This Merchant Privacy Notice (“Notice”) explains how KAI OS TECHNOLOGIES HONG KONG LIMITED (“KaiOS”, “we”, “us” or “our”) handles personal data when we provide the Kai MPoC Application and related attestation, monitoring, support and security services to merchants through an Acquirer.
It is published alongside the Merchant End User License Agreement (“Merchant EULA”) and forms part of it. It does not replace the privacy notice or the merchant services agreement given to you by your Acquirer.
1. Scope, and who this Notice is about
This Notice applies to personal data processed by KaiOS for the Kai MPoC Solution — the Application, the attestation and monitoring services, and related technical support. It does not govern processing by your Acquirer, the payment networks or other third parties.
Whose personal data. Where your business is a company, partnership or sole trader, this Notice concerns the personal data of the individuals connected with it: the proprietor, your named contacts, and the staff you authorise to use the Application. Information about your business as an entity is not personal data on its own, but is covered here where it is held together with information about those individuals.
2. Our role: when we are a controller, and when we act for your Acquirer
Our role depends on the data.
Payment acceptance data : your Acquirer is the controller Your Acquirer is the data controller for the merchant, cardholder and transaction data used to accept and process payments. KaiOS processes that data only as a service provider, on your Acquirer’s documented instructions, and for no purpose of its own.
KaiOS is not your Acquirer. We do not hold merchant funds, and we do not decide whether a transaction is approved or when you are settled.
Data we determine ourselves : KaiOS is the controller
For a limited set of data we decide the purposes and the means, and we are the controller:
- your acceptance of the Merchant EULA, the version you accepted, the date and time, and your merchant and Device identifiers;
- attestation, monitoring and service-performance information (section 6), which we collect to meet our obligations under the PCI MPoC Standard, to detect abnormal activity in the Solution, and to monitor the quality and performance of the service we provide; and
- records of support or security matters you raise with us directly.
Where we are the controller you can exercise your rights with us directly, see section 13.
3. The personal information we collect, and where it comes from
Depending on how the Solution is configured and used, we may process:
| Information | Where it comes from | Where we hold it |
|---|---|---|
| Merchant and terminal identifiers, Device and Application identifiers | Provisioning and activation, and the Application | Our production backend |
| Device model, operating system version, configuration and technical security information (section 6) | From the Device, through attestation and monitoring | Our production backend |
| Your acceptance of the Merchant EULA | Recorded in the Application when you accept | Our production backend |
| Contact details and other information in a support or security matter you raise with us | From you, or from your Acquirer or Distributor when they escalate to us | Our support and correspondence systems only |
Our production backend does not hold your name, your contact details or your business address. It identifies you only by merchant, terminal and device identifiers. Where you or your Acquirer contact us about a support or security matter, any names or contact details in that correspondence are held only in our support and correspondence systems, and only for as long as section 12 allows.
4. How we use your personal information
We use personal data only to:
- operate, maintain, secure and support the Solution;
- verify that your Device and the Application remain in a secure, approved state;
- investigate and resolve faults and security incidents;
- monitor the quality, performance and reliability of the Solution, and detect abnormal activity in it;
- send you the service, security and legal notices we are required or permitted to send; and
- meet our obligations under the PCI MPoC Standard, PCI DSS, payment network rules and applicable law.
We do not use this data to market to you, to build advertising profiles, or to sell personal data. We do not sell personal data to anyone.
5. Our legal basis
Where KaiOS is the controller (section 2), we rely on:
- Performance of a contract: to license the Application to you under the Merchant EULA, and to record your acceptance of it.
- Compliance with legal obligations: including our obligations under the PCI MPoC Standard, PCI DSS and payment network rules, and record-keeping obligations in the markets where the Solution is deployed.
- Legitimate interests: to keep the Solution secure, to detect and respond to security incidents, abnormal activity and fraud, to monitor the quality and performance of the service, and to provide support. We have weighed these interests against your rights and consider the processing necessary and proportionate.
Where KaiOS acts as a service provider for your Acquirer, your Acquirer determines the legal basis for that processing.
6. Technical information from your Device
The Solution continuously verifies that your Device and the Application remain in a secure state. This is required by the PCI MPoC Standard and it is what allows payment acceptance to be trusted.
The information we process from your Device falls into two groups.
- Security attestation, required by the PCI MPoC Standard. Device and Application identifiers and versions; Device hardware configuration, operating system state and integrity measurements; results of environment security checks such as root, tamper, debugger, emulator and integrity checks; installed-package and configuration signals relevant to security; network and location signals where necessary; audit logs used for risk assessment; and Application security event logs.
- Additional monitoring carried out by KaiOS. Records of key-injection, enrolment and transaction activity — the type, time and outcome of each operation, and the amount and currency of a transaction, but not the cardholder’s payment details — which we use to detect abnormal activity such as unexpected key injection or payment patterns, and to monitor the performance and reliability of the service (for example how long key injection or a transaction takes, and how often each succeeds).
What we cannot see. Cardholder payment data is encrypted at the point of capture and transmitted through the certified secure channel to the payment backend provider and your Acquirer. KaiOS cannot decrypt cardholder account numbers, PINs or PIN blocks — we do not hold the keys required to do so, and that data is never available to us in clear form. Our attestation and monitoring service does not collect your passwords or your Application activation credentials.
7. Automated checks and automatic protective action
The checks described in section 6 are automated and continuous.
If those checks detect a condition that presents a security risk (for example a rooted or tampered Device, a failed integrity check, a prohibited application, or a Device running software outside the approved configuration), payment acceptance on that Device may be suspended or blocked automatically, without prior notice, as set out in the Merchant EULA.
This is an automated decision, and we recognise it can stop you taking payments.
Where this happens we will tell you through the Application and, where the condition can be put right, explain what you need to do to restore service.
If you want the decision reviewed by a person, contact your Acquirer. Your Acquirer will raise it with us; KaiOS carries out the review, because KaiOS operates the checks, and your Acquirer will give you the outcome. Your Acquirer is the right first point of contact because they hold your merchant relationship. If your Acquirer is unable to assist, you may contact us directly at merchant@kaiostech.com.
8. Who we share information with
We share personal data only where it is necessary to provide or secure the Solution, or where we are required to by law.
Acting on our behalf, under contract (our processors and sub-processors):
- hosting and infrastructure providers
- security and monitoring service providers
- KaiOS group companies providing technical, security or support functions
Acting for their own purposes, or as a separate controller:
- your Acquirer and its payment backend provider
- authorised Distributors
- the payment networks
- independent assessors and auditors
- regulators, courts and law-enforcement authorities, where legally required
9. Where your information is processed
Who we are, and which entity holds your data
Kai OS Technologies Hong Kong Limited is the KaiOS entity responsible for the Solution and for the data described in this Notice. It is part of the KaiOS group: its parent is Kai OS Technologies Pte Ltd in Singapore, and its subsidiary Kai OS Technologies (Shanghai) Co., Ltd employs the engineering and operations staff who run the Solution on its behalf.
Where your data is held and accessed
Personal data processed for the Solution is held in AWS eu-west-1 (Ireland) in Europe, under a contract held by our Hong Kong entity.
It is accessed by our operations engineers, who are employed by our Shanghai subsidiary and are located in mainland China. They access it only to operate, monitor and support the Solution, under written instructions from our Hong Kong entity and subject to the access controls described in section 10.
Where personal data is transferred out of the country in which you are established, we rely on the transfer arrangements put in place by your Acquirer to protect it.
Where we are the controller (section 2), we rely on a written data transfer agreement between our Hong Kong and Shanghai entities, which requires the Shanghai entity to process the data only on our instructions and to apply the same protections. We have assessed the risks of this arrangement and keep that assessment under review.
You can ask us for more information about the safeguards that apply, using the details in section 18.
10. Security
We apply technical and organisational safeguards appropriate to the risks involved, including access controls, confidentiality obligations binding on our personnel, security monitoring, encryption where appropriate, vulnerability management and incident response procedures.
We engage sub-processors only where our arrangements with your Acquirer permit it, and we remain responsible for them as required by applicable law.
Your part. You must also protect your Device, your credentials and access to the Application, as required by the Merchant EULA. The security of payment acceptance on a shared device depends on both of us.
11. If something goes wrong
If personal data we hold is affected by a security incident, we will notify your Acquirer without undue delay and support them in meeting any notification obligations they have. Where the law requires us to notify you or a regulator directly, we will do so.
Separately, where a security incident affects the Solution itself, we will inform you as set out in the Merchant EULA.
12. How long we keep information
We keep personal data only as long as we need it:
| Information | How long |
|---|---|
| Your acceptance of the Merchant EULA | Five years from the end of your use of the Application, as stated in the Merchant EULA |
| Attestation and security event logs | One year |
| Support and incident records | Five years from closure of the matter |
| Enrollment status | Five years |
| Business contact details | For as long as you are an active merchant using the Solution, and one year afterwards |
| Data we process for your Acquirer | For the period set by our data processing arrangements with them, after which we delete it or return it |
The periods above are our standard retention periods. The PCI MPoC Standard requires attestation and security records to be kept for at least one year, and we apply that as a minimum. Where the law of the country in which you are established requires a different period — longer or shorter — we follow the local requirement for merchants in that country. Your Acquirer can tell you the period that applies in your market, and we maintain a record of the periods applied in each market.
13. Your rights
For payment acceptance data (merchant, cardholder and transaction data) your Acquirer is the controller. Requests to access, correct, delete, restrict or object to the processing of that data should go to your Acquirer, using the contact details in your merchant services documentation. If you send such a request to us, we will pass it to your Acquirer and help them respond.
For the data we control (section 2 – your EULA acceptance record, attestation and monitoring information, and support records you raise with us) you can contact us directly using the details in section 18, and we will respond in accordance with applicable law. Some of this information we are required to keep for compliance, certification or evidential reasons; where that applies to your request, we will tell you.
Automated decisions. Where payment acceptance has been suspended or blocked automatically, you can ask for the decision to be reconsidered by a person. See section 7. Contact your Acquirer, who will raise it with us.
Complaints. If you are not satisfied with how we have handled your personal data, you can complain to the data protection or privacy authority in your country.
14. Location signals
We process network and location signals only where necessary for attestation, risk assessment, fraud prevention, incident response or applicable compliance requirements.
We do not use them for advertising or for any unrelated commercial profiling.
15. Cookies and similar technologies
This Notice covers personal data processed through the Kai MPoC Solution. The Application itself does not use cookies.
When you visit the merchant website, cookies and similar technologies are covered by the cookie notice published at https://www.kaiostech.com/cookie.
16. Third-party sites and services
The merchant website or the Application may link to third-party sites or services. Their collection and use of personal data is governed by their own privacy notices, and this Notice does not apply to them.
17. Changes to this Notice
We may update this Notice to reflect changes to the Solution, to security or legal requirements, or to our processing practices.
The current version and its effective date are published at https://merchant.kaiostech.com/privacy, where previous versions also remain available.
Because this Notice forms part of the Merchant EULA, we will give you at least 30 days’ notice of any material change, through the Application or the contact details in your merchant profile, except where a shorter period is required for security, certification or legal compliance reasons.
18. How to contact us
For questions about this Notice, or about how KaiOS handles personal data for the Solution: merchant@kaiostech.com
For anything concerning your merchant account, payments, settlement, fees, refunds or disputes — and for rights requests over payment acceptance data — contact your Acquirer, using the details in your merchant services documentation.