Apay policies

Privacy Policy

Effective: 1 August 2026

Apay Financial Services Ltd (“Apay”, “we”) is the controller of your personal data. This policy explains what we collect, why, who we share it with, and the rights you can exercise. It applies to the Apay app, website and any related service.

1. Data we collect

  • Identity & KYC data: full name, date of birth, government ID, selfie/liveness image, address, occupation.
  • Contact data: phone number, email, next-of-kin (optional).
  • Transaction data: amounts, counterparties, timestamps, geolocation of the transaction, device used.
  • Device & technical data: device ID, IP address, operating system, app version, crash logs.
  • Support data: messages, call recordings, dispute evidence you submit.

2. Why we use it

  • To open and operate your wallet and process transactions.
  • To meet legal obligations: KYC, AML, sanctions screening, tax and regulatory reporting.
  • To detect and prevent fraud and financial crime.
  • To provide customer support and handle disputes.
  • To improve the service and — with your consent — to send marketing.

4. Who we share it with

  • Regulators & authorities where required by law (BoSS, FIU, courts).
  • Partner banks and payment networks that settle your transactions.
  • Verification & screening providers (identity, sanctions, PEP).
  • Cloud infrastructure and communications providers under written data-processing agreements.
  • Professional advisers (auditors, lawyers) under confidentiality.

5. International transfers

Some processors are outside South Sudan (for example, cloud regions in the EU or US). Transfers are protected by contractual safeguards and, where relevant, standard contractual clauses.

6. How long we keep it

  • KYC records: 7 years after account closure (AML retention rule).
  • Transaction records: 7 years.
  • Support tickets: 3 years.
  • Marketing consent logs: for the life of the consent plus 2 years.

7. Your rights

You can request access, correction, deletion (subject to AML retention), portability, or restriction of your data, and withdraw consent for marketing at any time. Email privacy@apay.ss. If you are unhappy with our response you may complain to the relevant data-protection authority.

8. Security

Data is encrypted in transit and at rest. Access is role-based and audited. We use biometric or PIN checks in-app and never store your PIN in plaintext. See our Security page for details.

9. Cookies

The website uses strictly necessary cookies to keep you signed in and, with your consent, analytics cookies to understand how the site is used. You can change your choice at any time from the cookie banner.

10. Children

Apay is not intended for anyone under 18. We do not knowingly collect data from minors.

Data Protection Officer: dpo@apay.ss.

This page is maintained by Apay to describe current practices and controls. It is not legal advice and is not an independent certification of compliance. Where the text conflicts with a signed customer agreement, the signed agreement governs.