BopenOpen Banking
  • Home
  • For Merchants
  • For Payers
  • Platform Operators
  • Contact
Get in touch →

Open Banking Privacy Policy

Effective Date: August 13, 2026

Provider: Bellator Tech Ltd ("we", "us", "our")


1. Data Controller Identification

This Privacy Policy applies to the BOpen software and services operated by Bellator Tech Ltd. Bellator Tech Ltd is the Data Controller responsible for your personal data obtained through Open Banking channels in accordance with the UK GDPR and Payment Services Regulations.


2. How We Collect and Use Open Banking Data

We process your financial information exclusively with your explicit consent. Depending on the services enabled, we process data in two capacities:

  • Account Information Services (AIS): Upon your authorization, we retrieve read-only bank data including account names, balances, sort codes, account numbers, and transaction history. This data is used solely to provide financial dashboards, insights, and account aggregation.
  • Payment Initiation Services (PIS): When you request a payment transfer, we transmit payment instructions (payee, amount, reference) directly to your Account Servicing Payment Service Provider (ASPSP/Bank). We do not store or hold your money directly.

3. Legal Basis & Explicit Consent

  • Consent: We only connect to your bank accounts after you grant explicit consent via Strong Customer Authentication (SCA) with your bank.
  • Duration & Renewal: Account information consent remains active for up to 90 days (or as specified by current regulatory frameworks) and can be renewed or revoked at any time.
  • Revocation: You can withdraw your consent instantly inside the BOpen app settings or directly within your bank’s mobile/online banking portal.

4. Data Sharing and Security

  • We do not sell, rent, or trade your Open Banking data to third parties for marketing purposes.
  • All data transfers occur over encrypted channels using TLS 1.3 and mutual TLS (mTLS) compliant with the Open Banking Standard.
  • We never request, store, or see your bank login credentials, passwords, or PINs. Authentication is performed directly on your bank’s infrastructure.

5. Your Data Rights

Under UK GDPR, you retain the right to request access to your data, request rectification of inaccurate details, request deletion of your data ("Right to be Forgotten"), and restrict or object to data processing. To exercise these rights, contact privacy@bopen.tech.


6. Contact Information

  • Company: Bellator Tech Ltd
  • Product: BOpen
  • Privacy enquiries: privacy@bopen.tech
  • Website: https://bopen.tech

bopen

The production-grade open banking platform connecting merchants to UK bank accounts via instant A2A payments.

London, United Kingdom

hello@bopen.tech

Product

  • Home
  • For Merchants
  • For Payers
  • Platform Operators
  • Contact

Compliance

  • FCA regulated open banking PISP
  • Open Banking Limited (OBL) compliant
  • FAPI 1.0 baseline security profile
  • GDPR data processor
  • ISO 20022 payment messaging
Terms of ServicePrivacy Policy© 2026 bopen. All rights reserved.

Built on AWS · UK Open Banking · PSD2 A2A rails