B2B Enterprise Scope: Finlinks Payment Inc. is an enterprise financial technology provider specializing in commercial B2B trade clearing, multi-currency routing, and virtual account APIs. This policy applies to corporate clients, authorized representatives, and commercial platform users.
1. Introduction & Regulatory Scope
At Finlinks Payment Inc. ("Finlinks", "we", "us", or "our"), protecting enterprise data and maintaining transactional confidentiality is paramount. This Privacy Policy outlines how we collect, use, process, and safeguard commercial and personal information in connection with our B2B trade settlement services, virtual collection accounts, and API infrastructure.
As an entity incorporated in Ontario, Canada, we strictly comply with applicable federal and provincial data privacy and financial security legislation, including:
- Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) as applicable to organizations in Ontario.
- Regulatory standards under Canada's Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA) as overseen by FINTRAC.
- Applicable provincial privacy standards (including Quebec's Law 25 for cross-border data protection principles, where applicable).
2. Privacy Officer Designation
In accordance with PIPEDA statutory standards and Canadian privacy compliance principles, Finlinks Payment Inc. has designated a Chief Compliance & Privacy Officer responsible for overseeing corporate privacy standards and data protection protocols:
3. Data Collection & KYB Standards
As a B2B money services and technology provider, we collect data required for enterprise onboarding, trade verification, and regulatory compliance.
3.1 Corporate & Identity Information Provided Directly
- Corporate Know Your Business (KYB) Data: Articles of Incorporation, business registration certificates, corporate ownership structures, and tax identification numbers.
- Ultimate Beneficial Owner (UBO) & Representative Data: Government-issued identification, full names, corporate titles, and official contact details of legal directors, officers, and major shareholders (holding 25%+ ownership).
- Commercial Transaction & Invoice Metadata: B2B trade invoices, bills of lading, cross-border payment instructions, and beneficiary banking details required to execute transit clearing.
3.2 Technical & API Telemetry Data Collected Automatically
When interacting with our web dashboard or API endpoints, our infrastructure automatically records:
- IP addresses, API authentication tokens, access timestamps, and request payload signatures.
- Browser and device hardware profiles to protect against unauthorized API access and session hijacking.
4. Purpose of Data Processing
We process collected information strictly for legitimate commercial and regulatory purposes:
- Executing B2B Clearing: Facilitating cross-border trade payment routing, virtual account provisioning, and multi-currency FX conversions.
- Regulatory & AML Compliance: Fulfilling mandatory Know Your Customer/Business (KYC/KYB) obligations, conducting real-time transaction screening against global sanction lists (OFAC, OSFI, UN), and reporting to FINTRAC as required under Canadian law.
- Platform Security: Detecting, preventing, and mitigating fraudulent commercial activities, cyber threats, or unauthorized access.
5. Information Sharing & Third-Party Disclosures
Finlinks Payment Inc. does not sell, rent, or trade client or corporate data. Data disclosures are restricted to essential operational and compliance channels:
- Banking Clearing Partners & Trustee Entities: Sharing required settlement metadata with Tier-1 Canadian financial institutions, corresponding clearing banks, and authorized trustee account guardians to execute fund routing.
- RegTech & Verification Partners: Engaging automated identity verification, sanction screening, and corporate registry lookup tools strictly for regulatory compliance.
- Regulatory Authorities: Disclosing information to law enforcement or statutory regulators (e.g., FINTRAC, CRA) only under lawful demand, court order, or mandatory statutory reporting rules.
6. Security Infrastructure & Cloud Residency
We enforce enterprise-grade security controls to protect client information:
- Data Encryption: End-to-end 256-bit SSL/TLS encryption for data in transit and AES-256 encryption for stored data.
- Cloud Architecture: Enterprise hosting on secure Microsoft Azure cloud infrastructure in compliance with ISO/IEC 27001 standards and Canadian data localization protocols.
- Transit-Only Non-Custodial Model: Commercial funds are processed strictly on a 24-hour transit basis through segregated trustee safeguarding accounts, minimizing long-term data and monetary exposure.
7. Mandatory Retention Schedule
Finlinks retains records in accordance with statutory obligations under Canadian anti-money laundering regulations:
| Data Category |
Statutory Retention Period |
Legal / Business Basis |
| Corporate KYB & UBO Identity Records |
5 Years post-account closure |
Mandatory FINTRAC PCMLTFA record-keeping rules |
| B2B Transaction & Clearing Logs |
5 Years from transaction execution |
FINTRAC compliance, financial audit, and CRA requirements |
| API System & Access Logs |
12 to 24 Months |
Cybersecurity monitoring and system integrity audits |
8. Your Privacy Rights
Under PIPEDA and Quebec's Law 25, corporate clients and authorized representatives have the right to:
- Request access to personal and corporate records held by Finlinks.
- Request correction of inaccurate or outdated information.
- Inquire about automated screening processes and request human compliance review.
To exercise your privacy rights, please submit a written request to our Privacy Officer at compliance@finlinkspay.ca. Verification of identity and corporate authorization will be required before fulfilling requests.
9. Updates to This Policy
We may update this Privacy Policy periodically to reflect technological enhancements or regulatory revisions under Canadian law. The effective date at the top of this document will indicate the latest revision.