Legal · Draft

Privacy Policy

Last updated · Draft v0.1

Unreviewed draft, not legal advice, not published

This page is a first-pass working draft prepared for review by qualified legal counsel and EKKA's compliance and issuing partners. It has not been approved, is not in effect, and must not be relied upon, quoted, or published until reviewed and sign-off is obtained from counsel and the relevant compliance / issuing partners.

ContentsController and processorsOpenClose
  1. 1Controller and processors
  2. 2What we collect
  3. 3Lawful bases
  4. 4Purposes of processing
  5. 5Sharing your data
  6. 6International transfers
  7. 7Retention
  8. 8Your rights
  9. 9Cookies and tracking
  10. 10Children
  11. 11Security measures
  12. 12Breach notification
  13. 13Contact and complaints

1. Controller and processors

Needs legal input

This policy currently names [[LEGAL ENTITY NAME]] as controller of customer data collected for the EKKA app and card. However, the card infrastructure provider (Swipeo) and the underlying issuer/BIN sponsor also independently process cardholder data (identity, KYC, transaction) to issue and operate the card. Whether EKKA and these partners act as independent controllers, joint controllers, or controller/processor requires a documented data-processing agreement and legal sign-off before this section can be finalised.

Data Protection Officer / privacy contact: [[DATA PROTECTION OFFICER CONTACT]].

2. What we collect

  • Identity and KYC documents (government ID, proof of address, selfie/liveness images)
  • Biometric data derived from selfie/liveness verification, where used: [[BIOMETRIC PROCESSING BASIS]]
  • Device and usage data (device identifiers, IP address, app interaction, crash and diagnostic logs)
  • Transaction data (card spend, funding events, merchant, amount, timestamp)
  • Blockchain addresses and on-chain transaction data associated with USDC/USDT funding
  • Other categories: [[ADDITIONAL DATA CATEGORIES]]

3. Lawful bases

Processing is carried out on the basis of contract performance, legal/regulatory obligation (including AML/KYC law), legitimate interests, and consent where required. Jurisdiction-specific lawful basis mapping for India (DPDP Act) and the UAE (PDPL): [[LAWFUL BASIS MAPPING BY JURISDICTION]].

4. Purposes of processing

  • Identity verification and onboarding (KYC/AML)
  • Card issuance, funding, and transaction processing
  • Fraud prevention and transaction monitoring
  • Customer support and service communications
  • Product analytics and service improvement
  • Marketing, where consented: [[MARKETING CONSENT MECHANISM]]

5. Sharing your data

Personal data is shared with parties necessary to issue and operate the card and to meet legal obligations, including:

  • The card infrastructure provider (Swipeo) and the underlying issuer / BIN sponsor
  • The card network (Visa)
  • KYC and identity verification vendors: [[KYC VENDOR / VERIFICATION STANDARD]]
  • Blockchain analytics vendors: [[BLOCKCHAIN ANALYTICS VENDOR + RISK THRESHOLDS]]
  • Analytics, infrastructure, and cloud providers: [[COOKIE LIST / VENDOR NAMES]]
  • Regulators and law enforcement, where legally required: [[REGULATOR]]

6. International transfers

Needs legal input

EKKA operates across India and the UAE and works with infrastructure and issuing partners that may process or store data outside the customer's home jurisdiction. Cross-border transfer mechanisms (standard contractual clauses, adequacy, or local-law equivalents under India's DPDP Act and the UAE's PDPL) are not yet defined and must be confirmed with counsel for each transfer flow, including transfers to [[ISSUING PARTNER + LICENCE NO.]] and any group/vendor entities outside India or the UAE.

7. Retention

Personal data is retained for the periods set out below, or as required by applicable law, whichever is longer: [[DATA RETENTION PERIODS BY CATEGORY]].

8. Your rights

Needs legal input

Data subject rights differ across jurisdictions: India's Digital Personal Data Protection (DPDP) Act, the UAE's Personal Data Protection Law (PDPL), and, depending on where [[LEGAL ENTITY NAME]] is incorporated and which customers it serves, the EU/UK GDPR may separately apply. The specific rights available to a given customer (access, correction, erasure, portability, objection, withdrawal of consent, and the applicable complaint route) must be confirmed per jurisdiction before publication.

Requests can be made to [[COMPLIANCE CONTACT EMAIL]].

9. Cookies and tracking

The EKKA app and website use cookies and similar technologies for authentication, security, analytics, and (where consented) marketing. Full vendor and purpose list: [[COOKIE LIST / VENDOR NAMES]].

10. Children

EKKA is not directed at, and is not intended for use by, individuals under the age of majority in their jurisdiction. We do not knowingly collect personal data from children.

11. Security measures

We apply technical and organisational measures appropriate to the sensitivity of the data processed, including encryption in transit and at rest, access controls, and vendor due diligence. Detailed security programme reference: [[SECURITY PROGRAMME / CERTIFICATIONS]].

12. Breach notification

In the event of a personal data breach that meets the applicable notification threshold, we will notify affected individuals and the relevant regulator within the timeframe required under applicable law. Notification procedure and timelines: [[BREACH NOTIFICATION PROCEDURE]].

13. Contact and complaints

Privacy questions or requests: [[DATA PROTECTION OFFICER CONTACT]]. If you are not satisfied with our response, you may lodge a complaint with [[REGULATOR]] or the applicable data protection authority for your jurisdiction.