Privacy Policy Statement

This Privacy Policy Statement (“PPS”) is issued by Payment Asia Limited and its affiliates (collectively “Payment Asia”, “we”, “us” or “our”) in accordance with the Personal Data (Privacy) Ordinance (Cap. 486) (“PDPO”) of Hong Kong. It explains our policies and practices regarding the collection, use, disclosure, transfer, retention, and security of personal data.

We are committed to protecting personal data in compliance with the PDPO’s Data Protection Principles (DPPs) and PCPD guidance. This PPS applies to our websites, applications, merchant onboarding, services, and related activities. We encourage you to read it carefully. A copy of our Personal Information Collection Statement (PICS) is provided in relevant forms or upon collection of your data.

Last updated: July 2026

1. Our Commitment to Privacy

We collect, use, and handle personal data only for lawful purposes directly related to our functions, with transparency and accountability. Key principles we follow:

  • Collect only necessary personal data.
  • Use it only for specified or directly related purposes (or with consent).
  • Take practicable steps to ensure accuracy, security, and retention no longer than necessary.
  • Limit access to authorized personnel.
  • Respect your rights to access, correction, and objection (including direct marketing opt-out).

2. Types of Personal Data We Collect

We collect personal data directly from you (e.g., via merchant applications, website forms, or enquiries) and from other sources where lawful.

Direct collection may include:

  • Contact details (name, address, email, phone).
  • Identification and verification data (e.g., HKID/passport copies, where required for KYC/AML).
  • Business/merchant details (company name, BR certificate, bank account info).
  • Payment and transaction data.
  • Technical data (IP address, browser info, usage logs collected automatically via cookies or similar technologies).

Other sources (including for merchant applications):

  • Public registers such as the Companies Registry (e.g., using company name to retrieve and process directors’ names, addresses, or other filed information via manual or AI-assisted means to verify and populate merchant application details).
  • Credit reference agencies, business partners, or third-party service providers (with your consent or as permitted by law).
  • Publicly available information where relevant to our services.

Business registration certificates themselves typically do not contain personal data, but ancillary processing (e.g., Companies Registry searches) may involve personal data of directors or officers. We use this solely for legitimate business verification purposes.

Collection Channels

We may collect the above personal data and documents through various channels, including our website, online forms, email, and messaging applications such as WhatsApp. When you submit documents via WhatsApp or other third-party platforms, please note that these platforms are operated by independent providers (e.g., Meta for WhatsApp) and are subject to their own terms and privacy policies, which we do not control. We recommend reviewing their policies. Once we receive the information, it will be handled in accordance with this PPS and our security measures. By submitting via such channels, you acknowledge the associated risks.

Submission via WhatsApp

You may submit your Business Registration certificate and other required documents via WhatsApp as a convenient method. Please note that:

  • WhatsApp is operated by Meta and is subject to Meta’s own terms of service and privacy policy. We do not control how WhatsApp collects, stores, uses, or secures your information.
  • Transmission occurs over WhatsApp’s platform, which uses end-to-end encryption for messages in transit. However, once received by us, your documents will be handled in accordance with this Privacy Policy Statement and our internal security measures.
  • We recommend that you only submit documents containing personal or sensitive information through secure, official channels where possible. Avoid sending sensitive details (e.g., full HKID numbers) unless necessary and redacted where practicable.
  • By submitting documents via WhatsApp, you acknowledge and accept the inherent risks associated with using this third-party service.

3. Purposes of Collection and Use

We use personal data for the following purposes (or directly related purposes):

  1. Processing merchant applications, onboarding, verification (including KYC/AML using public registry data), and providing payment services.
  2. Operating, improving, and personalizing our websites, apps, and services.
  3. Responding to enquiries and providing customer support.
  4. Conducting statistical analysis, research, and service improvements (often in aggregated/anonymized form).
  5. Complying with legal, regulatory, or compliance obligations (e.g., anti-money laundering, fraud prevention).
  6. Internal record-keeping, auditing, and risk management.
  7. Direct marketing (see Section 5).
  8. Other purposes with your consent or as permitted by the PDPO.

For merchant applications, we may use AI tools to assist in populating forms from verified public data, but human oversight applies where appropriate. We do not use personal data for automated decision-making with significant legal effects without safeguards or consent.

4. Disclosure and Transfer of Personal Data

We do not sell personal data. We may disclose or transfer it to the following classes of persons, as necessary:

  • Service providers, agents, contractors, or vendors (e.g., payment processors, cloud/storage providers, KYC/AML verification services, AI processing tools) under contractual obligations to protect data.
  • Credit card processors and financial institutions.
  • Professional advisers, auditors, or regulators.
  • Law enforcement, courts, or government authorities as required by law.
  • Our affiliates or group companies (in or outside Hong Kong) for operational purposes.
  • In connection with mergers, acquisitions, or business transfers (with notice where practicable).

Transfers outside Hong Kong are protected by appropriate safeguards (e.g., contracts incorporating PDPO-equivalent protections).

5. Direct Marketing

We may use your name, contact details, and preferences for direct marketing of our payment services, promotions, or related products (including from selected partners). We will obtain your consent or indication of no objection first, as required by the PDPO. You may opt out at any time by contacting us (see Section 10) or using unsubscribe links. We will not disclose your data to third parties for their direct marketing without consent.

6. Cookies and Automated Technologies

We use cookies, analytics tools, and similar technologies to improve user experience, analyze traffic, and personalize content. You can manage cookie preferences via browser settings. For details, refer to any separate Cookie Policy linked on our site.

7. Data Security

We implement reasonable technical and organizational measures (e.g., encryption, access controls, secure servers, SSL/TLS) to protect personal data against unauthorized access, loss, or misuse. However, no system is completely secure. We conduct regular reviews and training for staff.

8. Retention of Personal Data

We retain personal data only as long as necessary for the purposes stated, legal obligations, or legitimate business needs (e.g., merchant records for ongoing compliance). Upon expiry, we securely erase or anonymize the data in accordance with DPP2.

9. Your Rights

Under the PDPO, you have rights to:

  • Access and correction of your personal data (we may charge a reasonable fee for access requests).
  • Request cessation of use for direct marketing.
  • Withdraw consent (where applicable), subject to legal limitations.
  • Lodge complaints with the PCPD.

To exercise these, contact our Data Protection Officer (details below). We will verify your identity and respond within the statutory timeframe.

10. Contact Us

For enquiries, data access/correction requests, or opt-outs, please contact:

Data Protection Officer
Payment Asia
Email: [email protected]

11. Changes to This PPS

We may update this PPS from time to time. The latest version will be posted on our website. Continued use of our services after changes constitutes acceptance.

English version prevails in case of inconsistency.

Chat with AI Assistant PACO on WhatsApp
PACO Chatbot