III. Data Processing Within The Framework of Tiers Products
1. Data Collection and Processing In Case of Opening and Using the Tiers Account
Personal data related to your identification, contact data, economic data and finance data will be processed by Tiers for the purpose of opening an account with Tiers (hereinafter: "Sign-up") and using the Services of Tiers. The legal basis of the processing of these data is The Data Protection Act. These data include the following personal data:
- Mobile telephone number
- Tax-ID and tax residence
- Identification document including type of identification document, issue date, document number and issuing authority
- Data concerning your economic situation and your Tiers products and services usage history which are your account number, customer ID, card details, transaction details (card payment and banking transfer amounts and recipients) based on products and services contracted with Tiers.
Please note that it is not possible to open an account, if you do not provide your personal data as mentioned above.
In order to process transactions, Tiers receives personal data and transfers personal data according to the applicable legal and regulatory framework to payers, recipients and other financial institutions. The personal data received by other entities in this regard concerns your name and surname, including transaction details like the payment reference and registered accounts.
During the creation of your Tiers account we will need access to your geolocation upon your consent in the settings of your smartphone; you will find further information in the privacy policy of the operating system of your smartphone. The lawful basis of this processing is our legitimate interest in confirming that you are located in your country of residence in order for us to comply with our legal obligations related to fraud prevention. For more information on the legitimate interest as a legal basis for processing data, please see section II. above.
In addition, we might ask you to submit additional documents for verification. The lawful basis of this processing is The Data Protection Act as the processing is required to comply with legal obligations stemming from Anti Money Laundering and Countering of Terrorism laws.
What personal data we will be processing depends on the document we are requesting and receiving from you. Such documents can be a proof of residence (such as a gas, water or electricity bill less than 3 months old or a registration certificate), a proof of salary (such as an employment contract, salary statement or statement of assets and income; in case you send us one of the two latter ones, we ask you to please black out any data related to your religious beliefs and family status, if provided therein), your visa documentation or proof of study which states the reason why you live in the country indicated by you as country of residence, or a document attesting your source of wealth (contracts, bank statements, information around asset sales, capital gains or inheritance).
Once you send us any of the mentioned documents they will be assessed manually by Tiers to verify and confirm that we have all the data about you that we need in order to open your account with us or to allow you to continue using our Services. In case the information you sent us upon our request is not sufficient, we will reach out to you and ask you for more documentation, which is equally subject to the above mentioned.
2. Visibility as a Tiers Customer When Using Certain Tiers Features
In the context of using certain Tiers features like M-Pesa, Contacts, Request from friends, Transfer to a contact, Split the Bill or Money QR Code, we ask for your consent, to be visible to other Tiers customers as a Tiers customer. By granting Tiers permission to share your status as a Tiers customer, we can display this information to other Tiers customers, in the context of their use of certain Tiers features, if you are present on their mobile device’s contact list. You are then visible to your contacts if they are also customers of Tiers.
3. Data Processing Related to Using Tiers Features in Connection to Your Contacts
To facilitate your use of Tiers features in connection with your contacts, we will access your mobile device’s contact list and upload your contacts’ information to your Tiers account, based on your consent. This will include a regular sync with your mobile device to ensure your contacts’ information is up-to-date. You can withdraw or manage your consent at any time directly through your mobile device’s operating system. You will be able to see all contacts from your mobile device in your Tiers account, including which of them are also Tiers customers. We will store your contacts to make them available to you in your Tiers account and combine this data with other contact information you provide when using our services to make it easier for you to search and find your contacts in the context of a transaction and the use of other Tiers features. For these purposes, we rely on our legitimate interest, to provide you with improved service functionality and a better customer experience. For more information on legitimate interest as a legal basis for processing data, please see section II. above.
4. Data Transmission Within the Framework of Tiers Foreign Currency Transfers
In order to facilitate Tiers Foreign Currency Transfers, we collaborate with IntaSend Solutions Limited, ("IntaSend"). IntaSend facilitates transactions in foreign currencies with your Tiers account. Upon your request, the transfer amount is converted to the target currency and sent to the recipient’s bank account in the target country. For this purpose, we process and share with IntaSend your name, address, customer ID, birthdate, account number, as well as the timestamp of the transfer, payment reference text, source currency code, transfer amount in source currency, target currency code, exchange rate value, transfer amount in target currency, the recipient’s name and bank account number. IntaSend processes this data according to our instructions to facilitate the transfer, as our data processor. Your personal data is processed based on the execution of our agreement with you.
Additionally, we process your data as described above to comply with our legal obligations under applicable laws and regulatory requirements, as specified in section II, above. Furthermore, we process the data to detect and prevent fraud and criminal acts and to manage risks, based on our legitimate interests under The Data Protection Act. For more information on our legitimate interest as a legal basis for processing data, please see section II, above.
IntaSend also processes the data above as a separate data controller for their own purposes, namely satisfying their legal and regulatory obligations, such as anti-money laundering and banking sanction checks. For this purpose and upon a lawful inquiry by IntaSend, we may also share with IntaSend some additional information related to you, including the stated purpose of the transfer, source of funds, place of birth, phone number, email address, occupation, proof of address and data related to your identity verification process, including a copy of your identification document used when opening your Tiers account. IntaSend will retain your data, unless otherwise required to comply with applicable laws and regulations. You can find more information on IntaSend’s Privacy Policy.
5. Data Transmission in The Framework of Open Banking
To comply with a request to access your Tiers account for payment initiation services, account information services and confirmation on the availability of funds (hereinafter: "Open Banking Request"), your personal data is provided to authorized third party payment service providers. The personal data transmitted will include your account number and customer ID. We provide the personal data you request through a licensed third party described in this section on the basis that it is necessary to comply with our obligation under the applicable legal and regulatory framework to provide an interface for communication with licensed payment service providers of your choice and that it is necessary to perform our obligations under the Tiers account contract.
6. Data Processing In The framework of Tiers Savings Wallet
Tiers Savings Wallet offers you a way to save money. To enable the product, if you choose to open a Tiers Savings Wallet account, we process your name, legal address, identification document, tax identification number, tax residence, customer ID, device ID and mobile operating system. We also process data specifically related to your Tiers Savings Wallet account, which are the account number, status and account balance, and data related to your use of it, including transaction data, which consist of deposits and withdrawals, dates, amounts and, if applicable, recipients and senders. Moreover, we process applicable interest rates, amount of interest earned, applicable withholding tax and other tax related information. The legal basis for the data processing is the execution of our agreement with you. Additionally, we process data that you share with us about the expected monthly deposit amount and source of funds in order to conduct research and analysis regarding the use customers make of our products and features. In this case, we rely on the legal basis of our legitimate interests. For more information on legitimate interest as a legal basis for processing data, please see section II, above. We further process your data to comply with our legal obligations under applicable laws and regulatory requirements, based on The Data Protection Act, including the Proceeds of Crime and Anti-Money Laundering Act (POCAMLA), enacted in 2009, and other binding measures related to financial matters, as well as to detect and prevent fraud and criminal acts and to manage risks, based on our legitimate interests under The Data Protection Act.
7. Data Transmission In The Framework of The Add Money Feature
The Add Money Feature provides an easy method for customers to add funds to their accounts instantly. IntaSend Solutions Limited. (hereinafter: "IntaSend") is providing the technical setup and integration with the relevant payment processors, as a processor. In order to be able to use the Add Money Feature, Tiers transmits information regarding payment details (cardholder name, email address, customer ID, order ID, bank account details, payment card details, card expiration date, CVC code, date, time and amount of transaction, merchant name/ID and location) to IntaSend. IntaSend will also process your data in order to fulfill its legal obligations, as a separate controller, like monitoring fraudulent payment transactions, know-your-customer obligations and anti-money-laundering screening. IntaSend and Tiers only exchange anonymized tokens and Tiers never sees or stores the details of the card used for the deposit. The usage of the Add Money Feature is entirely voluntary for eligible customers, as part of your contract with Tiers and the respective data processing is based on The Data Protection Act.
8. Data Processing In The Framework of The Insights Feature
The Insights feature is available within the App. The feature sorts your transactions/payments and visualizes your spendings in a variety of categories to offer you valuable insights on your spending behavior. In order to offer the Insights feature to you within the App, we process transaction data (i.e. data relating to the sender and recipient of transactions, such as the name of the retailer, amount of transitions, subject(hashtag of transactions) and data relating to certain actions by the user (i.e. hashtags created by the user for purposes of spending categorization), as part of your contract with Tiers and the respective data processing is based on The Data Protection Act.
9. Data Processing When Displaying In-App Updates
If you use the App, so-called in-App updates will be displayed. The purpose of the in-App updates is to inform you about the content of your contract, new functionalities of the App or App updates and releases and to give you tips for an optimized use of the App. We will process your user and transaction data (recent deposits, payments, withdrawals, friend referrals) in order to provide you with the relevant in-App updates. We process your data to the extent necessary to display relevant information about your contract with Tiers or the improved use or new functionalities in the App. In addition, the in-App updates may help you to find information about our new services and products related to the App. In order to display in-App updates relevant to you, we will process your user and transaction data (recent deposits, withdrawals, payments, friend referrals). We process your data within the scope of our legitimate interests in informing you about new services and products implemented in our App, as far as this is necessary to display our new features, services and products so you can use any of them if you are interested. For more information on the legitimate interest as a legal basis for processing data, please see section II, above.
10. Data Processing When Using The Help Center
When discussing any contractual matters (such as account related information or your transactions) with us on our Help Center or on our Website or within our App, your IP-address and the information you provide us in your chat communication will be collected and processed, to the extent this is necessary for Tiers to provide you the products and services under the contract between you and Tiers or any pre-contractual actions required by Tiers or as requested by you. In addition, we process your data within the scope of our legitimate interest in answering your general questions about our services and products and to help you find information about our new services and products related to the App, so you can use any of them if you are interested. For more information on the legitimate interest as a legal basis for processing data, please see section II, above.
11. Data Processing In The Framework of Informational Communication
We use informational emails, in-App updates and push notifications to inform you about transactions, withdrawals, and other relevant information related to your usage of our products and services. For some informational emails, in-App updates and push notifications we analyze your user behaviour (status of signup to Tiers, recent transactions, withdrawals, interaction with services offered such as friend referrals) to send you (additional) information about these processes via emails, in-App updates or push notifications. We will only send you these emails, in-App updates and push notifications based on your user behaviour if the processing is necessary for the performance of the contract or within the scope of our legitimate interests of informing you about transactions, withdrawals, and other relevant information related to your usage of our App, as far as necessary to provide such information, based on The Data Protection Act. For more information on the legitimate interest as a legal basis for processing data, please see section II, above.
12. Preparing Anonymised Statistical Datasets
We use your personal data to prepare anonymised statistical datasets about our customers’ spending patterns for forecasting purposes, refining product development and understanding consumer behaviour and assess our company’s performance. The reports are produced by using information about you and other customers, however, the information used is anonymised so that it is no longer personal data. You cannot be linked back as an individual within anonymised statistical data and you will therefore never be identifiable from it. We may share these datasets with third parties. This processing is based on Tiers’s legal obligations, in accordance with The Data Protection Act, or based on Tiers’s legitimate interest, under The Data Protection Act. For more information on the legitimate interest as a legal basis for processing data, please see section II, above.
13. Data Processing In The Framework of The Waiting Lists
When you ask us to add you to our waiting list for information on when we’re able to provide our banking services to you, the following data will be collected and processed so that we can inform you once we are able to offer you our services:
- Language selected by you when using our website
The legal basis of the processing of these data is The Data Protection Act. Please note that it’s not possible to include you in the waiting list if you do not provide us with the referred personal data. Based on your decision to be added to the waiting list, we will send you emails or SMS containing the following information:
Confirmation that you were successfully added to the waiting list
Information on products/services you may expect as a future Tiers customer in your market, once the launch is getting closer, so you can decide if you are still interested to sign-up
Notification that Tiers is available again soon, for example containing the envisaged launch date and information about how to sign up
Information containing a link to sign up for a Tiers account, once Tiers is available again.
14. Data Processing When Participating in In-App Surveys
When you share your feedback with us in the App by participating in surveys, on a voluntary basis, we process the information that is technically necessary to provide the survey function and enable us to display it to you (metadata). We process your data, as described, for the purpose of displaying surveys to you and obtaining your feedback, based on our legitimate interests, in accordance with The Data Protection Act. Depending on the survey, we may also process the content of your responses and, in particular, the information that you choose to share with us. Additionally, we may combine the data collected through the survey with other customer data that we process in the context of our contractual relationship with you, including your customer ID, date of account creation, age group, gender, country and city of residence. In this case, we will inform you accordingly in the respective information note at the beginning of the survey. We process your data, as described, for analysis purposes and to improve our products, processes and service levels, based on our legitimate interests, in accordance with The Data Protection Act. If you decide to share your feedback with us, we may anonymise the data obtained to create research reports and publications. This is done based on our legitimate interest to conduct and produce statistical research and reports and analysis regarding the use customers make of the products and features provided by Tiers, in accordance with The Data Protection Act. For more information on legitimate interest as a legal basis for processing data, please see section II. above.
15. Data Processing When Using The M-Pesa Payment Scheme
M-Pesa is a payment method that you can use to make transfers and payments through your Tiers App or Web App, for example in an online store or to transfer money to your friends. It facilitates a direct transfer from your Tiers account to that of a beneficiary (e.g. a merchant). The M-Pesa scheme is operated by Safaricom Limited, located at P.O Box 66827, 00800 Nairobi, Kenya (Safaricom), which provides the infrastructure and technical setup for the connection between the payment environment and your Tiers account. When you initiate an M-Pesa payment using your Tiers account, we process your name and phone number, data related to the M-Pesa transaction, which include amount, breakdown, type of transaction (i.e. online, in-store, customer-to-customer or QR), currency, transaction ID (a number used to identify an M-Pesa transaction executed by you), reference ID (a number used to identify the transaction authorisation request), status and period of validity (maximum authorisation time for an M-Pesa payment request), as well as a unique code to confirm that you have been recognised and authenticated when connecting to your Tiers account. Additionally, we process the name and ID of the M-Pesa payment beneficiary (e.g. a merchant), their bank ID, account number, as well as the merchant category code (if applicable). We further process data related to the device you used to make the M-Pesa transaction, namely device fingerprint. We process this data as a data controller to verify your identity and authenticate you as a Tiers customer and to enable your M-Pesa payment, based on the execution of our agreement with you as per The Data Protection Act. In this context, we collaborate with Safaricom, which acts as a data processor on our behalf. Safaricom also processes your data as a separate data controller for their own purposes. You can find more information about the processing of your data by Safaricom in the Safaricom Data Privacy Statement & Cookies Policy. We further process your data to detect and prevent fraud and criminal acts, including money laundering and terrorism financing, as well as to manage risks and for reporting purposes, based on our legitimate interests under The Data Protection Act. For more information on legitimate interest as a legal basis for processing data, please see section II, above. In addition, we process your data to comply with our legal obligations stemming from applicable laws and regulatory requirements, including anti-money laundering and tax laws as well as other binding measures related to financial matters, based on The Data Protection Act and The Proceeds of Crime and Anti-Money Laundering Act.
When sharing your ideas using the designated "Share your ideas" feature, we process the information that is technically necessary to enable the feature and display it to you, including app operating system (e.g. iOS, Android, Web), app language version (e.g. EN), app version, country, membership tier and time intervals since passing the KYC process. Additionally, we combine your ideas with data that we process in the context of our contractual relationship with you, including your app operating system, date of account creation (limited to month and year), app version and country of residence. We will not link your ideas to any direct identifiers, such as your customer ID, and the feedback you provide will not have any influence on our actions towards you. We merely link the data to your idea to better understand the context of your ideas, e.g. if it is something that is specifically interesting for a specific market or if the idea is linked to a specific usage period of our app. We process your data, as described, for research purposes to improve our products, processes and service levels, based on our legitimate interests, in accordance with The Data Protection Act. For more information on legitimate interests as a legal basis for processing personal data, please see section II. above.