Privacy Policy
Last Updated: NaNundefined Invalid Date
This Privacy Policy outlines how we handle the information you share with us, detailing both permissible and restricted uses. At NASS, we prioritize safeguarding your personal data.
This policy is applicable to all services provided by NASS, including but not limited to our digital platforms, mobile applications, products, and any additional tools or offerings (including Issuing, Acquiring, Processing, Card Personalization, Digital Wallet Services). It outlines the methods we use to gather, manage, utilize, and secure your personal data. Reviewing this Privacy Policy is essential for understanding your rights and our responsibilities. The term "personal information" refers to data that identifies or can be linked to a specific individual. Anonymous data that cannot identify a person is not considered personal information.
By using our services—signing up, accessing, or utilizing our website, apps, or any other NASS services—you acknowledge and agree to the terms of this Privacy Policy.
By voluntarily submitting your personal data, you authorize us to process it in accordance with this policy.
NASS may revise this policy at any time by publishing the updated version on nass.iq. The updated policy takes effect immediately upon posting. Continued usage of our site, services, or your NASS account after updates implies your acceptance of the revised terms. We recommend checking our policy periodically to stay informed of any changes.
Scope of this Privacy Policy includes:
• How we collect personal data
• How we utilize the information
• How you can access, review, or modify your information
• How we communicate with you
• Links to external websites
• Use of cookies
• Participation in contests or promotions
• Security of your data
Introduction
When referring to "we," "our," or "us," we mean NASS. Our headquarters are based in Erbil, Iraq. NASS is a leading entity in Iraq's financial technology landscape, committed to reshaping digital finance through advanced technologies and expert-driven services. Since our inception in 2019, our mission has been to revolutionize how individuals and businesses manage and move their finances using innovative financial solutions. More about us can be found on our "About NASS" page.
Information We Collect
We gather personal information when you visit our sites or use our platforms. This information is only used and shared in accordance with this Privacy Policy. The data we collect falls into two categories:
a. Automatically Collected Data
We automatically gather technical details from your devices, including:
• Pages accessed
• IP address
• Unique device identifiers
• Device model and network data
• Location data
• Connection details, page view statistics, referring URLs
• Advertisement data and standard log files
b. Data You Provide Directly
Information you input or share while using NASS may include:
• Web form entries
• Account and identity verification updates
• Chats or interactions with support
• Correspondence records
When using our services, we also capture details about your activities and transactions. If you open an account or use NASS offerings, we may collect:
Personal Identification Information:
• Full name, date of birth, ID documents (passport or national ID), email, and phone number
• KYC compliance information
Financial Information:
• Bank details, card information (CVV, expiry), transaction logs, income data, and credit score
Usage Data:
• Device and browser types, IP address, pages visited, login/logout details, location data, and user navigation patterns
Technical Data:
• Cookie identifiers, session logs, device fingerprint data (e.g., screen size, OS version), and analytics tool results
Biometric Information (if applicable):
• Data such as facial recognition, voice, or fingerprints used for multi-factor authentication
We may also obtain information from:
• Customer service interactions
• Surveys and feedback forms
We might record or monitor phone conversations for security, training, and quality control purposes.
By interacting with NASS, you acknowledge that your communication could be monitored.
You might allow us to access personal data from third-party platforms (e.g., Facebook, YouTube). The type of data we access depends on your settings with those platforms. By linking accounts, you authorize NASS to use the information in line with this policy.
When accessing our mobile services, we may gather location data and device IDs to offer geo-specific features. Most smartphones allow you to adjust these settings to control location tracking.
Choosing not to share your personal information may limit your ability to use certain features or services. In cases where we are unable to collect required data, we may not be able to deliver our full range of services.
Legal Grounds for Processing Data
Our rationale for collecting and processing your personal information is based on various legal foundations, depending on context. Typically, we process your data when:
• You have given explicit consent
• It is essential to fulfill a contract
• It aligns with our legitimate interests, provided your rights are not compromised
• We are legally obligated to process the data
How We Use the Information
We use your data to operate, manage, and improve our services. This includes:
• Creating and maintaining your user account, verifying your identity, and processing transactions
• Delivering services and offering customer support
• Meeting regulatory requirements such as anti-money laundering (AML) and counter-terrorist financing (CTF)
• Preventing fraud by monitoring account activity
• Offering tailored product recommendations and marketing campaigns
Additional uses include:
• Fulfilling contractual obligations
• Diagnosing and resolving technical issues
• Developing new services or enhancements
• Personalizing user experience, where applicable
• Tracking service performance
• Maintaining system security
• Issuing service-related updates or breach notifications
• Any other use that is either disclosed at the time of collection or is reasonably anticipated under this policy and our Terms & Conditions
Sharing Your Information
We do not sell your data. We may share it under the following conditions:
1. With your explicit authorization
2. With affiliates, business partners, or trusted third parties assisting in service provision
3. With vendors and contractors handling infrastructure, legal, support, or payment services
4. With regulatory authorities or legal bodies as required for compliance or in defense of rights
Data Accuracy
We strive to keep your personal information accurate and current. However, we rely on you to notify us of any updates or changes. You can make these updates through your account dashboard.
Information Security
We maintain robust measures to guard your personal data against unauthorized access, misuse, or loss. Our systems are designed to provide a secure user environment.
In the event of a significant breach that could impact your rights, we will notify the appropriate authorities (e.g., CBI) and contact you promptly unless the breach poses minimal risk, such as if the data was encrypted.
If you suspect a data breach or unauthorized account use, contact [email protected] immediately.
Data Retention
We keep your information only as long as necessary to fulfill business, legal, or regulatory obligations, including service operations and compliance purposes.
Once it is no longer needed, we either delete or anonymize it, consistent with our retention policies.
You can request access to your personal data by emailing [email protected]. We aim to respond within a reasonable time frame.
Use of Cookies
To optimize your experience, we utilize cookies—small files that store information about your activity and preferences.
We may use the following cookie types:
1. Essential cookies – necessary for secure logins and basic site features
2. Performance/analytics cookies – used to evaluate user behavior and improve navigation
3. Functional cookies – store settings like preferred language or region
External parties, such as advertising and analytics providers, may also place their own cookies on your device. These are managed independently from NASS.
Contact Information
If you have any inquiries, feedback, or privacy concerns, feel free to reach us at: