Effective date: 30/07/26
We are committed to protecting and respecting your privacy and to handling your information in an open and transparent way. Keeping your personal information secure is extremely important to us.
This global privacy notice ("Notice") applies to the processing of personal information by NALA companies in connection with our money transfer and remittance services, the NALA app and websites, the NALA USD Global Account, and any other product that links to this Notice. It explains what we do with your information, how we keep it secure, who we share it with, how we contact you, your rights, and who to contact.
Which NALA company is responsible for your information depends on where you live and which product you use. The country sections at the end tell you which company is responsible for you, which law applies, which regulator supervises us, and any additional rights you have. Where a country section differs from the general sections, the country section applies to you.
NALA is a group of companies providing cross-border payment services. The company responsible for your information, and its address, is in your country section. Our Data Protection Officer is Sunny Vara, contactable at privacy@nala.money.
This is not a contract, and not a request for your consent. Reading it or continuing to use our services does not mean you have consented to anything. Most of what we do is based on our contract with you, on legal obligations that apply to us as a regulated financial business, or on our legitimate interests. Where we do need consent, for example for marketing or for access to your device contacts, we ask separately and you must take positive action such as ticking a box that we have not pre-ticked. We never treat silence, an unticked box, or continued use as consent. You can withdraw consent at any time, as easily as you gave it, without affecting anything we did lawfully beforehand.
These are the categories of information we collect. If we need to start collecting something that does not fit one of them, we will update this Notice before we begin.
We get this information directly from you; automatically from your device; from identity, screening, credit reference and fraud prevention providers; from our Partners, banks and mobile money operators; from public registers, government identity databases where we may check them, and public sources used for adverse media screening; and from third-party sign-in providers where you use them.
If someone sends you money. We hold your name, contact details and payment details because the sender gave them to us. We will provide you with this Notice when we first contact you or when you open an account, whichever is earlier. We will not send you marketing based on information a sender gave us.
To open an account, you must prove who you are. Depending on your country and product, we ask you to photograph an identity document and take a photograph or short video of your face. Where that image is analysed automatically to represent your facial features, compare your face with your document, or confirm a real and living person is present, the result is biometric information used to identify you. Biometric information is sensitive in every country where we operate and receives additional protection.
We use it only to verify your identity, prevent impersonation and fraud, and show our regulators we verified you properly. We do not use it to advertise to you, build a commercial profile of you, or analyse your mood or emotions. The legal condition we rely on is in your country section. In most cases it is the substantial public interest in preventing and detecting unlawful acts, or your explicit consent where no other condition applies. Additional written notice and permission rules apply in parts of the United States and are set out in that section. We keep biometric information for the period set out in section 10, because our financial crime record-keeping obligations require us to be able to show how we verified you.
Checking where you are. Some of our services are only available to people living in countries, and financial services law requires us to know where our customers are. Where the phone number you sign up for, or the identity document you give us, already shows this, we do not need anything further. Where it does not, we will ask your permission to check the location of your device when you sign up or make a payment.
You can say no. If you do, we will not refuse you the service on that basis alone. Instead, we will either check the address you have already given us against an independent database or ask you for a document confirming your address. We use the device location only to confirm the country you are in. We do not use it to track your movements, we do not keep a history of where your device has been, and we never use it for advertising. You can withdraw the permission at any time in your device settings.
We use automated systems to accept or reject verification attempts, to flag or block payments for financial crime screening, and to restrict, suspend or close accounts where fraud rules are triggered, for example where an account is accessed from several devices in a short period.
Where a decision is made by automated means with no meaningful human involvement and has a legal or similarly significant effect on you, you can ask for a person to review it, explain your point of view, and contest the outcome. Suspending or closing your account, and refusing to open one, are significant decisions. Contact us using the details in section 13 and say you are asking for review of an automated decision. A person with authority to change it will review it and tell you the outcome and our reasons. Where a decision is required by anti-money laundering or sanctions law, we may be unable to reverse it, and the law may prevent us explaining why. If so, we will tell you a legal restriction applies rather than give you a different reason.
We contact you by in-app message and push notification, email, SMS, WhatsApp and similar messaging apps, telephone, and post where necessary. Our communications fall into two types, and the difference matters because your choices apply to one and not the other.
Artificial intelligence. Some communications are managed by artificial intelligence systems rather than a person, including some telephone calls, chat sessions, and message responses. Where that is the case we will tell you clearly at the start, and you can ask at any point to be transferred to a person. We will not present an artificial intelligence system as though it were a named member of our staff. An artificial intelligence system will never be the one to tell you that your account has been restricted, suspended, or closed, will never manage your request to have an automated decision reviewed, and will never manage a complaint. Those always involve a person. We do not use artificial intelligence to analyse your voice, face, or choice of words to infer your emotional state.
Call recording. We will record some calls and will tell you before recording begins. Where the law requires your permission, we will ask, and if you decline, we will continue the call without recording rather than end it. Recordings are used to confirm identity, resolve disputes, meet our regulatory record-keeping obligations, and monitor service quality.
Message security. NALA will never ask for your password, a one-time passcode, your full card number, or a photograph of your identity document by SMS, WhatsApp, email, or telephone. If you receive such a message, it is not from us. Report it to privacy@nala.money.
How we ask. We are introducing a new way of asking for your permission. When you sign up, we will ask you separately whether you want to hear from us, using a tick box that is not pre-ticked and is not bundled with accepting our terms or with opening your account. You will be able to open and use a NALA account without agreeing to marketing, and to change your mind at any time in your app settings. We will ask you channel by channel, so agreeing to email will not mean you have agreed to SMS, WhatsApp or telephone calls. Until that is in place, we rely on the permissions you have already given us and on the routes in your country section, and you can stop marketing at any time as described below.
What we send. New products, features and corridors as they become available in your country; offers, promotional rates and referral schemes; invitations to give feedback, join a testing group or attend an event; and reminders where you started something and did not finish it, such as an incomplete registration or an unsent transfer.
How often. How often we contact you depends on the products you use, where you live and what is happening with your account, so we do not set a fixed monthly number. What we do commit to is not sending you marketing messages in quick succession and giving you a straightforward way to reduce or stop them entirely at any time.
Our legal basis. Your consent, in every country where consent is required. In a small number of countries, the law allows us to contact you about products similar to those you already hold without separate consent, provided we offered you the chance to opt out when we collected your details and offer it in every message. Where we rely on that, we rely on our legitimate interests, and it is stated in your country section. We never rely on it for automated or artificial intelligence telephone calls.
What is always true? Every marketing message identifies NALA and the NALA company sending it, gives you a way to contact us, and contains a straightforward way to opt out. Opting out is free and no harder than giving permission. We keep a record of the permission or objection you gave, when you gave it and how, so we can show we honoured it.
How to stop it. You can stop marketing on a single channel or on all of them. To stop one channel, use the unsubscribed link in any email, reply STOP to any SMS, or use the opt-out in any WhatsApp message. That stops marketing on the channel you use. To stop all marketing at once, use the marketing preferences in the app, tell any NALA agent, or email privacy@nala.money. We will stop marketing you on every channel and across every NALA company, and we are building a single control so that one instruction takes effect everywhere automatically. Whichever route you use, we act on it as soon as we can and without unnecessary delay. Some laws allow us to stay up to ten business days; we do not use that time as a target. If a message reaches you after you have opted it out, tell us and we will investigate it as a complaint.
What we will never do. We will never market to a person whose details came from another customer’s contact list, or to a person who has only ever received money through NALA without opening an account. We will never contact your friends, family or contacts about your account, your balance, or any money you owe. We will never sell your information to another company or that company to market to you.
Every provider processing information on our behalf must sign a written agreement requiring it to act only on our instructions, keep your information secure, help us respond to your requests, and delete or return it at the end of the arrangement. Where a Partner, bank or platform acts as a controller, its own notice also governs what it does. This Notice governs your relationship with NALA.
Moving information across borders is part of a cross-border payments service. Separately from any movement of money, several of the providers who help us run the service, including Twilio, Intercom, Meta and Amazon Web Services, are based in or route information through the United States. We do not simply assert that your information is protected. For every transfer route we rely on a specific legal mechanism, which we record and will describe to you on request.
We keep information only as long as we need it, unless a longer period is required by law, a regulator or a court, or the information is needed for a live investigation, complaint or claim, in which case we keep it until that is resolved and for a reasonable period afterwards. Closing your account does not by itself end these periods, because the law requires us to keep certain records after you leave. Anti-money laundering law sets a minimum retention period that differs by country, so where you live determines which period applies to you. Where more than one period could apply, we keep the record for the longest of them.
When a period ends, we delete your information or make it permanently anonymous. Because anti-money laundering law requires us to keep identity and transaction records, we cannot always delete everything when you ask. Where we cannot delete, we restrict instead, which means we keep the information but stop using it for anything other than the legal purpose requiring us to hold it.
We use technical and organisational security measures appropriate to the risk, including encryption in transit and at rest, access controls limiting access to those who need it, multi-factor authentication for internal systems, network monitoring, logging and audit trails, secure development and code review, vulnerability scanning and independent penetration testing, security assessment of suppliers before appointment, staff background screening and mandatory training, and documented incident response and business continuity procedures. Where you have a password, you are responsible for keeping it confidential.
If a personal data breach is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within the period required by law, which is 72 hours in most countries where we operate. Where it is likely to result in an elevated risk to you, we will also tell you directly and without undue delay, explaining what happened, what it means to you, what we are doing, and what you can do. Report a suspected compromise or security problem to privacy@nala.money.
Subject to the conditions and exceptions in the law where you live, you have the following rights. Two of them are often confused, so we set them out separately.
To exercise a right, contact our Data Protection Officer. We will verify your identity first, because we will not disclose your information to someone who is not you. We do not charge a fee unless a request is clearly unfounded or excessive. If we cannot do what you asked, we will tell you why and how to complain. You may ask someone else to make a request for you where local law allows, with written evidence of your authorisation.
Please complain to us first, by emailing privacy@nala.money or by using our complaints procedure at nala.com/complaints-procedure. We will acknowledge your complaint, investigate, keep you updated and tell you the outcome and our reasons. The time limits that apply to us are in your country section. You also have the right to complain to your data protection regulator, named in your country section, and complaining to us does not take that away.
Children. Our services are for adults, and you must be at least eighteen to hold a NALA account. We do not knowingly collect information from children and will delete it if we learn we hold it.
Cookies. We use cookies and similar technologies on our websites and comparable identifiers in our app. Strictly necessary technologies are used without asking you. For everything else, including analytics and any advertising technology, we ask permission through our cookie banner, except where local law allows a specific technology to work on an opt-out basis, as noted in your country section. You can change your choices at any time. Our Cookie Notice sets out each technology, what it does, how long it lasts and who provides it.
Changes. We review this Notice at least annually and whenever we change what we do with your information. Where a change is material, we will tell you at least 30 days beforehand by email or prominent in-app notice, and where it affects something, we rely on your consent for we will ask again. Minor changes take effect when published. Continuing to use our services after a change does not mean you have accepted it. Previous versions are available on request.
Contact. Data Protection Officer: Sunny Vara, as Data Protection Officer for NALA. Email privacy@nala.money. Telephone, United States: (877) 716-9669. Post: NALA Payments Ltd, International House, 64 Nile Street, London N1 7SR, United Kingdom; NALA Payments Netherlands B.V., Johan Cruijff Boulevard 65, 1101 DL Amsterdam, Netherlands; Nala Payments LLC, 221 River Street, 9th Floor, Hoboken, New Jersey 07030, United States; Mirage Towers, Tower 2, Floor 8, Nairobi, Kenya; 36 Toronto Street, Suite 850, Toronto, Ontario M5C 2C5, Canada.
This section applies in addition to the general sections if you hold or apply for a NALA USD Global Account, sometimes called the USD Wallet or a Global Account. Where it differs from the general sections, this section applies to your Global Account.
Responsible company. NALA Payments Limited, registered in England and Wales with company number 12792210, International House, 64 Nile Street, London N1 7SR. A registered EMD agent of Modulr FS Limited, an Electronic Money Institution authorised by the Financial Conduct Authority, firm reference number 900573. Electronic money products are not covered by the Financial Services Compensation Scheme. Funds are held in segregated accounts and safeguarded under the Electronic Money Regulations 2011.
Law and legal bases. UK GDPR and the Data Protection Act 2018 as amended by the Data (Use and Access) Act 2025, the Privacy and Electronic Communications Regulations 2003, and the Money Laundering Regulations 2017. We rely on Article 6(1)(b) contract, 6(1)(c) legal obligation, 6(1)(f) legitimate interests, and 6(1)(a) consent. For biometric information we rely on Article 9(2)(g), read with paragraph 12 of Part 2 of Schedule 1 to the Act, supported by the appropriate policy document required by Part 4, or on your explicit consent.
Automated decisions. Articles 22A to 22D of the UK GDPR permit significant automated decisions where safeguards are in place. We provide them: we tell you when such a decision is made, you can make representations, obtain human review, and contest it.
Marketing. We ask for your consent for marketing by email, SMS, or messaging app. Where you are an existing customer, the marketing relates to similar NALA products, and we gave you the chance to opt out when we collected your details, regulation 22(3) of the Privacy and Electronic Communications Regulations allows us to contact you without separate consent; where we use that, our basis is legitimate interests. We will not make a marketing call to a number registered with the Telephone Preference Service unless you have told us we may. Marketing calls using an automated or artificial intelligence voice require your prior consent under regulation 19 and the existing-customer route is not available for them. We ask for consent for all non-essential cookies.
Rights and complaints. We respond within one month, extendable by two further months for complex or numerous requests with notice within the first month. Where we need to verify your identity or clarify your request, the period runs from when we receive that. You have a statutory right under section 164A of the Data Protection Act 2018 to complain directly to us. You can do so by emailing privacy@nala.money or through our complaints procedure at nala.com/complaints-procedure. We will acknowledge within 30 days, respond, and keep you informed of progress and the outcome. You may also complain to the Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, ico.org.uk, 0303 123 1113.
Transfers. The UK International Data Transfer Agreement or the Addendum to the European Commission Standard Contractual Clauses, supported by a transfer risk assessment; the UK Extension to the EU-US Data Privacy Framework where the United States recipient is certified to that Extension; or an adequacy determination by the Secretary of State.
Responsible company. NALA Payments Netherlands B.V., registered with the Netherlands Chamber of Commerce under number 90375696, Johan Cruijff Boulevard 65-71, 1101 DL Amsterdam, Netherlands. A partner of Modulr Finance B.V., company number 81852401, authorised and regulated by De Nederlandsche Bank as an Electronic Money Institution, relationship number R182870. Your account and related payment services are provided by Modulr Finance B.V. and funds are safeguarded under the Financial Supervision Act.
Law and legal bases. The GDPR (EU) 2016/679, the ePrivacy Directive as implemented in the Netherlands by the Telecommunicatiewet, the EU Artificial Intelligence Act (EU) 2024/1689, and the anti-money laundering directives as implemented locally. We rely on Article 6(1)(b), (c), (f) and (a), and for biometric information on Article 9(2)(g) as implemented in Dutch law or your explicit consent under Article 9(2)(a).
Automated decisions and artificial intelligence. Article 22 of the GDPR applies: we make significant solely automated decisions only where necessary for our contract, authorised by law, or based on your explicit consent, always with the safeguards in section 5. Under Article 50 of the Artificial Intelligence Act we will tell you when you are interacting with an artificial intelligence system unless it is already obvious, and we mark artificial intelligence generated content we publish.
Marketing. We ask for your consent for marketing by email, SMS, messaging app, or telephone. A narrow exception applies for existing customers in respect of our own similar products. We ask for consent for all non-essential cookies, including analytics.
Rights and complaints. One month, extendable by two further months for complex or numerous requests with notice within the first month. You may complain to the Autoriteit Persoonsgegevens at autoriteitpersoonsgegevens.nl, or to the supervisory authority in the EU country where you live, where you work, or where you believe the problem occurred.
Transfers. The EU-US Data Privacy Framework where the United States recipient is certified to it, or the European Commission Standard Contractual Clauses supported by a transfer impact assessment, or an adequacy decision. Transfers to the United Kingdom rely on the European Commission’s adequacy decision for the United Kingdom.
Responsible companies. Nala Inc., a Delaware corporation, registration number 6862795, 251 Little Falls Drive, Wilmington, Delaware 19808; Nala Payments LLC, a Delaware limited liability company, registration number 7492957; and Mufasa Payments LLC, a Delaware limited liability company, registration number 451168047. Both LLCs operate from 221 River Street, 9th Floor, Hoboken, New Jersey 07030. Nala Inc. is a financial technology company, not a bank, and partners with Sila Inc. and Priority Technology Holdings Inc., directly or through Finxera, Inc. and their partner banks, to offer electronic fund transfers. Mufasa Payments LLC is a financial technology company, not a bank, and partners with Lead Bank. In certain states in the United States where it holds the necessary licenses, money transmission services may be provided by Nala Payments LLC (NMLS: 2530895), a subsidiary of Nala Inc., pursuant to its own state-issued money transmitter licenses and registration as a Money Services Business (MSB) with the United States Treasury Financial Crimes Enforcement Network (MSB: 31000335047569). Your funds are held at our partner banks. NALA does not insure your funds, and we do not represent that any balance held with NALA is insured by the Federal Deposit Insurance Corporation.
Which laws apply to you? Our collection and use of information in providing a financial product or service is governed primarily by federal law, including the Gramm-Leach-Bliley Act and Regulation P. Information that falls outside that scope is governed by the privacy law of your state. Some states no longer exempt financial institutions at entity level, so their state law applies to us alongside federal law. Connecticut removed that exemption with effect from 1 July 2026.
States with a comprehensive privacy law. As at the date of this Notice these are Arkansas, California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia. Washington and Nevada have separate consumer health laws. If you live in one of these states, the rights set out below apply to you. If your state introduces a law after this Notice is published, we will apply it from the date it takes effect whether we have updated this Notice by then.
Your rights in those states. To confirm whether we hold information about you and to access it; to receive a copy in a portable and readily usable format; to correct information that is inaccurate; to have information deleted; to opt out of the sale of your information, of sharing it for targeted advertising, and of profiling used to make decisions that produce legal or similarly significant effects; to limit or withhold your consent for the use of sensitive information; to appeal if we refuse a request; and not to be treated worse for exercising any of these rights. Some states go further. Connecticut and Oregon ask for a list of the specific third parties we disclosed your information to. Minnesota lets you question the result of profiling. Connecticut lets you ask us to review a decision made about you by automated means.
Sensitive information. Most states require your opt-in consent before we process sensitive information, including Virginia, Colorado, Connecticut, Indiana, Kentucky, and Rhode Island. California takes a different approach and lets you limit how we use it after collection. The sensitive information we hold about you may include your Social Security Number, government identifiers such as a driver’s licence number, financial account details combined with login credentials, facial images used to identify you, and the precise location of your device where you have given permission for us to check it. Most states treat precise geolocation as sensitive information requiring your opt-in consent. The permission prompt on your device is how we obtain that consent, and you can withdraw it at any time in your device settings without losing access to the service. Several states, including Connecticut and Maryland, restrict or prohibit the sale of sensitive information. We do not sell sensitive information in any state.
Universal opt-out signals. We honour the Global Privacy Control browser signal as a valid opt-out request. Recognising a universal opt-out signal is required in California, Colorado, Connecticut, Delaware, Maryland, Minnesota, Montana, New Hampshire, New Jersey, Oregon and Texas, and we apply it in every state rather than only where it is mandatory.
Sales, sharing, and targeted advertising. We do not sell your personal information, and we do not share it with cross-context behavioral advertising. If that ever changes, we will update this Notice before it happens and provide a clearly labelled Do Not Sell or Share My Personal Information link.
California. Under the CCPA as amended by the CPRA you have the right to know, access, delete, correct, port, limit the use of sensitive personal information, opt out of sale and sharing, and non-discrimination. The categories we collect, our sources, our purposes, the categories of recipient and our retention periods are set out in sections 2, 3, 8 and 10. To make a request, email privacy@nala.money or call (877) 716-9669, giving your full name, your preferred method of response and your address if you want a postal reply. We may need to verify your identity. For security reasons we do not accept privacy requests by fax. Under California Civil Code section 1798.83 you may request a list of third parties to whom we disclosed personally identifiable information for their direct marketing purposes in the preceding calendar year; we have made no such disclosures. Where we use automated decision-making technology in a way that produces a significant effect on you, we give you the pre-use notice and the opt-out required by the California Privacy Protection Agency regulations.
Nevada. Under chapter 603A of the Nevada Revised Statutes you may ask us not to sell your covered information. We do not sell your information, but you may still submit a request to privacy@nala.money.
Biometric information. If you live in Illinois, Texas or Washington, additional biometric identifier laws apply. Where they do, we give you written notice of the specific purpose for which we are collecting your biometric information and how long we will keep it, and we obtain your written permission before we collect it. The retention period that applies to you is in section 10.
Text messages and WhatsApp. We will only send you marketing text messages or WhatsApp messages where you have given us your prior express written consent, which we will collect through the unbundled tick box described in section 7. Consent to receive marketing messages is not a condition of buying any product or service from NALA, and you can open and use an account without giving it. When we ask, we will tell you the name of the messaging programme, that message frequency varies, and that message and data rates may apply. You can stop at any time by replying STOP to any message, and you can get help by replying HELP. You can also stop by emailing privacy@nala.money, changing your preferences in the app, or telling any NALA agent, and we will act on it immediately whichever route you use. Federal rules allow up to ten business days to give effect to a revocation, and we do not use that time. Carriers are not liable for delayed or undelivered messages, and delivery depends on your carrier, your device and network conditions. WhatsApp messages are delivered by Meta and are also subject to Meta’s own business messaging rules, which require you to have opted in to receive business messages regardless of what the law requires. We will never send you marketing on a number we obtained from anyone other than you.
Telephone calls. Under the Telephone Consumer Protection Act, calls using an artificial or prerecorded voice, including a voice generated by artificial intelligence, are made only with your prior express consent. On any such call we identify NALA at the start and give you a telephone number or address you can use to contact us. Marketing calls to a mobile number are made only with your prior express written consent. We screen against the National Do Not Call Registry and our own internal do-not-call list, and we call only between 8am and 9pm local time. Several states, including Florida, Oklahoma and Maryland, have their own telemarketing and text messaging laws that are stricter than the federal rules. Where a stricter state rule applies to you, we follow it.
Call recording. Where the law of your state requires the consent of all parties to record a call, we ask for your consent before recording and we do not record if you decline.
Rights and complaints. We acknowledge your request within 10 days and respond within 45 days, extendable to 90 days in total, where we tell you the reason. Access and portability requests are limited to twice in any 12-month period. Where we refuse a request and your state gives you an appeal right, we tell you how to appeal and we respond to the appeal within the period your state allows. If we deny your appeal, we will tell you how to complain to your State Attorney General. You may complain to your State Attorney General, and in California to the California Privacy Protection Agency. Complaints about Lead Bank may be made to the Federal Deposit Insurance Corporation, 1100 Walnut Street, Suite 2100, Kansas City, Missouri 64106, (800) 209-7459.
Responsible company. NALA Payments Canada Inc., an Ontario corporation, corporation number 1000609102, registered office 100 King Street West, Suite 6200, 1 First Canadian Place, Toronto, Ontario M5X 1B8. Correspondence address 36 Toronto Street, Suite 850, Toronto, Ontario M5C 2C5. Registered with FINTRAC as a money services business, licence M233633667.
Law and consent. The Personal Information Protection and Electronic Documents Act, Canada’s Anti-Spam Legislation, and, in Quebec, the Act respecting the protection of personal information in the private sector. Canadian law is built around meaningful consent: we identify our purposes at or before collection and obtain your consent for them, except where the law allows us to proceed without it, such as meeting a legal obligation or investigating a breach of an agreement.
Marketing. We will not send a commercial electronic message, including email, text, or messaging app message, without your express consent or implied consent from an existing business relationship. Implied consent lasts 24 months after a qualifying transaction or six months after an enquiry. Every message identifies NALA, gives our contact information, and contains an unsubscribe mechanism that stays working at least 60 days. Canadian law allows us up to ten business days to give effect to an unsubscribe request; we do not use that time and we act immediately. We keep consent records for three years after our relationship ends. Telephone calls are governed by the Unsolicited Telecommunications Rules and the National Do Not Call List, and calls using an automated dialling announcing device require your express consent.
If you live in Quebec. You have additional rights. We tell you before using technology that identifies, locates, or profiles you and how to switch it off. Where a decision is based exclusively on automated processing we tell you, and you may make representations to a member of our staff who can review it. You have rights to data portability and to ask us to stop disseminating information about you or to de-index it. Documents we provide are available in French. We conduct a privacy impact assessment before communicating personal information outside Quebec.
Transfers and complaints. We remain accountable when we transfer information for processing and use contractual measures to ensure comparable protection. You may complain to the Office of the Privacy Commissioner of Canada at priv.gc.ca, in Quebec to the Commission d’accès à l’information du Québec, and about commercial electronic messages to the Canadian Radio-television and Telecommunications Commission.
In each of these markets we are registered with the supervisory authority as required, we rely on performance of our contract with you, compliance with anti-money laundering and payment services law, our legitimate interests in preventing fraud and improving our service, and your consent for marketing, and we treat biometric information as sensitive personal data requiring a qualifying condition or your explicit consent. We do not use any existing-customer marketing exception in these markets. We aim to respond to rights requests within 30 days.
We operate corridors into the markets below. If you send or receive money through NALA in one of them, this Notice applies to you, and local data protection law applies to your information. We register with the local supervisory authority where registration is required, and we rely on the same lawful bases set out in section 3. In all these markets we ask for your consent before sending you marketing, we act immediately if you tell us to stop, and we do not use any existing-customer marketing exception.
Asia
We operate corridors into the markets below. If you send or receive money through NALA in one of them, this Notice applies to you, and local law applies to your information. In all these markets we ask for your consent before sending you marketing, and we act immediately if you tell us to stop.
NALA operates in a changing set of markets, and this Notice applies to you even if your country does not have its own section. That will usually be because you have received money sent through NALA rather than opened an account, or because we have recently opened a corridor into your country.
The standard we apply everywhere. Wherever we operate, and whatever the local law says, we commit to the following as a minimum. We tell you what we collect and why, and we do not use your information for a new purpose without telling you. We rely on a lawful basis for everything we do, and we do not rely on your consent where a different basis is more appropriate. We collect only what we need and keep it only as long as we need it, subject to the record-keeping periods in section 10. We keep your information secure using the measures in section 11 and tell you about a serious breach. We only send you marketing if you have asked for it, and we act immediately when you tell us to stop. We give you the rights in section 12, including access, correction, deletion, objection, and withdrawal of consent, whether your local law requires them. We only transfer your information across a border on one of the mechanisms in section 9. We hold our service providers to written contracts on the terms in section 8. And you can always complain to us using the details in section 13.
Where local law says more. Where the law in your country gives you rights or protections beyond this Notice, those apply in addition, and you can exercise them by contacting our Data Protection Officer in the ordinary way. Where the law in your country conflicts with this Notice, we follow local law and apply the higher standard of protection to the extent we are permitted to. Where your country has a data protection regulator, you may complain to it; if you are not sure who that is, ask us and we will tell you.
Where local law says less. Some countries have no data protection law, or a law that is not yet in force. We do not treat that as a reason to give you less. The standard above applies to you regardless.
New markets. When we open a corridor into a new country, we assess the local requirements before we start, register with the local authority where registration is required, and update this Notice. If you want to know which NALA company holds your information, what law applies to you, or how to exercise your rights, contact our Data Protection Officer at privacy@nala.money and we will tell you.
This Privacy Notice was last updated on 30/07/26. Previous versions are available on request.