AF flagGB flag
Sarafi Asif

Privacy Policy

How we collect, use and protect your personal information.

Last updated: 26 July 2026

1. Who we are

Sarafi Asif is a UK money remittance business operated by Tech & Transfer Ltd ("we", "us"). We are the data controller for the personal data described in this policy. Contact us at privacy@sarafiasif.com.

2. What we collect

  • Identity data — full name, date of birth, nationality, photo ID documents and reference numbers.
  • Contact data — address, postcode, phone number, email address.
  • Transaction data — amounts, currencies, exchange rates, fees, beneficiary details, payout location, purpose of transfer and source of funds.
  • Compliance data — sanctions and PEP screening results, risk scores, records of enhanced due diligence and any suspicious activity assessments.
  • Technical data — IP address, device and browser information, login timestamps and session records.

3. Why we use it and our lawful bases

  • To provide the transfer service — performance of a contract.
  • To verify identity, screen against sanctions lists and monitor transactions — legal obligation (Money Laundering Regulations 2017, Proceeds of Crime Act 2002, sanctions legislation).
  • To prevent fraud and secure our systems — legitimate interests.
  • To respond to complaints and regulatory requests — legal obligation.
  • To send service messages (status updates, receipts) — performance of a contract. Marketing, if any, is consent-based and can be withdrawn at any time.

4. Who we share it with

We share personal data only where necessary with: our payout agents and partner institutions in the destination country; banks and payment providers; identity, sanctions and screening providers; our regulators, HM Revenue & Customs, the National Crime Agency and law enforcement where legally required; and our IT and hosting suppliers acting on our instructions.

We never sell personal data. Payout proof documents are accessible only to authorised staff.

5. International transfers

Because we send money abroad, beneficiary and sender details are transferred to payout partners outside the UK, including Afghanistan and Pakistan. Where the destination is not covered by UK adequacy regulations, we rely on appropriate safeguards such as standard contractual clauses, and share the minimum data needed to complete the payout.

6. How long we keep it

We retain identity, transaction and compliance records for five years after the end of the business relationship or the completion of an occasional transaction, as required by the Money Laundering Regulations. Records are then deleted or irreversibly anonymised through our automated retention process. Complaint files are held for five years from resolution. Security logs are held for up to two years.

7. Your rights

You have the right to request access to your data, correction of inaccurate data, erasure (where no legal retention duty applies), restriction of processing, portability, and to object to processing based on legitimate interests. To exercise any right, email privacy@sarafiasif.com. We respond within one month. We may need to verify your identity first.

Note that anti-money-laundering law prevents us from deleting transaction and verification records during the five-year retention period, and we may not tell you if a suspicious activity report has been made.

8. Security

Data is encrypted in transit and at rest. Access is role-based and audited, staff accounts require multi-factor authentication, and ID documents are held in private storage that is never publicly accessible.

9. Cookies

We use strictly necessary cookies only. See our Cookie Policy.

10. Complaints

If you are unhappy with how we handle your data, please tell us first via our complaints process. You can also complain to the Information Commissioner's Office (ICO) at ico.org.uk or on 0303 123 1113.