Privacy Policy

Betalo AB (publ)

Privacy Policy

Background
This policy describes the personal data we collect and what we do with it, in accordance with the rules established in the European Parliament and Council Regulation (EU) 2016/679 of April 27, 2016 (GDPR). The statement also describes your rights and how you can exercise them.

General
This privacy statement applies to Betalo AB (publ), org.nr 559245-2931 (“Betalo”), as the data controller for the processing of personal data in connection with the delivery of payment services via the app under the Betalo brand (“the Service”).
When you, as a customer, create an account and/or use the Service, Betalo processes your personal data by collecting and providing information on your mobile phone, tablet, or other devices.

Terminology and Definitions
Personal data refers to any information that can directly or indirectly identify a living individual, e.g., name, personal identification number, or address.
Processing of personal data refers to anything that happens to the personal data. Each action performed with personal data constitutes processing, regardless of whether it is performed automatically or not. Examples of common processing activities include collection, registration, organization, structuring, storage, processing or modification, transmission, and deletion.

Information We Collect

Information You Provide Us
Registration – when you open an account with Betalo, you must provide information such as personal identification number via BankID, email address, and mobile number.
Stored Cards – to use the service and make payments, you must add a Visa or Mastercard. Betalo does not store your card information; this is handled by Nets Branch Sweden (Nets), but we store the type of card you use to provide you with the correct service fee.
Enhanced Customer Control – to comply with the regulations applicable to us as a payment institution, we will occasionally ask for additional information about you, e.g., the country you were born in, the country of your citizenship, where your main income comes from, and whether you, someone in your family, or a close associate have or have had a politically exposed position.

The processing of this information is a prerequisite for you to use the Service and is carried out so that we can fulfill our agreement with you and comply with the legal obligations that apply to us.

Information from Others
In addition to the information you provide us, we may also collect personal data from third parties. For example, Betalo collects address information from public registers to ensure that we have the correct address information for you.

The processing of this information is a prerequisite for you to use the Service and is carried out so that we can fulfill our agreement with you and comply with the legal obligations that apply to us.

Use of the Service
Payments – information you provide us to register a payment, such as the payee, payment reference, amount, and payment date.

We log usage data when you visit or use our services, including the mobile app and website, for example, when you visit or click on content or install or update our mobile app. We use logins, cookies, device information, and IP addresses to identify you and log your usage.

Apart from the use of cookies, the processing of this data is a prerequisite for you to use the service and is carried out so that we can fulfill our agreement with you and comply with the legal obligations that apply to us. Read more about the terms for using cookies in section 3.4 below.

Cookies, Tracking Pixels, and Similar Technologies
The services on Betalo’s website use cookies and other technologies to function properly. Cookies are used so that Betalo can keep visitor statistics and improve the experience for you as a user. The information we collect consists of IP address, operating system, browser, device and screen size, date and time of use, visited pages, and referring page. The use of cookies is only done if you consent to this when visiting Betalo’s website.

Your Device and Location
When you visit or use our services, we receive information about which page you came from. We also receive information about your IP address, proxy server, operating system, browser, date and time, and/or internet service provider or mobile operator. The processing of cookies is based on consent in accordance with section 3.4 above.

When you download Betalo’s app on your mobile phone, tablet, or another device, Betalo must store and retrieve certain technical information from the equipment for Betalo to provide and update the service. The processing of this data is a prerequisite for you to use the Service, and the information is stored for Betalo to fulfill the agreement with you to provide the Service. If you no longer want Betalo to store and retrieve the technical information, you must uninstall the app.

Other
Our services are dynamic, and we continually introduce new features that sometimes require us to collect new information. If we collect personal information that significantly deviates from the information already obtained or if we significantly change how we use your personal data, we will notify you before such further processing begins. If necessary, the content of this privacy statement may also change.

How We Use Your Information
As mentioned above, Betalo processes your personal data for several different purposes based on different legal grounds. Betalo primarily processes personal data for the purpose of delivering, managing, developing, and customizing the service and its functionalities to fulfill the agreement with you. Furthermore, personal data is processed to ensure customer due diligence, manage the customer relationship with you, and fulfill security requirements and other legal obligations for Betalo. The personal data in sections 3.1-3.5 above may also be used as a basis for market and customer analyses, market research, statistics, business follow-up, and business and method development, which are conducted with the support of either consent that Betalo obtains from you in connection with your registration to create an account with Betalo or Betalo’s legitimate interest in marketing itself and its services and developing and offering customers an improved range of services.

Betalo further processes your personal data to provide better and more personalized offers and services. Personal data and information about location data may, for example, be processed, combined, segmented, and analyzed to provide information, offers, or recommendations about Betalo’s or partners’ goods and services through targeted marketing, tailored to the user’s preferences, behavior, needs, or lifestyle. This is done with the support of either consent that Betalo obtains from you in connection with your registration to create an account with Betalo, or Betalo’s legitimate interest in marketing itself and its services and being able to offer customers an improved range of services.

Furthermore, personal data may be processed to protect Betalo’s legal interests or to detect, prevent, or draw attention to fraud and other security or technical issues, which constitutes legitimate interests for Betalo to perform the processing.

If you do not want Betalo to process your personal data for direct marketing, you can notify Betalo in writing via the contact information in section 10, or use the unsubscribe functionality in the communication.

How We Share Your Personal Data
Personal data may be disclosed if necessary to comply with applicable legal requirements or requests from authorities; this is done so that Betalo can fulfill its legal obligations.

Furthermore, Betalo may share your information with other parties to process your order and execute payments, facilitate future payments, enable updates to your payment status, and to send offers from Betalo and Betalo’s partners via SMS, email, and other direct marketing. This processing occurs to fulfill the agreement you have entered into with Betalo and, regarding marketing, based on consent or legitimate interest.

To provide the service, Betalo will disclose your personal data to partners, such as Nets, for processing card data and card details.

In cases where it is necessary for Betalo to offer you the service, we share your personal data with companies that are so-called data processors for Betalo. A data processor is a company that processes information on behalf of Betalo and in accordance with Betalo’s instructions. Betalo has data processors who assist Betalo with IT, as well as actors that Betalo engages for Betalo’s marketing activities. However, it is always Betalo that is responsible for ensuring that your personal data is processed correctly. Betalo controls all data processors to ensure they can provide adequate guarantees regarding the security and confidentiality of personal data. Betalo has written agreements with all data processors (data processing agreements) where they guarantee the security of personal data being processed and commit to comply with Betalo’s security requirements and requirements for international transfer of personal data.

Betalo also shares your data with certain companies that are independent controllers. The fact that the company is an independent controller means that it is not Betalo that controls how the information provided to the company is processed. Independent controllers with whom Betalo shares your personal data include, for example, financial and legal advisors and auditors. When your personal data is shared with a company that is an independent controller, that company’s privacy policies and principles for handling personal data apply.

Where Is Your Personal Data Processed?
Generally, your personal data is only processed within the EU/EEA.

Your personal data may be transferred to or stored in a country outside the EU/EEA, provided that there is a legal basis, such as consent from you, and that there is an adequate level of protection, or that Betalo and its data processors have implemented adequate protective measures.

Upon request, additional information can be obtained about the transfer of personal data to countries outside the EU/EEA.

Information on Storage
Data Storage
Your personal data is normally stored only as long as it is necessary to retain them to fulfill the purposes for which the personal data was collected. When you close your account with Betalo, Betalo will delete or anonymize the information.

When we close an account, we usually delete information (except for information that Betalo is legally required to retain according to section 7.1.1 above) stored on the closed account within 30 days after the account is closed.

Your Choices and Rights

The right to access and control your personal data

For the personal data we have about you:

  • Delete personal information: You can request that we delete or remove all or some of your personal information (e.g., if it is no longer necessary to provide services to you) and Betalo is not obligated to retain the information.
  • Change or correct personal information: You can edit some of your personal information through your account. You can also ask us to change, update, or correct your personal information in certain cases, especially if the personal information is inaccurate.
  • Object to, restrict, or limit the use of personal information: You can ask us to stop using all or some of your personal information or limit our use of it (e.g., if your personal information is inaccurate or stored unlawfully).
  • Right to object to certain types of processing: You may at any time object to Betalo’s processing of your personal information if the legal basis for processing is a public interest or balancing of interests in accordance with Article 6.1 (e) and (f) of the GDPR, and if the processing concerns processing for direct marketing. You also have the right to withdraw your consent to the processing of personal data based on your consent at any time.
  • Right to access and/or retrieve your personal data: You can request information about the personal data that Betalo processes about you and request a copy of the personal data in a machine-readable format. You can also ask to be informed about the purpose of the processing Betalo has carried out and who has received your personal data. If technically feasible and the legal basis for processing personal data is consent or that the processing is necessary for the performance of a contract, you also have the right to receive the personal data you have provided us to transfer them to another data controller.
  • In case of unreasonable or excessive requests (e.g., if they are made repeatedly), Betalo may charge an administrative fee – you will be notified of this in advance. Betalo will normally respond to your request within one (1) month of receipt, inquiries should be directed to info@betalo.no.

Other Important Information

Security

We use security measures designed to protect your information, such as encrypting your data during all processing. We regularly monitor our systems to detect potential vulnerabilities and attacks. However, we cannot guarantee the security of all the information you provide us. There is no guarantee that information will not be accessed, disclosed, altered, or destroyed by attacks on our physical, technical, or managerial firewalls.

Handling of personal identification numbers

Betalo will only process your personal identification number when it is clearly justified concerning the purpose, necessary for secure identification, or if there is another significant reason. Betalo always minimizes the use of your personal identification number as much as possible by using a user ID that does not include your birth date where sufficient.

Legal basis for processing

We will only collect and process your personal data on a legal basis. These legal bases include when you provide us with your consent (when you have given your consent), agreements (when processing is necessary for the performance of the agreement (e.g., to provide the services from Betalo that you have requested)), and legitimate interests, such as protecting you, us, or others from security threats or fraud, improving your experience of the service, and complying with laws applicable to us. In cases where we rely on your consent for processing your personal data, you have the right to withdraw your consent at any time. Where we rely on legitimate interests, you have the right to object to our processing. If you have questions about the legal basis on which we collect and use your personal information, you can contact us as indicated in section 9 below.

Betalo reserves the right to change this policy at any time. Betalo will, with reasonable notice, notify users who have an account with Betalo of upcoming changes to the policy via email, website, or app. If you do not accept the amended terms, you have the right to terminate the agreement with Betalo before the amended policy comes into effect. You terminate the agreement with Betalo by closing your account with Betalo.

Contact

Do not hesitate to contact Betalo if you have questions about the processing of your personal data or any complaints. Written or verbal inquiries and complaints should primarily be directed to:

Betalo AB
iOffice, Engelbrektsgatan 35A
 11432 Stockholm
Email: info@betalo.no (write “Privacy” in the subject line).

If you are still dissatisfied after contacting us, you can contact the Data Protection Authority at:
Data Protection Authority
Postboks 458 Sentrum
0105 Oslo
which is the supervisory authority for the processing of personal data, and to which you can report your complaint.

Privacy Authority (IMY)
Box 8114
104 20 Stockholm
www.imy.se
Phone: +468-657 61 00
Email: imy@imy.se