Last revised: 25 May 2026
This Privacy Policy explains how Nano Advanced Services Limited (“NAS”, “we”, “us”) collects, uses, and shares personal data of:
- Visitors to nas.cards (covered also by our website-visitor privacy notice at /privacy.html).
- Partner representatives — officers, directors, employees, contractors and other personnel of organisations that have entered into the NAS Partner Platform Terms with us (each a “Partner”), and who access the NAS Business Portal, Support Portal, Admin Back-office, or other Surfaces.
- Prospective Partners — people who contact us about our Services, attend a demo, request a proposal, or otherwise engage in commercial discussions with us.
This Privacy Policy describes NAS’s processing in those roles, where NAS acts as the controller of the relevant personal data.
This Privacy Policy does not cover NAS’s processing of personal data relating to end-customers of our Partners’ Programs. When NAS handles end-customer data, NAS acts as a processor on the Partner’s behalf, and the Partner (as controller) provides its own privacy notice to its customers. The NAS Data Processing Addendum, executed with each Partner, governs that processing.
1. Who we are
NAS — Nano Advanced Services Limited — is a company incorporated in the Hong Kong Special Administrative Region (company number 76848773) with registered office at Unit 1603, 16th Floor, The L. Plaza, 367–375 Queen’s Road Central, Sheung Wan, Hong Kong. “NAS” is the brand under which Nano Advanced Services Limited provides its platform; references to “NAS” mean Nano Advanced Services Limited unless the context requires otherwise. Contact us about this Privacy Policy by emailing privacy@nas.cards or by writing to us at the registered office.
Nano Advanced Services Limited is registered with the U.S. Financial Crimes Enforcement Network (FinCEN) as a foreign-located money-services business; that registration is for US AML / money-services purposes and is not a general or cross-jurisdictional authorisation. NAS does not hold client funds as principal and does not independently control customer safeguarding arrangements, and does not provide regulated money-transmission, custody, or banking services directly to end-customers.
NAS has not appointed a representative under Article 27 of the EU GDPR or the UK GDPR. If you are in the European Union or the United Kingdom and wish to direct a data-protection enquiry to NAS, please email privacy@nas.cards — we will route your enquiry to the appropriate person internally. You retain your statutory rights, including the right to lodge a complaint with your local Supervisory Authority (see Section 8).
2. The personal data we collect
We collect personal data falling into the following categories.
2.1 From visitors to nas.cards
- Information you give us through our contact form: name, work email, company, message content, and the consent you record by ticking the consent box.
- Technical information collected automatically when you visit: IP address, browser type and version, device and operating-system information, referring URL, pages visited, and timestamps. See the Cookie Policy for detail on the use of local storage and any third-party tools.
2.2 From Partner representatives
- Identity and contact data: name, work email, work phone number, job title, work address.
- Authentication data: username, hashed password, multi-factor-authentication enrolment details, OTP records, device identifiers, IP address, login timestamps.
- Authorisation data: roles, permissions, and access scopes assigned within the Partner’s tenancy.
- Activity data: actions taken within the Business Portal, Support Portal, and Admin Back-office (including the records of administrative actions captured in the audit log).
- Support data: the content of communications with our support, sales, and account-management teams.
2.3 From prospective Partners
- Identity and contact data, company information, and any context you share about your business and your interest in the Services (whether through our contact form, by email, during a call or demo, or otherwise).
3. How we use the personal data, and on what legal basis
We process personal data for the following purposes, on the legal bases described.
| Purpose | Categories used | Legal basis (EU/UK GDPR) |
|---|---|---|
| Responding to enquiries (contact form, sales, support) | Visitor and prospective-Partner data; communication content | Performance of pre-contractual steps; our legitimate interest in handling enquiries |
| Administering Partner Accounts (creation, access management, MFA enrolment, password recovery) | Partner-representative identity, contact, authentication, authorisation data | Performance of the Platform Terms (contract); our legitimate interest in secure account administration |
| Authenticating users and securing the platform (fraud detection, abuse prevention, anomaly detection) | Authentication, activity, device, network data | Our legitimate interest in operating the platform securely; compliance with legal obligations |
| Providing support, training, and account management | Identity, contact, support data | Performance of the Platform Terms; our legitimate interest in maintaining the commercial relationship |
| Billing and invoicing | Identity, contact, transaction-volume data | Performance of the Platform Terms; legal obligation to maintain accounting records |
| Service-improvement analytics (aggregated and, where reasonably practicable, pseudonymised) | Activity, support data in aggregate | Our legitimate interest in improving the Services |
| Sanctions, PEP and adverse-media screening of Partner controllers, representatives and ultimate beneficial owners | Identity, contact, role data | Compliance with legal obligations (sanctions and anti-money-laundering law); our legitimate interest in operating an institutional financial-infrastructure stack |
| Compliance, audit, regulatory reporting, and responding to lawful Regulatory Authority requests | All categories, as relevant to the specific request | Compliance with legal obligations |
| Sending operational and security-related notifications | Identity and contact data | Performance of the Platform Terms; legal obligation in the case of security notifications |
| Sending marketing communications about our Services (where you have opted in or where permitted under soft-opt-in rules) | Identity and contact data | Consent; our legitimate interest where soft-opt-in conditions are met |
Where we rely on consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
Where we rely on legitimate interests, we have considered the impact on you and conclude that our interests are not overridden by your interests, rights and freedoms. You can ask us for more detail on this balancing analysis by contacting privacy@nas.cards.
Under the Hong Kong Personal Data (Privacy) Ordinance (the “PDPO”), we process personal data for the purposes described above on the basis that the processing is consistent with the purpose for which it was collected, or for a directly-related purpose, or with the consent of the data subject as required.
4. Who we share personal data with
We share personal data with the following categories of recipient. We do not sell personal data, and we do not share personal data with third parties for their independent marketing purposes.
- Our staff and contractors, on a need-to-know basis and subject to confidentiality obligations.
- Our sub-processors, who provide cloud hosting, email and SMS delivery, push notifications, web-form anti-bot services, brand-asset enrichment, and similar supporting services. Our sub-processors process personal data on our instructions and are subject to written contracts including data-protection obligations consistent with this Privacy Policy. The current list of sub-processors (identified by name, role, location, and data categories) is published to our Partners under non-disclosure agreement; a category-level summary is available on request.
- Our regulated back-end partners, which depending on the Program may include a third-party regulated card-issuer and/or a regulated custodian, or NAS’s own MPC-based custody infrastructure. Personal data is shared where it needs to be shared to operate the Services in respect of a specific Partner’s Program (for example, account-administration data for a Partner representative who is also a compliance-onboarding contact). The identities of these partners are NAS’s confidential information and are disclosed only under non-disclosure agreement.
- Professional advisers (lawyers, accountants, auditors) under appropriate confidentiality obligations.
- Regulatory Authorities where required by Applicable Law or by lawful order.
- Acquirers, investors, and successors in connection with a merger, acquisition, investment, financing, or similar corporate transaction, subject to appropriate confidentiality.
A list of the categories of recipient relevant to your role, and (on request) the specific recipients, is available by writing to privacy@nas.cards.
5. Where personal data is held
The Partner-representative and prospective-Partner personal data for which NAS is the controller is hosted on cloud infrastructure operated by a tier-one cloud-services provider in the European Union (primary location: Frankfurt, Germany). The nas.cards marketing site is hosted by the same provider in the same region and delivered globally through a content-delivery network. Customer-facing personal data processed in connection with a Partner’s Program (where NAS acts as processor) resides on the Partner’s own hosting infrastructure and is governed by the Data Processing Addendum executed with that Partner. Some sub-processors operate from other locations (including the European Union, the United Kingdom, the United States, and other jurisdictions).
Where personal data is transferred from the EEA, the UK, or Hong Kong to a country that does not provide an adequate level of protection under the source jurisdiction’s law, we rely on appropriate transfer mechanisms — typically the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Agreement, or the Hong Kong Privacy Commissioner’s Recommended Model Contractual Clauses, as applicable, supplemented where relevant by additional technical and organisational measures.
You can obtain a copy of the transfer mechanism in place for any specific transfer by writing to privacy@nas.cards (commercially-sensitive contractual terms may be redacted).
6. How long we keep personal data
We keep personal data for as long as we need it for the purposes described in this Privacy Policy, plus any retention period required by Applicable Law or required to defend against legal claims. Indicatively:
- Enquiry data: typically up to twelve (12) months from the date of enquiry, unless a commercial relationship develops.
- Partner-representative data: for the term of the Platform Terms with the relevant Partner, plus the wind-down period, plus the period required by Applicable Law (typically up to seven (7) years for accounting and tax records).
- Support records: typically up to three (3) years from closure of the relevant support ticket.
- Audit-log records: for the period required by Applicable Law and by the operating standards of NAS’s regulated back-end partners.
- Marketing-preference records: for as long as the preference is in force, plus up to two (2) years for evidence purposes.
We routinely delete or anonymise personal data once the retention period expires.
7. How we protect personal data
We maintain technical and organisational measures appropriate to the risk, including access control, encryption in transit and at rest, multi-factor authentication, network segmentation, secure software development, regular penetration testing, audit logging, sub-processor due diligence, and a documented incident-response plan. See the security measures described in our Data Processing Addendum for more detail.
8. Your rights
Depending on the jurisdiction in which you are located and the legal basis on which we process your personal data, you may have rights to:
- Access the personal data we hold about you.
- Request correction of inaccurate or incomplete personal data.
- Request erasure of your personal data in certain circumstances.
- Object to or restrict our processing of your personal data in certain circumstances.
- Receive your personal data in a portable format and ask us to transmit it to another controller (where the processing is based on consent or contract and is carried out by automated means).
- Withdraw any consent you previously gave.
- Not be subject to a decision based solely on automated processing that produces legal or similarly significant effects (we do not currently make decisions of this nature in relation to the personal data covered by this Privacy Policy).
To exercise any of these rights, please contact privacy@nas.cards. We will respond within the timeframe required by Applicable Law (typically one month for EU/UK GDPR requests; we may extend this in complex cases, with notice).
If you are in the EU/EEA, you have the right to lodge a complaint with your local Supervisory Authority. If you are in the UK, you may complain to the Information Commissioner’s Office (ico.org.uk). If you are in Hong Kong, you may complain to the Privacy Commissioner for Personal Data (pcpd.org.hk).
9. Rights of US residents (CCPA/CPRA and equivalent state laws)
If you are a resident of California, Colorado, Connecticut, Virginia, Utah, Texas, or another US state with a comprehensive privacy statute, you have rights in respect of personal data we process about you, including the right to:
- Know the categories and specific pieces of personal data we have collected about you, the sources from which it was collected, the purposes for which we use it, and the categories of recipients with whom we share it.
- Delete personal data we have collected from you, subject to legally-permitted exceptions.
- Correct inaccurate personal data we maintain about you.
- Portability — receive your personal data in a portable format.
- Opt out of sale of personal data, of sharing for cross-context behavioural advertising, and of targeted advertising. We do not sell personal data, do not share personal data for cross-context behavioural advertising, and do not engage in targeted advertising.
- Opt out of profiling that produces legal or similarly significant effects. We do not engage in such profiling in respect of Partner-representative or prospective-Partner data.
- Limit the use and disclosure of sensitive personal information, where applicable. We do not knowingly collect sensitive personal information from Partner representatives or prospective Partners as part of the Services.
- Non-discrimination — we will not discriminate against you for exercising any of these rights.
To exercise these rights, contact privacy@nas.cards. Authorised agents may submit a request on your behalf with written authorisation and verification of identity. We will respond within the timeframe required by the applicable state law (typically 45 days, extendable once with notice).
NAS honours Global Privacy Control (GPC) signals from your browser as a valid opt-out of sale/sharing where applicable.
10. Cookies and similar technologies
Our Cookie Policy explains how we use cookies, local storage, and similar technologies on nas.cards and on the Partner-facing Surfaces. See /cookie-policy.html.
11. Children
The Services are not directed to children. We do not knowingly collect personal data from children. If you believe we have collected personal data from a child, please contact privacy@nas.cards and we will take appropriate action.
12. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. The “Last revised” date at the top reflects the most recent revision. We will notify Partners of material changes through the Business Portal, by email, or by other appropriate means. The current version is always available at this URL.
13. How to contact us
For any privacy-related question, request, or complaint, please contact privacy@nas.cards, or write to us at our registered office. We aim to acknowledge enquiries within five (5) business days.