Legal

Partner Privacy Policy

How NAS handles personal data of Partner representatives and prospective Partners — the contexts in which NAS acts as a controller.

Last revised: 25 May 2026

This Privacy Policy explains how Nano Advanced Services Limited (“NAS”, “we”, “us”) collects, uses, and shares personal data of:

This Privacy Policy describes NAS’s processing in those roles, where NAS acts as the controller of the relevant personal data.

This Privacy Policy does not cover NAS’s processing of personal data relating to end-customers of our Partners’ Programs. When NAS handles end-customer data, NAS acts as a processor on the Partner’s behalf, and the Partner (as controller) provides its own privacy notice to its customers. The NAS Data Processing Addendum, executed with each Partner, governs that processing.


1. Who we are

NAS — Nano Advanced Services Limited — is a company incorporated in the Hong Kong Special Administrative Region (company number 76848773) with registered office at Unit 1603, 16th Floor, The L. Plaza, 367–375 Queen’s Road Central, Sheung Wan, Hong Kong. “NAS” is the brand under which Nano Advanced Services Limited provides its platform; references to “NAS” mean Nano Advanced Services Limited unless the context requires otherwise. Contact us about this Privacy Policy by emailing privacy@nas.cards or by writing to us at the registered office.

Nano Advanced Services Limited is registered with the U.S. Financial Crimes Enforcement Network (FinCEN) as a foreign-located money-services business; that registration is for US AML / money-services purposes and is not a general or cross-jurisdictional authorisation. NAS does not hold client funds as principal and does not independently control customer safeguarding arrangements, and does not provide regulated money-transmission, custody, or banking services directly to end-customers.

NAS has not appointed a representative under Article 27 of the EU GDPR or the UK GDPR. If you are in the European Union or the United Kingdom and wish to direct a data-protection enquiry to NAS, please email privacy@nas.cards — we will route your enquiry to the appropriate person internally. You retain your statutory rights, including the right to lodge a complaint with your local Supervisory Authority (see Section 8).


2. The personal data we collect

We collect personal data falling into the following categories.

2.1 From visitors to nas.cards

2.2 From Partner representatives

2.3 From prospective Partners


We process personal data for the following purposes, on the legal bases described.

Purpose Categories used Legal basis (EU/UK GDPR)
Responding to enquiries (contact form, sales, support) Visitor and prospective-Partner data; communication content Performance of pre-contractual steps; our legitimate interest in handling enquiries
Administering Partner Accounts (creation, access management, MFA enrolment, password recovery) Partner-representative identity, contact, authentication, authorisation data Performance of the Platform Terms (contract); our legitimate interest in secure account administration
Authenticating users and securing the platform (fraud detection, abuse prevention, anomaly detection) Authentication, activity, device, network data Our legitimate interest in operating the platform securely; compliance with legal obligations
Providing support, training, and account management Identity, contact, support data Performance of the Platform Terms; our legitimate interest in maintaining the commercial relationship
Billing and invoicing Identity, contact, transaction-volume data Performance of the Platform Terms; legal obligation to maintain accounting records
Service-improvement analytics (aggregated and, where reasonably practicable, pseudonymised) Activity, support data in aggregate Our legitimate interest in improving the Services
Sanctions, PEP and adverse-media screening of Partner controllers, representatives and ultimate beneficial owners Identity, contact, role data Compliance with legal obligations (sanctions and anti-money-laundering law); our legitimate interest in operating an institutional financial-infrastructure stack
Compliance, audit, regulatory reporting, and responding to lawful Regulatory Authority requests All categories, as relevant to the specific request Compliance with legal obligations
Sending operational and security-related notifications Identity and contact data Performance of the Platform Terms; legal obligation in the case of security notifications
Sending marketing communications about our Services (where you have opted in or where permitted under soft-opt-in rules) Identity and contact data Consent; our legitimate interest where soft-opt-in conditions are met

Where we rely on consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

Where we rely on legitimate interests, we have considered the impact on you and conclude that our interests are not overridden by your interests, rights and freedoms. You can ask us for more detail on this balancing analysis by contacting privacy@nas.cards.

Under the Hong Kong Personal Data (Privacy) Ordinance (the “PDPO”), we process personal data for the purposes described above on the basis that the processing is consistent with the purpose for which it was collected, or for a directly-related purpose, or with the consent of the data subject as required.


4. Who we share personal data with

We share personal data with the following categories of recipient. We do not sell personal data, and we do not share personal data with third parties for their independent marketing purposes.

A list of the categories of recipient relevant to your role, and (on request) the specific recipients, is available by writing to privacy@nas.cards.


5. Where personal data is held

The Partner-representative and prospective-Partner personal data for which NAS is the controller is hosted on cloud infrastructure operated by a tier-one cloud-services provider in the European Union (primary location: Frankfurt, Germany). The nas.cards marketing site is hosted by the same provider in the same region and delivered globally through a content-delivery network. Customer-facing personal data processed in connection with a Partner’s Program (where NAS acts as processor) resides on the Partner’s own hosting infrastructure and is governed by the Data Processing Addendum executed with that Partner. Some sub-processors operate from other locations (including the European Union, the United Kingdom, the United States, and other jurisdictions).

Where personal data is transferred from the EEA, the UK, or Hong Kong to a country that does not provide an adequate level of protection under the source jurisdiction’s law, we rely on appropriate transfer mechanisms — typically the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Agreement, or the Hong Kong Privacy Commissioner’s Recommended Model Contractual Clauses, as applicable, supplemented where relevant by additional technical and organisational measures.

You can obtain a copy of the transfer mechanism in place for any specific transfer by writing to privacy@nas.cards (commercially-sensitive contractual terms may be redacted).


6. How long we keep personal data

We keep personal data for as long as we need it for the purposes described in this Privacy Policy, plus any retention period required by Applicable Law or required to defend against legal claims. Indicatively:

We routinely delete or anonymise personal data once the retention period expires.


7. How we protect personal data

We maintain technical and organisational measures appropriate to the risk, including access control, encryption in transit and at rest, multi-factor authentication, network segmentation, secure software development, regular penetration testing, audit logging, sub-processor due diligence, and a documented incident-response plan. See the security measures described in our Data Processing Addendum for more detail.


8. Your rights

Depending on the jurisdiction in which you are located and the legal basis on which we process your personal data, you may have rights to:

To exercise any of these rights, please contact privacy@nas.cards. We will respond within the timeframe required by Applicable Law (typically one month for EU/UK GDPR requests; we may extend this in complex cases, with notice).

If you are in the EU/EEA, you have the right to lodge a complaint with your local Supervisory Authority. If you are in the UK, you may complain to the Information Commissioner’s Office (ico.org.uk). If you are in Hong Kong, you may complain to the Privacy Commissioner for Personal Data (pcpd.org.hk).


9. Rights of US residents (CCPA/CPRA and equivalent state laws)

If you are a resident of California, Colorado, Connecticut, Virginia, Utah, Texas, or another US state with a comprehensive privacy statute, you have rights in respect of personal data we process about you, including the right to:

To exercise these rights, contact privacy@nas.cards. Authorised agents may submit a request on your behalf with written authorisation and verification of identity. We will respond within the timeframe required by the applicable state law (typically 45 days, extendable once with notice).

NAS honours Global Privacy Control (GPC) signals from your browser as a valid opt-out of sale/sharing where applicable.


10. Cookies and similar technologies

Our Cookie Policy explains how we use cookies, local storage, and similar technologies on nas.cards and on the Partner-facing Surfaces. See /cookie-policy.html.


11. Children

The Services are not directed to children. We do not knowingly collect personal data from children. If you believe we have collected personal data from a child, please contact privacy@nas.cards and we will take appropriate action.


12. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. The “Last revised” date at the top reflects the most recent revision. We will notify Partners of material changes through the Business Portal, by email, or by other appropriate means. The current version is always available at this URL.


13. How to contact us

For any privacy-related question, request, or complaint, please contact privacy@nas.cards, or write to us at our registered office. We aim to acknowledge enquiries within five (5) business days.