law enforcement, courts and tax authorities (including the National Bank of Belgium, the Financial Services and Markets Authority (FSMA), the Belgian tax authorities, and the Belgian Data Protection Authority);
- monitor communications (including calls and emails) where required or permitted by law;
- respond to requests you make to exercise your rights under data protection law;
- establish, exercise or defend legal claims.
4.3 For our legitimate interests
We process your personal data where it is necessary for our legitimate interests (or those of a third party), provided your interests, rights and freedoms do not override those interests. Our legitimate interests include:
- Operating, securing and improving our business – governance, accounting, internal management, audit, information security, business continuity, and product development.
- Preventing and detecting financial crime – fraud prevention and additional financial-crime controls that go beyond our strict legal obligations.
- Research and analytics – market research, statistical analysis and customer insight, generally using aggregated or pseudonymised data.
- Direct marketing of our own similar products and services to existing customers, with a clear right to opt out at any time.
4.4 With your consent
We rely on your consent for:
- electronic marketing where the law requires your consent;
- the use of non-essential cookies and similar technologies on our website (see our Cookie Policy);
- disclosing your personal data to third parties at your specific request.
You can withdraw your consent at any time, without affecting the lawfulness of processing carried out before withdrawal. To withdraw consent, contact us using the details in section 1 or use the unsubscribe link in any marketing email.
5. Automated decision-making and profiling
We use automated processes, including some that involve profiling, in the following ways:
- Identity verification and fraud prevention – we use automated systems to check the information you provide against external data sources, biometric matching tools, and fraud and sanctions databases. These checks are run by us and our service providers.
- Application assessment – where we make a decision about your application for a product using automated means, this is necessary in order to enter into a contract with you. The system checks the information you provide against records held by identity verification and fraud prevention agencies – to confirm your identity and to detect fraud and financial crime – against pre-set rules and risk indicators.
- Transaction monitoring – we use automated rules and models to identify transactions that may indicate fraud, money laundering or other financial crime. Where required by law, we may block or delay transactions and report to the relevant authorities.
- Marketing analytics – we may segment customers based on transactional history and other account information to decide what marketing communications might be relevant. This activity is based on our legitimate interests and does not produce legal or similarly significant effects on you.
The significance and consequences of these processes can include refusal of your application, restriction or closure of your account, declining a transaction, or referral of your case to the relevant authorities.
Your rights. Where a decision that produces legal or similarly significant effects is made solely by automated means, you have the right to obtain human intervention, to express your point of view, and to contest the decision. To exercise these rights, contact our DPO using the details in section 1.
6. Who we share your personal data with
We do not sell or rent your personal data. We share it only with the categories of recipient set out below, and only to the extent necessary for the purposes described in this policy:
- Group companies within the Equals group, for the administration of our services and shared operational functions.
- Banking and e-money partners that hold safeguarded funds, execute payments and provide access to payment systems, together with messaging and payment infrastructure providers.
- Card schemes and card issuing, processing and personalisation partners that enable the operation of our cards.
- Identity verification agencies used to verify your identity and assess applications.
- Fraud prevention agencies, with whom we share personal data to prevent fraud and money laundering and to verify identity (see section 7).
- Sanctions, politically exposed person (PEP) and adverse media screening providers.
- Transaction monitoring providers, used to detect potentially fraudulent or suspicious activity.
- Customer support providers, including support ticketing, telephony and outsourced contact centre services.
- Marketing, communications and analytics providers, including email and SMS platforms, customer relationship management systems, website analytics and advertising platforms.
- Other technology and infrastructure providers, including cloud hosting, security, communications and business productivity tools.
- Professional advisers such as lawyers, auditors, regulatory consultancies, accountants and insurers.
- Regulators, ombudsmen and authorities, including the National Bank of Belgium, the Financial Services and Markets Authority (FSMA), the Belgian Data Protection Authority, the Financial Intelligence Processing Unit (CTIF-CFI), the Belgian tax authorities, and the Belgian financial ombudsman service (Ombudsfin), together with the police and courts where required by law.
- Prospective or actual purchasers of all or part of our business or assets, and their advisers, in connection with a sale or restructuring (subject to appropriate confidentiality protections).
A current list of the named third-party recipients of personal data within these categories is available on request from our Data Protection Officer using the contact details in section 1.
Where a third party processes personal data on our behalf, we put a written contract in place that requires it to protect your personal data and to use it only on our instructions. Where a third party acts as an independent or joint controller, it will be responsible for how it uses your personal data.
Merchants. We do not share your personal data with merchants (sellers) who accept payment from you using your equals card, beyond what is needed to process the transaction. Where we collect information from competitions or surveys, we do not share that information with merchants, although we may share aggregated, non-identifiable statistics.
7. Fraud prevention and anti-money laundering checks
We are required by law to verify your identity and to monitor your account in order to prevent fraud, money laundering, terrorist financing and other financial crime.
For these purposes, we share personal data with fraud prevention agencies and screening providers, and we report suspicious transactions to the Belgian Financial Intelligence Processing Unit (CTIF-CFI) as required by the AML Law. If fraud or other financial crime is identified or suspected, we may refuse, restrict or close your account or decline a transaction, and the relevant information may be recorded by fraud prevention agencies and made available to other organisations carrying out similar checks. You can ask us for more information about the agencies we use, and about your data protection rights, by contacting our DPO using the details in section 1.
8. International transfers of personal data
Some of our service providers and group companies are located outside the European Economic Area (EEA). Where we transfer personal data outside the EEA, we make sure that an appropriate safeguard is in place, which will usually be one of the following:
- An adequacy decision of the European Commission – transfers to a country, territory or sector that the European Commission has determined provides an adequate level of protection.
- The European Commission’s Standard Contractual Clauses (SCCs), supplemented where necessary by additional contractual, technical and organisational measures identified through a transfer impact assessment.
- Binding Corporate Rules, where applicable to our providers.
- In limited cases, a specific derogation permitted by the GDPR, such as your explicit consent or the necessity of the transfer for the performance of a contract with you, where no other mechanism is available.
You can obtain a copy of the safeguards we use for a specific transfer by contacting our DPO using the details in section 1.
9. How long we keep your personal data
We keep personal data only for as long as necessary for the purposes set out in this policy. For most records connected with our products and services, our baseline retention period is ten years from the end of our relationship with you. This reflects the record-keeping obligations in the AML Law, which requires us to keep identification and transaction records for ten years after the end of the business relationship or the date of an occasional transaction, as well as other regulatory record-keeping obligations and the time limits for bringing legal claims.
We do not keep personal data for longer than is necessary, and where it is no longer needed for the purposes for which it was collected, we will delete or anonymise it earlier.
The retention period is calculated from one of the following starting points, whichever is later:
- the date our contractual relationship with you ends (for example, the date your account is closed);
- the date of the last transaction or interaction on your account;
- the date of the application, where you applied for a product but did not become a customer;
- the date a complaint, dispute or legal claim is finally resolved.
Some categories of personal data are kept for a shorter period where the maximum retention period is not appropriate:
- Marketing preferences and suppression lists: for as long as we operate the relevant marketing channel, so that we can honour your opt-out.
- Website usage and cookie data: as set out in our Cookie Policy.
- Recorded telephone calls and customer support records: retained within the maximum retention period, but may be deleted earlier where they are no longer needed for regulatory, dispute resolution or training purposes.
Where it is not practicable to delete personal data immediately (for example, because it is held in backup systems), we will isolate it from further active use until secure deletion is possible.
10. How we keep your personal data secure
We use appropriate technical and organisational measures to protect personal data against unauthorised or unlawful processing, accidental loss, destruction or damage, taking into account the nature of the data and the risks involved. These measures include access controls, encryption in transit and at rest where appropriate, network security, staff training, vendor due diligence, and incident response procedures. If we become aware of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Belgian Data Protection Authority and, where required, you.
11. Your rights
Under the GDPR, you have the following rights in relation to your personal data:
- The right to be informed about how we use your personal data (which this policy provides).
- The right of access to the personal data we hold about you, and to certain related information.
- The right to rectification of inaccurate personal data, and to have incomplete personal data completed.
- The right to erasure (“the right to be forgotten”), in certain circumstances.
- The right to restrict processing in certain circumstances.
- The right to data portability – to receive certain personal data in a structured, commonly used, machine-readable format, and to have it transmitted to another controller where technically feasible.
- The right to object to processing based on our legitimate interests, and an absolute right to object to direct marketing.
- Rights in relation to automated decision-making and profiling, as described in section 5.
- The right to withdraw consent at any time where we rely on your consent, without affecting the lawfulness of processing before withdrawal.
- The right to lodge a complaint with a data protection supervisory authority (see section 12).
Some of these rights are qualified and only apply in certain circumstances. We will respond to a valid request within one month, although we may extend this by up to two further months for complex requests, in which case we will let you know within the first month. There is normally no fee for exercising your rights, although we may charge a reasonable fee or refuse to act where a request is manifestly unfounded or excessive.
To exercise any of your rights, please contact our DPO using the details in section 1. Where you contact us by email, please use privacy@equalsmoney.com.
12. Complaints
You have the right to lodge a complaint at any time with the Belgian Data Protection Authority (Autorité de protection des données / Gegevensbeschermingsautoriteit), the supervisory authority for data protection in Belgium. Its address is Rue de la Presse 35 / Drukpersstraat 35, 1000 Brussels, Belgium; its email is contact@apd-gba.be; its telephone number is +32 (0)2 274 48 00; and its website is www.dataprotectionauthority.be. If you live or work in another EEA country, you may also complain to your local data protection authority. We would, however, appreciate the chance to deal with your concerns first, so please contact us in the first instance.
13. Marketing communications and your choices
You can opt out of receiving marketing communications from us at any time by contacting us, by logging into your online account, or by using the unsubscribe link in any marketing email.
Communications about changes to your products or services, our terms and conditions, or this policy are service communications. They are not marketing, and you cannot opt out of them while you are a customer.
14. Cookies and similar technologies
Our website uses cookies and similar technologies. A cookie is a small file placed on your device when you visit a website. We use strictly necessary cookies, and – with your consent, given through our cookie banner – analytics and advertising cookies. You can manage your preferences at any time through the cookie banner or your browser settings. Full details, including the cookies we use, their purposes and their duration, are set out in our Cookie Policy. We are responsible for obtaining your consent for non-essential cookies set via our website, including those set by third parties.
15. Children
Our products and services are not directed at children under the age of 18, and we do not knowingly collect personal data from anyone under that age. If you believe that a child has provided us with personal data, please contact our DPO so that we can take appropriate action.
16. Links to third-party websites
Our website and app may contain links to websites and services operated by third parties. We are not responsible for the privacy practices or content of those third parties. We encourage you to read their privacy notices before providing them with any personal data.
17. Changes to this privacy policy
We may update this privacy policy from time to time. Where we make material changes, we will notify you by email to your registered email address. If you have not given us an email address, you should check the website regularly for the most recent version. The date at the top of this policy shows when it was last updated. We will only use your personal data in accordance with the version of this policy in force at the relevant time.
18. Reviewing, correcting or updating your personal data
If any of your details are recorded incorrectly and need to be changed, please contact us with the details of the required changes. We may need proof of certain changes (such as a change of address). You can also write to our DPO using the details in section 1.