Privacy Statement
Last Updated: August 1, 2026

At NEOP Bank (“NEOP”, “we”, “us”, or “our”), your privacy and data security are our top priorities. We will never sell or rent your personal data to third parties.

This Privacy Statement (“Statement”) explains what personal data we collect, why we collect it, how we process it, and what rights you have regarding your information under the General Data Protection Regulation (GDPR) and other applicable privacy laws.

Table of Contents
  1. Introduction & Data Controller
  2. What Personal Data We Collect
  3. Lawful Basis for Processing
  4. Purposes of Data Processing
  5. Automated Decision-Making & AI
  6. Data Sharing with Third Parties
  7. International Data Transfers
  8. Data Retention
  9. Your Legal Rights
  10. Managing Your Preferences & Consents
  11. Updates to This Policy
  12. Contact & Complaints
1. Introduction & Data Controller
NEOP Bank is the data controller responsible for processing your personal data.
  • Registered Entity: NEOP Bank
  • Chamber of Commerce (KVK): 81247213
  • Headquarters: The Netherlands, The Hague, Carnegieplein 4, 2517 KJ
  • Data Protection Officer (DPO): support@neopbank.com
If you have any questions regarding how we process your personal data, you can reach out to our DPO or contact our Support Team directly through the NEOP App.

2. What Personal Data We Collect
We collect personal data directly from you, automatically through your use of our services, and from verified third parties.

A. Information You Provide directly
  • Identity & Onboarding Data: Full name, date and place of birth, nationality, gender, government-issued identification document details, photo/video verification data, and tax identification number (TIN/BSN).
  • Contact Information: Residential address, email address, phone number.
  • Financial & Tax Information: Source of funds, employment status, tax residency, linked bank account numbers (IBANs).
  • Communication Data: Customer support chats, call recordings, emails, and feedback forms.
B. Information Collected Automatically
  • Device & Usage Data: IP address, device type, operating system, unique device identifiers, advertising ID, app usage statistics, and cookie data.
  • Transaction Data: Amounts, dates, merchant details, counterparty information, payment descriptions, and card numbers.
  • Location Data: GPS location data (only if enabled for features such as Fraud/Card Protection or Travel Services).
C. Information from Third Parties
  • Public Registers & Credit Agencies: Credit scoring checks, company register data, sanctions list screenings, and PEP (Politically Exposed Persons) checks.
  • Open Banking Data: Information from external bank accounts linked via Open Banking (upon your explicit consent).
  • Social Media & Public Web: Publicly available information when you tag or mention NEOP Bank in public forums.
3. Lawful Basis for Processing
We process your personal data based on the following legal grounds:

Legal Basis

Description / Examples

Legal Obligation

To comply with Anti-Money Laundering (AML), Know Your Customer (KYC), tax reporting, and banking regulations.

Contract Performance

To open and manage your NEOP account, issue payment cards, process transactions, and provide customer support.

Legitimate Interest

To prevent fraud, ensure network security, improve product features, and analyze user sentiment.

Consent

For direct marketing, biometric authentication (fingerprint/Face ID local unlock), and Open Banking integrations.


4. Purposes of Data Processing
We use your data specifically to:
  1. Verify your identity and onboard you as a customer.
  2. Provide core banking, payment, and transaction services.
  3. Protect your account against fraud, unauthorized access, and cyber threats.
  4. Provide customized customer support via automated systems and human agents.
  5. Comply with regulatory obligations and respond to requests from financial oversight authorities.
  6. Personalize your app experience, analytics, and budgeting insights.
5. Automated Decision-Making & AI
NEOP Bank utilizes advanced algorithms and Artificial Intelligence (AI Assistants) to streamline operations:
  • Automated Identity Verification & Onboarding: Document checks and initial risk scoring may be performed automatically to accelerate account opening.
  • Fraud Detection: Automated systems monitor transaction patterns in real time to block suspicious activities and prevent unauthorized transactions.
  • AI Smart Assistant: Our in-app AI assistant helps answer general queries, categorize expenses, and offer financial insights. AI systems will never make automated decisions that produce legally binding effects on you without human intervention.
6. Data Sharing with Third Parties
We only share your data when necessary and legally permissible:
  • Service Providers: Cloud storage partners, payment processors, card issuing partners, IT security vendors, and KYC verification providers.
  • Financial Institutions & Card Networks: Visa/Mastercard networks, intermediary banks, and clearing systems to execute transactions.
  • Governmental Authorities: Tax authorities, central banks, law enforcement, and judicial bodies when required by law.
  • Open Banking Partners: Third-party providers authorized by you to access account information.
7. International Data Transfers
When we transfer personal data outside the European Economic Area (EEA), we ensure adequate protection standards are in place through:
  • European Commission Adequacy Decisions.
  • Standard Contractual Clauses (SCCs) approved by the European Commission.
8. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected.
  • Regulatory Data: Transaction history and KYC/identification data are stored for at least 5 to 7 years after account closure to comply with statutory AML/KYC laws.
  • Marketing & Analytics Data: Retained until you withdraw consent or object to processing.
9. Your Legal Rights
Under the GDPR, you have the following rights:
  • Right of Access: Request a copy of the personal data we hold about you.
  • Right to Rectification: Request correction of inaccurate or incomplete data.
  • Right to Erasure ("Right to be Forgotten"): Request deletion of data, provided retention is not required by law.
  • Right to Restrict Processing: Request limited processing under specific circumstances.
  • Right to Data Portability: Receive your personal data in a structured, machine-readable format.
  • Right to Object: Object to processing based on legitimate interests or direct marketing.
  • Right to Withdraw Consent: Withdraw consent at any time without affecting prior lawful processing.
10. Managing Your Preferences & Consents
You can manage permissions and privacy settings directly inside the NEOP App:
  • Enable or disable location services.
  • Toggle marketing notifications and promotional communications.
  • Manage biometric authentication settings.
  • Revoke connected Open Banking integrations.
11. Updates to This Policy
We may update this Privacy Statement periodically to reflect changes in our services or legal requirements. We will notify you of material changes via the NEOP App or by email prior to the changes taking effect.
12. Contact & Complaints
If you have questions, concerns, or wish to exercise your legal rights, please contact our Data Protection Officer:
  • Email: support@neopbank.com
If you are unsatisfied with our response, you have the right to lodge a complaint with your local Data Protection Authority (e.g., Autoriteit Persoonsgegevens in the Netherlands).