Privacy Policy

Version: 1.0.0

Effective Date: April 14, 2024

Last Updated: April 14, 2024

1. Introduction

BESPOKE TECHNICAL LEADERSHIP LTD ("we," "our," or "us") is committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our LocalPay mobile application and related services (collectively, the "Service").

This Privacy Policy applies to information we collect through our Service, in email, text, and other electronic communications sent through or in connection with our Service.

Important Note About Our Service: The LocalPay Service is provided by BESPOKE TECHNICAL LEADERSHIP LTD, a company registered in the United Kingdom, which acts as the data controller for your personal information. LocalPay is currently in private beta. Access is limited while we onboard verified users and ensure full regulatory compliance.

Please read this Privacy Policy carefully before using our Service. If you do not agree with our policies and practices, please do not use our Service. By using our Service, you acknowledge that you have read and understood this Privacy Policy. Your use of the Service does not constitute consent to the processing of your personal data. We rely primarily on legitimate interest and legal obligations as explained in Section 4. Where consent is required, such as for marketing communications, we will ask for it explicitly.

2. Definitions

To help you better understand this Privacy Policy, we use the following terms:

3. Information We Collect

We adhere to the principle of data minimization and collect only the information necessary to provide our Service. The specific types of information we might collect include:

3.1 Account Information

3.2 Verification Information

Depending on your verification tier, we may collect:

Basic Verification Tier:

Enhanced Verification Tier:

3.3 Transaction Information

3.4 Device and Technical Information

3.5 Communications

We do not collect any Special Category Data unless required by law for specific purposes.

3A. Know Your Customer (KYC) Requirements

To comply with anti-money laundering (AML) and counter-terrorism financing (CTF) regulations, we require users to complete a Know Your Customer (KYC) process. This involves providing a valid government-issued ID, a selfie, and, in some cases, proof of address. KYC verification is carried out by a trusted third-party provider that complies with GDPR and international data protection standards. All personal information is processed securely and only for the purpose of verifying identity and meeting legal obligations.

4. How We Use Your Information

We use the information we collect for specific, explicit, and legitimate purposes, including:

4.1 Service Provision and Account Management

Legal basis: Contract performance (necessary to provide the Service you have requested), legitimate interests (to improve our Service)

4.2 Verification Processes

Legal basis: Contract performance, legitimate interests (to protect our Service and users)

4.3 Security and Fraud Prevention

Legal basis: Legitimate interests (to protect our Service and users)

4.4 Communications

Legal basis: Legitimate interests (to respond to your inquiries and improve our Service), consent (for marketing communications)

4.5 Legal Compliance

Legal basis: Legal obligation, legitimate interests (to enforce our terms and protect our rights)

4.6 Automated Decision-Making

We use automated decision-making in the following circumstances:

These processes are subject to human review by our security team, and you have the right to:

To exercise these rights, please contact us using the details in Section 13.

5. Information Sharing and Disclosure

We share your personal information only in the specific circumstances described below:

5.1 Service Providers

We work with third-party service providers who perform services on our behalf, such as:

These service providers are contractually obligated to use your information only with appropriate confidentiality and security measures.

We might anonymize parts of information such as IP before sharing it with third-party service providers.

5.2 Payment Processors

To process transactions, we share necessary information with:

The specific information shared includes only what is necessary to complete your transactions, such as recipient details, transaction amounts, and payment instructions.

5.3 Legal Requirements

We may disclose your information if required to do so by law or in response to valid requests by public authorities (e.g., a court or government agency). We will only disclose the specific information requested and required by law.

5.4 Business Transfers

If we are involved in a merger, acquisition, or sale of all or a portion of our assets, your information may be transferred as part of that transaction. We will notify you via email and/or a prominent notice on our Service at least 30 days before any change in ownership or uses of your personal information, as well as any choices you may have regarding your personal information.

5.5 With Your Consent

We may share your information with third parties when you have given us your explicit consent to do so. You can withdraw this consent at any time.

We do not sell your personal information to third parties.

6. International Data Transfers

LocalPay operates globally, which means your information may be transferred to, stored, and processed in countries other than the one in which you reside. These countries may have data protection laws that are different from those in your country.

6.1 Transfers to Service Providers

When we transfer your data to service providers in countries without adequate data protection laws (as determined by the European Commission or UK authorities), we implement appropriate safeguards, including:

6.2 Your Rights Regarding International Transfers

You have the right to obtain a copy of the safeguards we use for international transfers. To exercise this right, please contact us using the details in Section 13.

7. Data Security

We implement appropriate technical and organizational measures to protect your personal information, including:

7.1 Data Breach Notification

In the event of a data breach that affects your personal information:

8. Data Retention

We retain your personal information for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law. The specific retention periods include:

These retention periods may be extended if:

Upon expiration of the retention period, we will either delete it or anonymize it so that it can no longer be associated with you.

9. Your Rights

Depending on your location, you may have certain rights regarding your personal information:

9.1 Access

You have the right to request access to the personal information we hold about you. We will provide this information within 30 days of your request.

9.2 Rectification

You have the right to request that we correct inaccurate or incomplete information about you. We will process such requests within 30 days.

9.3 Erasure

You have the right to request the deletion of your personal information in certain circumstances, such as when the data is no longer necessary for the purposes for which it was collected. We will process such requests within 30 days.

Limitations: We may not be able to delete certain information if retention is required by law. In such cases, we will clearly explain why the data cannot be deleted and, where possible, restrict its further processing.

9.4 Restriction

You have the right to request that we restrict the processing of your personal information in certain circumstances, such as when you contest the accuracy of the data. We will process such requests within 30 days.

9.5 Data Portability

You have the right to receive your personal information in a structured, commonly used, and machine-readable format, and to transmit that data to another controller. We will provide this information within 30 days of your request.

9.6 Objection

You have the right to object to our processing of your personal information in certain circumstances, such as for direct marketing or when processing is based on legitimate interests. We will process such requests within 30 days.

9.7 Automated Decision-Making

You have the right not to be subject to a decision based solely on automated processing that produces legal effects concerning you. You can request human intervention, express your point of view, and contest automated decisions.

9.8 How to Exercise Your Rights

To exercise these rights, please contact us at privacy@localpay.asia or through the contact details provided in Section 13. We will respond to your request within 30 days. We may need to verify your identity before fulfilling your request.

If we decline to take action on your request, you have the right to lodge a complaint with a supervisory authority and to seek a judicial remedy. We will provide reasons for any refusal to act on your request.

10. Cookies and Tracking Technologies

Our Service uses cookies and similar tracking technologies to collect information about your browsing activities and to distinguish you from other users. This helps us provide you with a good experience when you use our Service and allows us to improve our Service.

10.1 Types of Cookies We Use

10.2 Your Choices

You can control cookies through your browser settings. Most web browsers allow you to:

If you disable certain cookies, you may not be able to use all features of our Service.

10.3 Do Not Track

We currently do not respond to "Do Not Track" signals from web browsers.

11. Children's Privacy

Our Service is not directed to children under the age of 18, and we do not knowingly collect personal information from children under 18.

Our age verification process includes analyzing government-issued identification documents to confirm the user's age. We use trusted third-party services to verify the authenticity of these documents.

11.1 Age Verification

We implement age verification measures during the registration process, including:

11.2 Deletion of Children's Data

If we learn that we have collected personal information from a child under 18, we will:

If you are a parent or guardian and believe that your child has provided us with personal information, please contact us at privacy@localpay.asia.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. The updated version will be indicated by an updated "Version" and "Last Updated" date at the top of this policy.

12.1 Material Changes

For material changes that significantly affect your rights or how we use your data:

Material changes include:

12.2 Non-Material Changes

For non-material changes (such as clarifications or minor updates):

12.3 Review of Changes

We encourage you to review this Privacy Policy periodically. Your continued use of the Service after changes take effect constitutes acknowledgment of the updated Privacy Policy, but does not constitute consent where explicit consent is required by law.

12.4 Version History

A complete version history of this Privacy Policy is available at https://localpay.asia/privacy-policy/history.

13. Contact Us

If you have questions or concerns about this Privacy Policy or our data practices, please contact us:

Data Controller:
BESPOKE TECHNICAL LEADERSHIP LTD
124 City Road, London, England, EC1V 2NX.
Email: privacy@localpay.asia

Supervisory Authority:
If you are located in the European Economic Area or the UK, you have the right to lodge a complaint with your local data protection authority. In the UK, this is the Information Commissioner's Office (ICO): https://ico.org.uk/.

We aim to respond to all inquiries within 5 business days and to resolve any concerns as quickly as possible.

14. Jurisdiction-Specific Provisions

14.1 European Economic Area (EEA) and United Kingdom

If you are located in the EEA or UK:

14.2 California Residents

If you are a California resident, you have certain rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), including:

We do not sell your personal information as defined by the CCPA/CPRA. We also do not share your personal information for cross-context behavioral advertising. If we use your sensitive personal information, such as geolocation data, it is only for purposes necessary to provide the Service, and you have the right to limit such use. To exercise your CCPA/CPRA rights, please contact us using the details in Section 13.

14.3 Service Restrictions

Our Service is available only to invited members of our internal circle. We reserve the right to:

14.3.1 Enforcement of Restrictions

We enforce these restrictions through:

14.3.2 Handling of Unauthorized Access

If we identify unauthorized access to our Service:

15. Security and Risk Management

15.1 Transaction Monitoring

We employ a risk-based approach to transaction monitoring:

Risk indicators include:

15.2 Verification Tier Transitions

When users transition between verification tiers:

If a user fails to meet enhanced verification requirements:

15.3 Transaction Limits Enforcement

Transaction limits are enforced through:

If a transaction exceeds the applicable limit:

15.4 Security Program

Our security program includes:

15.5 Suspicious Activity Reporting

We monitor for suspicious activities:

When suspicious activity is detected:

Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, including compliance with legal, accounting, or reporting requirements. When data is no longer required, we securely delete or anonymize it.

Data Portability

You have the right to request a copy of your personal data in a structured, commonly used, and machine-readable format, and to transmit those data to another controller where technically feasible.

Withdrawal of Consent

Where we rely on your consent for processing, you may withdraw it at any time by contacting us at privacy@localpay.asia. This does not affect the lawfulness of any processing carried out before you withdraw your consent.

By using our Service, you acknowledge that you have read and understood this Privacy Policy.