Privacy Policy
This Privacy Policy (the “Policy”) set out below governs how we collect, process, retain, share and/or transfer your Personal Data, when you use our Services or Sites. We have designed this Policy to help you understand our approach to privacy and keep you informed on your choices about the collection and use of your information.
Data Controller
Any information (including personal data) submitted to us by Users, are handled by us and will be transmitted to us.
1. DATA PROTECTION PRINCIPLES
We are committed to protecting your privacy and we strive to ensure that all personal information we hold about you is:
- Used lawfully, fairly and transparently.
- Collected only for valid purposes that we have clearly explained to you and not used in any way that is incompatible with those purposes.
- Relevant to the purposes we have told you about and limited only to those purposes.
- Accurate and kept up to date.
- Kept only for as long as necessary for the purposes we have told you about.
- Kept securely.
2. WHY DO WE COLLECT PERSONAL DATA?
We collect, process and retain your personal data for the least amount of time necessary to:
- Allow for the provision of NETinfoPAY services you use
- Where it is necessary for our legitimate interests (or those of a third party) and your interests and fundamental rights do not override those interests.
- Where we need to comply with a regulatory or legal obligation.
Note that we may process your personal data for more than one lawful purpose. Please contact us if you need details about the specific legal purposes pursuant to which we process your personal data.
3. WHAT INFORMATION DO WE COLLECT?
PERSONAL DATA COLLECTED | LAWFUL BASIS OF PROCESSING | RETENTION PERIOD |
Registration, Identity Verification & Security Data |
Contractual Obligation Legitimate Interests Legal Obligation |
5 years |
This is information you submit to us by filling forms in the app, our website, or any other available channel we may make available. It also includes information you provide to us for the purpose of securing your payment instrument and verifying your identity.
The information you submit to us may include your full name, date of birth, address, phone number, e-email address, ID/Passport number, username, PIN, password, other security credentials and any other relevant information we may require, including, but not limited to, copies of your identification documents.
PERSONAL DATA COLLECTED | LAWFUL BASIS OF PROCESSING | RETENTION PERIOD |
Transaction & Service Data | Contractual Obligation Legitimate Interests Legal Obligation |
5 years |
This is information we collect and process as part of offering and fulfilling NETinfoPAY Services. Such information may include data related to transactions such as transaction amounts, date/time, descriptions, beneficiary details, sender details, , financial details of your bank account including the bank account number, IBAN, bank sort code and/or any other data required to facilitate NETinfoPAY services you make use of.
PERSONAL DATA COLLECTED | LAWFUL BASIS OF PROCESSING | RETENTION PERIOD |
Device Data | Contractual Obligation Legitimate Interests Legal Obligation |
5 years |
Device data such as the internet protocol (IP) address used to connect your computer to the Internet, your login information, browser type and version, time zone setting, operating system and platform, device information and the type of mobile device you use, location data, correspondence data and any other data required to facilitate the services you make use of.
4. HOW IS MY PERSONAL DATA USED?
We will only process your personal data for lawful purposes including, but not limited to:
- Verifying and/or updating your identification information
- Implementing measures for the purpose of preventing fraud, money laundering, terrorist financing, limiting our credit risk and/or any other risk we may be exposed to by your use of our services
- Communicating with you about your Account, Services, NETinfoPAY, or our Sites
- Authenticating your access to your e-money account and/or any other NETinfoPAY Service
- Performing the contractual obligations that arise from any NETinfoPAY Services you use including, but not limited to:
- e-money payments e-money transfers
- e-money top-ups
- e-money redemption
- location based services (e.g. showing you nearby agents or merchants)
- earning and redeeming loyalty points
- payment initiation services
- account information services
- Notifying you about changes to our terms and/or services
- Displaying which of your contacts are also NETinfoPAY users
- Improving the security and ease-of-use of our online portal as well as our app user experience
- Analysing, monitoring and improving the performance and functionality of the services we offer
- Complying with our regulatory obligations
DATA RETENTION: How long will you retain my personal data for?
We will only retain your personal data for as long as reasonably necessary to fulfill the purposes we collected it for, including for the purpose of satisfying any legal, regulatory, tax, accounting or reporting requirements. We may retain your personal data for a longer period in the event of a complaint or if we reasonably believe there is a prospect of litigation in respect to our relationship with you.
To determine the appropriate retention period for personal data, we consider the amount, nature and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal, regulatory, tax, accounting or other requirements.
5. MARKETING
We do not use your personal data for marketing or advertising purposes.
6. CHANGE OF PURPOSE
We will only use your personal data for the purposes for which we have collected it, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose. If you wish to get an explanation as to how the processing for the new purpose is compatible with the original purpose, please contact us.
If we need to use your personal data for an unrelated purpose, we will notify you and we will explain the legal basis which allows us to do so.
Please note that we may process your personal data without your knowledge or consent, in compliance with the above rules, where this is required or permitted by law.
7. DISCLOSURES OF YOUR PERSONAL DATA
We may share your personal information with other entities in our group such as NETinfo PLC. Also, we might share your personal data where companies of the group are acting as Data Processors in relation to your personal data. Please contact us in case you wish to find out more on 3rd parties involved in the process of collection and use of your data.
8. INTERNATIONAL TRANSFERS
We take care so as not to transfer any of your data outside the European Economic Area. In case we do transfer your data outside of the EEA, we ensure a similar degree of protection is afforded to it by ensuring at least that we use specific contracts approved by the European Commission which give personal data the same protection it has in Europe.
Please contact us if you want further information on the specific mechanism used by us when transferring your personal data out of the EEA.
9. DATA SECURITY
We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. In addition, we limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal data on our instructions and they are subject to a duty of confidentiality.
We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.
10. CHANGES TO THE POLICY
We reserve the right, at our discretion, to make changes to any part of this Policy. Should this Policy be amended, we will publish details of the amendments on the Website.
11. SEVERABILITY
If this Policy or any part of it should be determined to be illegal, invalid or otherwise unenforceable under the laws of any country in which this Policy is intended to be effective, then to the extent that it is determined to be illegal, invalid or unenforceable, it shall in that country be treated as severed and deleted from this Policy and the remaining terms of this Policy shall survive and remain in full force and effect and continue to be binding and enforceable in that country.
12. EVENTS BEYOND OUR CONTROL
We are not responsible for any breach of this Policy caused by circumstances beyond its reasonable control.
13. YOUR RIGHTS
If you submit or have already provided us with personal data about you, then you have the following rights under this Policy and the relevant legislation on the protection on personal data. You may at any time send us any of the following requests:
- A request for us to permanently delete all, or some of your personal data from our records.
- A request for you to access your personal data that are in our records.
- A request for us to provide you with a copy of your personal data that are in our records, in digital or hard copy form.
- A request for us to update or correct your personal data that are in our records.
- A request for us to forward to another party of your choosing, a copy of all or some of your personal data that are in our records.
- A request for us to limit what we do with your personal data or to stop all processing of your personal data.
If you wish to exercise any of the above rights or if you wish to notify us of a breach of your personal data, you will be able to do so by contacting us at any of the following:
Address: Kyriakou Matsi 16, Eagle House, 8th Floor, 1082, Agioi Omologites, Nicosia, Cyprus.
Tel: +357 22510165
Fax: +357 22318214
Email: [email protected]
You also have a right to lodge a complaint with the supervisory authority. The Office of the Commissioner for the protection of personal data, however we would appreciate the chance to deal with your concerns before you approach the supervisory authority.
At any time after providing your consent, you will have a right to withdraw it by visiting any of our offices or by contacting us electronically or in writing using the above contact details.
14. CONTACTING OUR DPO OR THE OFFICE OF THE COMMISSIONER
Our appointed Data Protection Officer is D. Hadjinestoros & Co LLC who can be contacted at:
Address: Kyriakou Matsi 16, Eagle House, 8th Floor, 1082, Nicosia, Cyprus
Tel: +357 22510165
Fax: +357 22318214
Email: [email protected]
The competent authority in Cyprus for the enforcement of personal data protection legislation is The Office of the Commissioner for the protection of personal data:
Address: Iasonos 1, 1082 Nicosia Cyprus or P.O.Box 23378, 1682 Nicosia Cyprus
Telephone: +357 22818456
Fax: +357 22304565
Email: [email protected]