NEXGO TAP Privacy Policy
The Privacy Policy is published on 31st, March, 2023NEXGO TAP is a mobile application with security controls that provides the ability for smartphones to complete transactions by reading contactless payment cards through NFC, and provides the necessary security monitoring and protection during the process. This Privacy Policy applies when you use the NEXGO TAP Application (the “NEXGO TAP”) offered by NEXGO GLOBAL LIMITED and its affiliates (collectively, "NEXGO", "we", "us", and "our" ). We are committed to protecting and respecting your privacy, please carefully read and fully understand the content of each term herein. BY YOUR DOWNLOADING, USING, ACCESSING NEXGO TAP, YOU ARE FULLY AGREEING TO BE BOUND BY THIS PRIVACY POLICY AND EXPERSSLY AUTHORIZE US TO COLLECT, USE, SHARE, PROTECT, MANAGE AND TRANSFER YOUR DATA, UNDER THE TERMS AND CONDITIONS AS STIPULATED HEREIN. IF YOU DO NOT AGREE TO THE TERMS OF THIS PRIVACY POLICY, YOU SHALL DISCONTINUE THE ACCESS TO OR USE OF NEXGO TAP, ITS CONTENT OR RELATED SERVICE FORTHWITH. This Privacy Policy may be updated from time to time, in order to comply with our latest business and usage scenarios and applicable laws. We will send you a timely notice to remind you every time when we update, please read carefully, and make re-authorization, if you do not agree, please stop using NEXGO TAP, your continual use of NEXGO TAP shall be regard as acceptance of our latest Privacy Policy. We will not compromise your rights under this Privacy Policy without your express consent.
-
1. HOW WE COLLECT YOUR PERSONAL DATA
NEXGO TAP is developed solely for commercial use of the payment acquiring companies, we will not collect your information for the purpose of obtaining personal data. However, in order to realize the basic functions of NEXGO TAP, necessary data and information will be collected by us, which may contain your personal data. If you refuse to provide necessary data and information to us, some of the functions may be affected accordingly.
Our collection methods are divided into the following two types: (i) collection from data sharing authorized by a third-party application, in most cases, the application of a payment acquiring company, with direct consent of the data subjects; and (ii) collection during your use of NEXGO TAP.
-
2. PERSONAL DATA WE COLLECT
The overarching data processing/collecting principle and purpose is to diagnose whether there exist any factors of risks during the process of any transaction involved, so as to provide a fundamentally reliable framework for secure transaction. -
2.1 Information Obtained from Authorized Third Parties
We collect the merchant IDs, terminal IDs, and other transaction related information (the transaction related information may be varied in different trading scenarios, common examples are order number, order amount, and order type) from the other third-party payment acquiring institutions with authorization.
Information that we may obtain from the authorized third parties shall have the following features and safeguards:- We collect information that is essential for the proper function of NEXGO TAP and thereby our fundamental business purposes, sometimes from other APP developers;
- Such information is also needed to verify your identity and qualification for using NEXGO TAP and associating services (e.g., to identify whether your identity matches one that is to be served by any of our business partners);
- Such third parties shall certify to us that they have already secured consent from the rightful owners of the above said information.
-
2.2 Information that We Collect from Your Use of NEXGO TAP
- Device Information.Such information concerns OS and version, communication ports, processor, GPU, memory speed, gyroscope, screen size, present power status, memory use, installed apps, developer mode, device system time, device running time, application startup timestamp, and chip architecture, etc
- Log Information.Such information is generated when you use our NEXGO TAP services or access contents associating therewith. In that case, NEXGO TAP will automatically collect some information such as access duration, access times, IP address, event information (e.g., abnormality reporting, error, crash, restart, upgrade), etc.
- Location Information.This information will not be accessed without your express consent. With your authorization, such information will be accessed during the NEXGO TAP running process, which is collected for the sole purpose of transactional security monitoring analysis or parameter transmission among payment institutions. If your region has strict legal and policy restrictions on the delivery of location information, we will not collect this data if it does not affect our business operation. If our business has the need to send (to relevant institutions), please be sure to authorize us to access such information to the extent permissible by applicable laws, otherwise please stop using our related services.
- Payment Information.To facilitate payment function of NEXGO TAP, certain payment information, including primary account number (PAN), expiration date, service code, full track data, card verification code, PINs/PIN blocks, will be transmitted to us. All processing of aforesaid payment information is with proper certification thereof and strictly in compliance with payment card industry standards, such as PCI MPoC Solution standards and EMV, etc., as amended from time to time by the relevant international organizations. We only store payment information in a highly encrypted format, which is further subject to mandatory laws and regulations in the payment industry, for the purposes of creating a secure transaction environment, anti-money-laundering, and other lawful purposes. We adopt a vigorously stringent regime to encrypt any payment information we receive, and will not use for any purposes other than those permitted by laws. Notwithstanding the above, we do not proactively access cardholder’s payment information, and you agree that you shall be solely responsible for ensuring your compliance with all applicable industry standards, laws, and regulations, and assume all risks associating with any breaches thereof, including without limitation any disputes that take place as a result of said breaches between you and the cardholders.
- Information Collected by Third-Party API.To protect your safe use of NEXGO TAP, we use the following service: [Google Play Integrity API] to further check your transaction environment under necessary circumstances, such as during device initialization process, when your device is detected in unsafe state, and any other suspicious circumstances that we deem necessary to intervene. Google Play Integrity API will conduct check on whether your actions and requests are coming from unmodified app binaries, installed by Google Play, or running on a genuine Android device. To realize such functions, Google Play Integrity API needs to collect certain information from you, which may contain your personal data, including but not limited to nonce provided in the request, package name, application version, application signing certificate, a device attestation token generated by Google Play services, and other necessary information. For details, please refer to the terms of Google Play Integrity API ( https://developer.android.com/google/play/integrity/terms). For your knowledge, however, if you do not agree with Google Play Integrity API to collect the aforementioned information, your access to the relevant services may be compromised, which may further affect your normal use of other functions or services. If you agree that Google Play Integrity API collects the aforesaid information from you, you acknowledge that Google shall be the responsible party regarding your information collected thereby.
-
3. APP PERMISSIONS WE REQUEST
Besides personal data we collect as detailed above, we will request various app permissions and app information, based upon the type of device you use. Our request is to ensure the whole transaction process is under proper supervision, and we access your information solely for the purpose of filtering out risky factors to provide a secure transaction environment for you and the cardholders. All information accessed under aforesaid app permissions will be encrypted in compliance with our strict security mechanism, and we will not use any information acquired hereunder for any purposes other than those expressly stated in this Privacy Policy.
The following chart is the app permissions that we need to obtain, and descriptions for how we use them:App permissions How to use Storage Store application security files and add or delete service data during service processing Network Connect to the network to access background services for service processing Location - only collect with your prior consent, during the application running process;
- whether to obtain location data will be adjusted according to the corresponding security policy issued by your country/region;
- in some cases, payment acquiring institutions will request to obtain location data for transaction risk control verification;
- such location data will only be used for transaction security monitoring analysis.
NOTE : If your country/region has strict legal and policy restrictions regulating the location data, we will not collect location data if it does not affect normal service operation; if the service does need to collect location data or it will be unable to process, please be sure to make prior consent according to the laws and regulations, or stop using our services immediately.
NFC Used to read payment cards, and we will maintain exclusive use of NFC during payment card reading process, to ensure the security of the transaction environment on your device Battery Obtain battery power statistics for analyzing whether the device is a real device, rather than an emulator, to ensure the security of the transaction environment on your device Camera Prohibit other apps from accessing camera of your device in certain process, to ensure the security of the transaction environment on your device Bluetooth Used to check whether the device has Bluetooth to analyze whether the device is a real device, rather than an emulator, to ensure the security of the transaction environment on your device Recording Prohibit other apps from accessing the recording function in certain process to ensure the security of the transaction environment on your device list of installed apps Obtain the list of applications installed on your device to determine whether there are risky applications which may impair the security of the transaction environment of your device -
4. HOW WE USE YOUR PERSONAL DATA
We collect and store some information about you in order to provide services to you. The information you provide us, and that which we gather based on your activity, helps us to:
- Improve your smoothness of using NEXGO TAP and create a seamless experience for you;
- Ensure the security of your payment environment;
- Improve our loss prevention programs, which includes security protection, prevention and prohibition of illegal activities, risk reduction;
- Process necessary info pursuant to laws and regulations, e.g., supervision authority requests;
- Archive and backup necessary encrypted information pursuant to laws and regulations;
- Comply with the laws, regulations and regulatory requirements of your country/region and ours.
-
5. HOW WE SHARE YOUR PERSONAL DATA
We do not share personal data with other companies, organizations, and individuals unless one of the following circumstances applies:
5.1 Sharing with consent: after obtaining your consent, we may share the information authorized by specified third parties or categories of third parties, which you have lawfully obtained;
5.2 Sharing in compliance with legal obligation and laws and regulations: we may share your information:- as required by laws and regulations for resolving legal disputes;
- as required by administrative or judiciary authorities pursuant to applicable laws and regulations;
- for other reasonable and necessary purposes to implement relevant agreements signed between you and NEXGO or this Privacy Policy; or
- to protect public interest, personal safety and property and other legitimate rights of our clients, ourselves, our subsidiaries, our affiliates, our users, or employees.
5.3 Sharing within NEXGO’s subsidiaries and affiliates: your information may be shared within NEXGO’ s subsidiaries and affiliates only for explicit and legitimate purposes, and the sharing is limited to information necessary required by providing services under this Privacy Policy.
5.4 Sharing with cooperative third-party service provider(s) necessary for providing our services, such third-party service provider(s) are subject to contractual obligations and security precautions no less strict than this Privacy Policy. We discreetly select our service provider(s), and we currently cooperate with the following third-party service providers: Amazon Web Services, Inc. and MYHSM Ltd., who store and process your Personal Data in [Singapore].
-
6. HOW WE PROTECT YOUR PERSONAL DATA
6.1 We attach great importance to the security of your personal data and we have adopted standard industry practices to protect your personal data and prevent it from unauthorized access, disclosure, use, modification, damage, or loss. To this end, we have implemented the following measures:
- We take reasonable and feasible measures to ensure that the personal data collected is minimal and directly relevant to what is necessary in relation to the stated purposes for which they are processed under this Privacy Policy
- We use a range of industry-standard technologies such as cryptographic technologies, identity, credential, and access management measures to ensure the confidentiality of data in transmission. We implement trusted protection mechanisms to protect data from attacks.
- We hold security and privacy protection training courses, tests, and publicity activities to maintain our employees' personal data protection awareness at a high level.
- We have adopted emergency security incident response processes, including data breach notification.
- We select third-party service providers prudently and implement essential security requirement for personal data protection to the business contract between you and us.
Notwithstanding the above, you recognize that no security measure is perfect and no product, service, website, data transfer, computing system, or network connection is absolutely 100% secure. You shall take the initiative to take good care of your sensitive personal data and do not provide such data to anybody without inquiring into associated risks
If any personal data incident occurs, we will timely notify you, pursuant to relevant legal and regulatory requirements, of the basic information about the security incident and its possible impact, measures that we have taken or will take, suggestions about active defense and risk mitigation, and remedial measures. The notification may take the form of an email, text message, push notification, and any other reasonably feasible format in the view of NEXGO. If it is difficult to notify data subjects one by one, we will take appropriate and effective measures to release a security notice. In addition, we will also report the handling status of personal data security incidents as required by supervisory authorities.
-
7. DATA RETENTION
We securely store your information and hold it only for as long as we need to provide our services to you in accordance with (i) applicable law and regulations, or (ii) the time-frame set out in any relevant contract you have with us or our clients.
We will need to retain the minimum amount of information about you so that we can ensure to meet your request and the requirements of applicable laws and regulations. Please note and you acknowledge that if you ask us to completely remove all information about you, and you subsequently use our products and services, we will no longer be able to recognize your previous request.
-
8. HOW YOU CAN MANAGE YOUR PERSONAL DATA
8.1 The personal data we collect is listed in paragraph 2 above. Legislation in some countries and regions to which NEXGO provides services or from where NEXGO processes personal data, has established that data subjects have the right to request (hereinafter referred to as "Requests") access to, rectification of, or erasure of your personal data retained by NEXGO. In addition, data subjects have the right to data portability and to restrict and or object to the processing of your personal data by NEXGO including to withdraw consent where such processing is based on consent.-
Access to Your DataFor data which is generated during your use of services, you may request through the contact information specified in Article 11 of this Privacy Policy, or get in touch with your designed customer manager; this step may require you to provide reasonable verification of your personal identity so that we can determine whether you are eligible for such request. And this verification process is also made pursuant to the safeguards as under this Privacy Policy.
-
Change or Correct Your DataYou have the right to change or correct your data, but there may be very few situations where our services may cause you to use such right, which is determined by the type of information we collect. If it does happen, you may request through the contact information specified in Article 11 of this Privacy Policy, or get in touch with your designed customer manager.
-
Requesting Modes and ChannelsData subjects’ requests shall be submitted in accordance with NEXGO designated customer service email channels in Article 11 “How to Contact us” at the end of this Privacy Policy or your designed customer managers to facilitate feedback of progress and result. The requests are valid even when the requester does not specify the laws on which the requests are based.
-
Validity of RequestsMost laws require data subjects to comply with specific requirements when you initiate requests. This Privacy Policy requires data subjects to:
- submit requests through dedicated channels provided by NEXGO;
- provide sufficient information for NEXGO to verify your identities (to ensure those who initiate the requests are the data subjects yourselves or those authorized by you); and
- ensure that your requests are specific and feasible. THERE ARE SOME CIRCUMSTANCES, PROVIDED BY LAWS AND REGULATIONS, IN WHICH NEXGO MAY NOT HAVE TO COMPLY WITH THE REQUEST IN FULL OR AT ALL.
-
-
8.2 Consent withdrawalYou can change the authorized personal data collection scope or withdraw your consent without affecting the lawfulness of the processing activities based on the consent made prior to such change or withdrawal. You may request to withdraw your consent for specific products and services, following the methods and channels set forth in this Privacy Policy. Our contact information is specified at the end of this Privacy Policy. HOWEVER, THERE ARE SOME CIRCUMSTANCES, PROVIDED BY LAWS AND REGULATIONS, IN WHICH NEXGO MAY NOT HAVE TO COMPLY WITH THE REQUEST IN FULL OR AT ALL. FOR EXAMPLE, THE CONSENTED INFORMATION YOU ARE REQUESTING TO WITHDRAW IS SUBJECT TO COMPULSORY SUPERVISION BY PAYMENT INDUSTRY LAWS AND REGULATIONS.
-
9. INTERNATIONAL TRANSFER
9.1 To offer our services, we may need to transfer personal data that you submit in your jurisdiction to the [secured servers] located in [Singapore]. For limited purpose of processing, providing, and promoting our services, authorized personnel of NEXGO and necessary third-party service providers acting on our behalf may access, use, and process personal data collected from you in a country/region that is different from the country/region where you entered the personal data, which may have less stringent data protection laws. When we transfer your personal data to other countries/regions, we will protect the personal data as described in this Privacy Policy or as otherwise disclosed to you at the time the data is collected (e.g. via privacy notice or supplementary statement of specific service).
9.2 NEXGO strives to implement legally accepted means and privacy practices for processing personal data protected under applicable data protection laws. NEXGO transfers personal data between the jurisdictions as disclosed in this Privacy Policy as well as operate in accordance with the standards and conditions of applicable data protection laws, including standards and conditions related to security and processing.
9.3 With respect to users from the European Union, we only provide services to entities such as enterprises and organizations in line with local laws and regulations. Nevertheless, to continuously improve and expand our global business, NEXGO strives to comply with applicable legal requirements providing adequate safeguards for the transfer of personal data to countries outside of the European Economic Area ("EEA"). We adopt a variety of robust legal mechanisms as envisioned under applicable laws to implement the cross-border transfer of your personal data; or implement security measures before the cross-border data transfer.
-
10. UPDATES
We may update this Privacy Policy from time to time in order to reflect, for example, changes to our practices or other operational, legal, or regulatory reasons. Any changes made thereunder will be reflected in this statement, so you should check here regularly
-
11. HOW TO CONTACT US
If you have any questions, comments, suggestions, or want to exercise your privacy rights, or have any privacy issues for which you need to lodge a privacy complaint, or want to inquire about general data protection, please contact us via Email: sales@xgd.com or liaise with your own NEXGO customer manager.