Notra One

This Privacy Policy explains how Notra One Limited (“we”, “us”, “our”) collects and uses personal data when you use the website at https://notraone.com and any related pages that link to this policy (the “Site”).

  1. Controller and contact details

NotraOne is a trading name of Notra One Limited. For the purposes of UK data protection law, Notra One Limited is the controller of personal data collected through the Site.

We operate NotraOne-branded payment and card programmes that run over the regulated infrastructure of a small network of electronic money institutions, payment providers and banks (“Banking Partners”). In some cases our Banking Partners will also act as independent controllers of your personal data for their own regulatory and operational purposes. In other cases they may process data as our processors, strictly under our instructions, to enable the NotraOne programmes to run.

Where a particular product or service involves a Banking Partner acting as its own controller, this will be explained in the customer terms and privacy notices you are shown at sign-up. Those notices will tell you how that partner handles your data for its own purposes.

You can contact us about privacy matters at: privacy@notraone.com.

  1. Personal data we collect

We collect the following categories of personal data when you use the Site or interact with us in connection with NotraOne programmes:

• Identifiers and contact details such as your name, email address, phone number, company name, job title and country, when you submit a form, contact us or otherwise provide these details.
• Business information you choose to provide about your company, use case, expected volumes or similar information relevant to discussing potential services.
• Device and usage data such as IP address, browser type, operating system, pages viewed, referring URLs and interactions with the Site. This may be collected using cookies and similar technologies.
• Application and referral data such as whether you asked us to connect you to one of our Banking Partners or other providers, whether you clicked through from the Site to their platforms, and high level status updates that a provider may share with us to help manage programmes and referrals, where permitted by law and by our agreements with that provider.
• Marketing preferences such as whether you have opted in or out of receiving marketing communications from us.

We do not intentionally collect special category data through the Site.

  1. How we use your personal data and legal bases

We use personal data for the following purposes:

• Responding to enquiries and providing information about our services
To respond when you contact us, request information or ask us to get in touch, including via any messaging tools we provide links to.
Legal basis: our legitimate interests in operating our business and responding to requests, or steps taken at your request before entering into a contract.

• Operating NotraOne programmes and coordinating with partners
To understand your business needs, discuss potential NotraOne programmes and, where appropriate, coordinate onboarding and communication with relevant Banking Partners or other providers. This includes sending your contact details and relevant business information to a provider when you ask us to set up or progress a programme.
Legal basis: performance of a contract with you or steps taken at your request before entering into a contract, and our legitimate interests in managing our partner and programme relationships.

• Marketing communications
To send you newsletters, updates and other marketing communications about our services where permitted.
Legal basis: your consent where required by law for certain email marketing, otherwise our legitimate interests in promoting our services to business contacts.
You can opt out of marketing at any time by following the unsubscribe instructions in our emails or by contacting us.

• Improving the Site and analytics
To operate, maintain and improve the Site, including understanding how visitors use it and which content is most useful.
Legal basis: consent for non-essential cookies and analytics, and our legitimate interests for essential cookies and basic analytics that are strictly necessary to provide the Site.

• Legal and compliance
To maintain records, handle complaints or enquiries, and exercise or defend legal claims.
Legal basis: compliance with legal obligations and our legitimate interests in protecting our rights and managing risk.

We will only use your personal data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another compatible purpose and we have a lawful basis to do so.

  1. Sharing your personal data

We share personal data with:

• Our Banking Partners and other third party providers when you ask us to connect you to a programme or where it is necessary to progress onboarding and services you have requested. Depending on the structure, these providers may act as independent controllers for their own processing and or as processors acting on our instructions.
• Service providers that host the Site or provide supporting services such as analytics, forms, CRM, email delivery, IT and security. These providers act as processors under our instructions and are not permitted to use your personal data for their own purposes.
• Professional advisers such as lawyers, accountants and consultants where necessary in the course of our business.
• Authorities and third parties where required by law, by a court or regulator, or to protect our legal rights, for example in connection with legal claims, compliance, fraud prevention or security.

We do not sell your personal data.

  1. International transfers

Some of our service providers and Banking Partners may process personal data outside the United Kingdom.

Where we transfer personal data internationally, we take appropriate steps to protect it, such as:
• using the UK International Data Transfer Agreement or other approved standard contractual clauses, or
• relying on adequacy regulations issued by the UK government for the relevant country.

You can contact us for more information about international transfers relating to your data.

  1. Data retention

We keep your personal data only for as long as necessary for the purposes described in this policy, including to respond to enquiries, manage our relationship with you and comply with legal obligations.

As a guide:
• enquiry and lead data is typically retained for up to three years from the last interaction, unless we need to keep it longer for legal reasons, and
• cookie and analytics data is retained in line with our cookie policy and the settings you choose.

We may retain anonymised or aggregated data that does not identify you indefinitely.

  1. Your rights

Subject to legal limits and applicable law, you may have the right to:
• request access to your personal data
• request correction of inaccurate or incomplete data
• request deletion of your data in certain circumstances
• request restriction of processing
• object to certain processing, including where we rely on legitimate interests or for direct marketing
• request data portability, to receive your data in a structured, commonly used, machine readable format and or have it transmitted to another controller where technically feasible

Where we rely on your consent, you can withdraw your consent at any time. This will not affect the lawfulness of processing before consent was withdrawn.

To exercise your rights, contact us at privacy@notraone.com.

You also have the right to lodge a complaint with the UK Information Commissioner’s Office at ico.org.uk or with your local supervisory authority.

  1. Security

We use appropriate technical and organisational measures to protect personal data, taking into account the nature of the data and the risks involved.

However, no method of transmission or storage is completely secure and we cannot guarantee absolute security. You are responsible for keeping any login details confidential and for notifying us promptly if you suspect unauthorised access.

  1. Children

The Site is not intended for children, and we do not knowingly collect data from anyone under 18. If you believe we have collected data from a child, please contact us and we will take appropriate steps to delete it.

  1. Changes to this policy

We may update this policy from time to time.

If we make material changes, we will post the updated policy on the Site and update the “Last updated” date below. Your continued use of the Site after changes are made means you accept the updated policy.

  1. Contact

If you have questions about this policy or how we handle your data, contact us at privacy@notraone.com.

Last updated: 3 November 2025

 

Any IBANs, accounts, cards and payment services you access through NotraOne are supported by our regulated Banking Partners. Those partners are responsible for their own regulatory permissions and for the way they process personal data in that capacity, as explained in their customer and privacy documentation.