LoginRequest Account
// Legal

Privacy Notice

Last updated July 2026
01

Controller

MYRA Bank Ltd. Contact: office@myrabank.com.

02

What we collect

Enquiry data: name, contact details, country of residence, the party who introduced you, and any note you choose to include.

Onboarding data for members: identity and residence documentation, beneficial ownership information, source-of-wealth and source-of-funds evidence, tax residence, and politically-exposed-person and sanctions screening results.

Relationship data: account and transaction records, correspondence, and records of instructions.

Technical data: server logs required to deliver and secure the site.

03

Why we process it, and on what legal basis

To respond to an enquiry and to take steps at your request prior to entering into a contract — Art. 6(1)(b) GDPR.

To perform the client relationship once established — Art. 6(1)(b) GDPR.

To meet MYRA’s anti-money-laundering, counter-terrorist-financing, sanctions, record-keeping and reporting obligations under the law of the Union of the Comoros and the requirements of its correspondent institutions — Art. 6(1)(f) GDPR, MYRA’s legitimate interest in lawful operation and in maintaining its correspondent banking relationships. Art. 6(1)(c) is not relied upon, because obligations arising under the law of a third country do not by themselves constitute a legal obligation for the purposes of that provision.

To secure the site and prevent abuse — Art. 6(1)(f) GDPR.

Where processing rests on legitimate interests, you may object under Art. 21 GDPR; we will then stop unless we can demonstrate compelling grounds or the processing is required for legal claims.

04

Who receives it

Correspondent and settlement institutions, to the extent required to execute a payment — including payer and payee identification data under applicable payment transparency rules.

Identity verification, sanctions screening and adverse media providers.

Auditors, external counsel and professional advisers under confidentiality obligations.

Competent authorities, where MYRA is required to disclose.

We do not sell personal data and do not use it for advertising or cross-site profiling.

05

International transfers

Personal data is processed in the Union of the Comoros. The European Commission has not adopted an adequacy decision for the Union of the Comoros.

Where personal data of persons in the European Economic Area is transferred to MYRA, the transfer is made on the basis of the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914, supported by a transfer impact assessment and, where required, supplementary measures. A copy of the clauses is available on request.

MYRA does not rely on the derogations in Art. 49 GDPR as a basis for regular or repetitive transfers.

06

Retention

Declined enquiries: deleted within 6 months, unless a record is required to evidence why the enquiry was declined.

Client identification, due diligence and transaction records: retained for the statutory period following the end of the relationship.

Server logs: 90 days.

07

Your rights

You have the right to access, rectification, erasure, restriction, data portability and objection (Art. 15–21 GDPR), and the right to withdraw consent at any time without affecting prior processing.

These rights are limited where MYRA is required to retain data for anti-money-laundering purposes, or where disclosure would prejudice the prevention or detection of financial crime.

There is no automated decision-making producing legal effects within the meaning of Art. 22 GDPR.

To exercise a right, contact office@myrabank.com.

08

Complaints

If you are in the European Economic Area, you may lodge a complaint with the supervisory authority of your habitual residence or place of work, or with the authority competent at the seat of our Art. 27 representative.

You may also complain directly to us; see the complaints procedure in our Terms.

09

Cookies

This site sets only cookies strictly necessary to deliver pages. It runs no analytics, no advertising and no cross-site tracking, and therefore does not request consent under Art. 5(3) of Directive 2002/58/EC.

If non-essential technologies are introduced, a consent layer will be presented before they are loaded.