Last updated: July 2026
Privacy Policy
Magma Fintech Inc.
1. Introduction
This Privacy Policy explains how Magma Fintech Inc., a Delaware corporation (“Magma”, “we”, “us”), collects, uses, shares and protects personal data when you: (a) visit our websites at magma.builders and their subdomains (the “Site”); (b) interact with us as a prospective client; (c) are a Magma client, or act on behalf of one (for example as a director, officer, beneficial owner or authorized representative); or (d) are an end user of a client that uses Magma’s platform.
The controller of personal data described in this Policy is Magma Fintech Inc., 1111B S Governors Ave STE 88027, Dover, DE 19904, United States. You can contact us at privacy@magma.builders.
2. Personal data we collect
Site and contact data. Name, business contact details, company and role, the content of your messages and requests, and technical data such as IP address, browser and device information, pages visited and approximate location, collected through the Site and through cookies (see Section 12).
Identity and verification data. Where you are onboarded to the services, or act for a client that is: name, date and place of birth, nationality, residential address, government identification numbers and tax identifiers, copies of identity documents, photographs and selfie or liveness captures (which may involve biometric-derived data processed for identity matching, with your consent where required by law), beneficial-ownership information, role and authority information, and source-of-funds information where required.
Screening data. Results of sanctions, politically-exposed-person, watchlist, adverse-media and fraud screening performed in connection with onboarding and ongoing monitoring.
Financial and transaction data. Account identifiers and balances, payment instructions, counterparties and beneficiaries, amounts, currencies, purpose of payment, and related records and communications.
Sources. We collect personal data directly from you; from the client on whose behalf you act; from identity-verification providers and financial institutions engaged in connection with the services — including providers engaged earlier in the relationship, from whom we may receive existing verification files in order to maintain the continuity of your verification; and from public registers, screening databases and other lawful sources.
3. How we use personal data
We use personal data to:
- provide, operate, administer and support the services, including onboarding and account administration (where EU/UK law applies: performance of a contract, or our legitimate interests where you act on behalf of a client);
- verify identity and comply with anti-money-laundering, counter-terrorist-financing, sanctions and fraud-prevention requirements, perform ongoing screening and transaction monitoring, and maintain records and make reports to competent authorities (compliance with legal obligations, and our and our financial partners’ legitimate interests in meeting applicable AML and sanctions standards);
- maintain verification portability: we may retain verification data and re-use it to onboard, re-verify or maintain you or the client you represent with the banking and verification partners participating in our platform, so that verification completed once can be relied upon across our partner network without repeated onboarding (our and our clients’ legitimate interests; consent where required);
- protect the security and integrity of our services and prevent and detect misuse (legitimate interests);
- respond to your inquiries and communicate with you, including limited marketing communications where permitted, from which you can opt out at any time (consent or legitimate interests);
- improve our services and produce analytics, using de-identified or aggregated data that does not identify you;
- establish, exercise or defend legal claims.
Where we rely on your consent, you may withdraw it at any time; withdrawal does not affect processing already performed.
4. Automated screening and human review
Onboarding and ongoing monitoring involve automated processing, including document-authenticity checks, identity matching performed by our verification providers, and screening against sanctions, politically-exposed-person, watchlist, adverse-media and fraud databases. Automated results can affect whether onboarding or a transaction proceeds. Adverse outcomes that produce legal or similarly significant effects are subject to human review, and, where required by applicable law, you may request human intervention, express your point of view and contest a decision by contacting privacy@magma.builders.
5. Monitoring of communications and platform activity
We may monitor, log, record and retain communications with us (including e-mail and support channels) and activity on our platform (including API calls, instructions and session logs) for compliance, security, fraud-prevention, audit and evidentiary purposes, as permitted by applicable law.
6. How we share personal data
We share personal data with: banking partners and other licensed financial institutions participating in the services; identity-verification and screening providers; payment networks and correspondent or receiving institutions; service providers that support our operations under contractual confidentiality and security obligations; professional advisors, auditors and insurers; regulators, tax authorities and law enforcement where required or permitted by law; and, in connection with a corporate transaction, prospective acquirers or successors under appropriate safeguards.
We do not sell personal data, and we do not “sell” or “share” personal data as those terms are defined under applicable U.S. state privacy laws, including for cross-context behavioral advertising. We do not share personal data with third parties for their own marketing purposes.
7. International transfers
We are based in the United States and process personal data there. Where personal data is transferred from the European Economic Area, the United Kingdom, Switzerland, Singapore or other jurisdictions with data-transfer restrictions, we implement appropriate safeguards recognized under applicable law (such as standard contractual clauses, or reliance on adequacy where available). Further information about applicable safeguards is available on request.
8. Retention
We retain identity, verification and transaction records for at least five (5) years after the end of the relevant relationship, or longer where required by applicable law, our financial partners, audits, insurance or disputes. Site and contact data is retained for as long as needed for the purpose for which it was collected and then deleted or anonymized. Where you request deletion, we honor the request except to the extent retention is required by law (see Section 9).
9. Your rights
Depending on your jurisdiction, you may have rights to: access your personal data; correct inaccurate data; request deletion; restrict or object to certain processing; receive a copy of certain data in a portable format; withdraw consent; and lodge a complaint with a supervisory authority (for example, your local data protection authority in the EU, the Garante per la protezione dei dati personali in Italy, or the Personal Data Protection Commission in Singapore). We will not discriminate against you for exercising your rights.
Please note that anti-money-laundering and similar laws require us to retain verification and transaction records for minimum periods; requests for deletion cannot override those legal obligations, and we will tell you when this is the case.
To exercise your rights, contact privacy@magma.builders. We may need to verify your identity before acting on a request. An authorized agent may submit a request on your behalf with proof of authority. We respond within the timelines required by applicable law.
10. End users of our clients
Where a client uses our platform to provide services to its own end users, that client is responsible for its relationship with you, including its own privacy notices and any consents required for its services. We process end-user personal data in order to provide services to that client and to meet our own legal and compliance obligations; for compliance processing required of us by law, we act as an independent controller. If you are an end user, please direct requests first to the client you have a relationship with; we support clients in responding in accordance with our agreements, and we act directly where the law requires us to.
11. Security
We maintain administrative, technical and physical safeguards appropriate to the sensitivity of the personal data we process. No method of transmission or storage is completely secure; where required by law, we will notify you and the competent authorities of incidents affecting your personal data.
12. Cookies
The Site uses cookies that are necessary for its operation. You can control cookies through your browser settings; disabling necessary cookies may affect Site functionality.
13. Children
The Site and the services are not directed to individuals under 18, and we do not knowingly collect personal data from them.
14. Changes to this Policy
We may update this Policy from time to time by posting the revised version with a revised “Last updated” date. Where required by law, we will provide additional notice of material changes.
15. Contact
Magma Fintech Inc.
1111B S Governors Ave STE 88027, Dover, DE 19904, United States
Email: privacy@magma.builders