• Solutions
  • Platform
  • Compliance
  • Company
Talk to our team

LEGAL

Privacy & Cookies Policy

This Policy explains how BOREAN SERVICES FZCO collects, uses, stores and protects personal information, and how cookies and similar technologies are used across the BORQR website and platform.

Document Code

BORQR-LEGAL-PRIVACY-COOKIE

Version

1.1

Effective Date

27 July 2026

Last Updated

13 August 2026

Applicable Entity

BOREAN SERVICES FZCO

Jurisdiction

Dubai, United Arab Emirates

Table of Contents
1. Scope and Data Controller2. Information We Collect3. How We Use Information4. Legal Grounds for Processing5. Cookies and Similar Technologies6. Technologies We Use7. Geolocation and Local Analytics8. Cookie Consent and Your Choices9. Sharing and Service Providers10. International Data Transfers11. Data Retention and Security12. Your Privacy Rights13. Children and External Services14. Changes and Contact InformationVersion History

1. Scope and Data Controller

This Privacy & Cookies Policy explains how BOREAN SERVICES FZCO collects, uses, discloses, stores and protects personal information when a person visits or interacts with:

•the BORQR website;
•contact and onboarding forms;
•the BORQR platform;
•APIs, dashboards and developer tools;
•customer and partner communications; and
•other services where this Policy is referenced.

BOREAN SERVICES FZCO is the primary data controller for the processing described in this Policy, unless another entity is identified as the controller for a specific Service.

BORQR operates as a technology and operational interface for partner-enabled payment workflows. Where payment execution or another regulated financial service is performed by an independent bank, financial institution or payment service provider, that entity may process relevant personal and Transaction information under its own legal and regulatory responsibilities and may act as an independent data controller.

Company details:

BOREAN SERVICES FZCO

Registration Number

DMCC204977

Commercial Licence No.

DMCC-1030436

Commercial activity

Payment Services Provider

Registered Office

Unit 4501-010-D59
Mazaya Business Avenue BB2
Jumeirah Lakes Towers
Dubai, United Arab Emirates

Website

https://borqr.com

Privacy Contact

legal@borqr.com

This Policy applies to business contacts, website visitors, authorised customer users, prospective customers, partners, suppliers and other individuals whose information is processed in connection with BORQR.

2. Information We Collect

Depending on how a person interacts with BORQR, we may collect the following information.

2.1 Information provided directly

This may include:

•full name;
•job title;
•company name;
•business email address;
•business telephone number;
•country of incorporation or operation;
•company website;
•business activity;
•requested Services;
•expected markets, currencies and transaction volumes;
•information contained in messages, enquiries or complaints;
•onboarding and compliance information;
•identification and authorisation information; and
•documents voluntarily submitted to the Company.

Users must not submit passwords, full payment card details, online banking credentials or unnecessary identity documents through the public website contact form.

2.2 Technical and device information

When a person visits the website or Platform, we may automatically collect:

•IP address;
•browser type and version;
•device type;
•operating system;
•screen and language settings;
•referring website or source;
•pages viewed;
•links and buttons used;
•date and time of access;
•session duration;
•error and performance information;
•network and security information;
•Cloudflare Ray ID and related request information; and
•cookie, local storage and similar identifiers.

2.3 Approximate geolocation information

We may determine an approximate country, region, city or time zone using:

•IP address;
•browser language;
•device and system settings;
•network information; and
•first-party geolocation and routing systems.

This information may be used to localise content, apply security controls, identify unusual access patterns and understand the geographic distribution of website traffic.

We do not use the public website to collect precise GPS coordinates unless a user separately enables a feature requiring precise location and grants the required browser or device permission.

2.4 Information received from Service Providers

We may receive information from:

•KereX Technologies L.L.C-FZ;
•banking and payment partners;
•identity verification and compliance providers;
•Cloudflare;
•Google Analytics;
•cybersecurity and fraud-prevention providers;
•professional advisers; and
•publicly available corporate and regulatory sources.

3. How We Use Information

We may use personal and technical information to:

•operate and secure the website and Platform;
•respond to enquiries and requests;
•assess business and partnership opportunities;
•perform customer and partner onboarding;
•verify companies, beneficial owners and authorised representatives;
•provide payment-connectivity, technical, integration and operational-coordination Services;
•maintain APIs and integrations;
•process Transaction data, transmit relevant payment instructions and status information, and support transaction monitoring and operational controls in coordination with relevant Service Partners;
•detect fraud, abuse, bots and cyber threats;
•apply sanctions, compliance and risk controls;
•personalise language, region and website content;
•measure website use and performance;
•understand how visitors navigate the website;
•diagnose technical issues;
•maintain business, compliance and security records;
•communicate service, legal or policy updates;
•establish, exercise or defend legal claims; and
•comply with applicable laws, court orders and regulatory requirements.

We do not sell personal information.

We do not use website analytics data to make automated decisions that produce legal or similarly significant effects for website visitors.

4. Legal Grounds for Processing

Depending on the context and applicable law, the Company may process personal information where:

•the individual has provided valid consent;
•processing is required to take steps requested before entering into a contract;
•processing is required to perform a contract;
•processing is required to comply with a legal or regulatory obligation;
•processing is necessary to protect the Platform, users or other persons;
•processing is necessary to establish, exercise or defend legal claims;
•processing is necessary for fraud prevention, information security or risk management;
•processing is permitted for legitimate business purposes under applicable law; or
•another lawful ground applies.

Strictly necessary technologies may be used for security, network management, consent storage and requested website functions.

Analytics, performance and optional functional technologies are used only where the required consent has been obtained.

A person may withdraw consent at any time through Cookie Settings or by contacting the Company.

Withdrawal does not affect processing lawfully carried out before consent was withdrawn.

5. Cookies and Similar Technologies

Cookies are small text files stored on a browser or device when a website is visited.

The Company may also use:

•local storage;
•session storage;
•scripts;
•tags;
•server logs;
•device and browser identifiers; and
•first-party analytics or geolocation identifiers.

Cookies may be:

•first-party cookies set by BORQR;
•third-party cookies set by an external provider;
•session cookies deleted when the browser closes; or
•persistent cookies retained until they expire or are deleted.

5.1 Strictly necessary technologies

These technologies may be required for:

•website and Platform security;
•bot and abuse prevention;
•network routing;
•session management;
•fraud prevention;
•availability and performance;
•storing cookie preferences; and
•delivering functions requested by the user.

Strictly necessary technologies cannot be disabled through the BORQR cookie preference tool.

5.2 Analytics and performance technologies

These technologies help BORQR understand:

•visitor numbers;
•website traffic sources;
•pages viewed;
•session activity;
•navigation patterns;
•technical performance; and
•errors or failed interactions.

Google Analytics and optional first-party analytics must not be activated before the required consent is received.

5.3 Functional technologies

These technologies may remember:

•language;
•selected country or region;
•display preferences;
•cookie choices; and
•other user preferences.

Where a functional technology is not strictly necessary, it will be controlled through Cookie Settings.

5.4 Advertising technologies

BORQR does not currently use advertising or behavioural targeting cookies on the public website.

If advertising technologies are introduced, this Policy and Cookie Settings will be updated before they are activated.

6. Technologies We Use

Provider or TechnologyCategoryPurposeInformation UsedTypical DurationConsent
CloudflareStrictly necessaryWebsite security, traffic management, bot detection, challenge verification and protection against malicious requests.IP address, request headers, browser and device information, security signals and Cloudflare identifiers.Session or short-term, depending on the security feature.Not required where strictly necessary.
Cloudflare __cf_bmStrictly necessaryDistinguishes legitimate traffic from automated or malicious traffic where Cloudflare bot protection is enabled.Encrypted bot-management and session signals.Approximately 30 minutes after inactivity.Not required where strictly necessary.
Cloudflare cf_clearanceStrictly necessaryRecords that a Cloudflare security challenge has been successfully completed.Challenge and security verification state.Based on the configured security challenge period.Not required where strictly necessary.
Google AnalyticsAnalytics and performanceMeasures website use, traffic, navigation, engagement and technical performance.Cookie identifiers, device and browser information, website activity, approximate location and referral information.Depending on the analytics configuration and cookie used.Required before analytics storage is enabled where applicable.
Google Analytics _gaAnalytics and performanceDistinguishes browsers and measures website usage.Randomly generated browser identifier and website interaction data.Up to 2 years, subject to configuration.Required where applicable.
Google Analytics _ga_<container-id>Analytics and performanceMaintains and measures session activity for a Google Analytics property.Session and website interaction information.Up to 2 years, subject to configuration.Required where applicable.
BORQR local analyticsAnalytics and performanceMeasures website and Platform usage using first-party systems.Pages viewed, events, browser information, approximate location, session identifiers and performance information.Session or up to 12 months, depending on configuration.Required where the technology is not strictly necessary.
BORQR geolocation and regional settingsFunctional or strictly necessary, depending on purpose.Determines or remembers an approximate country, region, time zone or language for localisation, security and routing.IP-derived location, browser language, network information and selected regional preferences.Session or up to 12 months where a preference is stored.Required where the technology is optional and stores a non-essential identifier.
Cookie consent preferenceStrictly necessaryStores the visitor’s cookie choices so they do not need to be requested on every visit.Consent categories, date, version and preference identifier.Up to 12 months.Not required because it records the user’s privacy choices.

The exact names and duration of cookies may vary depending on browser, device, Cloudflare security configuration, Google Analytics configuration and updates to the BORQR Platform. The current options available to a visitor are displayed in Cookie Settings.

7. Geolocation and Local Analytics

BORQR uses first-party systems to collect and analyse approximate geographic and website usage information.

These systems may process:

•IP-derived country, region or city;
•browser language;
•time zone;
•network and device type;
•page views;
•navigation events;
•referral source;
•technical performance;
•session information; and
•fraud and security indicators.

Approximate geolocation may be used without storing a long-term identifier where it is necessary for security, fraud prevention, network routing or delivery of a requested regional experience.

Where geolocation or local analytics uses a non-essential cookie, local-storage value or persistent identifier, it will be activated only in accordance with the visitor’s cookie preferences.

BORQR does not use approximate website geolocation to determine a person’s precise home or business address.

BORQR does not request precise device location through the browser unless the relevant feature clearly explains why location is needed and requests separate permission.

8. Cookie Consent and Your Choices

When a visitor first accesses the website, BORQR displays a cookie banner with the following options:

•Accept all;
•Reject non-essential; and
•Manage preferences.

The buttons should be clear and reasonably equal in prominence.

Before a visitor provides consent:

•strictly necessary technologies may operate;
•Google Analytics analytics storage remains denied;
•optional first-party analytics remains inactive;
•advertising storage remains denied; and
•no non-essential persistent identifiers are stored.

A visitor may change or withdraw cookie consent at any time through the Cookie Settings link in the website footer.

Cookie Settings should allow separate control of:

•strictly necessary technologies;
•analytics and performance technologies; and
•optional functional technologies.

Strictly necessary technologies remain active because the website may not function securely or correctly without them.

Visitors may also control cookies through browser settings. Blocking all cookies may prevent some website or Platform functions from working correctly.

Deleting cookies may also delete saved cookie preferences, in which case the cookie banner may be displayed again.

BORQR does not currently treat browser Do Not Track signals as a replacement for Cookie Settings because there is no single consistently implemented technical standard.

9. Sharing and Service Providers

The Company may share relevant information with:

•KereX Technologies L.L.C-FZ, as technology provider for the Platform and integrations;
•Banking Partners and payment institutions where required to provide a requested Service;
•Google, for Google Analytics;
•Cloudflare, for security, performance and network services;
•identity verification, sanctions-screening and fraud-prevention providers;
•cloud-hosting, software, communication and cybersecurity providers;
•auditors, lawyers, accountants and professional advisers;
•insurers and financial counterparties;
•regulators, courts, law-enforcement bodies and public authorities; and
•another company involved in a merger, acquisition, financing, restructuring or transfer of business.

Service Providers may process information only for agreed purposes, subject to applicable contracts, confidentiality duties and legal requirements.

The Company does not sell or rent personal information to third parties.

Where an independent financial institution provides a separate service, that institution may act as an independent data controller and apply its own privacy notice.

Such financial institutions may receive and process information required to execute payments, receive or transfer funds, perform settlement, conduct customer or transaction due diligence, comply with sanctions requirements and meet other regulatory obligations applicable to the services they provide.

10. International Data Transfers

The Company and its Service Providers may process or store information in the United Arab Emirates and other countries.

Google, Cloudflare, KereX Technologies and other providers may operate infrastructure or personnel outside the country where the visitor is located.

Where personal information is transferred internationally, the Company will apply safeguards required under applicable law. These may include:

•contractual data-protection obligations;
•data-processing agreements;
•confidentiality requirements;
•security assessments;
•approved contractual clauses;
•access controls;
•encryption; and
•transfers to jurisdictions recognised as providing an adequate level of protection.

International transfers may also take place where:

•necessary to perform a contract;
•required to provide a requested Service;
•required to establish or defend legal claims;
•required by applicable law; or
•valid consent or another lawful basis applies.

11. Data Retention and Security

The Company retains information only for as long as reasonably required for the purposes described in this Policy, including legal, compliance, security, operational and dispute-resolution requirements.

Indicative retention periods may include:

•cookie consent preferences: up to 12 months;
•optional regional or functional preferences: up to 12 months;
•Google Analytics cookies: up to 2 years, subject to configuration;
•Google Analytics event-level data: up to 14 months, unless a shorter period is configured;
•security and access logs: generally up to 12 months, unless required for an investigation;
•business enquiries and related communications: up to 5 years after the last meaningful interaction;
•customer, Transaction and compliance records: for the period required by applicable law, regulation or contractual obligations; and
•complaint and legal records: for as long as required to resolve the matter and protect legal rights.

Information may be retained for longer where required by law, a competent authority, litigation hold, investigation or legitimate legal claim.

The Company applies reasonable technical and organisational safeguards, which may include:

•encryption in transit;
•access controls;
•authentication;
•system logging;
•security monitoring;
•role-based permissions;
•backup and recovery controls;
•vendor-risk management;
•incident-response procedures; and
•staff confidentiality requirements.

No website, system or transmission method can be guaranteed as completely secure.

Where required by applicable law, the Company will notify the relevant authority or affected individuals of a qualifying personal-data breach.

12. Your Privacy Rights

Subject to applicable law and relevant exceptions, an individual may have the right to:

•request information about personal data processed by the Company;
•request access to personal data;
•request correction of inaccurate or incomplete information;
•request deletion of personal data;
•request restriction or suspension of processing;
•withdraw consent;
•object to certain processing;
•request transfer of personal data in an appropriate format;
•object to decisions based solely on automated processing where applicable; and
•submit a complaint to a competent data-protection authority.

Requests may be sent to:

legal@borqr.com

A request should include sufficient information to identify the requester and understand the requested action.

The Company may request additional information to verify identity and authority before responding.

Certain information may be retained or a request may be refused where processing is required to:

•comply with law or regulation;
•fulfil payment or contractual obligations;
•prevent fraud or protect security;
•maintain legally required records;
•establish, exercise or defend legal claims; or
•protect the rights of another person.

The Company will respond within the period required by applicable law.

13. Children and External Services

The BORQR website and Services are intended for businesses and authorised business representatives.

They are not directed to children.

BORQR does not knowingly use the public website to collect personal information from children.

The website may contain links to external websites or services operated by third parties.

BORQR is not responsible for the privacy, cookie or security practices of an external website. Visitors should review the relevant third-party policies before providing information.

Google Privacy Policy, Cloudflare Privacy Policy, Banking Partners and other independent providers may maintain their own privacy policies.

14. Changes and Contact Information

The Company may update this Policy to reflect changes in:

•law or regulation;
•the website or Platform;
•cookies and analytics tools;
•Service Providers;
•information-security practices; or
•business operations.

The current version, effective date and last updated date will be displayed at the top of this page.

Material changes will be communicated where required by applicable law.

Continued use of the website does not replace consent where fresh consent is legally required for a new category of cookie or processing.

Contact details:

BOREAN SERVICES FZCO

Registered Office

Unit 4501-010-D59
Mazaya Business Avenue BB2
Jumeirah Lakes Towers
Dubai, United Arab Emirates

Privacy, cookie, legal and compliance enquiries

legal@borqr.com

Version History

1.1
VersionEffective DateLast UpdatedSummary
1.027 July 202627 July 2026Initial publication

API infrastructure for corporate clients.

BOREAN SERVICES FZCO
DMCC Registration No. DMCC204977

Navigation

ServicesAPIComplianceCompany

Legal & Contact

Privacy & Cookies PolicyTerms of UseFraud & Security PolicyContact

© 2026 BOREAN SERVICES FZCO

Dubai, United Arab Emirates