Consenso Privacy Statement

Overview

This Privacy Statement is intended to explain how and for what purposes Consenso will collect, store, use, and share your personal information when you browse our website or use our services. Reading this statement will help you understand:

"Consenso" in this statement refers to Consens products. We are committed to protecting your privacy and data. The security of your personal information is of utmost importance to us. We follow strict internal guidelines, legal requirements, and industry best practices to ensure the security of your data and its use only for authorized purposes.

This Privacy Statement only applies to your use of the Consenso account and related Consenso services. To learn about the privacy policies applicable to our other products or services, please browse the privacy statements of those products or services.

We recommend that you carefully read the contents of this statement and make the choices you deem appropriate. Please note that we have highlighted in bold the items that may involve personal sensitive information.

What personal information we collect and the purposes for which we collect such personal information

A. Opening an account and using payment services

When you register or use our payment services, for example, when you open an account, make a payment, shop on a merchant's website, or maintain your account (including closing your account), we may collect your personal information.

The purposes for which we collect your personal information include:

The types of personal information (including sensitive personal information) that must be collected to open an account for you or to provide you with payment services are listed below. If you do not agree to our collection of such personal information, you will not be able to open a Consenso account, and we will not be able to provide you with Consenso services. We will collect and process sensitive personal information only to the extent necessary to open an account and provide you with services, and we will take strict measures to protect all personal information we collect (see the section "How we protect your personal information").

Collecting your personal information when using non-branded services - Some of our services can be used without logging in or creating an account. When you interact with merchants and use the non-branded bank card payment service to pay merchants and use Consenso checkout without logging in, we will collect your personal information. For our non-branded payment services, your interaction with merchants takes place on their platforms. If you are an account holder or create an account later, we may collect information about non-branded transactions and associate it with your account for the purpose of improving your customer experience as an account holder and for compliance and analysis purposes. If you are not an account holder, we will collect and store all the information you provide and use this information in accordance with this Privacy Statement.

B. Additional features

If you agree, we can also provide you with additional features and collect your personal information for the following purposes:

We collect the following types of additional personal information for all additional features:

You can choose at any time whether to provide us with your personal information for such additional features. This will not affect our provision of our core payment services to you.

Sources of Personal Information

For the purposes we describe above in the “What Personal Information We Collect and Why We Collect It” section, we may collect Personal Information about you from various sources, such as:

We do not systematically or on a large scale purchase or obtain any personal information from third parties, but we may collect your personal information from third parties through legal channels (such as under a contract) in the process of providing Consenso services to you.

We will also collect, use, process and share your personal information in accordance with applicable laws or requirements of governments or regulators.

How we use tracking technologies such as cookies

When you use our services, visit our websites, or visit websites that provide our services, we or our authorized service providers may use cookies and similar tracking technologies to collect your personal information. Such tracking technologies may include scripts, click streams, web beacons, and software development kits (SDKs). The information collected through these technologies will help us personalize your experience, measure the effectiveness of our advertising, prevent fraud, and enhance the security of our websites and services.

You can disable or reject some cookies on our websites and services. However, because some parts of our services rely on essential cookies to operate, if you disable or reject essential cookies, these services may become difficult or unusable. Some web browsers have an optional setting called "Do Not Track" (DNT) that allows you to choose not to be tracked by advertisers and some third parties. Without tracking information, many of our services will not work, so once you accept the use of cookies, we will not respond to DNT settings.

How and why we share personal information

We do not sell your personal information. However, we may share your personal information across services or with other members of Consenso. Sometimes we share the personal information we collect with third parties to help us provide our services, protect our customers from risk and fraud, market our products, and comply with legal obligations.

You can read the What Personal Information We Collect section to learn what personal information we may share. Examples of the types of personal information involved include:

We may share personal information with:

How we protect your personal information

Helping you keep your personal information secure from loss, misuse, unauthorized access, disclosure and alteration is our priority.

To protect your personal information, we use technical, physical and administrative security policies and procedures that comply with industry best practices (such as ISO 27001 and PCI DSS) to safeguard the confidentiality, privacy and integrity of your personal information. These policies and standards are reviewed and/or updated regularly. Specific security measures we take to protect your personal information include, but are not limited to:

You are responsible for maintaining the confidentiality of your password and account information while we protect our systems and services. You are also responsible for ensuring that your personal information is accurate and up-to-date.

Your Privacy Rights and Choices

You have choices about how we collect, store, use and share your personal information.

Know Your Rights

  • You have the right to request access to the personal information we collect and hold about you, request that we correct or update our records, request that we transfer your personal information to another service provider, or request that we explain the rules for processing your personal information.
  • You also have the right to request that we delete any of your personal information that we collect and hold if: (i) it is not described in this Privacy Statement or is collected and held in violation of the law, (ii) the processing purpose has been achieved, cannot be achieved, or is no longer necessary for the specific purpose for which the personal information was previously collected, (iii) you withdraw your consent where the law requires the collection or processing of the relevant personal information (such as sending you updates on the services we provide from time to time); but please note that in most cases our processing of your personal information is based on the basis that it is necessary to enter into and perform a contract with you, so your consent is not required under legal provisions, or (iv) we stop providing the relevant service, or the retention period of the relevant information has expired.
  • If the retention period has not expired or the deletion of personal information is technically difficult to achieve, we may not be able to respond to your request to delete personal information, but we will stop processing your personal information other than storing it and taking necessary security measures. We will limit the retention period of personal information in accordance with legal requirements and for the time required to achieve the purposes described in this statement.
  • If you wish to review, transfer or delete your personal information or completely cancel your account, please contact us or operate through your account.
  • If you wish to delete your personal information, you can choose:
  • Some aspects of our services, such as account login, verification and fraud prevention, may rely on automated decision-making mechanisms such as algorithmic processes. If these decisions significantly affect your rights and interests, you have the right to ask us for an explanation of the automated decision-making mechanism and request a manual review of the above decisions. If you would like a manual review, please contact us.
  • We will not refuse to provide you with services, charge different prices or provide you with different services simply because you exercise your privacy rights.
  • We will respond to your request to cancel your account within 15 business days (or you can cancel your account online immediately). For other requests related to your exercise of privacy rights, we will respond to your request within the period prescribed by law. In any of the above cases, if we cannot meet your request, we will explain. If you are not satisfied with our response, you can contact the relevant consumer protection agency.
  • Understand your choices

  • You can control how your personal information is collected or shared and how we communicate with you through the settings in your account. Here are some ways you can personalize your choices:
  • Choose how we collect personal information

  • In the “What Personal Information We Collect and Why We Collect It” section above, we explain what Personal Information is necessary to provide you with the Services and what Personal Information you can choose not to provide.
  • Choices about how Personal Information is collected and used across linked accounts

  • If you link your account to a service provided by a third party, you can manage how your Personal Information is collected, used, and shared with them. Please read the third party’s privacy policy to review the choices it makes available to you.
  • You can control which third-party services are linked to your account and what Personal Information they can collect about you. For example, you can manage permissions by going to the security settings in your Consenso account.
  • Choices about how we communicate with you

  • Your choices regarding how we communicate with you vary depending on the purpose and method of delivery of the relevant notification. Some notifications are optional, while others are necessary for you to manage your account. We communicate with you by email, text message, push notification to your mobile device, or physical mail, depending on the circumstances and your preferences.
  • You can opt out of receiving text messages by clicking on the unsubscribe link in marketing emails, sending a reply stating "unsubscribe," or turning off notifications on your device. You can also change your account notification settings or notification preferences on your device.
  • You will not be able to opt out of receiving notifications necessary for you to manage your account, such as receipts and emails alerting you to changes in your account status that require your attention. However, you can decide how we send you these notifications, such as by email, text message, or push notification to your mobile device.
  • How we protect the personal information of the deceased

  • If you are a close relative of a deceased Consenso user, you can exercise the rights under the "Know Your Rights" section, unless Consenso learns that the deceased has made other arrangements before his or her death.
  • Once you notify us that you wish to exercise the above rights, you will need to provide us with the deceased's valid identification document and death certificate, your own valid identification document, a notarized document that can prove your relationship with the deceased, and other documents that we may require based on the specific circumstances in order to protect the deceased's personal information rights.
  • Age Limits for Using Our Services

  • You must be at least 18 years old to open a Consenso account and use Consenso Services. If we learn that a person who is not permitted to use our Services has opened a Consenso account, we have the right to immediately cancel that account upon our request. We do not knowingly collect personal information from people who are not permitted to use our website and services, such as minors under the age of 18. If you believe that we have mistakenly collected personal information from someone who is not permitted to use our Services, please contact us. We will delete that personal information immediately unless we are required by law to retain it.
  • How we store and transfer your personal information globally

  • In principle, the personal information we collect will be stored. We will only store your personal information for the period necessary for the purposes described in this statement.
  • Because our services involve payment transactions, we need to transfer your personal information collected to overseas institutions. Cross-border transmission of personal information will be carried out in accordance with laws, regulations and relevant regulatory rules.
  • How this statement will be updated in the future

  • We may revise this privacy statement from time to time. This helps us keep up to date with changes in our business and the latest laws. When a new version is published, we will collect, store, use and protect your personal information in the same manner as outlined in the revised statement.
  • If a new version reduces your rights or changes the types of personal information we collect or the reasons for collecting it, we will post the relevant information on the page on our website at least 21 days before it takes effect. We may notify you of such changes by email or other communication.
  • How to contact us

  • If you have any questions about this privacy statement, your personal information or your deceased next of kin‘s personal information, please contact us so that we can help you.
  • Consenso隐私声明

    概述

    本隐私声明旨在说明在您浏览我们的网站或使用我们的服务时,Consenso将如何以及出于何种目的收集、存储、使用并共享您的个人信息。阅读本声明有助于您了解:

    “Consenso”在本声明中指Consens产品,我们致力于保护您的隐私和数据。您的个人信息安全对我们至关重要,我们遵循严格的内部准则、法律要求和行业最佳实践,以确保您的数据安全并仅用于授权目的。

    本隐私声明仅适用于您使用Consenso账户及相关的Consenso服务。欲了解适用于我们其他产品或服务的隐私政策,请浏览该等产品或服务的隐私声明。

    我们建议您仔细阅览本声明的内容并做出您视为适当的选择。请注意,我们特以黑体字标出可能涉及个人敏感信息的项目。

    我们收集哪些个人信息以及收集该等个人信息的目的

    A. 开设账户及使用支付服务

    当您注册或使用我们的支付服务时,例如当您开设账户、作出支付、在商户网站购物或维护您的账户(包括注销账户)时,我们可能收集您的个人信息。

    我们收集您个人信息的目的包括:

    为您开设账户或向您提供支付服务而必须收集的个人信息(包括敏感个人信息)类型载列如下。您如果不同意我们收集该些个人信息,将无法开立Consenso账户,而我们将无法向您提供Consenso服务。我们将仅在开设账户以及向您提供服务所需的情况下收集并处理敏感个人信息,并且我们将采取严格措施保护我们收集的所有个人信息(详见“我们如何保护您的个人信息”章节)。

    使用非品牌服务时收集您的个人信息–我们的某些服务在未登录或建立帐户的情况下也可使用。当您与商家互动并使用不带有Consenso品牌的银行卡支付服务向商家付款以及在不登录帐户就使用Consenso结帐时,我们将收集您的个人信息。对于我们的非品牌支付服务,您与商家的互动是在其平台上进行。如果您是帐户持有人或在稍晚创建帐户,我们可能以改善您作为帐户持有人的客户体验以及合规和分析目的,收集有关非品牌交易的信息并将其与您的帐户相关联。如果您不是帐户持有人,我们将收集和存储您提供的所有信息,并根据本隐私声明使用这些信息。

    B. 附加功能

    如果您同意,我们亦可向您提供附加功能,并因以下目的收集您的个人信息:

    我们为所有的附加功能收集以下类型的附加个人信息:

    您可以在任何时候选择是否为该等附加功能向我们提供您的个人信息。这将不会影响我们向您提供我们核心支付服务。

    个人信息的来源

    基于我们在上述“我们收集哪些个人信息以及收集该等个人信息的目的”部分描述的目的,我们可能从各种来源收集关于您的个人信息,例如:

    我们不会系统性地或大规模地从第三方购买或获得任何个人信息,但我们可能在向您提供Consenso服务的过程中,通过合法渠道(例如根据合同)从第三方收集您的个人信息。

    我们亦会根据适用法律或者政府或监管机构对我们的要求,而收集、使用,处理及共享您的个人信息。

    我们如何运用Cookie等追踪技术

    当您使用我们的服务、访问我们的网站或访问提供我们服务的网站时,我们或我们授权的服务提供商可能会使用 Cookie和类似的追踪技术来收集您的个人信息,此类追踪技术可能包括脚本、点击流、网络信标和软件开发工具包(SDK)。通过这些技术收集的信息将帮助我们个性化您的体验、衡量我们的广告效果、防止欺诈并加强我们的网站和服务的安全性。

    您可以禁用或拒绝我们的网站和服务的一些Cookie。但由于我们服务的某些部分依赖于关键Cookie运行,如果禁用或拒绝关键Cookie,这些服务可能会变得难以进行或无法使用。一些网络浏览器有一个名为“请勿追踪”(Do Not Track,DNT)的可选设置,让您选择不被广告商和一些第三方追踪。若没有追踪资料,我们的许多服务将无法运行,所以一旦您接受了 Cookie的使用,我们不会对DNT设置做出响应。

    我们如何及为什么共享个人信息

    我们不会出售您的个人信息。但是,我们可能会跨服务或与Consenso的其他成员共享您的个人信息。有时我们会与第三方共享我们收集到的个人信息,以便帮助我们提供服务、保护我们的客户免遭风险和欺诈、营销我们的产品,并遵守法律义务。

    您可以阅览我们收集哪些个人信息部分以获悉我们可能会共享哪些个人信息。相关个人信息类型的示例包括:

    我们可能会与以下对象共享个人信息:

    我们如何保护您的个人信息

    帮助确保您的个人信息安全,不致遗失、滥用、未经授权访问、披露和更改是我们的首要工作。

    为保护您的个人信息,我们运用符合行业最佳实践(例如ISO 27001和PCI DSS)的技术、物理和行政安全政策和程序以保障您个人信息的保密性、隐私性和完整性。这些政策和标准被定期审查和/或更新。我们为保护您的个人信息而采取的特定安全措施包括但不限于:

    在我们保护系统和服务的同时,您有责任将您的密码和帐户信息保密。您还有责任确保您的个人信息准确无误并保持最新。

    您的隐私权利及选择

    您有权选择我们如何收集、储存、使用和共享您的个人信息。

    了解您的权利

  • 您有权要求查看我们所收集并持有的关于您个人信息、要求我们更正或更新我们的记录,要求我们将您的个人信息转给另一服务提供者,或要求我们解释有关处理您的个人信息的规则。
  • 您亦有权要求我们在以下情况下删除我们收集并持有的任何您的个人信息:(i)未在本隐私声明中说明或者违反法律而收集并持有的,(ii)就此前收集个人信息的具体目的而言,处理目的已经实现、无法实现或者为实现处理目的不再必要,(iii)在法律要求收集或处理相关个人信息需要个人同意的情况下(例如不时向您发送我们所提供服务的更新信息),您撤回同意;但请注意在多数情况下我们处理您的个人信息是基于与您订立、履行合同所必需,因此根据法律规定无需取得您的同意,或(iv)我们停止提供相关服务,或相关信息的保存期限已经届满。
  • 如果保存期限未届满或删除个人信息从技术上难以实现,我们可能无法响应您提出的删除个人信息的要求,但我们将停止对您的个人信息进行除存储和采取必要安全保护措施之外的处理。我们将依照法律法规要求以及达到本声明所述目的所需时限制定个人信息的保存期限。
  • 如果您希望查阅、转移或删除您的个人信息或完全注销您的账户,请与我们联系或通过您的账户进行操作。
  • 如果您希望删除您的个人信息,您可以选择:
  • 我们服务的某些方面,例如账户登录、验证和防范欺诈行为,可能依赖诸如算法过程等自动决策机制。如果这些决定对您的权利和权益造成重大影响,您有权要求我们对自动决策机制予以说明并要求人工审查上述决定。如果您希望开展人工审查,请与我们联系。
  • 我们不会纯粹因为您行使隐私权而拒绝向您提供服务、收取不同的价格或向您提供差异性服务。
  • 我们将在15个工作日之内回应您注销账户的要求(或者您可以即时在线注销账户)。至于有关您行使隐私权的其他要求,我们将在法律规定的期限内回应您的要求。在上述任一情况下,如果我们无法满足您的要求,我们会予以解释。如果您对我们的回复不满意,您可以联系相关的消费者保障机构。
  • 了解您的选择

  • 您可以通过您账户中的设定,控制您的个人信息收集或共享方式以及我们与您的通讯方式。以下列举您可以个性化您选择的一些方法:
  • 选择我们收集个人信息的方式

  • 在上文“我们收集哪些个人信息以及收集该等个人信息的目的”一节中,我们向您说明哪些个人信息为向您提供服务所必要,以及哪些个人信息您可以选择是否提供。
  • 选择关联账户收集和使用个人信息的方式

  • 如果您将您的账户与某第三方所提供的服务相关联,您可以管理您个人信息的收集、使用和与其共享的方式。请阅读第三方的隐私政策,以查看第三方向您提供的选项。
  • 您可以控制将哪些第三方服务关联到您的账户,以及该等第三方可以收集哪些与您有关的个人信息。例如,您可到您Consenso账户中进行安全设定以管理权限。
  • 选择我们如何与您通信

  • 关于我们如何与您通信,您的选择根据相关通知的目的和交付方式有所不同。某些通知是选择性的,而另外一些通知对您管理账户是必要的。我们根据情况和您的偏好,运用电邮、短信、向您的移动设备推送通知,或者寄发纸质信件的方式与您通信。
  • 您可以点击营销电邮所附的取消订阅链接、发送注明“退订”的回函以拒绝收取短信,或关闭设备上的通知功能。你亦可以变更您设备上的账户通知设定或通知偏好。
  • 你将无法拒绝收取您管理账户所需的通知,例如提醒您的账户状态出现需要您关注的变动的收据和电邮。不过,您可以决定我们向您发送该等通知的方式,例如是以电邮、短信还是向您的移动设备推送通知。
  • 我们如何保护逝者的个人信息

  • 如果您是已故Consenso用户的近亲属,您可以行使“了解您的权利”章节下的权利,除非Consenso获悉逝者生前另有安排。
  • 一旦您通知我们希望行使上述权利,您需要向我们提供逝者的有效身份证件以及死亡证明,您本人的有效身份证件,能够证明您与逝者关系的公证文件,以及我们为保护逝者个人信息权利所需而根据具体情况可能要求的其他文件。
  • 使用我们服务的年龄限制

  • 您必须至少年满18岁,才可以开立Consenso账户并且使用Consenso服务。如果我们获知未获允许使用我们服务的人开立了Consenso账户,我们有权按照我们的要求即时注销该账户。我们不会在知情情况下收集未获允许使用我们网站和服务的人的个人信息,例如18岁以下的未成年人。如果您认为我们错误地从不被允许使用我们服务的人收集了个人信息,请与我们联系。除非我们依法需要予以保留,否则我们将立即将该个人信息删除。
  • 我们如何存储及在全球传输您的个人信息

  • 原则上,我们收集的个人信息将存储。我们仅就本声明所述目的在所需的期限内存储您的个人信息。
  • 由于我们服务涉及支付交易,我们需要将在收集的您的个人信息传送至海外机构。跨境传输个人信息将根据法律、法规和相关监管规则进行。
  • 本声明今后如何更新

  • 我们将不时修订本隐私声明。这有助于我们根据自身的业务变化和最新的法律与时俱进。新版本发布后,我们将按照在该经修订声明中概述的方式收集、存储、使用和保护您的个人信息。
  • 如果新版本削弱您的权利或变更我们收集的个人信息的类型或收集上述信息的原因,我们将在其生效前至少21天在我们网站内的页面发布有关信息。我们可能会通过电邮或其他通信方式通知您上述变更。
  • 如何与我们联系

  • 如果你对本隐私声明、您或您已过世近亲属的个人信息有任何疑问,请与我们联系,以便我们提供协助。