Privacy Policy

Last updated: August 5, 2026

1. Introduction

Jalda Fintech AB (Org.nr. 559482-9276, "Jalda", "we", "our", or "us") is committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, store, and protect information when you use our micropayment platform and services.

As a payment service provider operating in the European Economic Area, we comply with the General Data Protection Regulation (GDPR) and applicable Swedish data protection law.

2. Data Controller

Jalda Fintech AB is the data controller for the personal data we process through our services:

Jalda Fintech AB

Organization number: 559482-9276

Stockholm, Sweden

Email: privacy@jalda.io

3. Information We Collect

We practice data minimization, collecting only the information necessary to provide our payment services:

3.1 Transaction Information

  • Mobile phone number (verified via operator)
  • Transaction amounts and timestamps
  • Content provider and service identifiers
  • Transaction status and delivery confirmation

3.2 Technical Information

  • IP address and user agent
  • Device fingerprints for fraud prevention
  • Authentication tokens and session data
  • API request logs

3.3 Security and Fraud Prevention Data

  • SIM swap detection results
  • Device swap and behavioral analytics
  • WebAuthn authentication events
  • Fraud risk scores and flags

4. How We Use Your Information

We process personal data for the following purposes:

  • Payment Processing: To execute and settle micropayment transactions
  • Identity Verification: To confirm phone number ownership via CAMARA APIs
  • Fraud Prevention: To detect SIM swap, device swap, and fraudulent activity
  • Service Delivery: To track delivery and enable refunds
  • Compliance: To meet legal obligations under payment services regulations
  • Analytics: To improve service quality and detect system issues (aggregated data only)

5. Legal Basis for Processing

We process your personal data based on:

  • Contractual Necessity: Processing necessary to provide payment services you request
  • Legitimate Interest: Fraud prevention and security measures to protect you and our platform
  • Legal Obligation: Compliance with anti-money laundering, payment services directives, and financial regulations
  • Consent: Where required by law or where you have explicitly agreed

6. Data Sharing and Third Parties

We share data only when necessary to provide our services or comply with legal obligations:

  • Mobile Network Operators: For billing, identity verification, and SIM swap detection
  • Content Providers: Transaction status and delivery confirmation (no personal identifiers)
  • Payment Settlement Partners: For multi-currency settlement and reconciliation
  • Security Providers: Fraud detection, device fingerprinting, and WebAuthn services
  • Legal Authorities: When required by law or court order

We do not sell your personal data to third parties.

7. Data Retention

We retain personal data only as long as necessary:

  • Transaction Records: 7 years (accounting and tax law requirements)
  • Fraud Detection Data: Up to 2 years after account closure
  • Session Data: 90 days
  • Technical Logs: 12 months

8. Your Rights Under GDPR

You have the following rights regarding your personal data:

  • Right of Access: Request a copy of your personal data
  • Right to Rectification: Correct inaccurate or incomplete data
  • Right to Erasure: Request deletion of your data (subject to legal retention requirements)
  • Right to Restrict Processing: Limit how we use your data
  • Right to Data Portability: Receive your data in a structured, machine-readable format
  • Right to Object: Object to processing based on legitimate interest
  • Right to Withdraw Consent: Where processing is based on consent

To exercise your rights, contact us at privacy@jalda.io.

9. Data Security

We implement industry-standard security measures to protect your data:

  • End-to-end TLS encryption for data in transit
  • AES-256 encryption for data at rest
  • Multi-layer authentication and access controls
  • Regular security audits and penetration testing
  • DynamoDB encryption with AWS KMS
  • HMAC-SHA256 signatures for API authentication

10. International Data Transfers

Our services primarily operate within the European Economic Area. Where data is transferred outside the EEA (e.g., to AWS regions), we use Standard Contractual Clauses and ensure adequate safeguards are in place.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or through our platform. The "Last updated" date at the top indicates when changes were last made.

12. Contact and Complaints

For privacy-related questions or to exercise your rights:

Email: privacy@jalda.io

If you are not satisfied with our response, you have the right to lodge a complaint with the Swedish Authority for Privacy Protection (IMY) or your local data protection authority.