Welcome to NALA INC (“NALA”, “we”,“our”, “us”)
This Privacy Notice describes how NALA collects, uses, discloses, and otherwise processes your personal information in connection with our services, including when you visit our website
www.nala.com (the “Website”), our mobile application(s) (the “App”), contact our customer service agents, open our ads, receive or open our emails or text messages, or otherwise interact or communicate with us in relation to any of these services, or when you interact or use one of our products or services that link to this Privacy Notice , (all collectively referred to as the “Services”).
We reserve the right to change this Privacy Notice from time to time. When we make changes to this Privacy Notice, we will change the “Last Updated” date at the beginning of this Privacy Notice. If we make material changes to this Privacy Notice, we will notify you by email to your registered email address, by prominent posting on this website or our online services, or through other appropriate communication channels. All changes shall be effective from the date of publication unless otherwise provided.
REGION-SPECIFIC DISCLOSURES
We may choose or be required by law to provide different or additional disclosures relating to the processing of personal information about residents of certain countries, regions or states. Please refer below for disclosures that may be applicable to you:
- If you are based outside of the US, please click here for additional country or region-specific privacy disclosures.
- If you are a resident of the State of Nevada in the United States, Chapter 603A of the Nevada Revised Statutes permits a Nevada resident to opt out of future sales of certain covered information that a website operator has collected or will collect about the resident. We do not sell your personal information within the meaning of Chapter 603A. However, to submit such a request, please contact us at support@nala.com .
The Service is controlled and operated from facilities in the United States and UnitedKingdom. NALA makes no representations that the Service is appropriate or available for use in other locations. Those who access or use the Service from other jurisdictions do so at their own volition and are entirely responsible for compliance with all applicable laws and regulations, including but not limited to export and import regulations. You may not use the Service if, and you represent and warrant that you will not use the Service if, you are a resident of a country embargoed by the United States or that has been designated by the United States government as a “terrorist supporting” country, or you are a foreign person or entity blocked or denied by the United States government. Unless otherwise explicitly stated, all materials found on theService are solely directed to individuals, companies, or other entities located in the United States.
1. What personal information do we collect from you?
We collect personal information about you in connection with your use of our Service. This collection includes information that you may provide in connection with the Service, information from third parties, and information that is collected automatically such as through the use of cookies and other technologies.
Information you give to us:
We may collect the following personal information from you when you use our Services—for example when you register for an account, when you transfer or receive money, or when you communicate with us. In such cases, we may ask you to provide us with one or more of the following pieces of information:
o Your full name
o Your residential address
o Your contact details (email address and your telephone number)
o Your date of birth
o Your social security number
o Your identification information, including a photo verification
o Your identity information including your image through a selfie verification
o Your payment information (bank, debit card or pre-paid card information including billing address, PAN and CVV details, the sender name as well as the sort code and account number)
o If you send high-value or high-volume transactions or as needed to comply with our anti-money laundering obligations under applicable law we may request additional commercial, personal and/or identification information.
o Account sign-in information, such as email address, username, and password.
o Communications you send to us (by telephone, email or otherwise), for example, to report a problem or to submit queries, concerns or comments regarding the Website, our service, or general comments.
Information automatically collected:
When you use the Services, we may automatically collect and record certain information from your computer, web browser, and/or mobile device, including the following information, without limitation:
- Device Technical information, including the Internet protocol(IP) address used to connect your computer to the Internet, your login information, browser type and version, time zone setting, browser plug-in types and versions, operating system.
- Information about your visit, including the full Uniform Resource Locators (URL) clickstream to, through and from the Website (including date and time); products you viewed or searched for; page response times, download errors, length of visits to certain pages, page interaction information (such as scrolling, clicks, and mouse-overs), and methods used to browse away from the page and any phone number used to call our customer service number.
Information we receive from others:
- Beneficiary Information. If you are an individual who is the intended recipient of a money transfer (the “beneficiary”), the individual making the transfer will provide us with your name, phone number, bank account, and purpose of payment. We may also give you the ability to invite people you know to use the Services, including by importing your address book or manually entering their contact information. You are responsible for ensuring your sharing of this personal information with us is compliant with applicable laws. This may require you to get permission from the people you invite before you share their information.
- Single Sign-On Account Login. We may also obtain information about you when you log in using single sign-on (“SSO”) through a third-party social network or authentication service, such as Google or Apple. We do this by using OAuth authentication, a secure mechanism to give NALA access to your account data without letting us know your password. We have access to certain information from those third parties in accordance with the authorization procedures determined by those third parties, including, for example, your username, password, name, email address, and profile picture.
- Referrals. We may also get personal information from you about other prospective NALA users, such as through our referral program, or when an existing NALA user adds you to their list of contacts within the app. We process this personal information to help you and your contacts connect through our Services. If you want to remove personal information stored by us, follow any instructions in the Service or see Control Over Your Information below.
- Social Media. When you interact with us through a social media site or third party service, such as when you like, follow, or share NALA content on Facebook, Twitter, Instagram, or similar sites, we may receive information from the social network, including your profile information, picture, user ID associated with your social media account, and any other information you permit the social network to share with third parties, The data we receive from these third-party sites is dependent upon that third party’s policies and your privacy settings on that third-party site. You should always review and, if necessary, adjust your privacy settings on third-party websites and services before linking or connecting them to our Services. If you make a comment or post other content on our Social Media pages, please be aware that you are providing information directly to the social media network subject to their Privacy Notice and terms of use. As with other third party sites, we have no control over and are not responsible for their privacy practices.
- Service Providers and Business Partners. We are also working closely with third parties (including, for example, service providers, business partners, sub-contractors in technical, payment and delivery service providers, advertising networks, analytics providers, search information providers, credit reference agencies) and may receive information about you from them.
If we combine or associate information from other sources with your information that we collect through the Services, we will treat the combined information in accordance with this Privacy Notice, the Terms, and applicable law.
2. Access to contact list information
We may also collect and process your contact list information on your mobile device but only with your express permission.This information may include names, phone numbers, email addresses, images associated with the contacts etc.
This is to make it easier for the recipient data to be pre-filled and enable transactions to be processed faster and free of apparent errors.We shall only access your contact list with your explicit consent and only share applicable information with third parties solely for the purpose of processing the transaction.
We shall not send any information to your contacts or make use of any of the collected data for any other purpose apart from what is provided here.
3. How do we use your data?
We use your personal data for the following purposes:
- i. Service Relationship, which includes:
- Providing our services to you. These services include e-money and related payment services including but not limited to: the storage of electronic funds, the transfer of electronic funds both domestically and cross-border, the withdrawal of electronic funds, other capabilities surrounding the functionalities of digital wallets, and the operation of related financial services.
- Providing customer support and account administration and communicating with you about your engagement with us, such as changes in our terms or following up on an incomplete registration process.
- Managing payments for the services we provide you, which includes billing process. - ii. Communicating with you to provide you with information of our services. For example, to respond to your inquiries, resolve your problems and concerns, and in order to take steps prior to entering into a service engagement.
- iii. Performing service enhancement activities. This includes conducting statistical analysis on online activity, usage, browser, device and other data.
- iv. Ensuring proper administration of our business which includes keeping appropriate records, training and quality assurance purposes, resolving complaints and managing our business relationships and opportunities.
- v. Preventing, detecting and fighting fraud or other illegal or unauthorized activities which includes monitoring operations, user activity and networks for fraud prevention and crime detection purposes, including information from third parties who may monitor our Website and systems and alert us about suspicious activities, auditing our systems and deploying security measures.
- vi. Request and verify by automated means your financial related information, as well as share it, where required, with the relevant authorities to comply with our legal obligations related to financial, Anti-Money Laundering and tax regulations, among others. When you enter in your personal details to obtain an initial quote using our service, we will check your identity and credentials provided through our third party Know Your Customer / Anti-Money Laundering provider.
- vii. Providing you with marketing communications about our services: We may use your personal data to provide you with information on related products and services that you may be interested in, such as other e-money and related payment services. This information will be provided electronically, either via our Website, App, or email. We will not transfer any of your personal data to third parties for this purpose unless you give us your explicit consent. You may opt out of this at any time by emailing us at support@nala.com. If you do not wish to receive marketing emails from us, you can also opt out of receiving emails from us (except for emails related to the completion of your registration, correction of user data, change of password, and other similar communications essential to your transactions through the Services) by using the unsubscribe process at the bottom of any marketing email from us. Although your changes are reflected promptly in active user databases, we may retain all information you submit for a variety of purposes, including backups and archiving, prevention of fraud and abuse, and analytics.
- viii. To manage Cookies and allow you to manage your Cookie preferences.
- ix. To comply with our legal obligations, as part of our general business operations, and for other business administration purposes. Where necessary, we may use your personal data to establish, exercise or defend legal claims in suspected or actual legal proceedings.
4. Who does NALA share your information with and why?
In order to deliver our services, your personal data may also be transferred to the following third parties:
- i. Our service providers and partners:
We use third parties to help us operate and improve our services and facilitate the fulfilment of essential service functions. These third parties assist us with various tasks, including personal information hosting and maintenance, with security tools and others, to verify and confirm the information that you provide to us. We may also share your information with the banks, telecommunications providers and other financial services firms who facilitate payments, among others. - ii. In corporate transactions:
We may transfer your personal information if we are involved, whether in whole or in part, in a merger, sale, acquisition, divestiture, restructuring, reorganization, dissolution, bankruptcy or other change of ownership or control. - iii. When required by law:
We may disclose your personal information if reasonably necessary with regulators, law enforcement agencies or authorities or where mandatory under a court order: (i) to comply with a legal process, such as a court order, subpoena or search warrant, government / law enforcement investigation or other legal requirements; (ii) to assist in the prevention or detection of crime (subject in each case to applicable law); (iii) to protect the health and safety of us, our users, or any person; or (iv) as otherwise required by applicable law. - iv. To enforce legal rights:
We may also share information: (i) if disclosure would mitigate our liability in an actual or threatened lawsuit; (ii) as necessary to protect our legal rights and legal rights of our users, business partners or other interested parties; (iii) to enforce our agreements with you; (iv) to reduce credit risk and collect debts owed to us; and (v) to investigate, prevent, or take other action regarding illegal activity, suspected fraud or other wrongdoing. - v. With other entities within NALA Group:
When it is necessary for operational reasons such as the use of a group-wide logistics and IT infrastructure and for any administrative purposes to organise, develop and deliver our services and products, run our organisation and decide on future strategies.
In certain circumstances, including where required by applicable law, we may ask for your consent to share your personal data with explicitly identified third parties, including entities within NALA Group, so that they can contact you for marketing purposes or provide you with their own products or services. You can withdraw your consent at any time by emailing us.
5. How long will we keep your data for?
We retain personal data about you for as long as necessary for the purposes set out in these Disclosures, unless a longer period is required under applicable law or is needed to resolve disputes or protect our legal rights.. This means that we will retain your personal data for as long as we have an active contract or business relationship with you, and after this, we will only keep your data for as long as is necessary for the purposes which it is stored and for legal/regulatory requirements. We will take reasonable measures to delete your personal information if you delete your account, however, you acknowledge that we will retain some information after you have closed, or we have deleted, your account with us where necessary to enable us to meet our legal/regulatory obligations or to exercise, defend, or establish our rights.
In some cases, we may be required to retain your personal data for a longer period where applicable laws or regulations require or allow us to do so. Where possible, we aim to anonymise the information or remove unnecessary identifiers from records that we may need to keep for longer periods beyond the specified retention period.
In case of any questions relating to data retention, please contact us at:
privacy@nala.money.
6. How do we protect your information?
We have implemented, and will maintain current, reasonable physical, technical, and organizational security measures to protect your personal information from loss, misuse, and unauthorized access, disclosure, alteration, or destruction. However, no security system is impenetrable, and we cannot guarantee the 100% security of our systems. In the event that any information under our control is compromised as a result of a breach of security, we will take reasonable steps to investigate the situation and, where appropriate, notify those individuals whose information may have been compromised and take other steps, in accordance with applicable laws and regulations. Where we have given you (or where you have chosen) a password which enables you to access certain parts of our services, you are responsible for keeping this password confidential. We ask you not to share a password with anyone.
7. How we use clickstream data
NALA may collect and use clickstream data to profile your behaviour on our website and to understand how you interact with our online presence. This data is collected through the use of web analytics software, and may include information about the websites and pages you visit, as well as the actions you take on those pages.
We use this data to improve our website and to better understand our users' needs and preferences. We may also use this data to personalise your experience on our website and to show you relevant content and offers.
We take the protection of your personal data seriously and have implemented appropriate technical and organisational measures to ensure that your data is collected, used, and stored in compliance with the General Data Protection Regulation (GDPR) and other relevant local legislation in our various countries of operation. We also ensure that your data is only used for legitimate business purposes and is not shared or sold to third parties without your consent.
You have the right to access, correct, and delete any personal data that we collect about you. If you wish to exercise any of these rights, please contact us at
privacy@nala.money 8. What cookies and similar technologies do we use?
Please see our
https://www.nala.com/cookies-policy for more information on why we use them and how you can better control their use through your browser settings and other tools.
9. Control Over Your Information
- Modifying Account Information. Once you have registered for a NALA account, you may update or correct your profile information at any time by accessing your profile page through the Site.
- Deactivating Your Account. We do not delete information about you upon deactivation of your account. Although your deactivated status is reflected promptly in our user databases, we may retain the information you submit for a variety of purposes including legal/regulatory, compliance, backups and archiving, prevention of fraud and abuse, and analytics. Upon deactivation, you will no longer receive emails from us and links to third party financial accounts, and Services will automatically terminate. If you have a money transfer transaction pending at the time you deactivate your account, your link to this service will terminate but your pending transfer will continue to completion.
- Email Communications. From time to time, we may send you emails regarding updates to our Service, notices about our company, or information about the Services we offer. If you wish to unsubscribe from such emails, simply click the “unsubscribe” link provided at the bottom of the email communications. Note that you cannot unsubscribe from certain service-related email communications (e.g., account verification, technical or legal notices).
10. Children’s Personal Information
Our websites and online services are not directed to, and we do not intend to, or knowingly, collect or solicit personal information from children under the age of 13. If you are under the age of 13, please do not use our website or online services or otherwise provide us with any personal information either directly or by other means. If a child under the age of 13 has provided personal information to us, we encourage the child’s parent or guardian to contact us to request we remove the personal information from our systems. If we learn that any personal information has been provided by a child under the age of 13, we will promptly delete that personal information.
11. Third Party Websites
Our websites and online services may include links to third-party websites, plug-ins and applications. Except where we post, link to, or expressly adopt or refer to this Privacy Notice, this Privacy Notice does not apply to, and we are not responsible for, any personal information practices of third-party websites and online services or the practices of other third parties. To learn about the personal information practices of third parties, please visit their respective privacy notices.
12. How can you contact NALA?
If you have questions regarding your privacy and rights, please let us know how we can help.
- Email: privacy@nala.money·
- Post mail: International House, 64 Nile Street, London, N1 7SR
ADDITIONAL EUROPEAN ECONOMIC AREA, UNITED KINGDOM, AND SWITZERLAND PRIVACY DISCLOSURES
NALA maintains operations in the United Kingdom and may direct our Services to individuals located in the EEA, United Kingdom, and Switzerland, including through our Site (collectively, our “European Services”). The following disclosures apply to our personal data in connection with our European Services.
NALA is the data controller responsible for the processing of personal data in connection with our European Services. This means that we determine and are responsible for how your personal data is used.
Personal Data: When we use the term “personal data” in this section, we mean information relating to an identified or identifiable person.
Legal Bases for Processing
In connection with our European Services, we will only collect, use, share, or otherwise process your personal data in accordance with one of the below lawful bases:
- - Performance of a contract: This is where the processing is necessary for a contract we have with you, or you have asked us to take specific steps before entering into a contract, such as providing you with a quote. This lawful basis covers the following purposes:
o Providing our services to you.
o Providing customer support and account administration and communicating with you and about your engagement with us.
o Managing payments for the services we provide you which includes billing process through our Website.
o Communicating with you at your request to provide you with information of our services in order to take steps prior to entering into a service engagement. - - Our legitimate interests: This is where we collect and process data in accordance with our “legitimate interests” which may be pursued by us or our service providers acting on our behalf or by a third-party insofar as such interests do not pose a high risk to your rights and freedoms. Our legitimate interests include the following purposes:
o Performing service enhancement activities. Our legitimate interest is making services and features more relevant and improving our services and user experience.
o Ensuring proper administration of our business. Our legitimate interest is ensuring the continuity of our service.
o Preventing, detecting and fighting fraud or other illegal or unauthorized activities, as well as checking your identity and credentials. Our legitimate interest is preserving the security of our service.
o Providing you with marketing communications about our services. Where consent is not required, as you or the company you represent are an existing customer who purchased or negotiated to purchase a similar service or product in the past, we may send you marketing communications based on our legitimate interest pursued by us or our service providers acting on our behalf or by a third-party. Our legitimate interest is promoting our business and to provide you with offers of relevant services. - - Consent: We may provide and send you marketing communications based on your consent. You may be given the option to explicitly consent to share your data with selected third parties for marketing purposes or to sign up for related products and services. This will be via a separate notice via the Website or App. We will never assume that we have your consent unless you have explicitly opted in, and you can withdraw your consent at any time by contacting us.
- - Compliance with our legal obligations: We may be required to process or share your personal data in compliance with a legal/regulatory obligation, statutory codes of practice and other legal or tax related obligations to:
o Exercise or perform any right or obligation which is conferred or imposed by law on us. This may include the request and verification of your financial information to comply with our legal obligations related to financial, Anti-Money Laundering and tax regulations, among others.
o Establish, exercise or defend legal claims in suspected or actual legal proceedings when investigating, for example, a civil claim.
Data Retention
We retain personal data about you for as long as is necessary for the purposes set out in these Disclosures, unless a longer period is required under applicable law or is needed to resolve disputes or protect our legal rights.The criteria used to determine the period for which personal data about you will be retained varies depending on the legal basis under which we process the personal data:
- Legitimate Interests: Where we are processing personal data based on our legitimate interests, we generally will retain such information for a reasonable period of time based on the particular interest, taking into account the fundamental interests and the rights and freedoms of data subjects.
- Consent: Where we are processing personal data based on your consent, we generally will retain the information for the period of time necessary to fulfil the underlying agreement with you, subject to your right, under certain circumstances, to have certain of your data erased (please see the Your Privacy Rights section below).
- Contract: Where we are processing personal data based on contract, we generally will retain the information for the duration of the contract plus some additional limited period of time that is necessary to comply with law or that represents the statute of limitations for legal claims that could arise from the contractual relationship.
- Legal Obligation: Where we are processing personal data based on a legal obligation, we generally will retain the information for the period of time necessary to fulfil the legal obligation.
- Legal Claim: We may need to apply a “legal hold” that retains information beyond our typical retention period where we face threat of legal claim. In that case, we will retain the information until the hold is removed, which typically means the claim or threat of claim has been resolved.
In all cases, in addition to the purposes and legal bases, we consider the amount, nature and sensitivity of the personal data as well as the potential risk of harm from unauthorized use or disclosure of your personal data.
Your Privacy Rights
In accordance with applicable privacy law, you may exercise the following rights in respect of your personal data that we hold:
- You have the right to be informed over what personal data we hold and how we are using it. This information is contained within this Privacy Notice.
- If you have consented to particular uses of your personal data, you have the right to withdraw this consent at any time. Withdrawing your consent will not affect the lawfulness of any processing we conducted prior to your withdrawal, nor will it affect processing of your personal information conducted in reliance on lawful processing grounds other than consent. You can always withdraw your consent, as we explain the Control Over Your Information section of our Privacy Notice.
- You have the right to portability of your personal data. This means that you can request copies of the personal data we hold in a structured, commonly used, and machine-readable form.
- You have the right to request a copy of the personal data we hold under the GDPR by making a “subject access request” to us.
- If some of the personal data we hold is inaccurate or incomplete, you can request that we rectify our records by contacting us.
- Where we are using your personal data in accordance with our legitimate interests, you can object to further use of your data. If you object, we will stop using your personal data in this way immediately, unless there are compelling legitimate grounds for processing your personal data which override your interests, rights and freedoms (such as requests by law enforcement) or we need to process your data for the establishment, exercise or defence of legal claims.
- You have the right to request erasure of the personal data we hold by contacting us.
- You have the right to restrict the processing of your personal data in certain circumstances, such as where the accuracy of the personal data is contested by you.
- You have the right to not be subject to automated decision making.
You have the
right to complain to a data protection authority about our collection and use of your personal information if you feel that we have not been complying with our obligations on data protection law. For more information, please contact the Information Commissioner’s Office (ICO) or your applicable local data protection authority. A list of European data protection authorities is available here:
https://edpb.europa.eu/about-edpb/board/members_en.
You can exercise any of your rights by contacting us via the details in Section “
How can you contact NALA”. Please note that we may need to verify your identity before complying with any of the above requests.
We respond to all requests we receive from users in accordance with applicable data protection laws. In some cases, we may reject requests for certain reasons (for example, if the request is unlawful or if it may infringe on trade secrets or intellectual property or the privacy of another user).
1. How do we send information outside of your country?
The personal data we collect may be transferred and stored in countries outside of the jurisdiction you are in where we and our third party service providers have operations. If you are located in the EEA, United Kingdom, or Switzerland, your personal data may be processed outside of those regions, including in the United States.
In the event of such a transfer, we ensure that: (i) the personal data is transferred to countries recognized as offering an equivalent level of protection; or (ii) the transfer is made pursuant to appropriate safeguards, such as standard contractual clauses adopted by the European Commission.
You may request further information on the measures used for international transfers at
privacy@nala.money.
Electronic Fund Transfers (EFTs) and Account Balances. NALA partners with financial services software company Sila Inc. (“Sila”) and banking services provider Evolve Bank & Trust (“Evolve”), member FDIC, to offer you electronic fund transfers (“EFTs”). When you create a NALA Account, link a bank account, or initiate an EFT, you are authorizing us to share your identity and banking information with Sila and Evolve to support your account. You are also agreeing to the terms of Sila’s privacy policy,
https://silamoney.com/privacy-policy/, Evolve’s privacy policy,
https://www.getevolved.com/privacy-policy/, and Evolve’s communications consent and disclosure,
https://silamoney.com/evolve-electronic-communications-consent-and-disclosure/ (the “Partner Terms”). It is your responsibility to make sure the data you provide us is accurate and complete, which is necessary for our partners to process EFTs on your behalf. The Partner Terms may be modified from time to time, and the governing versions are incorporated by reference into this Privacy Policy. Any term not defined in this section but defined in the Partner Terms assumes the meaning as defined in the Partner Terms. IT IS YOUR RESPONSIBILITY TO READ AND UNDERSTAND THE PARTNER TERMS BECAUSE THEY CONTAIN TERMS AND CONDITIONS CONCERNING YOUR NALA ACCOUNT, INCLUDING BUT NOT LIMITED TO USE OF YOUR PERSONAL INFORMATION.