Privacy, Data Use and Retention Policy
This data privacy, use and retention notice (the “Privacy Notice”) applies to all personal information collection and processing activities carried out by Crydit companies (“Crydit”). Crydit companies include Crydit Inc. (BVI), ArcaneQuantix Ltd (CZ), Crydit Capital Limited (HK), Crydit Venture Investments Aps (DK). Crydit is a data controller in respect of personal information that we process in connection with our business (including the products and services that we provide through the Crydit app). In this notice, references to “we”, “us” or “our” are references to Crydit. Different Crydit companies may control and process your data depending on where you are ordinarily resident. The Crydit company that provides you with access to the Crydit Service and your Crydit Profile, as identified in the Crydit General Terms of Service above ("Crydit", or “we”, “our”, or “us”) is the Crydit company directly responsible for handling your personal data. Our privacy email address for all Crydit companies is [help@crydit.com]. We respect individuals’ rights to privacy and to the protection of personal information. The purpose of this Privacy Notice is to explain how we collect and use personal information in connection with our business. “Personal information” means information about a living individual who can be identified from that information (either by itself or when it is combined with other information). We may update our Privacy Notice from time to time. When we do, we will communicate any changes to you and publish the updated Privacy Notice on our website. We would encourage you to visit our website regularly to stay informed of the purposes for which we process your information and your rights to control how we process it.
We collect and process various categories of personal information at the start of, and for the duration of, your relationship with us. We will limit the collection and processing of information to information necessary to achieve one or more legitimate purposes as identified in this notice. Personal information may include:
A. basic personal information, including name and address, date of birth and contact details;
B. financial information, including account and transactional information and history;
C. goods and services we provide to you;
D. visual images and personal appearance (such as copies of passports or real-time biometric facial scans); and
E. online profile and social media information and activity, based on your interaction with us and our websites and applications, including for example your login information, Internet Protocol (IP) address, smart device information, location coordinates, online and mobile app security authentication, mobile phone network information, searches, site visits and spending patterns; and
F. anonymised personal data from your contact book if you choose to enable the Send Money to Contacts Feature.
We may also process certain special categories of information for specific and limited purposes, such as detecting and preventing financial crime or to make our services accessible to customers. We will only process special categories of information where we’ve obtained your explicit consent or are otherwise lawfully permitted to do so (and then only for the particular purposes and activities set out at Schedule B for which the information is provided). This may include biometric information, relating to the physical, physiological or behavioural characteristics of a person, including, for example, fingerprint or facial recognition or similar technologies to help us prevent fraud and money laundering. Where permitted by law, we may process information about criminal convictions or offences and alleged offences for specific and limited activities and purposes, such as to perform checks to prevent and detect crime and to comply with laws relating to money laundering, fraud, terrorist financing, bribery and corruption, and international sanctions. It may involve investigating and gathering intelligence on suspected financial crimes, fraud and threats and sharing data with taxation, law enforcement and regulatory bodies.
Your information is made up of all the financial and personal information we collect and hold about you/your business and the proprietors, officers and beneficial owners of that business and your transactions. It may include:
A. information you give to us;
B. information that we receive from third parties – including other Crydit companies, third parties who provide services to you or us, credit reference, fraud prevention or government agencies,
C. and other financial institutions (where permitted by law);
D. information that we learn about you through our relationship with you and the way you operate your accounts and/or services, such as the payments made to and from your accounts;
E. information that we gather from the technology which you use to access our services (for example location data from your mobile phone, or an IP address or telephone number) and how you use it (for example pattern recognition). This includes information from the contact book stored on your device, if you enable the Send Money to Contacts Feature; and
F. information that we gather from publicly available sources, such as the press, the electoral register, company registers and online search engines.
We want to make sure you are aware of your rights in relation to the personal information we process about you. We have described those rights and the circumstances in which they apply in the table at Schedule A. If you wish to exercise any of these rights, if you have any queries about how we use your personal information that are not answered here, or if you wish to complain to our Data Protection team, please contact us at [help@crydit.com]. Please note that in some cases, if you do not agree to the way we process your information, it may not be possible for us to continue to operate your account and/or provide certain products and services to you through the Crydit app. In the event our relationship with you terminated (for example, you choose to close your Crydit Account), you may request the erasure of your personal data by contacting [help@crydit.com]. Please note that Crydit will only comply with such requests to the extent it is legally obligated to and depending on your account activity until that date, certain personal data may be maintained in accordance with anti-money laundering and counter-terrorist financing legislation to which Crydit is subject.
From time to time we may change the way we use your information. Where we believe you may not reasonably expect such a change we will notify you and will allow a period of at least 30 days for you to raise any objections before the change is made. However, please note that in some cases, if you do not agree to such changes it may not be possible for us to continue to operate your account and/or provide certain products and services to you through the Crydit app.
We will only use and share your information where it is necessary for us to lawfully carry out our business activities. Your information may be shared with and processed by other Crydit companies. We want to ensure that you fully understand how your information may be used. We have described the purposes for which your information may be used in detail in a table in Schedule B – Purposes of Processing.
We will not share your information with anyone outside of the Crydit group except:
A. where we have your permission;
B. where required to provide your product(s) or service(s). This may include sharing your name with other Crydit customers if you are already in the contact book stored on their device or when we are required to do so by the applicable law;
C. where we are required by law and by law enforcement agencies, judicial bodies, government entities, tax authorities or regulatory bodies around the world;
D. with other financial institutions and third parties where required by law to help recover funds that have entered your account as a result of a misdirected payment by such a third party;
E. with third parties providing services to us, such as market analysis and benchmarking, correspondent banking, and agents and sub-contractors acting on our behalf, such as the companies which print our packing labels and provide your currency accounts;
F. with other financial institutions to help trace funds where you are a victim of suspected financial crime and you have agreed for us to do so, or where we suspect funds have entered your account as a result of a financial crime;
G. with debt collection agencies;
H. with credit reference and fraud prevention agencies;
I. with third-party guarantors or other companies that provide you with benefits or services (such as insurance cover) associated with your product or service;
J. where required for a proposed sale, reorganisation, transfer, financial arrangement, asset disposal or other transaction relating to our business and/or assets held by our business;
K. in anonymised form as part of statistics or other aggregated data shared with third parties; or
L. where permitted by law, it is necessary for our legitimate interests or those of a third party, and it is not inconsistent with the purposes listed above.
If you ask us to, we will share information with any third party that provides you with account information or payment services. If you ask a third-party provider to provide you with account information or payment services, you’re allowing that third party to access information relating to your account. We are not responsible for any such third party’s use of your account information, which will be governed by their agreement with you and any privacy statement they provide to you. In the event that any additional authorised users are added to your account, we may share information about the use of the account by any authorised user with all other authorised users. Crydit will not share your information with third parties for their own marketing purposes without your permission.
We may transfer your information to or your information may be collected directly by organisations in other countries (including other Crydit companies) on the basis that anyone to whom we pass that information or who collects it directly protects it in the same way we would and in accordance with applicable laws. In the event that we transfer information to countries outside of the European Economic Area (which includes countries in the European Union as well as Iceland, Liechtenstein and Norway), we will only do so where:
A. the European Commission has decided that the country or the organisation we are sharing your information with will protect your information adequately;
B. the transfer has been authorised by the relevant data protection authority; and/or
C. we have entered into a contract (deed of adherence) with the organisation with which we are sharing your information (based on the model clauses proposed by the European Commission) to ensure your information is adequately protected.
Upon signing up to, and continued use of Crydit’s services, you agree to hear from us regarding marketing updates and receive targeted marketing materials. We will send you relevant marketing information (including details of other products or services provided by us or other Crydit companies which we believe may be of interest to you) by postal or electronic communication methods, including but not limited to email and SMS. If you change your mind about how you would like us to contact you, or you no longer wish to receive direct marketing material from us, you can simply unsubscribe from:
Our marketing emails. By clicking “unsubscribe” in any emails we have sent.
Our marketing text message. By texting “STOP” in any text messages we have sent.
Our postal marketing material. By contacting us at: [help@crydit.com]
We will contact you with information relevant to the operation and maintenance of your Crydit account (including updated information about how we process your personal information), by a variety of means including via email, text message, and in-app notifications. If at any point in the future you change your contact details you should tell us promptly about those changes. We may monitor or record calls, emails, text messages or other communications in accordance with applicable laws for the purposes outlined in Schedule A – Purposes of Processing.
We may access and use information from fraud prevention agencies when you open your account and periodically to:
A. manage and take decisions about your accounts;
B. prevent criminal activity, fraud and money laundering; and
C. check your identity and verify the accuracy of the information you provide to us;
Application decisions may be taken based solely on automated checks of information, for example from fraud prevention agencies and internal Crydit records. To help us make decisions on verifying your Crydit account, as well as transaction limits on your Crydit account, we look at information you give us when you apply for a Crydit Account; including biometric data such as your photograph and/ or facial scan, information regarding your location, age, nationality and/ or citizenship and other information which enables us to verify your identity and perform a risk assessment for money laundering and fraud prevention purposes. You have rights in relation to the automated decision-making used in the verification process, including a right to attempt account verification again, or contact our Customer Support team if your application is refused. We will also profile your Crydit Account to assign a risk rating for the purposes of fraud and unusual transaction monitoring and unauthorised access prevention. The information we will use to profile you will include your age, bank country of residence and status as a politically exposed person or otherwise. We will continue to collect and monitor information about how you manage your Crydit account including your account balance, payments into your account, the regularity of payments being made, and any default in making payments, while you have a relationship with us. This information may be made available to other organisations (including fraud prevention agencies and other financial institutions) so that they can take decisions about you. If false or inaccurate information is provided and/or fraud is identified or suspected, details will be passed to relevant fraud prevention agencies. Law enforcement agencies and other organisations may access and use this information. We cooperate fully to the extent of our legal obligations in the prevention of fraud, money laundering and counter-terrorism. If we, or a fraud prevention agency, determine that you pose a fraud, money laundering or other criminal risk, we may refuse to provide the services you have requested, or we may stop providing existing services to you. A record of any fraud, money laundering or other criminal risk will be retained by the fraud prevention agencies, and may result in others refusing to provide services, financing or employment to you. Fraud prevention agencies can hold your information for different periods of time, and if you are considered to pose a fraud or money laundering risk, your data can be held for up to six years. When fraud prevention agencies process your information, they do so on the basis that they have a legitimate interest in preventing fraud and money laundering, and to verify your identity, in order to protect their business and to comply with laws that apply to them.
By providing you with products or services, we create records containing your information, such as customer account records and activity and transaction records. Records can be held on a variety of media (physical or electronic) and formats, but they are primarily held electronically. We manage our records to help us to better serve our customers (for example for operational reasons, such as dealing with any queries relating to your account) and to comply with legal and regulatory requirements. Records help us demonstrate that we are meeting our responsibilities and to keep as evidence of our business activities. Retention periods for records are determined based on the type of record, the nature of the activity, product or service, the country in which the relevant Crydit company is located and the applicable local legal or regulatory requirements. We normally keep customer account records for up to six years after your relationship with Crydit ends. Retention periods may be changed from time to time (or waived where deemed low-risk) based on business or legal and regulatory requirements. Where there has been no activity on your Crydit account since it was opened, we may delete your data after a period of 6 months, as you will be deemed an "unactivated user". If there has been any transactional activity on your account, we will maintain your data until you request that we delete it, unless we are obligated to maintain such data to comply with our legal obligations. We may on exception retain your information for longer periods than those stated above, particularly where we need to withhold destruction or disposal based on an order from the courts or an investigation by law enforcement agencies or our regulators. This is intended to make sure that Crydit will be able to produce records as evidence, if they’re needed. If you would like more information about how long we keep your information, please contact us at: [help@crydit.com]
Rights Description
Access – You have a right to get access to the personal information we hold about you. |
If you would like a copy of the personal information we hold about you, please write to: Crydit Inc., Subject Access Requests, by emailing us at [ email]; For more information on how to get access to your information and the documents we need you to submit, please email [help@crydit.com]. You will be required to complete a form outlining your request and will also need to provide proof of your identity (to ensure we are dealing with the account owner). |
Rectification – You have a right to rectification of inaccurate personal information and to update incomplete personal information. |
If you believe that any of the information that we hold about you is inaccurate, you have a right to request that we restrict the processing of that information and to rectify the inaccurate personal information. Please note that if you request us to restrict processing your information, we may have to suspend the operation of your account and/or the products and services we provide to you through the Crydit app. For more information on how to rectify your information and the documents we need you to submit, please email [help@crydit.com]. You will be required to complete a form outlining your request and will also need to provide proof of your identity (to ensure we are dealing with the account owner). |
Erasure – You have a right to request that we delete your personal information. |
You may request that we delete your personal information if you believe that: |
Restriction – You have a right to request us to restrict the processing of your personal information. |
You may request us to restrict processing your personal information if you believe that: |
Portability – You have a right to data portability. |
Where we have requested your permission to process your personal information or you have provided us with information for the purposes of entering into a contract with us, you have a right to receive the personal information you provided to us in a portable format. You may also request us to provide it directly to a third party, if technically feasible. We’re not responsible for any such third party’s use of your account information, which will be governed by their agreement with you and any privacy statement they provide to you. |
Objection – You have a right to object to the processing of your personal information. |
You have a right to object to us processing your personal information (and to request us to restrict processing) for the purposes described in Section C of Schedule B – Purposes of Processing (below), unless we can demonstrate compelling and legitimate grounds for the processing, which may override your own interests, or where we need to process your information to investigate and protect us or others from legal claims. Depending on the circumstances, we may need to restrict or cease processing your personal information altogether or, where requested, delete your information. Please note that if you object to us processing your information, we may have to suspend the operation of your account and/or the products and services we provide to you. |
Marketing – You have a right to object to direct marketing. |
You have a right to object at any time to processing of your personal information for direct marketing purposes, including profiling you for the purposes of direct marketing. |
Withdraw consent – You have a right to withdraw your consent |
Where we rely on your permission to process your personal information, you have a right to withdraw your consent at any time. We will always make it clear where we need your permission to undertake specific processing activities. |
Lodge complaints – You have a right to lodge a complaint with the regulator. |
.If you wish to raise a complaint on how we have handled your personal information, you can contact our Data Protection Officer at [ [help@crydit.com]] who will investigate the matter. |
We will only use and share your information where it is necessary for us to carry out our lawful business activities. Your information may be shared with and processed by Crydit companies. We want to ensure that you fully understand how your information may be used. We have described the purposes for which your information may be used in detail in the table below:
12.1 Contractual Necessity |
|
We may process your information where it is necessary to enter into a contract with you for the provision of our products or services or to perform our obligations under that contract. Please note that if you do not agree to provide us with the requested information, it may not be possible for us to continue to operate your account and/or provide products and services to you. This may include processing to: |
A. assess and process applications for products or services; |
12.2 Legal obligation |
|
When you apply for a product or service (and throughout your relationship with us), we are required by law to collect and process certain personal information about you. Please note that if you do not agree to provide us with the requested information, it may not be possible for us to continue to operate your account and/or provide products and services to you. This may include processing to: |
A. confirm your identity, including using biometric information and facial recognition technology and other identification procedures, for example fingerprint verification; D. share data with police, law enforcement, tax authorities or other government and fraud prevention agencies where we have a legal obligation, including reporting suspicious activity and complying with production and court orders; M. monitor dealings to prevent market abuse. |
12.3 Legitimate Interests of Crydit We may process your information where it is in our legitimate interests to do so as an organisation and without prejudicing your interests or fundamental rights and freedoms. |
|
We may process your information in the day-to-day running of our business, to manage our business and financial affairs and to protect our customers, employees and property. It is in our interests to ensure that our processes and systems operate effectively and that we can continue operating as a business. This may include processing your information to: |
A. monitor, maintain and improve internal business processes, information and data, technology and communications solutions and services; |
It is in our interest as a business to ensure that we provide you with the most appropriate products and services and that we continually develop and improve as an organisation. This may require processing your information to enable us to: |
A. identify new business opportunities and to develop enquiries and leads into applications or proposals for new business and to develop our relationship with you; |
We may perform data analysis, data matching and profiling to support decision-making with regards to the activities mentioned above. It may also involve sharing information with third parties who provide a service to us. It is in our interest as a business to manage our risk and to determine what products and services we can offer and the terms of those products and services. It is also in our interest to protect our business by preventing financial crime. This may include processing your information to: |
A. carry out financial and insurance risk assessments; |
13.BIOMETRIC INFORMATION AUTHORIZATION AND PRIVACY TERMS
To enhance login convenience and security, this application may provide facial recognition and fingerprint recognition features (hereinafter referred to as "biometric login"). When you choose to use biometric login, we will process your biometric information in accordance with the following terms and conditions.
13.1 Collection and Use of Biometric Information
- Before enabling biometric login, your authorization to access the camera (for facial recognition) or fingerprint scanner (for fingerprint recognition) is required.
- Only biometric information necessary for identity verification is collected and will not be used for other purposes.
- Collected biometric information is stored on your device and protected by the device's security system.
13.2 User Authorization
- You authorize the application to use your biometric information for biometric login.
- You can revoke biometric login at any time through the application settings and delete the related biometric information.
- In providing services to you, we need to collect various pieces of information, including personal identity, contact details, occupation and income, transaction records, credit information, internet usage habits, biometric data, mobile device information, and call monitoring recordings, etc., to meet regulatory requirements, enhance service quality, and manage risks.
13.3 Privacy and Security
- We respect and protect user privacy, and will not obtain or disclose your biometric information to third parties from your device.
- Reasonable security measures will be taken to protect the security of biometric information and prevent unauthorized access, disclosure, use, modification, or destruction.
13.4 User Responsibility
- You should ensure the security of your biometric information and not disclose or provide it to others for biometric login use.
- If your biometric information is leaked or likely to be leaked, you should immediately change your login method and notify us.
13.5 Changes and Updates
- We reserve the right to update these terms from time to time to reflect changes in services or legal requirements. Changes will be published through this application or the official website.
13.6 Data Processing and Sharing
- Without your explicit consent, we will not use your biometric information for any data processing or sharing other than biometric login.
- Within the scope allowed by law, we may need to share some of your information if required by judicial or administrative authorities.
13.7 Right to Know and Choose
- You have the right to know how we collect, use, and protect your biometric information, and you may choose not to use the biometric login feature.
By using the biometric login feature, you confirm that you have read, understood, and agreed to all the above terms. If you do not agree with these terms, please do not enable the biometric login feature.