Privacy Policy
1. Introduction
This Privacy Policy explains how Alph4digiTEC FZE (“Alph4digiTEC”, “we”, “us” or “our”) collects, uses, stores, discloses and protects personal data obtained through the Alph4digiTEC website and, where applicable, in connection with our technology products and services, including Alpha DigiWallet.
We aim to process personal data fairly, transparently and only for appropriate purposes. This Policy should be read together with any specific privacy notices or contractual data-processing terms that apply to a particular product, service or customer relationship.
2. Who we are
Alph4digiTEC FZE is a Free Zone Establishment registered with Sharjah Publishing City Free Zone, Sharjah, United Arab Emirates, under licence number 4431346.01.
Alph4digiTEC is a technology company and the owner of Alpha DigiWallet. Alpha DigiWallet is a payment orchestration technology solution and is not itself a bank, payment institution, payment service provider, card issuer or merchant acquirer.
3. Scope
This Policy applies primarily to personal data collected through the Alph4digiTEC website, including contact forms, business enquiries, recruitment enquiries, subscriptions and website interactions. Where Alpha DigiWallet is used by a merchant or integrated with third-party payment providers, additional contractual privacy terms, data-processing agreements or privacy notices may apply depending on the parties’ respective roles.
4. Personal data we may collect
- Identity and contact information, such as name, company name, job title, email address and telephone number.
- Business and enquiry information, including messages, requirements, requested services and communications.
- Technical information, such as IP address, browser type, operating system, device information, referral source and website usage data.
- Cookie and similar technology data, subject to applicable consent requirements.
- Recruitment information where an individual applies for a role.
- Information provided voluntarily in connection with commercial discussions, demonstrations, onboarding or support.
5. Alpha DigiWallet and payment-related data
Where a merchant or other customer uses Alpha DigiWallet, the platform may process data required to provide the technology and orchestration functions requested by that customer. Depending on the implementation, this may include merchant account information, transaction references, payment status information, technical identifiers, reconciliation information and other operational data.
Payment card credentials, bank account information, regulated payment data and other financial information may be collected, stored or processed by the relevant payment service provider, bank, acquirer, processor or other payment partner. Alph4digiTEC does not represent that it itself holds or controls all payment information merely because Alpha DigiWallet connects with or orchestrates third-party payment services.
The exact controller/processor roles may vary by service and contractual arrangement. Where Alph4digiTEC acts as a processor on behalf of a customer, processing will be governed by the applicable customer instructions and contractual data-processing terms.
6. How we use personal data
- Respond to enquiries, requests, demonstrations and business communications.
- Provide, administer and support our technology services.
- Operate and improve our website, systems, products and user experience.
- Manage customer, supplier and business relationships.
- Maintain security, detect misuse and protect systems and users.
- Perform onboarding, verification and compliance activities where applicable to our role and contractual obligations.
- Send business or marketing communications where permitted by law and subject to applicable consent or objection rights.
- Meet legal, regulatory, accounting and record-keeping obligations.
- Establish, exercise or defend legal rights and claims.
7. Legal basis
Where applicable law requires a legal basis for processing, we may rely on consent, the performance of a contract or steps requested before entering into a contract, compliance with legal obligations, protection of legitimate interests, or another lawful basis permitted by applicable law.
Where processing relies on consent, consent should be clear and capable of being withdrawn. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
8. Sharing personal data
We do not sell personal data. We may share personal data where reasonably necessary with:
- Hosting, cloud, analytics, communications, cybersecurity and other technology providers.
- Professional advisers, auditors, insurers, legal counsel and other business service providers.
- Payment service providers, banks, acquirers, processors and other payment partners where required to provide an Alpha DigiWallet-related service and where applicable.
- Business partners and contractors operating under appropriate confidentiality and contractual requirements.
- Government authorities, regulators, law enforcement or courts where disclosure is required or permitted by law or necessary to protect legal rights.
9. International transfers
Our suppliers, technology providers and business partners may operate in jurisdictions outside the United Arab Emirates. Where personal data is transferred or processed internationally, we will take reasonable steps to apply appropriate safeguards and comply with applicable legal requirements governing international transfers.
10. Data security
We use reasonable technical, organisational and administrative measures designed to protect personal data against unauthorised access, disclosure, alteration, loss, misuse or destruction. Measures may include access controls, authentication, encryption where appropriate, monitoring, secure system design and supplier controls.
No online system or transmission method can be guaranteed to be completely secure. Where we become aware of a personal-data incident requiring notification under applicable law, we will take appropriate steps in accordance with the applicable legal requirements.
11. Data retention
We retain personal data only for as long as reasonably necessary for the purpose for which it was collected, including business, contractual, legal, security, accounting and compliance requirements. When personal data is no longer required, we will delete, anonymise or securely archive it where appropriate.
12. Cookies and similar technologies
The website may use cookies and similar technologies for essential functionality, preferences, security, analytics and other permitted purposes. Where consent is required, we will seek consent through an appropriate cookie mechanism. You may also manage cookies through your browser settings, although disabling certain cookies may affect website functionality.
Full details are set out in the Cookie Policy, including what is currently deployed on this website.
13. Data subject rights
Subject to applicable law and any lawful restrictions, individuals may have rights relating to their personal data, including rights to receive information about processing, request access or a copy of data, request correction, request erasure, restrict or object to certain processing, request transfer of data where applicable, and withdraw consent where processing is based on consent.
Individuals may also have rights concerning direct marketing and certain automated processing or profiling. Where applicable, requests should be made using the contact details in this Policy. We may need to verify identity before completing a request.
14. Automated processing
We may use automated systems for operational, security, analytics or service-management purposes. Where applicable law provides a right to object to a decision based solely on automated processing, individuals may contact us using the details below. Where required, we will provide appropriate human review.
15. Children's privacy
The website and our business services are not intended for children. We do not knowingly seek to collect personal data from children through the website.
16. Third-party websites
Our website may contain links to third-party websites or services. Those third parties operate under their own terms and privacy policies. We are not responsible for the privacy practices of third-party websites or services.
17. Controller and processor roles
Depending on the activity, Alph4digiTEC may act as a controller of personal data, a processor acting on behalf of a customer, or another role defined by applicable law and the relevant contractual arrangement. Where Alph4digiTEC acts as a processor, the customer's instructions and applicable data-processing agreement will govern the processing.
Third-party payment providers, banks, acquirers and processors may independently act as controllers or processors for data processed within their own services. Their own privacy notices and contractual terms may therefore apply.
18. Changes to this policy
We may update this Privacy Policy from time to time. The revised version will be published on the website and will state its effective date. Where required by law, we will provide additional notice or obtain consent for material changes.
19. Contact and privacy requests
Questions, privacy requests and complaints should be submitted using the official contact details published on the website or by email to contact@alphadigiwallet.com.
Where a Data Protection Officer is required under applicable law for a particular processing activity, the relevant contact details will be provided in the applicable privacy notice or contractual documentation.