Last Updated: July 31, 2026
This Privacy Policy explains how Contegen Tech Limited, a company incorporated in Hong Kong SAR with company number 79156927 and registered office at Room 602, 6/F, Kai Yue Comm Building, Mongkok, Kowloon, Hong Kong SAR, operating as "Nalo" ("we", "us", "our", "Nalo"), collects, uses, shares, and safeguards personal data in connection with the Nalo mobile application, our website, and related services (together, the "Services").
We process personal data in accordance with the Hong Kong Personal Data (Privacy) Ordinance (Cap. 486) ("PDPO"). Where users are located in the European Economic Area, we also apply the standards of the EU General Data Protection Regulation ("GDPR") to their personal data.
This Policy describes what personal data we collect, why and how we use it, with whom we share it, how long we keep it, and the rights you have. If you have any questions, please contact us using the details below.
For the purposes of this Policy:
"Personal Data" means information relating to an identified or identifiable individual, such as name, contact details, identification numbers, IP address, or device identifiers.
"Data Subject" means the individual to whom Personal Data relates (you, or any other person whose data we process, including recipients of transfers).
"Data Controller" means the entity that determines the purposes and means of processing Personal Data. Nalo acts as the data controller for the processing described in this Policy.
"Data Processor" means an entity that processes Personal Data on our behalf and on our instructions, such as our IT, hosting, and analytics providers.
"Recipient" means the person to whom you send a money transfer through the Services.
We have appointed a Data Protection Officer ("DPO"). To raise questions about this Policy, exercise your rights, or report a concern, contact the DPO at yo@naloapp.co.
We do not intentionally collect data about your racial or ethnic origin, sexual orientation, political opinions, philosophical or religious beliefs, genetic data, or trade union membership. When you create an account, complete identity verification, or use the Services, we may collect:
When you initiate a money transfer, you provide us with personal data of your recipient, such as the recipient's full name and payout details. We process this data solely to execute the transfer, comply with legal obligations (including AML and sanctions screening), and prevent fraud. By providing recipient data, you confirm that you are lawfully entitled to share it with us and with our payment partners for these purposes, and that you have informed the recipient about such processing where required by applicable law.
To provide seamless Services, we may obtain personal data from third-party partners and vendors, who must have lawful grounds for collecting and sharing your data with us. These sources include:
Payment service providers: transaction confirmations, payment statuses, fraud signals.
Identity verification providers: verification results and related data, where we engage such providers.
Sanctions, AML, and PEP screening providers: screening results required for compliance.
Attribution and analytics providers (for example, AppsFlyer and app analytics tools): install attribution, campaign data, and in-app event data.
Public blockchain data: publicly available on-chain transaction data and wallet addresses, used to monitor for illegal activity and ensure compliance with our terms.
Details of your payment instruments are collected and processed by our third-party payment providers in accordance with their own security standards (including PCI DSS where card payments are used). We do not store full payment instrument details; we may store masked details and payment tokens necessary to provide the Services.
We process personal data on the following lawful grounds: performance of a contract with you, compliance with legal obligations, your consent, and our legitimate interests (where they are not overridden by your interests and rights).
We do not sell your personal data.
We share personal data only where necessary for the purposes described above, with:
Payment partners and financial institutions that execute payments and payouts. To deliver a transfer, we share the data necessary for its execution (including recipient data) with the payment partner responsible for the payout, which may be located in the destination country of your transfer.
Identity verification and compliance screening providers.
IT, hosting, analytics, attribution, and communication service providers acting on our behalf.
Advertising and marketing partners, where you have consented where required.
Professional advisers (legal, audit, accounting) under confidentiality obligations.
Courts, regulators, and law enforcement authorities, where required by applicable law or to protect our legal rights.
A successor entity in the event of a merger, acquisition, restructuring, or insolvency, in accordance with applicable law.
Our partners and service providers may be located outside Hong Kong and outside your country of residence, including in the destination countries of your transfers. Where personal data is transferred internationally, we take steps to ensure it remains protected, including contractual data protection obligations with our partners and, where applicable to EEA users, appropriate safeguards under the GDPR (such as standard contractual clauses). Note that executing a money transfer inherently requires sharing the data necessary for the payout with the payment partner in the destination country. For questions about international transfers, contact our DPO at yo@naloapp.co.
We will only use your personal data for direct marketing (for example, emails or push notifications about offers, promotions, and referral programs) where you have given consent, or where otherwise permitted by applicable law. You may opt out of direct marketing at any time, free of charge, by using the unsubscribe link in our emails, adjusting notification settings in the App, or contacting us at yo@naloapp.co. Opting out of marketing does not affect service communications necessary for the operation of your account and transfers.
We apply technical, organizational, and administrative measures to protect personal data, including encryption of data in transit and at rest, access controls and the need-to-know principle, employee confidentiality and training, data minimization, backups, logging and monitoring, and incident response procedures. No system is completely secure; we encourage you to use a strong unique password, enable available authentication protections on your device, and keep your credentials, keys, and backup data confidential.
We retain personal data only as long as necessary for the purposes for which it was collected, and as required by law:
Subject to applicable law, you have the right to:
- access the personal data we hold about you and obtain a copy;
- request correction of inaccurate or incomplete data;
- request deletion of your data, subject to our legal retention obligations;
- object to, or request restriction of, certain processing;
- withdraw consent at any time, where processing is based on consent, without affecting processing before withdrawal;
- receive your data in a portable format, where applicable; and
- lodge a complaint with a supervisory authority, including the Office of the Privacy Commissioner for Personal Data, Hong Kong, or (for EEA users) your local data protection authority.
To exercise your rights, contact our DPO at yo@naloapp.co. We respond to legitimate requests within the timeframes required by applicable law (generally within 30 days); complex requests may require more time. Requests are handled free of charge unless they are manifestly unfounded or excessive, in which case a reasonable fee may apply or we may decline the request, as permitted by law.
Please note that certain data (for example, KYC/AML and transaction records) must be retained by law and cannot be deleted on request during the mandatory retention period. Data recorded on public blockchains cannot be altered or deleted by us.
Our website and App use cookies and software development kits (SDKs) for functionality, analytics, attribution, and (with consent, where required) marketing. This includes attribution and analytics tools such as AppsFlyer and app analytics services, which help us measure installs, campaigns, and in-app events. On our website, you can manage your cookie preferences through the consent banner. You can limit ad tracking and reset advertising identifiers in your device settings.
The Services are intended for persons aged 18 or over. We do not knowingly collect personal data from minors. If you believe a minor has provided us with personal data, please contact us and we will delete it.
We may update this Privacy Policy to reflect changes in our practices or legal requirements. Material changes will be communicated through the App and/or by email, and the updated Policy will be published on our website with a revised "Last updated" date.
