This statement outlines your rights to your personal information and contains general principles that apply to the handling of your personal information when you use any of SadaPay’s electronic money products or services, website and our mobile application.
SadaPay’s Commitment to Your Privacy
We believe that all of our customers should be able to trust SadaPay with their personal and financial information which is why we apply the following key privacy principles in every country in which we operate:
- We will process your personal information in accordance with this privacy statement and all applicable laws.
- We will do our best to be transparent on how we handle your personal information.
- We will only process your personal information for legitimate purposes, and only for as long as it is necessary to achieve those purposes. We will dispose of your personal information safely and securely once it is no longer required.
- We will enable you to exercise choice and control over our processing of your personal information, not only when we are required to do so by the applicable law, but also in other circumstances where we think it is the right thing to do.
- We will inform you about your privacy rights, respect them and help you to exercise those rights.
- We will make sure that your personal information is safe through appropriate security measures.
- We will take steps to ensure that your personal information is adequately protected.
- We build privacy and data protection into our products and services by design and by default. This means that we prioritise the privacy of your data, and we will endeavour to build privacy safeguards in everything we develop.
What data do we collect
The data we collect and the way we record and store your personal information vary depending on why we collect your information, which in turn depends on which one of our products and services you are using.
Generally, we collect and use your personal information where:
- We must obtain certain information to fulfil our requirements under Pakistan’s Anti-money laundering and counter terrorist legislation;
- The information is necessary for us to provide the financial services you receive from us;
- the information is needed for us to better improve our service and your user experience;
- the information is needed for us to help protect your security;
Information that is necessary for us to allow you access to our services and products
There is certain personal information that is necessary for us to perform services you use. These include:
- Your name, phone number, email address, home address, date of birth, and other information provided when you download our mobile application.
- Payment related information, such as credit or debit card information or other banking and payment information;
Typically, we collect this information:
- When you sign up, buy, or use our products or services;
- When you subscribe to our newsletters or promotions about our products or services;
- When you contact us for information, question or feedback about our product, service or website.
We generally use this information to perform the relevant service or provide the relevant product;
- manage your account;
- carry out credit checks;
- request payments; and
- communicate with you.
Other information that is needed for us to provide and improve our services
During the course of you using our products, services or websites, we may also collect other information from you.
Some examples of such information include:
- Information about your e-wallet account and our communications with you, such as any customer support requests that you make or any feedback that you provide, dates of payments, and date of invoices;
- Product usage data, such as your last active use of an application, the duration you spent on an application and how much you spent on a product;
- Network data, including mobile calls and sms data, such as the date and time of the calls and texts you send or receive, and the duration of calls received and made through our network;
- Your geo-location data, when:
- you use our telecommunications services, such as call, sms or broadband services;
- you choose to use our location-based service. For example, when you enable direction applications on your mobile phone; and
- you signed up to a certain location based promotional activities.
- Your browsing data, when you visit one of our websites and/or use some of our services. Information that we collect may include:
- information relating to your device, such as IP address, device model and settings;
- network information;
- details and logs of when, where and how you used the service;
- browser information such as type and version and browser plug-in; and
- information about your visit, including the websites that directed you to us, the pages on our website that you visited, services and products that you viewed or searched for, length of visit, our interaction with you, and the next websites you visit after our website.
Typically, we use the information above and any other information necessary to:
- perform our services upon requests. For example, where you have requested that we link your digital services with third parties such as social networks, we will collect any information necessary to enable us to link and integrate our services;
- improve customer experience, such as for troubleshooting, network management and network optimisation purposes;
- use the recorded communications information for training quality assurance, feedback or for records purposes;
- find ways in which we can better improve our service, such as using personal and/or aggregated statistics or de-identified information about sales, services, customers, network traffic and location patterns to conduct research to help improve our understanding of your behaviours;
- conduct research that create value for the community
- create customer profiles about you to offer you personalised content, provide a more relevant user experience or products and services, and to ensure that we will not be recommending you products and services that you may not be interested in. We may also use this information to find out whether you enjoy receiving our personalised services;
- analyse use of our network and services to identify general trends and partner with third parties to develop new services for you;
- send you marketing communications about products and services based on your preferences and interests; and/or
- share your information within our affiliate companies, for processing, advertising, service development, cross product marketing and sales, product and service creation, measurement, analytics and research purposes.
Information needed for us to protect your security
We use the information we have to keep our services and communities safe and secure:
- we may investigate or take action regarding suspicious and illegal activities that violate our Terms of Services, or the applicable law; and/or
- share your information, in accordance with applicable law/regulations and/or court orders, with the relevant authorities, for example, to protect you or someone else from harm or damage.
Information you consented to provide to us
We may also collect and process information about you when you consent to us collecting and processing this information.
Information that we collect from other sources
We sometimes collect personal information about you from third parties. Examples of the type of information that we collect are:
- Your credit information, to help us with customer authentication and credit-related decisions;
- If you consented, other information, such as demographic information, to better understand you and your interests and to offer you personalised services. Examples of third parties that we collect the information from include payment and delivery services, advertising networks, analytics providers, search information providers; and
- Social media information, such as your interests, “Likes” and friends list, when you use your social media credentials to interact with the SadaPay mobile application, our webpage or offer.
You can object to any of the processing above by, unless the information was required for us to perform the services.
How we share your information and other responsible entities
We may share your personal information with an affiliate company or third parties for the purposes listed above. Sometimes, the third party with which we share your personal information with may determine the purposes for which and the means by which your personal information is processed, and therefore we shall ensure that the said third party follows the same privacy practices towards your information in accordance with our key privacy principles, this privacy statement and applicable law.
More detailed examples of the third parties we may share your information with include:
- Any of SadaPay’s affiliate companies (including our parent Group);
- Data processors to process your information on our behalf;
- Third party services whom you have asked us to integrate with, such as social networks
- Third /parties who conduct research, analytics or marketing in conjunction with us or on our behalf;
- Relevant third parties whom you consented, or that you requested that we share the information with;
- Prospective business partners, following your consent, if we decide to sell, buy, merge or otherwise re-organize our business;
- Following your consent, third parties that conduct advertising, measurement and analytics;
- Law enforcement agencies, where we are required to provide our cooperation for law enforcement purposes; and
- Third party service providers such as debt collection agencies and credit check agencies.
How we protect your personal information
We ensure that your personal information is safe and secure through the following measures:
- When you log into your account to use our services with your phone number or username and password, all of the data is encrypted using cryptographic protocols such as Transport Layer Security (TLS) and Secure Socket Layer (SSL) encryption. We employ such cryptographic protocols on all pages on our websites where we collect personal information. To make purchases from these web pages, you must use a TLS or SSL-enabled browser such as Internet Explorer, Safari, Firefox, or Chrome. This ensures that your personal information remains confidential and is protected white it is transmitted over the Internet;
- If your username and password to access our services has been inactive for some time, we automatically log you out of the account to keep your details secure;
- When we use service providers or other data processors to process your personal information on our behalf, we ensure that the relevant providers and processors will implement appropriate technical and organisational measures to protect the information. Such controls include access control to the information and the infrastructure that stores the information, contractual arrangement that requires the third parties to comply with all relevant laws, We apply privacy and data protection by design and by default , and build privacy and data protection into the foundation of our products and services;
- We conduct Data Protection/Privacy Impact Assessment where appropriate to measure and reduce the impact of a particular activity to the privacy of your personal information.
How long we keep your personal information for
As mentioned in our 3rd Privacy Principle, we will only process your personal information for legitimate purposes, and only for as long as it is necessary to achieve those purposes. We will dispose of your personal information safely and securely once it is no longer required subject to applicable laws for retention of data.
It is important to us that you understand your privacy rights. Therefore, we have listed out below a non-exclusive list of privacy rights that you could exercise whilst entrusting us with your information:
- Right to withdraw consent: Where you have consented for us to use, process, or share your personal information, you can withdraw that consent any time, unless the information is required for us to perform our services.
- Right to access your information: You can access and request a copy of the personal information that we hold about you any time by contacting us or access the information directly through your e-wallet account.
to erasure: You can request that we erase some of the personal information
we hold about you, provided that certain circumstances apply:
- The information is no longer needed by us and there is no legal requirement on us to retain the information;
- You object to our profiling of your information, also in instances where the profiling is conducted for direct marketing purposes; and
- Other legal grounds which permit you to do so.
- We will do our best in accommodating the request, but please bear in mind that this may result in you being ineligible to receive certain services.
Handling Information for under-18’s
As a general rule, we do not process personal information of children under the age of 18, unless we have the consent from their guardians. If we become aware that we have collected information about children under the age of 18 without consent, we will take steps to inform the guardians, seek consent, and if consent is not obtained, erase the information. Where services are designed for use by children under the age of 18, we will seek the consent of the guardians and inform the guardians of their privacy rights.
Revision of this privacy statement
We commit to reviewing this statement at least once annually, and on an ongoing as needed basis. If there are substantial changes to the statement, we will inform you through ways in which we think fit, which may include a prominent announcement on our homepage, emails, SMS or message to your registered device.
We will consider factors such as materiality of the change, the services affected by the change, and the reach when we choose a method of notification. SadaPay is responsible for the handling of your personal information, and the legal frameworks in which we operate include:
- Pakistan Telecommunication (Re-organisation) Act, 1996
- Prevention of Electronic Crimes Act, 2016
- Investigation for Fair Trial Act, 2013
- Telecommunication Consumer Protection Regulations, 2016
- Protection from SPAM, Unsolicited fraudulent and obnoxious communication Regulations 2009