Draft for legal review — not publishable
Complete draft, written from the platform's actual data flows. It must be reviewed by counsel qualified in Canadian privacy law (PIPEDA), Nigerian law (NDPA 2023) and Kenyan law (Data Protection Act 2019) before publication. Two items still need a factual answer from you, marked in amber below:
- The registered office address
- Confirmation of the legal entity name after the Kunye rename
Privacy Policy
Last updated: 21 September 2026
Effective: on publication
Kunye Financial Inc., trading as Five Four Financial ("we", "us", "our"), operates the Five Four Financial platform — the website at fivefourfinancial.com, our cover planners, and our mobile applications.
We are registered with the Financial Transactions and Reports Analysis Centre of Canada (FINTRAC) as a Money Services Business, registration number M21256121.
This policy explains what personal information we collect, why we collect it, who we share it with, how long we keep it, and what you can ask us to do about it.
1. Who we are and how to contact us
- Legal entity
- Kunye Financial Inc., trading as Five Four Financial
- Registered address
[REGISTERED OFFICE ADDRESS]- Privacy contact
- privacy@fivefourfinancial.com
- General support
- support@fivefourfinancial.com
- Privacy accountability
- We have not appointed a Data Protection Officer. Responsibility for privacy sits with our compliance lead, reachable at the privacy address above.
Legal review: Kenya's Data Protection Act requires registration as a data controller with the Office of the Data Protection Commissioner where thresholds are met, and may require a local representative or DPO. Nigeria's NDPA has comparable provisions. Confirm whether either applies before the corresponding corridor opens, and amend this section if it does.
2. Information we collect
2.1 Information you give us
- Identity
- Full name, date of birth, gender, nationality — to open an account and meet identity-verification obligations.
- Contact
- Email address, phone number, street address, city, province, postal code — to contact you, and because our payments partner requires a full address for every customer.
- Identity documents
- Passport or national ID, document number, photographs of the document, and a selfie — legally required identity verification.
- Account security
- Password (stored hashed), security question and answer — to protect your account.
- Financial profile
- Occupation and source of income — required by anti-money-laundering rules.
- Beneficiary details
- Name, bank, account number and country of anyone you save as a recipient — to send money where you direct.
- Cover planner answers
- What you tell a planner about the person you are covering — their city, their age, what matters to you, and your budget. See section 5.
2.2 Information generated by your use of the service
- Transaction records — amount, currency, date, counterparty, status
- Wallet balances and history
- Order and payment records
- Device and connection information, including IP address
- Sign-in activity, including failed attempts
2.3 Information from third parties
- Identity verification results from Sumsub, including whether you passed, and if not, the reason
- Payment status and settlement confirmations from our payments partner
- Policy status from an insurance provider or broker, where you have taken out cover through a planner
3. Why we use your information, and our legal basis
- Providing the service — wallets, transfers, payments
- Performance of our contract with you
- Verifying your identity
- Legal obligation under anti-money-laundering law
- Detecting and preventing fraud and financial crime
- Legal obligation, and our legitimate interest
- Keeping transaction records
- Legal obligation
- Matching you to cover options in a planner
- Your request, made before entering a contract
- Notifying you about your account and transactions
- Performance of our contract
- Support and dispute resolution
- Performance of our contract
- Improving the service
- Legitimate interest
- Marketing
- Consent, which you may withdraw at any time
We do not sell your personal information, and we do not use it for automated decisions that produce legal effects other than the identity-verification outcome described in section 4, which you may ask us to review manually.
4. Identity verification
We use Sumsub, a specialist identity verification provider, to verify who you are. When you begin verification:
- You submit documents and a photograph directly to them
- They check the documents, compare the photograph, and screen against sanctions and politically-exposed-person lists
- They return a result — verified or not, with a reason
- We keep the result, their reference identifiers, and the record of their decision
Their processing is governed by their own privacy notice, published at sumsub.com.
If verification fails, we will tell you, and you may contact us to have the outcome reviewed by a person.
5. Cover planners
Our cover planners ask you about the person you want to cover so we can show you relevant options. You can use a planner and see your results without creating an account.
- If you only browse your results, your answers are used to produce them and are not shared with a provider.
- If you ask to be put on a waitlist, we keep your email address and your answers so we can contact you about that.
- If you proceed with cover, we pass what is needed — the covered person's name, age, location, and the plan chosen — to the licensed broker and the insurance provider so they can issue the policy. They become responsible for that information under their own privacy notices, which we will show you before you proceed.
Where the person you are covering is someone other than you, you are telling us their information. Please make sure they are content for you to do that.
Legal review: health cover planner answers may amount to health information about a third party, which attracts heightened protection under PIPEDA, Kenya's DPA and Nigeria's NDPA. Counsel should confirm whether express consent from the covered person is required, and whether the current flow obtains it. This section and the planner's own consent screen must match.
6. Payments and your money
Your funds are held in a wallet maintained by our regulated payments partner, FiatMatch. To operate it we share with them:
- Your name, email address, phone number and full address
- Your country of residence, occupation and source of income
- Transaction instructions and amounts
- Beneficiary details for any payment you make
Legal review: describe the fund-holding arrangement accurately. Whether customer funds are segregated, and how, is a material disclosure — and the settlement model is currently under review. This section must state what is true at publication, and must agree with section 5 of the Terms of Use.
7. Who else we share with
- Sumsub — identity verification
- Identity data and documents — legal identity-verification obligation
- FiatMatch — payments partner
- Identity, contact and transaction data — to hold funds and execute payments
- Licensed insurance brokers and providers
- Planner answers and covered-person details, only where you proceed with cover — to issue and administer the policy
- Vendors you order from
- Your name and order details — so they can fulfil your order
- Email delivery provider
- Email address and message content — to send account and transaction notifications
- Cloud hosting provider
- All data, at rest and in transit — to run the service
- Regulators and law enforcement
- As required — legal obligation
- Professional advisers
- As needed — legitimate interest
To complete before publication: name the email and hosting providers and their jurisdictions, and confirm a data-processing agreement is in place with every party in this table. Under PIPEDA you remain accountable for personal information transferred to a processor.
8. International transfers
We operate between Canada and Africa, so your information crosses borders. It is transferred to Canada, to Nigeria, and to any other country as we open service there, as well as to wherever our providers host their systems.
Where we transfer personal information out of a country whose law restricts it, we rely on standard contractual clauses with the receiving party, or on your explicit consent where the transfer is necessary to carry out your instruction.
Legal review: Kenya's DPA restricts transfers out of Kenya absent adequacy, appropriate safeguards, or consent; Nigeria's NDPA is comparable. Confirm the mechanism actually in place for each direction of flow, and correct the paragraph above if standard contractual clauses are not yet executed.
9. How long we keep it
- Transaction records
- At least five years after the transaction or the end of the relationship, whichever is later
- Identity verification records
- At least five years after the relationship ends
- Account and profile data
- For the life of the account, then five years
- Payment-provider notifications
- Retained as part of the transaction record, five years
- Planner answers, where you did not proceed
- 12 months, then deleted
- Security and sign-in logs
- 12 months
- Marketing preferences
- Until you withdraw consent, then a record of the withdrawal
The five-year periods follow anti-money-laundering record-keeping requirements. We cannot delete this data on request while those obligations apply, even if you close your account. See section 10.
Confirm the exact statutory periods with counsel. Canada, Kenya and Nigeria are not identical, and the longest applicable period governs.
10. Your rights
Subject to the retention obligations above, you may:
- Access the personal information we hold about you
- Correct anything inaccurate
- Delete your information, where no legal obligation requires us to keep it
- Object to or restrict certain processing
- Withdraw consent for marketing at any time
- Receive a copy of information you provided, in a portable format
- Complain to a regulator
To exercise any of these, write to privacy@fivefourfinancial.com. We will respond within 30 days. If we need longer, we will tell you why and when to expect an answer.
Be aware: because anti-money-laundering law requires us to retain identity and transaction records, a deletion request will not remove them until the retention period expires. We will tell you what we have deleted and what we must keep, and why.
Regulators
- Canada — Office of the Privacy Commissioner, priv.gc.ca
- Kenya — Office of the Data Protection Commissioner, odpc.go.ke
- Nigeria — Nigeria Data Protection Commission, ndpc.gov.ng
11. Security
We protect your information by:
- Encrypting all traffic in transit using TLS
- Storing passwords hashed, never in plain text
- Restricting staff access to personal data on a need-to-know basis
- Verifying the authenticity of every payment notification cryptographically
- Keeping an immutable audit record of financial transactions
- Taking regular, tested backups
No system is perfectly secure. If a breach occurs that is likely to result in a real risk of significant harm, we will notify you and the relevant regulators as the law requires, and we keep a record of every breach.
Legal review: PIPEDA requires breach reporting to the OPC and affected individuals where there is a real risk of significant harm, and a record of every breach. Kenya and Nigeria have their own timelines. Confirm a breach-response procedure exists before publishing this commitment.
12. Cookies and tracking
This site loads no analytics, no tag manager and no third-party scripts. It requests web fonts from Google Fonts, and sets no cookies of its own.
Our apps and signed-in areas set only the cookies needed to keep you signed in and to keep your session secure. Those are strictly necessary and are not used to track you.
Update this section the moment anything is added — particularly if the planner campaign uses advertising pixels. List every cookie and third-party script, its purpose and duration, separating strictly necessary from analytics and marketing, which require consent before they load. The previous site beaconed every visitor before consent; this one must not.
13. Children
Our service is not for anyone under 18. We do not knowingly collect information from children. If you believe a child has given us information, write to privacy@fivefourfinancial.com and we will delete it, other than anything we are legally required to keep.
14. Changes
We may update this policy. Material changes will be notified by email or in the app at least 30 days before they take effect. The date at the top always reflects the current version.
15. Contact
Privacy: privacy@fivefourfinancial.com
Support: support@fivefourfinancial.com
Post: Kunye Financial Inc., [REGISTERED OFFICE ADDRESS]