Privacy Notice
At bKash, we respect your privacy and are committed to protecting your personal and account information. This Privacy Notice explains how we collect, process/use, share, and protect your personal/account information, how we conform to these commitments, in accordance with applicable laws and regulations.
Categories of Information We Collect
We may collect the following types of personal information:
- Identity Information, e.g. name, date of birth, photograph, government-issued identification numbers (NID/Passport/Birth Certificate) or other photo ID (where applicable).
- Contact information, e.g. address, mobile number, email, etc.
- Financial Information, e.g. account number, balance information, transaction history and payment card details.
- Biometric Data, e.g. fingerprints, facial recognition data (if applicable and enabled by user).
- Usage Data, e.g. access logs, app usage behavior, support requests.
- Device Information, e.g. device type, operating system, IP address, location data (if required and permitted).
- KYC/AML Data, e.g. customer due diligence, source of funds, occupation, risk category.
Purpose of Processing
We collect and process your personal information for the following purposes:
- To register and manage your bKash account.
- To process your financial transactions and facilitate services.
- To verify your identity, ensure security and prevent fraud.
- To improve our services and user experience.
- To send important updates about your account.
- To provide customer support and respond to inquiries.
- To comply with legal and regulatory requirements.
- To send promotional offers.
Legal Basis for Processing
We process your information based on the following legal bases:
- Contractual Necessity: To provide the services you request, e.g. bank transfers, utility bill payments, remittances, and card transactions and manage your account.
- Legal Obligation: To comply with applicable laws and regulations.
- Legitimate Interests: To prevent fraud and improve services, where such interests do not override your rights.
- Consent: Where you have given clear, informed consent for one or more specific purposes, e.g., for receiving promotional messages or participating in surveys, location tracking, optional data sharing.
- Vital Interests: In case of emergency, to protect your life or safety or that of others (where consent can't be obtained) for example, suspected fraud/loss.
Data Retention
We retain your personal data to fulfill the purposes outlined herein at least for the period as required by laws and regulations.
Who We Share Your Data with and Why
Your personal information may be shared with the following categories of parties :
- Partner Banks/Financial Institutions/Card Networks/Payment Intermediaries: Solely to process co-partnered services (under Contractual Necessity) such as bank transfers, utility bill payments, remittances, and card transactions. Information is disclosed only to the parties directly involved in completing the transaction, and only to the extent necessary to provide the requested service.
- With Authorized Service Providers: Third-party service providers (e.g., vendors, etc.) under strict confidentiality agreements. This sharing is based on Contractual Necessity or Legitimate Interests and is limited to what is strictly required to provide the requested service.
- With Government and Regulatory Authorities: Government agencies or regulatory bodies under Legal Obligation as required by law.
- With any court of law or tribunal: Having jurisdiction over bKash Limited subject to applicable laws.
Data Security
We implement strong security measures (administrative, technical, and physical safeguards) to protect your personal information, including:
- Encryption: Encrypting sensitive data.
- Role Based Access Controls: Limiting access to personal information to authorized personnel.
- Regular Security Audits: Conducting regular security audits to identify and address vulnerabilities.
- Incident Response Plan: Having a robust incident response plan to respond to security breaches.
Your Rights
You have certain rights regarding your personal information, including:
- Access: The right to access (e.g. obtain a copy of) your personal information.
- Rectification: The right to request correction of inaccurate or incomplete personal information.
- Erasure: The right to request the erasure of your personal information, subject to legal limits (data retention period).
- Restriction of Processing: The right to restrict or limit the processing of your personal information in specific circumstances.
- Objection: The right to object to the processing of your personal information based on legitimate interests.
Contact
If you have any questions or concerns about our privacy notice or data practices, please contact us at [email protected]. We are committed to protecting your data and resolving any concerns promptly.
Updates to This Notice
We may update this Privacy Notice to reflect changes in our practices or regulatory requirements. We encourage you to review it periodically on our website or app.