{"id":47108,"date":"2025-12-12T14:20:10","date_gmt":"2025-12-12T14:20:10","guid":{"rendered":"https:\/\/masarat.ly\/?page_id=47108"},"modified":"2026-03-13T14:37:39","modified_gmt":"2026-03-13T14:37:39","slug":"privacy-policy-mobimal","status":"publish","type":"page","link":"https:\/\/masarat.ly\/privacy-policy-mobimal\/","title":{"rendered":"Mobimal Privacy Policy"},"content":{"rendered":"<div style=\"direction:ltr;\">\n<h1>Privacy Policy<\/h1>\n<p><strong>Effective Date 11\/03\/2026<\/strong><\/p>\n<p><strong>This Privacy Policy<\/strong> highlights the new services and features introduced in the updated version of the <strong>Mobimal<\/strong> mobile application. It also outlines our policies and procedures regarding the collection, use, and disclosure of your information when you use our Service. Additionally, it explains your privacy rights and how applicable laws protect you.<\/p>\n<p><strong>We provide Palm Pay for use with Yussor Pay<\/strong>, ensuring a high level of security and full compliance with Libyan regulations. By using the Service, you agree to the collection and use of information in accordance with this Privacy Policy.<\/p>\n<h2>Interpretation and Definitions<\/h2>\n<h3>Interpretation<\/h3>\n<p>Words with capitalized initials have defined meanings. These definitions apply regardless of whether the words appear in singular or plural form.<\/p>\n<h3>Definitions<\/h3>\n<p>For the purposes of this Privacy Policy:<\/p>\n<ul>\n<li><strong>Account<\/strong> refers to a unique profile created to access Our Service.<\/li>\n<li><strong>Affiliate<\/strong> means an entity that controls, is controlled by, or is under common control with Us.<\/li>\n<li><strong>Application<\/strong> refers to the <strong>Mobimal<\/strong> mobile application provided by the Company.<\/li>\n<li><strong>Company<\/strong> (referred to as \u201cWe,\u201d \u201cUs,\u201d or \u201cOur\u201d) means <strong>Masarat for IT and Financial Services<\/strong>, Tripoli, Libya.<\/li>\n<li><strong>Country<\/strong> refers to Libya.<\/li>\n<li><strong>Device<\/strong> means any device capable of accessing the Service, including computers, smartphones, and tablets.<\/li>\n<li><strong>Personal Data<\/strong> refers to any information related to an identified or identifiable individual.<\/li>\n<li><strong>Service<\/strong> refers to the Application and associated functionalities.<\/li>\n<li><strong>Service Provider<\/strong> means third parties engaged to process data on Our behalf.<\/li>\n<li><strong>Usage Data<\/strong> refers to data collected automatically when using the Service.<\/li>\n<li><strong>Add Friend<\/strong> refers to a feature enabling users to scan a QR code to add a beneficiary for money transfers to National Commercial Bank account holders and other banks in Libya.<\/li>\n<li><strong>You<\/strong> refers to the individual or entity accessing the Service.<\/li>\n<li><strong>LYPay \/ OnePay:<\/strong> Legal payment services launched by the Central Bank of Libya for bank transfers using IBAN &amp; enables you to make purchases using electronic payment methods.<\/li>\n<li><strong>Remote Onboarding<\/strong> refers to a process to perform facial forensics and verify the user&#8217;s identity by matching their face with their passport photo.<\/li>\n<li><strong>QR push mode:<\/strong> a service that allows users to generate QR code for push payment.<\/li>\n<li><strong>Palm Pay:<\/strong> refers to a biometric payment service that allows users to authorize payments using their palm.<\/li>\n<\/ul>\n<h2>Collecting and Using Your Personal Data<\/h2>\n<h3>Types of Data Collected<\/h3>\n<p><strong>Personal Data<\/strong><\/p>\n<p>We may collect the following personally identifiable information:<\/p>\n<ul>\n<li>Email address<\/li>\n<li>First and last name<\/li>\n<li>Phone number<\/li>\n<li>Usage Data<\/li>\n<\/ul>\n<p><strong>Usage Data<\/strong><\/p>\n<p>Usage Data is collected automatically and may include:<\/p>\n<ul>\n<li>IP address<\/li>\n<li>Browser type and version<\/li>\n<li>Pages visited, visit duration, and other analytics<\/li>\n<li>Device type and identifiers<\/li>\n<li>Mobile operating system details<\/li>\n<\/ul>\n<p><strong>Information Collected While Using the Application<\/strong><\/p>\n<p>With Your permission, We may collect:<\/p>\n<ul>\n<li><strong>Location Data<\/strong> (used per session only, for ATM\/branch locator features)<\/li>\n<li><strong>Camera Access<\/strong> (for QR code-based payments and Remote Onboarding process)<\/li>\n<li><strong>Network Access<\/strong> (to enable transaction processing)<\/li>\n<li><strong>Read Media:<\/strong> (Used to capture images of your face and passport as part of the identity verification process)<\/li>\n<li><strong>Read Video:<\/strong> (Used to verify that the facial image is captured in real time during identity verification)<\/li>\n<li><strong>SMS Autofill<\/strong> (for OTP verification)<\/li>\n<\/ul>\n<p>You can enable or disable access to these features at any time via Your device settings.<\/p>\n<h3>Money Transfer Service Using IBAN<\/h3>\n<p>To facilitate money transfers, We may collect:<\/p>\n<ul>\n<li><strong>Sender Information:<\/strong> Name, address, phone number, email<\/li>\n<li><strong>Recipient Information:<\/strong> Name, IBAN<\/li>\n<li><strong>Transaction Details:<\/strong> Amount, currency, reference (if provided)<\/li>\n<li><strong>Identification Verification:<\/strong> (Potential future requirement for compliance)<\/li>\n<li><strong>Device Information:<\/strong> Device type and operating system<\/li>\n<\/ul>\n<p><strong>Use of Your Information:<\/strong><\/p>\n<ul>\n<li>Process transactions securely<\/li>\n<li>Verify identity and prevent fraud<\/li>\n<li>Provide customer support<\/li>\n<li>Comply with regulatory obligations<\/li>\n<\/ul>\n<p><strong>Information Sharing:<\/strong><\/p>\n<ul>\n<li><strong>Third-Party Service Providers<\/strong> (e.g., payment processors, fraud screening services)<\/li>\n<li><strong>Regulatory Authorities<\/strong> (for anti-money laundering (AML) and know-your-customer (KYC) compliance)<\/li>\n<\/ul>\n<p><strong>Data Security Measures:<\/strong><\/p>\n<p>We implement safeguards such as:<\/p>\n<ul>\n<li><strong>Encryption:<\/strong> Data is encrypted in transit and at rest.<\/li>\n<li><strong>Access Controls:<\/strong> Only authorized personnel have access.<\/li>\n<li><strong>Regular Security Audits:<\/strong> We conduct periodic assessments to identify vulnerabilities.<\/li>\n<\/ul>\n<h3>Permissions and Access Control<\/h3>\n<p>We request permissions solely to provide essential functionalities, including:<\/p>\n<ul>\n<li><strong>Location Services (Optional):<\/strong> Find ATMs\/branches.<\/li>\n<li><strong>Read Media:<\/strong> To capture images of your face and passport for identity verification.<\/li>\n<li><strong>Read Video:<\/strong> To verify that the facial image is captured in real time.<\/li>\n<li><strong>Camera Access:<\/strong> Used for QR code-based payments (images not stored) and to verify and match the user\u2019s face with their passport photo as part of the remote onboarding process (for opening a new bank account).<\/li>\n<\/ul>\n<p><strong>Note:<\/strong> No images captured by users are stored \u2014 this process is strictly limited to verifying the match between the live image and the passport photo for identity purposes only.<\/p>\n<ul>\n<li><strong>Notifications (Optional):<\/strong> Account activity alerts, security updates.<\/li>\n<li><strong>Secure Login:<\/strong> Encrypted data storage for enhanced performance.<\/li>\n<\/ul>\n<p>You can modify permissions at any time via Your device settings.<\/p>\n<h2>ISO 27001 Compliance &amp; Security<\/h2>\n<p>As part of Our commitment to information security, We adhere to <strong>ISO 27001:2022<\/strong> standards to ensure confidentiality, integrity, and availability of data. Our security framework includes:<\/p>\n<ul>\n<li><strong>Risk Management:<\/strong> Regular risk assessments to identify and mitigate security threats.<\/li>\n<li><strong>Data Encryption:<\/strong> Secure encryption methods for data transmission and storage.<\/li>\n<li><strong>Incident Response:<\/strong> A structured plan to detect, respond, and recover from security incidents.<\/li>\n<li><strong>User Access Controls:<\/strong> Role-based access restrictions to limit data exposure.<\/li>\n<li><strong>Audit and Compliance Monitoring:<\/strong> Continuous audits to ensure adherence to regulatory and compliance requirements.<\/li>\n<\/ul>\n<p>In case of a data breach, We will promptly notify affected users and relevant authorities, as per applicable regulations.<\/p>\n<h2>Data Retention<\/h2>\n<p>We retain Personal Data only as long as necessary for:<\/p>\n<ul>\n<li>Service provision and legal compliance<\/li>\n<li>Fraud prevention and dispute resolution<\/li>\n<li>Business analytics and service improvement<\/li>\n<\/ul>\n<p>Usage Data may be retained for a shorter period unless required for security or legal compliance.<\/p>\n<h2>Children\u2019s Privacy<\/h2>\n<p>Our Service is not intended for individuals under 18. We do not knowingly collect data from minors. If You are a parent or guardian and believe Your child has provided Personal Data, please contact Us for removal.<\/p>\n<h2>Your Rights<\/h2>\n<p>Depending on Your location and applicable laws, You may have the right to:<\/p>\n<ul>\n<li><strong>Access Your Data:<\/strong> Request a copy of the information We hold.<\/li>\n<li><strong>Correct Inaccuracies:<\/strong> Update or rectify incorrect information.<\/li>\n<li><strong>Restrict Processing:<\/strong> Limit how We use Your data.<\/li>\n<li><strong>Deactivation request:<\/strong> request a temporarily deactivate your mobile banking account to proceed and delete it personally in your designated branch.<\/li>\n<li><strong>Data Portability:<\/strong> Transfer Your data to another provider.<\/li>\n<li><strong>Object to Processing:<\/strong> Opt-out of certain uses, such as marketing.<\/li>\n<\/ul>\n<p>To exercise these rights, contact Us via the details below.<\/p>\n<h2>OnePay Service<\/h2>\n<p>With <strong>OnePay<\/strong> \u2013 one payment for everything, and transfers to anyone!<\/p>\n<p>This is a unified payment service officially supported by the <strong>Central Bank of Libya<\/strong>, designed to make your payments and money transfers simple and secure. Through this service, you can:<\/p>\n<ul>\n<li><strong>Make electronic purchases<\/strong> using any of the supported payment providers such as: <em>Msarfey Pay, Yussor Pay, Sahara Pay, Daman Pay and Seraj Pay<\/em>.<\/li>\n<li><strong>Pay across banks and providers<\/strong> seamlessly, regardless of your primary payment app.<\/li>\n<li><strong>Transfer money<\/strong> between participating banks quickly and easily.<\/li>\n<\/ul>\n<h3>Privacy and Data Protection<\/h3>\n<ul>\n<li>We do not store your card or bank account details within the app.<\/li>\n<li>All payment and transfer operations are processed through encrypted channels, following <strong>PCI DSS<\/strong> and <strong>ISO 27001<\/strong> standards, and in compliance with applicable data protection regulations.<\/li>\n<li>The app only shares the minimum required information with <strong>OnePay<\/strong> and the authorized payment providers to complete the transaction. Your data is never used for marketing or any unauthorized purpose.<\/li>\n<li>We are committed to transparency in notifying you whenever your data is shared with third parties, in line with <strong>App Store<\/strong> and <strong>Google Play<\/strong> payment and consumer protection policies.<\/li>\n<\/ul>\n<h3>Your Consent<\/h3>\n<p>By using the <strong>OnePay<\/strong> service within the app, you consent to the processing of your financial data solely to complete your requested transactions, in accordance with the <strong>Central Bank of Libya regulations<\/strong> and applicable data protection laws.<\/p>\n<h2>Palm Pay Service<\/h2>\n<p>Palm Pay service offers secure biometric authentication for <strong>Yussor Pay<\/strong> to authorize payments without need for QR codes.<\/p>\n<p><strong>No palm images or media related to the palm recognition are stored<\/strong>. All biometric and transaction data are processed securely, using encryption both in transit and at rest, in compliance with <strong>ISO 27001<\/strong> and <strong>applicable Libyan regulations.<\/strong><\/p>\n<h2>Changes to This Privacy Policy<\/h2>\n<p>We may update this Privacy Policy from time to time. Changes will be notified via email or a prominent notice on Our Service. Please review this policy periodically for updates.<\/p>\n<h2>Contact Us<\/h2>\n<p>For any questions regarding this Privacy Policy, You can contact Us at:<\/p>\n<ul>\n<li><strong>Email:<\/strong> <a href=\"mailto:support@masarat.ly\">support@masarat.ly<\/a><\/li>\n<li><strong>Phone:<\/strong> 0900300900<\/li>\n<\/ul>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Privacy Policy Effective Date 11\/03\/2026 This Privacy Policy highlights the new services and features introduced in the updated version of the Mobimal mobile application. It also outlines our policies and procedures regarding the collection, use, and disclosure of your information when you use our Service. Additionally, it explains your privacy rights and how applicable laws [&hellip;]<\/p>\n","protected":false},"author":12,"featured_media":1615,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"_acf_changed":false,"footnotes":""},"class_list":["post-47108","page","type-page","status-publish","has-post-thumbnail","hentry"],"acf":[],"_links":{"self":[{"href":"https:\/\/masarat.ly\/qafevol\/wp\/v2\/pages\/47108","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/masarat.ly\/qafevol\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/masarat.ly\/qafevol\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/masarat.ly\/qafevol\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/masarat.ly\/qafevol\/wp\/v2\/comments?post=47108"}],"version-history":[{"count":6,"href":"https:\/\/masarat.ly\/qafevol\/wp\/v2\/pages\/47108\/revisions"}],"predecessor-version":[{"id":47309,"href":"https:\/\/masarat.ly\/qafevol\/wp\/v2\/pages\/47108\/revisions\/47309"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/masarat.ly\/qafevol\/wp\/v2\/media\/1615"}],"wp:attachment":[{"href":"https:\/\/masarat.ly\/qafevol\/wp\/v2\/media?parent=47108"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}