Legal

Privacy Policy

Last updated: 24 July 2026

This policy explains what personal information Lumier Private Bank collects, why we collect it, who we share it with, and what control you have over it. It applies to this website, to account applications submitted through it, and to the services we provide to clients.

01Who we are

Lumier Private Bank is a banking institution licensed in Anjouan, Union of the Comoros, under licence number 16305. For the purposes of this policy, Lumier Private Bank is the controller of the personal information described below.

Our registered office and contact details are set out in section 14.

02Information we collect

We collect information you give us directly, information generated through your use of our services, and information we obtain from third parties in the course of verification checks.

Information you provide

  • Application details. Your name, country of residence, email address, telephone number, the type of relationship you are enquiring about, your base currency, and the asset range you indicate.
  • Identity and onboarding documentation. If your application proceeds, we collect identity documents, proof of address, date and place of birth, nationality, tax identification numbers, and information about your source of wealth and source of funds.
  • Account credentials. The username and password you use to access the client portal, and any multi-factor authentication details.
  • Correspondence. Records of your communications with us, including email, telephone and secure messaging.

Information collected automatically

  • IP address, approximate location derived from it, browser and device type, operating system, and language settings.
  • Pages visited, time of access, referring page, and interactions with forms.
  • Cookies and similar technologies, as described in section 10.

Information from third parties

  • Identity verification, sanctions, politically-exposed-person and adverse-media screening providers.
  • Credit reference and fraud prevention agencies, where relevant to a service you have requested.
  • Publicly available registers and, where applicable, information from correspondent banks and intermediaries.

03How we use your information

  • To assess and respond to your account application, and to contact you about it.
  • To carry out customer due diligence and verify your identity before opening a relationship.
  • To provide, administer and service your accounts and to execute your instructions.
  • To meet our legal, regulatory, tax reporting and record-keeping obligations.
  • To detect, investigate and prevent fraud, money laundering, terrorist financing and other financial crime.
  • To secure our systems, authenticate users, and maintain audit trails.
  • To manage complaints, exercise or defend legal claims, and conduct internal audits.
  • To improve our website and services, using aggregated or de-identified data where possible.

We do not sell your personal information. We do not use your information for automated decision-making that produces legal effects for you without human involvement.

04Legal grounds for processing

We rely on one or more of the following grounds, depending on the purpose:

  • Performance of a contract — to take steps at your request before entering into a relationship, and to provide services once it exists.
  • Legal obligation — to comply with anti-money-laundering, counter-terrorist-financing, sanctions, tax reporting and supervisory requirements.
  • Legitimate interests — to protect our systems and clients from fraud and abuse, to manage risk, and to operate our business, provided those interests are not overridden by your rights.
  • Consent — for non-essential cookies and for any optional communications. You may withdraw consent at any time.

05Anti-money-laundering obligations

As a licensed bank we are required to identify and verify our clients, understand the purpose of the relationship, monitor transactions on an ongoing basis, and retain records of all of this.

Where we are required to make a report to a financial intelligence unit or other competent authority, we may be prohibited by law from informing you that a report has been made, and from explaining why an instruction has been delayed or declined. We may also be required to freeze funds or terminate a relationship in order to comply with sanctions measures.

These obligations limit some of the rights described in section 9. In particular, we cannot delete records we are required to keep, and we may be unable to disclose certain information to you.

06Who we share information with

  • Regulators and authorities — the Anjouan Offshore Finance Authority, financial intelligence units, tax authorities, courts and law enforcement, where legally required.
  • Correspondent banks, payment networks and intermediaries — to the extent needed to execute payments and settlements you instruct.
  • Service providers — identity verification and screening providers, IT hosting and security vendors, communications platforms, and professional advisers, all bound by confidentiality obligations and permitted to use the information only for the purposes we specify.
  • Auditors and professional advisers — lawyers, accountants and auditors acting for us.
  • Successors — in connection with a reorganisation, merger or transfer of business, subject to equivalent protections.

We do not disclose client information to anyone else except with your instruction or where we are legally compelled to do so.

07International transfers

We operate internationally and our service providers may be located outside the Union of the Comoros. Where we transfer personal information across borders, we take steps to ensure it remains protected — for example, by using contractual safeguards with the recipient and limiting what is transferred to what is necessary.

Data protection standards in the Union of the Comoros may differ from those in your country of residence, and may offer a lower level of protection than the regime you are accustomed to. By submitting information to us, you should be aware that it will be processed in and from that jurisdiction.

08How long we keep information

  • Client records and transaction data — for the duration of the relationship and for at least ten years after it ends, as required by anti-money-laundering record-keeping rules.
  • Applications that do not proceed — normally up to five years from the date of the application, so that we can evidence our due diligence decisions.
  • Website and technical logs — normally up to twenty-four months.
  • Correspondence — for the period necessary to handle the matter and any related claim.

Where a longer period is required by law or by an ongoing investigation or legal claim, we retain the information for as long as that requirement applies.

09Your rights

Subject to the limits described in section 5, you may ask us to:

  • Confirm what personal information we hold about you and provide a copy of it.
  • Correct information that is inaccurate or incomplete.
  • Delete information we no longer have a lawful basis to keep.
  • Restrict or object to certain processing, including processing based on our legitimate interests.
  • Receive certain information you provided to us in a portable format.
  • Withdraw consent where processing is based on consent.

To make a request, contact us using the details in section 14. We will verify your identity before acting and will respond within thirty days, or tell you if we need longer. If you are not satisfied with our response, you may raise the matter with the relevant supervisory authority in your jurisdiction.

10Cookies and website data

We use a small number of cookies and similar technologies:

  • Strictly necessary — to maintain your session, secure the client portal, and prevent fraudulent access. These cannot be switched off.
  • Preference — to remember choices such as language.
  • Analytics — to understand how the site is used in aggregate, where you have consented.

You can control cookies through your browser settings. Blocking strictly necessary cookies will prevent the client portal from functioning.

11Security

We use encryption in transit, access controls, multi-factor authentication for the client portal, network monitoring, and staff confidentiality obligations to protect personal information. Passwords are stored using one-way cryptographic hashing and are not visible to our staff.

No system is completely secure. You are responsible for keeping your credentials confidential and for notifying us immediately if you believe your account has been accessed without your authorisation. We will never ask you for your password, one-time codes, or full security details by email or telephone.

12Children

Our services are not directed at anyone under eighteen, and we do not knowingly collect their information other than in the context of a minor's account opened and operated by a parent, guardian or trustee.

13Changes to this policy

We may update this policy to reflect changes in our services or in applicable law. The date at the top shows when it was last revised. Where changes are material, we will notify clients directly through the client portal or by email.

14Contact us

For any question about this policy, or to exercise your rights, contact us at:

Lumier Private Bank
Boulevard De Coalancanthe
Mutsamudu, Anjouan
Union of the Comoros

operations@lumierbank.co