ALPHAPAY TECHNOLOGY LIMITED
Privacy Policy
Document control | Details |
Policy owner | [PRIVACY OFFICER NAME / TITLE] |
Version | [VERSION] |
Effective date | [EFFECTIVE DATE] |
Approved by / date | [APPROVING BODY] / [APPROVAL DATE] |
Next review date | [NEXT REVIEW DATE] |
Public URL | [PRIVACY NOTICE URL] |
Related documents | Business Money Services Terms and Conditions, clause 8; Complaints Handling and Management Policy, clauses 10.3 and 11.3 |
DRAFT COMPLETION NOTICE: Complete every yellow field and obtain Canadian legal review before approval or publication. Contact details and the public URL must match the Terms and Conditions and Complaints Policy. |
1. About this Privacy Policy
1.1 This Privacy Policy explains how ALPHAPAY TECHNOLOGY LIMITED (“Alphapay”, “we”, “us” and “our”) collects, uses, discloses, stores, protects and retains Personal Information in connection with its websites, applications, platforms, business money services, payment activities and related operations (collectively, the “Services”). Alphapay is incorporated under the laws of [JURISDICTION OF INCORPORATION] under corporation number [CORPORATION NUMBER], with its registered office at [REGISTERED OFFICE ADDRESS].
1.2 “Personal Information” means information about an identifiable individual. It does not include information that has been irreversibly anonymized. Business contact information used solely to communicate with a person about their employment, business or profession may be excluded from some privacy laws, but Alphapay will still handle it responsibly.
1.3 This Policy applies to current, former and prospective Clients; directors, officers, beneficial owners, employees and Authorized Persons of Clients; merchants; payers; beneficiaries; website and application users; complainants; job applicants; business partners; and other individuals whose Personal Information Alphapay handles. Employment privacy may be governed by a separate employee notice.
1.4 This Policy forms the privacy notice referenced in clause 8 of Alphapay’s Business Money Services Terms and Conditions (the “Terms and Conditions”) and must be read with Alphapay’s Complaints Handling and Management Policy (the “Complaints Policy”). Capitalized terms not defined here have the meanings given in the Terms and Conditions.
1.5 This Policy does not treat use of the Services as blanket consent to every practice described here. Alphapay obtains consent in a form appropriate to the sensitivity of the information and the circumstances, unless Applicable Law authorizes or requires collection, use or disclosure without consent.
2. Applicable privacy laws and accountability
2.1 Alphapay handles Personal Information in accordance with the Personal Information Protection and Electronic Documents Act (Canada) (“PIPEDA”) and, where applicable, substantially similar provincial private-sector privacy laws and other privacy, consumer-protection, electronic-commerce and anti-spam laws. The law applicable to a particular activity may depend on the individual’s location, the location of the activity and whether information crosses provincial or national borders.
2.2 Alphapay is accountable for Personal Information under its control, including information transferred to a service provider for processing. Alphapay has designated a Privacy Officer to oversee its privacy management program, policies, training, assessments, access requests, complaints and breach response.
2.3 Questions, requests and privacy complaints may be directed to the Privacy Officer at [PRIVACY OFFICER EMAIL], by telephone at [PRIVACY OFFICER TELEPHONE], or by mail to [REGISTERED OFFICE ADDRESS].
3. Personal Information we collect
Category | Examples |
Identity and contact | Name, date of birth, residential and mailing address, telephone number, email, nationality, country of residence, occupation, government-issued identification details, photograph and signature. |
Business and authority | Employer or business name, title, role, corporate records, directors and officers, ownership and control, beneficial owners, signing authority, Authorized Persons and specimen signatures. |
Financial and transaction | Bank and settlement account details, payment instructions, beneficiary and payer information, transaction history, currencies, amounts, exchange rates, source of funds or wealth, invoices, chargebacks, refunds and related records. |
Compliance and risk | Identity-verification results, third-party determinations, politically exposed person and head-of-international-organization status, sanctions and watchlist results, adverse-media information, fraud indicators, risk ratings and regulatory-reporting information. |
Technical and security | Internet Protocol address, device and browser identifiers, operating system, time zone, approximate location derived from technical signals, authentication events, session data, cookies, application logs, security events and diagnostic information. |
Communications and support | Emails, messages, call recordings where permitted, service requests, survey responses, complaints, investigation records and other communications with Alphapay. |
Preferences and marketing | Language, communication preferences, consent records, event participation, campaign interactions and unsubscribe choices. |
Derived information | Transaction patterns, fraud or compliance alerts, service-usage analytics and risk indicators generated from other information. Alphapay uses such tools to support, not replace, accountable review where human assessment is required by law or appropriate to the impact. |
3.1 Alphapay seeks to collect only Personal Information that is reasonably necessary for identified purposes. The information required in a particular case depends on the Service, transaction, legal obligation and risk. If required information is not provided, Alphapay may be unable to onboard a Client, verify identity, execute an Order, maintain an account or respond to a request.
3.2 Alphapay does not ask users to send account passwords in ordinary communications. Authentication credentials should be created, transmitted and stored only through approved secure systems.
4. How we collect Personal Information
4.1 Alphapay may collect Personal Information directly from an individual through an Application Form, website, application, portal, identity-verification process, transaction, customer-support interaction, complaint, survey, event, telephone call, email or other communication.
4.2 Alphapay may also receive Personal Information from a Client, employer, Authorized Person, payer, beneficiary, merchant, financial institution, payment network, correspondent, acquirer, processor, identity-verification provider, fraud-prevention provider, credit bureau where lawful, public registry, public source, affiliate, regulator, court or law-enforcement body.
4.3 A Client or other organization that provides Personal Information about another individual must have authority to do so, must give any required notices, and must obtain any consent required by Applicable Law. This requirement is consistent with clause 8.2 of the Terms and Conditions.
5. Why we collect, use and disclose Personal Information
5.1 Alphapay may handle Personal Information to: evaluate applications; verify identity, authority, ownership and control; establish and administer accounts; provide the Services; process, route, settle, reconcile, trace, reverse or refund transactions; provide statements and support; authenticate users; and communicate service, transaction and security notices.
5.2 Alphapay may handle Personal Information to prevent, detect and investigate fraud, cybersecurity threats, unauthorized activity, money laundering, terrorist financing, sanctions evasion and other unlawful or prohibited activity; manage credit, operational, compliance and reputational risk; maintain security; enforce agreements; and establish, exercise or defend legal claims.
5.3 As a Canadian money services business, Alphapay may be required to identify clients and related persons, understand the nature and purpose of business relationships and transactions, keep prescribed records, conduct ongoing monitoring and submit confidential reports to FINTRAC or other authorities. Alphapay may be prohibited from telling an individual that a report has been made or considered.
5.4 Alphapay may also use Personal Information to operate, troubleshoot, audit and improve the Services; conduct quality assurance, analytics and product development; train personnel; manage vendors and corporate governance; handle complaints under the Complaints Policy; satisfy tax, accounting, insurance and regulatory obligations; and carry out a proposed or completed financing, merger, acquisition, reorganization or sale where permitted by law.
5.5 Alphapay may send marketing communications where it has the consent or other authority required by Canada’s anti-spam legislation and privacy laws. Each commercial electronic message will include required identification information and an effective unsubscribe mechanism. Service, security and transaction messages are not marketing and may continue where necessary.
6. Consent and other legal authority
6.1 Where consent is required, Alphapay will explain in understandable language what information is being collected, the purposes, the principal disclosures and reasonably foreseeable consequences. Consent may be express or implied depending on the sensitivity of the information and reasonable expectations, but express consent will be used where required or appropriate for sensitive or unexpected practices.
6.2 An individual may withdraw consent at any time on reasonable notice, subject to legal and contractual restrictions. Withdrawal is prospective and does not invalidate prior lawful handling. It may limit or prevent Alphapay from providing the Services. Alphapay may continue to handle information without consent where Applicable Law authorizes or requires it, including for recordkeeping, regulatory reporting, fraud prevention, debt collection, legal proceedings or security.
6.3 Alphapay may collect, use or disclose Personal Information without knowledge or consent only as permitted or required by Applicable Law. Alphapay does not rely on terminology such as “legitimate interests” as a substitute for consent where Canadian law requires consent.
7. When we disclose Personal Information
7.1 Alphapay may disclose or transfer Personal Information to affiliates and service providers that support hosting, cloud services, cybersecurity, communications, identity verification, screening, fraud prevention, analytics, customer support, professional advice, audit, document management and other business operations. Service providers are authorized to use information only for the contracted purposes or as required by law.
7.2 Alphapay may disclose Personal Information to banks, correspondents, payment networks, payment service providers, acquirers, processors, merchants, payers, beneficiaries and other transaction participants where reasonably necessary to execute, settle, trace, reverse, refund or support a transaction or resolve a dispute.
7.3 Alphapay may disclose Personal Information to FINTRAC, sanctions authorities, tax authorities, privacy regulators, the Bank of Canada where applicable, courts, law-enforcement bodies, other regulators or other persons where required or permitted by law, legal process or a lawful request. Alphapay may also disclose information to protect rights, property, safety and the integrity of the Services, subject to Applicable Law.
7.4 In connection with an actual or proposed corporate transaction, Alphapay may disclose Personal Information to prospective purchasers, investors, lenders, advisers and counterparties under appropriate confidentiality and use restrictions, and may transfer relevant information where the transaction is completed, as permitted by law.
7.5 Alphapay does not sell or rent Personal Information for money. Alphapay does not disclose Personal Information to an advertising partner for that partner’s independent marketing unless it has provided appropriate notice and obtained any consent required by law.
8. Cross-border processing
8.1 Alphapay may use affiliates, financial institutions, payment networks and service providers in Canada and other countries. As a result, Personal Information may be stored, accessed or processed outside the province or territory where it was collected and outside Canada.
8.2 Information processed in another jurisdiction may be subject to that jurisdiction’s laws and may be accessible to courts, regulators, law-enforcement or national-security authorities. Canadian law does not require a foreign jurisdiction to be declared “adequate” before a PIPEDA-governed transfer for processing. Alphapay remains accountable for information under its control and uses contractual, due-diligence, security and oversight measures designed to provide a comparable level of protection.
8.3 An individual may contact the Privacy Officer for more information about Alphapay’s use of service providers outside Canada or outside their province, subject to security, confidentiality and legal restrictions.
9. Cookies, analytics and similar technologies
9.1 Alphapay may use cookies, software development kits, pixels, local storage and similar technologies to operate websites and applications, authenticate sessions, remember preferences, prevent fraud, measure performance, understand usage and support marketing where permitted.
9.2 Essential technologies are required for security and core functionality. Where required by law, Alphapay will obtain consent before using non-essential analytics or advertising technologies. Available choices may be managed through [COOKIE PREFERENCES LINK] or browser and device settings. Blocking essential technologies may prevent parts of the Services from working.
9.3 Browser “Do Not Track” signals are not governed by a uniform Canadian standard. Alphapay will honour legally required signals and will describe material changes to its practices in this Policy or its cookie notice.
10. Safeguards and account security
10.1 Alphapay uses administrative, technical and physical safeguards appropriate to the sensitivity, amount, format, location and use of Personal Information. Measures may include role-based access controls, encryption, multi-factor authentication, network and endpoint security, monitoring and logging, secure development, vulnerability management, backups, physical controls, confidentiality obligations, staff training, vendor assessments and incident-response procedures.
10.2 No method of transmission, storage or processing is completely secure. Alphapay does not guarantee absolute security. Individuals should use unique passwords, protect credentials and devices, use available authentication features, sign out of shared devices, verify communications and notify Alphapay promptly of suspected unauthorized access or fraud.
10.3 Before disclosing Personal Information or acting on a privacy request, Alphapay may verify the requester’s identity and authority using information proportionate to the sensitivity of the request.
11. Retention and disposal
11.1 Alphapay retains Personal Information only for as long as reasonably necessary to fulfil identified purposes and satisfy legal, regulatory, contractual, accounting, security, dispute-resolution and enforcement requirements. Retention periods vary by record type, sensitivity, relationship, transaction and legal hold.
11.2 Certain FINTRAC reports, client-identification, transaction, business-relationship and related money-services records generally must be retained for at least five years from the applicable statutory trigger. Complaint records are retained for at least seven years after closure under the Complaints Policy. Records of every breach of security safeguards under PIPEDA are retained for at least two years. A longer period may apply under other law, a regulatory direction, contract, limitation period or legal hold.
11.3 When Personal Information is no longer required, Alphapay will securely destroy it, erase it or irreversibly anonymize it, subject to technical limitations in backups and legal preservation requirements. Backup copies are protected and removed or overwritten through the applicable retention cycle.
12. Individual rights and choices
12.1 Subject to Applicable Law and lawful exceptions, an individual may request access to Personal Information Alphapay holds about them, an explanation of its use and disclosure, and correction of inaccurate or incomplete information. Where another person’s information, legal privilege, confidential commercial information, security or a statutory exception applies, Alphapay may redact or refuse access and will explain the reason where permitted.
12.2 Depending on the applicable province and circumstances, an individual may also have rights to withdraw consent, request deletion or de-indexation, obtain computerized information in a structured and commonly used technological format, receive information about certain automated decisions, or make another request provided by law. These rights are not absolute and do not override mandatory retention, reporting, security, legal-claim or transaction-integrity requirements.
12.3 Requests may be submitted to [PRIVACY OFFICER EMAIL]. Alphapay may require sufficient information to locate records and verify identity and authority. Alphapay will respond within the period required by Applicable Law and will not charge a fee except where the law permits a reasonable fee and the individual receives advance notice.
12.4 Marketing preferences may be changed through the unsubscribe mechanism in a message or by contacting the Privacy Officer. Alphapay will process unsubscribe requests without delay and within the period required by Canada’s anti-spam legislation. An individual may continue to receive non-marketing communications necessary for the Services, security, transactions or legal obligations.
13. Children and minors
13.1 The Services are intended for businesses and authorized adult representatives and are not directed to children. Alphapay does not knowingly open an account for a person under 18 or knowingly collect Personal Information directly from a child in circumstances requiring parental or guardian consent.
13.2 If Alphapay learns that a child’s Personal Information was collected inappropriately, it will take reasonable steps to delete or otherwise address the information, subject to legal retention and fraud-prevention requirements. A parent or guardian may contact the Privacy Officer.
14. Privacy breaches and security incidents
14.1 Alphapay maintains processes to identify, contain, investigate, document and remediate suspected or actual privacy breaches and security incidents. Service providers are required to notify Alphapay of relevant incidents in accordance with their contracts and Applicable Law.
14.2 Where PIPEDA applies, Alphapay will assess the sensitivity of the information and the probability of misuse. If a breach creates a real risk of significant harm, Alphapay will report it to the Office of the Privacy Commissioner of Canada, notify affected individuals as soon as feasible and notify other organizations or government institutions where doing so may reduce or mitigate harm, unless prohibited by law.
14.3 Alphapay will keep a record of every breach of security safeguards involving Personal Information under its control for the legally required period, whether or not the breach is reportable, and will meet any additional provincial notification, recordkeeping or incident-register obligations.
15. Privacy questions and complaints
15.1 An individual should first direct a privacy question, request or complaint to the Privacy Officer at [PRIVACY OFFICER EMAIL]. A privacy complaint may also be submitted through Alphapay’s complaint channels at [COMPLAINTS EMAIL] or [COMPLAINTS WEBPAGE URL]. Alphapay will handle it under the Complaints Policy, including the acknowledgement and response standards applicable to the circumstances.
15.2 Alphapay will investigate a privacy complaint impartially, keep the complainant appropriately informed, provide reasons for its outcome and implement corrective action where warranted. A person will not be penalized for making a complaint in good faith or exercising a privacy right.
15.3 If the matter is not resolved, the individual may contact the Office of the Privacy Commissioner of Canada or the provincial privacy regulator with jurisdiction. Current regulator information is available from the Office of the Privacy Commissioner of Canada’s “Report a concern” service. External regulators determine their own jurisdiction and procedures.
16. Changes to this Policy
16.1 Alphapay may update this Policy to reflect changes in law, technology, risk, products, services or business practices. The updated version will be posted at [PRIVACY NOTICE URL] with a revised effective date.
16.2 For a material change, Alphapay will provide additional notice appropriate to the circumstances and will obtain new consent where Applicable Law requires it. Continued use of the Services does not by itself authorize a materially new use or disclosure where new consent is required.
References
[1] Office of the Privacy Commissioner of Canada, “PIPEDA requirements in brief.”
[2] Office of the Privacy Commissioner of Canada, “What you need to know about mandatory reporting of breaches of security safeguards.”
[3] Office of the Privacy Commissioner of Canada, “Guidelines for processing personal data across borders.”
[4] Office of the Privacy Commissioner of Canada, “Report a concern.”
[5] FINTRAC, “Record keeping requirements for money services businesses and foreign money services businesses.”
[6] Canadian Radio-television and Telecommunications Commission, “Canada’s Anti-Spam Legislation guidance.”
[7] Alphapay Technology Limited, “Business Money Services Terms and Conditions,” clause 8.
[8] Alphapay Technology Limited, “Complaints Handling and Management Policy,” clauses 10.3 and 11.3.