Privacy by Design
Privacy Built Into Global Payments
XICUI is designed to protect sensitive business and personal information throughout the payment lifecycle while maintaining required financial compliance and transaction traceability.
THE XICUI PRIVACY PROMISE
Verify what is required.
Protect what is sensitive.
Share only what is necessary.
XICUI combines financial compliance with privacy-by-design principles to reduce unnecessary exposure of personal and commercial information across global payments.
Core Principle
Compliance without unnecessary exposure.
The platform
knows enough to comply.
The payment network
receives what is legally required.
The counterparty
sees what is operationally necessary.
Privacy Architecture
How XICUI protects your information
Data Minimisation
Collect and display only information reasonably necessary for the payment, compliance and operational purpose. Every data field has a reason.
Counterparty Privacy
Limit unnecessary exposure of personal contact information and internal company information between buyers, suppliers and payment recipients.
Controlled Access
Sensitive information is accessible only to authorised users, systems and compliance personnel based on role and purpose.
Privacy by Design
Privacy controls are built into the platform architecture — not added as an afterthought. Every feature is designed with data minimisation in mind.
Data Retention
Retention periods follow applicable legal and regulatory requirements. Data is not kept indefinitely simply because storage is available.
Regulatory Disclosure
XICUI may disclose information where required by applicable law, regulation, court order or lawful regulatory request. Privacy does not obstruct compliance.
Cross-Border Data Handling
Cross-border payment data is handled in accordance with applicable data protection laws in relevant jurisdictions.
User Rights
Depending on your jurisdiction, you may have rights to access, correct or delete your personal data. Contact us to exercise applicable rights.
Counterparty Privacy
Your payments shouldn't expose your entire business.
A payer should not automatically receive every piece of personal information held about the recipient. A recipient should not automatically receive every piece of personal information held about the payer.
Only information necessary to identify the transaction, complete payment, meet legal requirements, resolve disputes and meet compliance requirements should be displayed.
Without privacy controls
John Smith
Personal mobile number
Home address
Personal email
Passport information
Director date of birth
With XICUI
ABC Manufacturing Ltd.
China
Supplier ID: XC-48291
Invoice #PO-2026-482
Payment Reference
Verified Business ✓
Sensitive verification information remains within XICUI's controlled compliance environment.
Transaction Privacy
Three layers of transaction information
Not all transaction information is equal. XICUI separates transaction data into three access layers based on who needs to see what.
- Business display name
- Transaction amount & currency
- Payment reference
- Invoice reference
- Payment status
- Transaction date
- Business country (where appropriate)
- Internal business records
- Supplier profile
- Invoice & purchase order
- Team approval information
- Identity documents
- UBO documents
- Screening results
- Risk assessment
- CDD/EDD information
- Source-of-funds information
- Internal compliance notes
Never exposed to ordinary counterparties.
Platform Architecture
Planned FeatureXICUI Verified Business Identity
Instead of requiring businesses to repeatedly expose sensitive documents to every counterparty, XICUI is designing a verified business identity layer. Once a business completes KYB verification, counterparties see a verified identity — not the underlying documents.
Business
Completes KYB verification
XICUI KYB
Identity & document verification
XICUI Verified Business ID
Issued to verified business
Counterparty sees
Verified Business · Legal Name · Country · Reference
FAQ
Payment privacy questions
Does XICUI offer anonymous payments?
No. XICUI performs identity and business verification as required by applicable regulations. Privacy protection means limiting unnecessary disclosure of personal and commercial information — not bypassing financial compliance.
What information does my supplier see?
XICUI aims to display only information necessary for payment identification, settlement and applicable legal requirements. Exact information may vary by payment corridor and payment partner.
Can my customer see my identity documents?
Identity and business verification documents are maintained within restricted compliance processes and are not ordinarily shared with counterparties unless required for a legitimate legal or operational purpose.
Does XICUI share customer information with regulators?
XICUI may disclose information where required by applicable law, regulation, court order or lawful regulatory request.
Can XICUI hide my identity from regulators?
No. Privacy controls must never obstruct AML, sanctions screening, lawful regulatory requests, fraud investigations, court orders or legal reporting obligations.
What is Counterparty Privacy?
Counterparty Privacy means a payer should not automatically receive every piece of personal information held about the recipient, and vice versa. Only information necessary to identify the transaction, complete payment, meet legal requirements, resolve disputes and meet compliance requirements should be displayed.
Global payments with business privacy built in.
Share less. Pay securely. Stay compliant.