DoverkaSEND

Personal Data Processing Policy

This Privacy Policy (hereinafter — the Policy) is a document establishing the obligations of the Limited Liability Company "Doverka Fintekh" (hereinafter — Doverka Fintekh LLC, the Operator) to maintain the non-disclosure and confidentiality protection regime for any data provided by the User upon registration, verification, or authentication in the "DoverkaSEND" Service. The Service is available, including but not limited to, through the website at doverkasend.com, the mobile application and the Telegram Mini App; other access channels (including those updated by the Company from time to time) may be indicated in the Service interface and/or in the account settings.

The Company is a payment service provider and provides payment services to Users within the functional capabilities of the Service.

Chapter 1. Terms and Definitions

1. This Policy uses the following terms and definitions:

1.1. Company — Limited Liability Company "Doverka Fintekh", Republic of Belarus, 220004, Minsk, Pobediteley Avenue 7A, office 31, which carries out the processing and protection of Personal Data;

1.2. "DoverkaSEND" Service (Service) — a set of software and hardware resources ensuring the provision of payment services by the Company, top-up of Wallets, currency conversion, payment initiation, purchase of eSIMs, and verification of the identity of Users, available through the website, mobile application, Telegram bot, and Telegram Mini App;

1.3. Verification — a set of activities for checking and confirming the accuracy of information about the User, including establishment of the User's identity, identification, authentication, verification of the authenticity of submitted documents, and/or comparison of an image of the User's face with the photograph in the document, carried out with the involvement of a KYC service for the purposes of compliance with legislation on anti-money laundering and counter-terrorism financing (AML/CFT), as well as for the purposes of determining the limits and functional capabilities of the Service available to the User;

1.4. KYC Service — a third party engaged on a contractual basis to carry out procedures of remote identification and verification of Users, including verification of the authenticity of identity documents and comparison of an image of the User's face with the photograph in the document, as well as for transferring to the Operator the confirmed results of such verification;

1.5. Personal Data — any information relating to an identified (identifiable) natural person or a natural person who may be identified (determined);

1.6. Personal Data Subject or Subject — a natural person, other than an employee of the Company, to whom the Personal Data processed by the Company relate;

1.7. Processing of Personal Data — any action or set of actions performed with Personal Data, including collection, systematization, storage, modification, use, anonymization, blocking, distribution, provision, and deletion of Personal Data;

1.8. Authorization — a procedure by which a prospective User provides account credentials to the extent requested by the interface of the "DoverkaSEND" Service, comprising confirmation of the telephone number with a one-time password (OTP), the entry or creation of a six-digit PIN code, and, where additional two-factor authentication (2FA) is activated, confirmation with a code from an authenticator application (Google Authenticator, Authy, etc.) or a hardware security key; 1.9. User Profile — part of the "DoverkaSEND" Service containing the set of data about the User provided by the User independently, as well as data confirmed during verification;

1.10. User — a natural person who has completed (is completing) the registration procedure in the Service in the manner established by the Operator, and/or uses the functional features of the Service, including without completing registration (to the extent available to unauthenticated persons), acting on the User's own behalf and in the User's own interest;

1.11. Wallet — an information service of the Account reflecting the amount of the Company's indebtedness to the User in the corresponding currency. The Wallet is not a bank account. A separate record of indebtedness is maintained for each supported currency (RUB, THB, USD, EUR, etc.).

Chapter 2. General Provisions

2. This Policy applies to all information that the User provides upon registration, verification or authentication in the Service, as well as when receiving payment services.

3. By accepting the Public Offer, the User confirms full familiarization with the content of this Policy and unconditional agreement with its provisions, including those relating to the processing of information by the methods and for the purposes defined in this Policy.

4. If the User does not agree with the terms of this Policy, the User must discontinue the use of the Service.

5. The User's use of the Service constitutes consent to this Privacy Policy and to the Personal Data Processing Policy of Doverka Fintekh LLC.

6. The purpose of this Policy is to determine the information that may be requested from the User in connection with the use of the Service and to ensure an appropriate regime for the protection of the confidentiality of information about Users, including their personal data, from unauthorized access and disclosure.

7. The User's confidential information includes Personal Data, personal information and other data, including data transferred automatically in the course of use.

8. The Operator is entitled, without the consent of the User, to provide the information received to third parties in anonymized (aggregated) form for the purpose of conducting statistical and other research, as well as in connection with activities related to the maintenance (technical support) of the Service. The transfer of personal data to third parties for the purposes of marketing research and dispatch of advertising materials is carried out solely with the User's consent. The right of access to information is granted to third parties on the basis of this Policy and the legislation of the Republic of Belarus, and also for the purposes of protecting the rights and legitimate interests of the Company or third parties.

9. The Rightsholder ensures proper protection of personal and other data, as well as personal information, in accordance with the requirements of the Constitution of the Republic of Belarus, the requirements of the Law of the Republic of Belarus No. 99-Z dated 07.05.2021 "On Personal Data Protection" (hereinafter — Law No. 99-Z), and other legislative acts of the Republic of Belarus.

10. The User is obliged to ensure the safekeeping and confidentiality of secret parameters, including the PIN code, password, two-factor authentication secrets and other information necessary for access and for carrying out operations. The User undertakes to immediately notify the Service Operator of any suspected fact of unauthorized use of the User's account. The User's observance of the aforementioned recommendations will ensure maximum safekeeping of the information provided.

11. The general rights of Users in the field of Personal Data are described in the Personal Data Processing Policy of Doverka Fintekh LLC.

12. The Authorized Person of the Operator is the KYC Operator engaged on a contractual basis to carry out procedures of remote identification and verification of Users, and other KYC Operators.

Chapter 3. Purposes of Processing Personal Data

13. The Personal Data permitted to be processed under this Privacy Policy are provided by the User through registration in the Service.

14. The Service organizes the collection, use and processing of information transferred by the User when performing registration actions and using the functional capabilities of the Service, for the following purposes:

14.1. verification, authentication and identification of the User;

14.2. display of personal data in the User Profile;

14.3. enabling Users to use the functional capabilities of the Service, including the top-up of a Wallet, the receipt of international payment services, currency conversion between Wallets, payment initiation, the purchase of eSIMs, and participation in the referral programme;

14.4. communication with the User (contacting the User, including via notifications, requests and information regarding the use of the Service), including SMS notifications, push notifications, Telegram messages and email;

14.5. verification of the trustworthiness of Users (including the accuracy, relevance and/or compliance with legislation of any information provided by Users) — where a decision is taken on the necessity of such verification;

14.6. ensuring the technical operability of the Service;

14.7. posting (modifying) data in the User Profile; 14.8. protection of the User Profile from unauthorized access by third parties, including storage of the hash of the PIN code and the parameters of two-factor authentication;

14.9. conducting statistical, marketing and other research;

14.10. sending informational and advertising notifications;

14.11. for purposes arising from the requirements of legislation;

14.12. ensuring compliance with legislation and the Company's local acts;

14.13. ensuring the operation of the referral programme and the accrual of bonuses;

14.14. handling of User inquiries submitted to the support service.

15. The processing of Personal Data is proportionate to the declared purposes of processing and, at all stages of such processing, ensures a fair balance of the interests of all interested parties.

16. The processing of Personal Data is limited to the achievement of specific purposes previously declared by this Policy and other local acts of Doverka Fintekh LLC. The processing of Personal Data incompatible with the originally declared purposes of processing is not permitted.

17. If it becomes necessary to change the originally declared purposes of processing Personal Data, Doverka Fintekh LLC is obliged to obtain the consent of the Personal Data Subject for the processing of the Subject's Personal Data in accordance with the changed purposes, in the absence of other grounds for such processing provided for by Law No. 99-Z and other legislative acts.

Chapter 4. List of Processed Data

Users — categories, composition, purposes

Category of Personal Data Subjects: Users. Data provided upon registration and authorization (telephone number, email address (if any), Telegram account data (when registering via the Telegram Mini App or Telegram bot)) — for the purposes of creating the personal account (account, User Profile).

Passport data or data of another identity document — for the purposes of conducting basic verification of the User and complying with the requirements of the legislation of the Republic of Belarus.

"Image of the face (selfie)" — for the purpose of completing User verification (Level 2 and above).

Payee data (recipient of funds); the amount, currency and purpose of the payment service; operation history and saved payees — for the purpose of providing payment services (performance of the civil-law contract).

Data on payment services provided — for other purposes in accordance with clause 14 of this Policy.

Data on eSIMs purchased (ICCID, telephone number, parameters of the tariff plan) — for the purpose of performing the agency agreement for the provision of eSIM services.

Data on referral links (identifier of the inviting User, number of payment services received, amount of bonuses accrued) — for the purpose of ensuring the operation of the referral programme.

Other data provided by the User (country of residence, preferred currency, authorization code, PIN code hash, 2FA parameters) — for the purpose of providing services under the civil-law contract and ensuring the security of the account.

18. The processing of Personal Data is carried out with the consent of the Personal Data Subject, except in cases provided for by Law No. 99-Z and other legislative acts of the Republic of Belarus.

19. The Operator stores Users' Personal Data for 5 (five) years from the date of provision of the last service under the civil-law contract.

20. Where Personal Data are processed without the consent of the Personal Data Subject, the purposes of processing are established by Law No. 99-Z and other legislative acts of the Republic of Belarus.

21. The consent of the Personal Data Subject is a free, unambiguous, informed expression of the Subject's will, by which the Subject permits the processing of the Subject's Personal Data.

22. Unless otherwise established by legislation, the consent of the Personal Data Subject may be obtained in the following forms: in written form; in the form of an electronic document; in another electronic form, including by the Personal Data Subject placing the corresponding mark within the "DoverkaSEND" Service, upon Authorization, or in any other form permitting the fact of receipt of consent of the Personal Data Subject to be established.

23. If the period of storage of Personal Data processed by the Company is not determined by the legislation of the Republic of Belarus, such period shall be established by the Company independently on the basis of the purposes of processing Personal Data in accordance with this Policy.

24. The period of storage of Personal Data processed by the Company is 5 (five) years from the moment of deletion of the personal account (account, User Profile) by a User of the "DoverkaSEND" Service and/or from the moment of termination (expiration) of the User Agreement (public offer) with the Company, in accordance with the requirements of the legislation of the Republic of Belarus, including on AML/CFT, unless otherwise established by the legislation of the Republic of Belarus. In the absence of technical capability to delete Personal Data, the Company shall take measures to prevent further processing of Personal Data, including their blocking.

Chapter 5. Registration and Verification of the User

25. The "DoverkaSEND" Service provides for three levels of verification:

25.1. initial level (Level 1) — assigned automatically upon registration, does not require the provision of personal data beyond the telephone number;

25.2. basic verification (Level 2) — involves remote verification of the identity document through a KYC service, including the "liveness" confirmation procedure (liveness check / comparison of an image of the User's face with the photograph in the document);

25.3. extended verification (Level 3) — additionally includes the provision, upon request of the Company, of one or more of the following documents: (a) a document confirming the residential address (utility bill, bank statement, or other document issued no earlier than 3 months prior to the date of provision); (b) a document confirming the source of origin of funds (income certificate, tax declaration, or other document confirming the lawfulness of the origin of funds). The specific list of requested documents is determined by the Operator on an individual basis, taking into account the requirements of applicable legislation and internal AML/CFT policies.

26. The User's completion of Level 2 or Level 3 verification is carried out solely on a voluntary basis. A refusal to complete verification does not prevent the use of the Service within the scope available at Level 1, but restricts or fully excludes the possibility of carrying out financial operations.

27. The verification procedure is initiated by the User independently through the functionality of the personal account of the "DoverkaSEND" Service.

28. Interaction between the User and the KYC Service is carried out without participation of the Operator in the processes of input, transfer or temporary storage of raw personal data and document images.

29. In the course of completing verification, the User: 29.1. provides Personal Data (surname, given name, patronymic (if any), date of birth); 29.2. indicates the details of the identity document (series, number, date of issue, issuing authority, division code); 29.3. uploads an image or scanned copy of the identity document; 29.4. where basic verification (Level 2) or higher is completed — undergoes the "liveness" confirmation procedure (provides an image of the face for comparison with the photograph in the document).

30. The KYC Service performs: 30.1. verification of the authenticity of the submitted document; 30.2. verification for signs of counterfeiting, editing or distortion of the image; 30.3. matching of the data entered by the User; 30.4. (for Level 2 and above) comparison of an image of the User's face with the photograph in the document.

31. Upon completion of the verification, the KYC Service transfers to the Operator the verification result and the confirmed set of personal data, including: 31.1. surname, given name, patronymic (if any); 31.2. date of birth; 31.3. series and number of the identity document (or other document); 31.4. date of issue and the authority that issued the document; 31.5. division code.

32. The Operator does not receive and does not process: 32.1. original images of identity documents; 32.2. images of the User's face taken as part of the "liveness" confirmation procedure; 32.3. other information that is not included in the list of confirmed data specified in clause 31 of this Chapter; 32.4. data processed by authentication technologies on the User's device (Face ID, Touch ID or similar technologies) used by the User to sign in to the mobile application of the Service — such data are processed solely by the operating system of the User's device and are not transferred to the Operator.

Chapter 6. Obligations of the Parties

33. The User is obliged to: 33.1. provide information containing Personal Data and necessary for the use of the Service; 33.2. update and supplement the information provided about personal data if such information changes.

34. The Operator is obliged to:

34.1. explain to the personal data subject the subject's rights related to the processing of personal data;

34.2. obtain the consent of the personal data subject, except in cases provided for by Law No. 99-Z and other legislative acts;

34.3. use the information obtained solely for the purposes specified in clause 14 of this Privacy Policy;

34.4. ensure that confidential information is kept secret, not to disclose it without the User's prior written permission, and not to sell, exchange, publish or otherwise disclose the User's transferred personal data. The Company does not disclose Personal Data to third parties except as expressly provided in this Policy (including clause 8) and in the Personal Data Processing Policy of Doverka Fintekh LLC (Chapter 7, clauses 19– 21), as required by the legislation of the Republic of Belarus, or where disclosure is necessary for the performance of the agreement (provision of services) with the User, including the execution of payment transactions with payment partners and contractors;

34.5. ensure the protection of personal data in the course of their processing;

34.6. amend Personal Data that are incomplete, outdated or inaccurate, except in cases where a different procedure for amending Personal Data is established by legislative acts or where the purposes of processing personal data do not presuppose subsequent amendment of such data;

34.7. cease the processing of personal data and delete or block them (ensure the cessation of processing of personal data, and their deletion or blocking by the Authorized Person) in the absence of grounds for the processing of personal data provided for by Law No. 99- Z and other legislative acts;

34.8. notify the authorized body for the protection of the rights of personal data subjects of breaches of personal data protection systems without undue delay, but no later than three business days after the Operator becomes aware of such breaches, except in cases provided for by the authorized body for the protection of the rights of personal data subjects;

34.9. amend, block or delete inaccurate or unlawfully obtained personal data of a personal data subject upon request of the authorized body for the protection of the rights of personal data subjects, unless a different procedure for amending, blocking or deleting Personal Data is established by legislative acts;

34.10. perform other obligations provided for by Law No. 99-Z and other legislative acts.

Chapter 7. Organization of Personal Data Protection

35. Protection of Personal Data means a set of legal, organizational and technical measures aimed at: 35.1. ensuring the protection of information from unlawful access, destruction, modification, blocking, copying, provision, distribution, and other unlawful actions in respect of such information; 35.2. observance of the confidentiality of restricted- access information; 35.3. realization of the right of access to information. 36. To protect Personal Data, the Company takes the necessary measures provided for by law (including, without limitation):

36.1. restricts and regulates the staff and other persons whose functional duties require access to information containing Personal Data (including through the use of access passwords to electronic information resources);

36.2. ensures the conditions for the storage of documents containing Personal Data under restricted access;

36.3. organizes the procedure for the destruction of information containing Personal Data, where legislation does not establish requirements for the storage of such data;

36.4. monitors compliance with the requirements for the protection of Personal Data, including those established by this Policy (by conducting internal audits, establishing special monitoring tools, etc.);

36.5. investigates cases of unauthorized access to or disclosure of Personal Data, holding responsible employees accountable and taking other measures;

36.6. implements software and technical means of protecting information in electronic form, including encryption of personal data at rest (AES-256) and in transit (TLS 1.2+), masking of telephone numbers and other identifiers when displayed, and storage of PIN codes and passwords solely in hashed form;

36.7. ensures the ability to recover Personal Data modified or destroyed as a result of unauthorized access to them;

36.8. other measures provided for by the legislation of the Republic of Belarus.

37. The Company appoints a person responsible for carrying out internal control over the processing of Personal Data, and in the event that such person is not appointed, the person responsible for carrying out internal control over the processing of personal data shall be the head (director) of the Company.

38. The Company familiarizes employees and other persons directly performing the processing of Personal Data with the provisions of legislation on Personal Data, including the requirements for the protection of Personal Data, with this Policy, and provides training to such employees and other persons in the manner established by legislation.

39. The Company takes other measures aimed at ensuring the fulfilment by the Company of its obligations in the field of Personal Data, as provided for by the applicable legislation of the Republic of Belarus.

Chapter 8. Final Provisions

40. Employees of the Company and other persons responsible for violations of this Policy, as well as of the legislation of the Republic of Belarus in the field of Personal Data, may be held disciplinarily and financially liable in the manner established by the Labour Code, and may also be held civilly, administratively and criminally liable in the manner established by the legislation of the Republic of Belarus.

41. The regulation of the handling of Personal Data established by this Policy aims to ensure the rights and freedoms of Personal Data Subjects in the processing of Personal Data, the preservation of the confidentiality of Personal Data, and their protection.

42. This Policy serves as the basis for the development of local acts, including legal acts, regulating matters concerning the processing and protection by the Company of Personal Data of Personal Data Subjects when using the "DoverkaSEND" Service.

43. All matters not reflected in this Policy or in the Company's other local acts shall be governed by the legislation of the Republic of Belarus.