Privacy Policy
Last Updated: February 27th, 2026
This Privacy Policy explains how OneMAI ("we", "us") collects, uses, processes, and protects personal data when you access or use our platform.
OneMAI provides a technology-based coordination platform that enables users to organise structured community savings arrangements.
Important Clarification
- OneMAI does not hold or safeguard user funds.
- OneMAI does not provide regulated financial services.
All financial services are provided by licensed Electronic Money Institutions (EMI Partners) or regulated financial institutions under European Union law.
This Privacy Policy applies solely to data processed by OneMAI in connection with its platform services.
1. Introduction
2. Personal Data We Collect
2.1 Identity & Verification Data
- Full name
- Date of birth
- Government-issued identification (via verification providers)
- Profile information
2.2 Contact Data
- Email address
- Phone number
2.3 Financial & Account Data
- Linked bank or EMI account details (limited to identifiers such as IBAN or account reference)
- Transaction references (not full financial custody data)
2.4 Usage & Platform Activity Data
- Group participation history
- Contribution timing
- Group activity and engagement
- Communication within the platform
2.5 Device & Technical Data
- IP address
- Device type
- Browser type
- Log data
3. How We Use Your Data
3.1 Platform Operation
- Account creation and management
- Group coordination and tracking
- Communication and notifications
3.2 Compliance & Legal Obligations
- KYC/AML verification support
- Fraud detection and prevention
- Regulatory cooperation
3.3 Risk Monitoring & Platform Integrity
Analysis:
- Contribution consistency tracking
- Participation reliability indicators
- Detection of missed obligations
AI-Assisted Monitoring
- Identify potential defaulters
- Detect fraud or suspicious activity
- Analyse unusual contribution or payout patterns
- Flag high-risk group configurations
3.4 Service Improvement
- Platform optimisation
- Feature development
- Performance monitoring
4. Legal Basis for Processing
- Contractual necessity (to provide Platform Services)
- Legal obligation (AML/CFT and regulatory requirements)
- Legitimate interests including fraud prevention, risk management, platform security, and service improvement
- User consent where required
5. Automated Decision-Making & Profiling
OneMAI may use automated systems, including AI-based tools, to assess risk.
- Assigning behavioural reliability indicators
- Detecting potential default risk
- Restricting participation in certain Rotations
- Triggering compliance reviews
These systems are designed to enhance platform safety, reduce financial risk, and prevent fraud and misuse.
Safeguards
- Human oversight is applied where necessary.
- Decisions are not based solely on automated processing where legally restricted.
- Users may request review of decisions affecting them.
6. Data Sharing & Disclosure
6.1 EMI Partners & Financial Institutions
- Payment processing
- AML/CFT compliance
- Transaction monitoring
6.2 Service Providers
- Identity verification providers
- Cloud hosting providers
- Analytics and monitoring services
6.3 Regulatory Authorities
- Financial Intelligence Units (FIUs)
- Law enforcement agencies
- Regulatory bodies
6.4 Risk & Compliance Cooperation
- Investigate fraud
- Comply with legal obligations
- Protect platform integrity
We do not sell personal data.
7. International Data Transfers
Where personal data is transferred outside the European Economic Area (EEA), we ensure appropriate safeguards, including:
- Standard Contractual Clauses (SCCs)
- Adequacy decisions
- Secure processing frameworks
8. Data Retention
We retain personal data only as long as necessary to:
- Provide services
- Comply with legal and regulatory obligations
- Resolve disputes
- Enforce agreements
Retention periods may vary depending on AML requirements, contractual obligations, and regulatory expectations.
9. Data Security
- Encryption of data in transit and at rest
- Role-based access controls
- Secure authentication systems
- Monitoring and logging of platform activity
- Incident detection and response protocols
10. Your Rights
Under GDPR, you have the right to:
- Access your personal data
- Correct inaccurate data
- Request deletion ("right to be forgotten")
- Restrict processing
- Object to processing
- Data portability
- Withdraw consent (where applicable)
To exercise your rights, contact hello@joinonemai.com.
12. Third-Party Services
13. Children's Privacy
14. Changes to This Policy
15. Regulatory Framework
- General Data Protection Regulation (GDPR)
- Applicable EU data protection laws
- Relevant national laws (including Portugal where applicable)