• Call Our Support
    +44 02038763155

  • 70 Cricklewood Broadway London NW2 3EP

  • Our Working Hours
    Mon - Sat: 9 am - 6 pm

Privacy Policy

Privacy Policy

Sahar Exchange Limited T/A Amanat Exchange
Last updated: 2026/06/20    Version: 1.0
Sahar Exchange Limited T/A Amanat Exchange respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, store, share, and protect personal data when you use our money transfer and related services, visit our premises, use our website, contact us, or otherwise deal with us.
This Privacy Policy is intended to meet the transparency requirements under the UK General Data Protection Regulation, the Data Protection Act 2018, and relevant expectations of the Information Commissioner’s Office, HM Revenue & Customs, the Financial Conduct Authority, and other UK regulatory or law enforcement bodies.

1. Who we are

The data controller is:
Sahar Exchange Limited T/A Amanat Exchange
Registered office / trading address: 70 Cricklewood Broadway, London, NW2 3EP
Email: info@amanatexchange.co.uk
Telephone: 020 3876 3155
For data protection enquiries, please contact us using the details above.
We are registered with the Information Commissioner’s Office. ICO registration number: [insert current ICO registration number]
We are also regulated or supervised, as applicable, by the Financial Conduct Authority for payment services and by HM Revenue & Customs for anti-money laundering supervision.

2. Personal data we collect

We may collect and process the following types of personal data:

  • Identity information: This may include your full name, date of birth, nationality, place of birth, gender, signature, photograph, identification document details, passport, driving licence, residence permit, national ID card, or other identity documents.
  • Contact information: This may include your address, telephone number, email address, and other contact details.
  • Transaction information: This may include the amount sent or received, transaction date, transaction reference, fees, exchange rate, payment method, destination country, beneficiary details, purpose of payment, source of funds, source of wealth where required, and payout confirmation.
  • Beneficiary information: This may include the beneficiary’s name, address, telephone number, relationship to you, destination country, identification information where required, and payment collection details.
  • Compliance and risk assessment information: This may include customer due diligence records, enhanced due diligence information, sanctions and politically exposed person screening results, fraud prevention checks, transaction monitoring records, internal compliance notes, and suspicious activity review records.
  • Financial information: This may include cash payment details, bank account details where relevant, source of funds evidence, employment details, payslips, bank statements, business information, or other documents needed to verify funds or comply with legal obligations.
  • CCTV and premises security information: When you visit our premises, your image may be captured by CCTV for security, crime prevention, staff safety, and regulatory record-keeping purposes.
  • Website and communication information: This may include website usage data, cookies, enquiry forms, emails, call records or notes, complaints, and other communications with us.

We only collect personal data that is necessary for our services, legal obligations, regulatory obligations, security, and proper business administration.

3. How we collect your personal data

We may collect personal data directly from you when you:

  • visit our premises;
  • request or complete a money transfer;
  • provide identity documents or supporting documents;
  • contact us by telephone, email, website, or in person;
  • make a complaint or enquiry;
  • provide information about a beneficiary;
  • use our website.

We may also collect or verify personal data from third parties, including:

  • identity verification providers;
  • sanctions and PEP screening providers;
  • payment system providers;
  • payout agents and settlement partners;
  • banks and payment institutions;
  • fraud prevention agencies;
  • public registers and official databases;
  • regulators, supervisory authorities, law enforcement agencies, or government bodies.

4. Why we use your personal data and our lawful bases

We process personal data only where we have a lawful basis under UK data protection law. The main reasons are:

4.1 To provide money transfer and payment services

We use your personal data to process transactions, identify you, record transaction details, contact you about your transaction, and arrange payout to the beneficiary.
Lawful basis: performance of a contract and legitimate interests.

4.2 To comply with AML, counter-terrorist financing, sanctions, and regulatory obligations

We are required to verify customer identity, monitor transactions, keep records, conduct sanctions and PEP screening, assess risk, report suspicious activity where required, and respond to lawful requests from regulators and law enforcement agencies.
Lawful basis: legal obligation and substantial public interest, where special category data is involved.

4.3 To prevent fraud, financial crime, and misuse of our services

We use personal data to detect, prevent, investigate, and manage fraud, money laundering, terrorist financing, sanctions evasion, scams, and other unlawful activity.
Lawful basis: legal obligation and legitimate interests.

4.4 To manage our business and regulatory relationship

We use personal data for internal record keeping, audit, compliance reviews, staff training, complaints handling, risk management, regulatory reporting, accounting, insurance, legal claims, and business administration.
Lawful basis: legal obligation, legitimate interests, and, where applicable, establishment, exercise, or defence of legal claims.

4.5 To protect staff, customers, premises, and property

We use CCTV and security records to help protect our staff, customers, premises, cash, records, and equipment.
Lawful basis: legitimate interests and legal obligation, where applicable.

4.6 To respond to enquiries and complaints

We use personal data to respond to your enquiries, handle complaints, investigate issues, and provide customer support.
Lawful basis: performance of a contract, legal obligation, and legitimate interests.

4.7 Marketing and website communications

We may use your contact details to respond to your enquiry or, where permitted, to provide limited information about our services. We will not sell your personal data to third parties.
Lawful basis: consent or legitimate interests, depending on the circumstances.
You may object to marketing communications at any time.

5. Special category data and sensitive information

We do not usually need to collect special category data. However, some identity documents or supporting documents may indirectly include sensitive information, such as nationality, biometric image, health information, religion, or other protected information.
Where we process such information, we do so only where necessary for legal, regulatory, AML, sanctions, security, or substantial public interest reasons, or where otherwise permitted by law.

6. When we may refuse to provide services

We may refuse, delay, cancel, or report a transaction if:

  • you do not provide required identity or supporting documents;
  • we cannot verify your identity;
  • we cannot complete sanctions, PEP, fraud, or AML checks;
  • the transaction appears suspicious or inconsistent with your profile;
  • the transaction may breach applicable law or regulation;
  • we are required or permitted to do so by law, regulator, payment partner, payout agent, bank, or law enforcement authority.

In some circumstances, we may be legally restricted from explaining the reason for our decision.

7. Who we share personal data with

We may share personal data with the following parties where necessary and lawful:

  • payment system providers and remittance software providers;
  • payout agents and settlement partners;
  • banks, payment institutions, and safeguarding providers;
  • identity verification, sanctions screening, PEP screening, and fraud prevention providers;
  • HM Revenue & Customs;
  • the Financial Conduct Authority;
  • the National Crime Agency;
  • the Information Commissioner’s Office;
  • Companies House, where applicable;
  • police, courts, government bodies, regulators, and law enforcement agencies;
  • external compliance consultants, auditors, accountants, insurers, and legal advisers;
  • IT, website, cloud, data storage, CCTV, and system support providers;
  • complaint handling bodies or dispute resolution bodies, where applicable.

We only share personal data where this is necessary for providing services, meeting legal or regulatory obligations, preventing financial crime, protecting our rights, or managing our business.

8. International transfers

Some transactions require personal data to be sent outside the United Kingdom, including to payout agents, banks, payment partners, or beneficiaries in the destination country.
Where we transfer personal data outside the United Kingdom, we will take reasonable steps to ensure appropriate safeguards are in place, where required by law. These safeguards may include contractual controls, due diligence on payout agents or service providers, technical and organisational security measures, or other lawful transfer mechanisms.
You should be aware that some destination countries may not provide the same level of data protection as the United Kingdom. We will only transfer personal data where it is necessary for the service, compliance with legal obligations, or another lawful basis.

9. How long we keep personal data

We keep personal data only for as long as necessary for the purposes set out in this Privacy Policy.
As a money service business, we are generally required to keep customer due diligence, transaction, and AML records for at least five years after the end of the business relationship or completion of the relevant transaction, unless a longer period is required or permitted by law.
We may keep some records for longer where necessary for:

  • legal claims or disputes;
  • regulatory investigations;
  • fraud prevention;
  • law enforcement requests;
  • tax, accounting, or audit purposes;
  • complaint handling;
  • sanctions, AML, or financial crime risk management.

CCTV records are normally kept for a limited period unless footage is required for security, investigation, insurance, legal, regulatory, or law enforcement purposes.

10. How we protect personal data

We use appropriate technical and organisational measures to protect personal data against unauthorised access, loss, misuse, alteration, disclosure, or destruction. These measures may include:

  • restricted staff access;
  • password protection and system permissions;
  • secure storage of documents;
  • staff training;
  • CCTV and premises security;
  • transaction and compliance monitoring;
  • use of trusted system providers;
  • internal policies and procedures;
  • periodic review of records and access arrangements.

Staff, agents, contractors, and service providers who handle personal data are expected to keep it confidential and use it only for authorised purposes.

11. Your data protection rights

Subject to legal restrictions and exemptions, you may have the following rights:

  • the right to be informed about how we use your data;
  • the right of access to your personal data;
  • the right to correction of inaccurate or incomplete data;
  • the right to erasure in certain circumstances;
  • the right to restrict processing in certain circumstances;
  • the right to object to processing in certain circumstances;
  • the right to data portability, where applicable;
  • the right to withdraw consent where processing is based on consent;
  • the right to complain to the Information Commissioner’s Office.

Some rights may be limited where we are required to keep or use personal data for AML, sanctions, fraud prevention, regulatory, legal, or law enforcement purposes. For example, we may not be able to delete transaction or customer due diligence records where we are legally required to keep them.
To exercise your rights, please contact us at:
Email: info@amanatexchange.co.uk
Address: Sahar Exchange Limited T/A Amanat Exchange, 70 Cricklewood Broadway, London, NW2 3EP
We may ask you to verify your identity before responding to your request.

12. Complaints

If you are unhappy with how we handle your personal data, please contact us first so that we can try to resolve your concern.
You can contact us at:
Email: info@amanatexchange.co.uk
Telephone: 020 3876 3155
Address: 70 Cricklewood Broadway, London, NW2 3EP
You also have the right to complain to the Information Commissioner’s Office, the UK data protection regulator.

13. Cookies and website information

Our website may use cookies or similar technologies to operate the website, improve user experience, understand website traffic, and support website security.
Where required, we will obtain consent for non-essential cookies. You can control cookies through your browser settings. If we use analytics or marketing cookies, our cookie notice should explain the type of cookie, purpose, duration, and how you can refuse or withdraw consent.
The current cookie section should be reviewed and updated to ensure that any cookies actually used by the website are accurately listed.

14. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our services, systems, legal obligations, regulatory expectations, or business operations.
The latest version will be available on our website and, where appropriate, at our premises.

Recommended webpage action points

    • Replace the existing privacy policy with this revised version.
    • Remove irrelevant HR/employment wording, “affiliates and subsidiaries,” and brochure website template text.
    • Remove outdated references to the EU-US Privacy Shield and EU-only wording.
    • Insert the correct ICO registration number and confirm the exact FCA/HMRC wording.
    • Add a separate cookie banner or cookie notice if the website uses analytics or non-essential cookies.
    • Keep a version-controlled copy of the privacy policy in the AML/PCP folder, showing approval date, review date, and responsible person.