1. Introduction
Jalda Fintech AB (Org.nr. 559482-9276, "Jalda", "we", "our", or "us") is committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, store, and protect information when you use our micropayment platform and services.
As a payment service provider operating in the European Economic Area, we comply with the General Data Protection Regulation (GDPR) and applicable Swedish data protection law.
2. Data Controller
Jalda Fintech AB is the data controller for the personal data we process through our services:
Jalda Fintech AB
Organization number: 559482-9276
Stockholm, Sweden
Email: privacy@jalda.io
3. Information We Collect
We practice data minimization, collecting only the information necessary to provide our payment services:
3.1 Transaction Information
- Mobile phone number (verified via operator)
- Transaction amounts and timestamps
- Content provider and service identifiers
- Transaction status and delivery confirmation
3.2 Technical Information
- IP address and user agent
- Device fingerprints for fraud prevention
- Authentication tokens and session data
- API request logs
3.3 Security and Fraud Prevention Data
- SIM swap detection results
- Device swap and behavioral analytics
- WebAuthn authentication events
- Fraud risk scores and flags
4. How We Use Your Information
We process personal data for the following purposes:
- Payment Processing: To execute and settle micropayment transactions
- Identity Verification: To confirm phone number ownership via CAMARA APIs
- Fraud Prevention: To detect SIM swap, device swap, and fraudulent activity
- Service Delivery: To track delivery and enable refunds
- Compliance: To meet legal obligations under payment services regulations
- Analytics: To improve service quality and detect system issues (aggregated data only)
5. Legal Basis for Processing
We process your personal data based on:
- Contractual Necessity: Processing necessary to provide payment services you request
- Legitimate Interest: Fraud prevention and security measures to protect you and our platform
- Legal Obligation: Compliance with anti-money laundering, payment services directives, and financial regulations
- Consent: Where required by law or where you have explicitly agreed
6. Data Sharing and Third Parties
We share data only when necessary to provide our services or comply with legal obligations:
- Mobile Network Operators: For billing, identity verification, and SIM swap detection
- Content Providers: Transaction status and delivery confirmation (no personal identifiers)
- Payment Settlement Partners: For multi-currency settlement and reconciliation
- Security Providers: Fraud detection, device fingerprinting, and WebAuthn services
- Legal Authorities: When required by law or court order
We do not sell your personal data to third parties.
7. Data Retention
We retain personal data only as long as necessary:
- Transaction Records: 7 years (accounting and tax law requirements)
- Fraud Detection Data: Up to 2 years after account closure
- Session Data: 90 days
- Technical Logs: 12 months
8. Your Rights Under GDPR
You have the following rights regarding your personal data:
- Right of Access: Request a copy of your personal data
- Right to Rectification: Correct inaccurate or incomplete data
- Right to Erasure: Request deletion of your data (subject to legal retention requirements)
- Right to Restrict Processing: Limit how we use your data
- Right to Data Portability: Receive your data in a structured, machine-readable format
- Right to Object: Object to processing based on legitimate interest
- Right to Withdraw Consent: Where processing is based on consent
To exercise your rights, contact us at privacy@jalda.io.
9. Data Security
We implement industry-standard security measures to protect your data:
- End-to-end TLS encryption for data in transit
- AES-256 encryption for data at rest
- Multi-layer authentication and access controls
- Regular security audits and penetration testing
- DynamoDB encryption with AWS KMS
- HMAC-SHA256 signatures for API authentication
10. International Data Transfers
Our services primarily operate within the European Economic Area. Where data is transferred outside the EEA (e.g., to AWS regions), we use Standard Contractual Clauses and ensure adequate safeguards are in place.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or through our platform. The "Last updated" date at the top indicates when changes were last made.
12. Contact and Complaints
For privacy-related questions or to exercise your rights:
Email: privacy@jalda.io
If you are not satisfied with our response, you have the right to lodge a complaint with the Swedish Authority for Privacy Protection (IMY) or your local data protection authority.