Privacy Policy
Last updated: August 9, 2026
Your privacy and the security of your personal data are our top priorities. At Al-Mutakamila for Mobile Payment Services Company – Private Shareholding Company, hereinafter referred to as "Dinarak" or the "Company", we confirm that the personal data you provide to us is always treated as private and confidential. It is protected through appropriate technical and organizational measures and processed in accordance with the provisions of the Jordanian Personal Data Protection Law No. (24) of 2023, the instructions of the Central Bank of Jordan, and all relevant regulatory frameworks related to data protection and confidentiality of customer information (hereinafter referred to as the "Personal Data Protection Regulatory Requirements")
This Privacy Policy (hereinafter referred to as the "Policy") aims to provide you with information on how we use your personal data, the measures we take to ensure its confidentiality and security, the types of personal data we collect and process about you, as well as your rights regarding your data privacy and how you can exercise them
Key Definitions
Personal Data: Any data or information relating to a natural person that can directly or indirectly identify them, regardless of its source or form, including data related to their identity, family status, location, or transactions
Processing: Any operation or set of operations performed on personal data by any means, including collection, recording, copying, storage, organization, modification, use, transmission, disclosure, linking, restriction, erasure, anonymization, or destruction
Profiling: Automated processing of data to analyze or predict a person's behavior, preferences, trends, or characteristics
Sensitive Personal Data: Any data that directly or indirectly reveals a person's origin, ethnicity, political opinions, religious beliefs, financial status, health condition, genetic or biometric data, or criminal record
Processor: Any natural or legal person who processes personal data on behalf of the Company and in accordance with its instructions
Data Subject: The individual whose personal data is being processed
Controller: The person responsible for supervising databases and data processing
Prior Consent: The prior approval of the data subject for processing their personal data
Data Breach: Any unauthorized access, use, disclosure, or processing of data
How We Collect Your Data
Dinarak collects your data through one of the following methods:
1. Directly: We obtain your personal data directly from you in order to provide you with the Company's services or to deal with you, including but not limited to: opening an electronic wallet, using payment and transfer services, entering into a business relationship, submitting a complaint, updating your data, or through completing physical or electronic forms, direct communication, email, digital services and applications, or for any other purposes depending on the requested or agreed services
2. Indirectly: We may obtain your personal data indirectly from multiple sources, including website or application tracking tools such as "Cookies", automatic collection of information and technical data related to devices and browsing activities, social media, public sources, business partners, identity verification service providers, and regulatory authorities. This may occur through your interaction with the website and digital channels, cookies technologies, website and digital channel analytics, or integration with other entities, in order to better understand and serve you, fulfill legal obligations, or achieve other legitimate interests
3. Data collected about you from other parties: Such as data provided by other parties, for example: your employer, a family member, legal representative, beneficiary of a transaction or contract, representatives of legal entities, or the beneficial owner, or through publicly available sources, while ensuring that you are informed where required
How We Use Your Data
We collect your personal data for various reasons related to our services, products, or interactions with you, as well as for operational, commercial, and regulatory purposes. The Company also ensures that personal data is accurate and up to date and takes the necessary measures to correct any inaccurate data. You are responsible for providing us with any updates to your data to ensure its proper use, including, without limitation:
1. To provide and manage your electronic wallet, account, and our relationship with you
2. To provide you with additional information related to your wallet, account, or our services
3. To handle inquiries, complaints, and requests submitted by you
4. To provide our services to you, including payment, transfer, withdrawal, deposit, and other related services
5. To conduct evaluation, testing, and analysis for statistical, analytical, or market research purposes, provided that the data used or disclosed for such purposes is anonymized or aggregated in a manner that does not identify any individual
6. To communicate with you via mail, telephone, SMS, email, application notifications, and other digital channels
7. To collect any amounts or obligations owed to us
8. To comply with regulatory requirements and reporting obligations related to financial crime prevention, including anti-money laundering (AML), counter-terrorist financing (CFT), and the implementation of sanctions
9. To assess any request submitted by you
10. To monitor, record, and analyze any communications between you and us for service improvement and regulatory compliance purposes
11. To share your data with regulatory and governmental authorities, competent bodies, and fraud prevention and identity verification service providers, within the limits permitted by law
12. To share your data with service providers (processors) and external auditors, as described in the section below ("Who has access to your personal data and to whom it is disclosed")
13. For litigation purposes, legal consultation, notifications, or documentation of transactions
14. To carry out due diligence procedures, identity verification, risk classification, and screening against sanctions lists, the national list, internal lists, and any other lists adopted in accordance with applicable laws or the requirements of the Central Bank of Jordan
15. The Company may use your personal data to send you marketing messages about our products and services, in cases permitted by law and in accordance with your consent where required. You have the right to subscribe to or unsubscribe from such messages at any time
Legal Basis for Processing Your Personal Data
We rely on the following legal bases when processing your personal data:
1. Contractual obligation: We process your personal data as necessary to enter into a contract with you and/or to perform a contract, or to take steps at your request prior to entering into a contract, such as opening an electronic wallet, executing payment and transfer transactions, or providing any of our services
2. Compliance with legal and regulatory obligations: We process your personal data as necessary to comply with laws, regulations, and instructions applicable to us, including anti-money laundering (AML) and counter-terrorist financing (CFT) laws and regulations, compliance monitoring instructions, anti-fraud laws and regulations, and the requirements of the Central Bank of Jordan. For example, the collection of "Know Your Customer (KYC)" data, including identity details, address, employment, source of funds, and nature of activity, is a requirement under the applicable laws and regulatory instructions to which the Company is subject
3. Legitimate interests: We process your personal data as necessary to achieve the Company's legitimate interests, such as protecting against cyber risks, preventing misuse of services, improving the Company's products and services, and conducting analytical and profiling activities aimed at enhancing the suitability of products and services to customers' preferences and needs. This also includes security purposes, such as CCTV monitoring. In line with personal data protection regulatory requirements, where processing is based on legitimate interests, the Company ensures that such interests do not override or adversely affect the rights and interests of individuals
4. Consent: In cases where the above legal bases do not apply, we will process your personal data based on your consent. You have the right to withdraw such consent by submitting a request in this regard. For more information, please refer to the section below (What are your rights and how can you exercise them)
What Personal Data We Collect and Process
The personal data we collect includes the data you provided at the beginning of our relationship or at any time thereafter, such as:
1. Personal details, such as name, date of birth, place of birth, nationality, marital status, gender, and contact information
2. Current residential address and permanent address
3. Identity-related data, including official documents, ID card details, passport details, and any other approved identification documents
4. Employment details, including employer name and location, employment status, job title, full name, email (if available), address, and work-related phone number(s)
5. Financial data, such as income, source of income, source of funds or wealth, average financial activity of the wallet or account, and contractual data
6. Tax-related data, such as foreign tax identification number, tax compliance forms, and other relevant information where applicable
7. Transaction details carried out by you or related persons, including dates, amounts, currencies, payer and beneficiary details, transaction parties, and execution channels
8. Audio and visual data, including images captured via CCTV systems or through the application or digital channels
9. Digital identifiers, such as IP address, email address, device type, operating system, browser type, date and time of access, and visited pages
10. Website or application usage data, including Cookies
11. Risk classification data, including customer, wallet, relationship, or transaction risk ratings
12. Due diligence data, including information required for compliance with financial crime regulations, such as AML/CFT obligations, sanctions implementation, and data required to meet regulatory reporting requirements, including reporting suspicious activities or transactions
13. Information about other individuals, such as corporate-related information of the client, authorized signatories, legal representatives, family members, emergency contacts, and/or guardians, which may include their signatures, addresses, and relationship to you where necessary
14. Information related to legal disputes, complaints, and grievances
15. Information related to agreements, contracts, invoices, and commissions
16. Security and protection-related information
17. Geolocation data when using the application or digital services, where necessary and permitted
18. Data related to your use of the application, website, or self-service channels
19. Information on whether you are a person with disabilities, for the purpose of providing services appropriately and ensuring accessibility. Such information is treated with strict confidentiality and is only used when necessary
20. Information on whether you are a Politically Exposed Person (PEP) or related to one, including identifying the degree of relationship and name where applicable, for compliance purposes. Such data is handled with strict confidentiality and used solely for this purpose
21. Information regarding the purpose of your wallet usage, for understanding the nature of service usage and compliance with AML/CFT requirements. Such data is treated confidentially and used only within this scope
Data Storage and Hosting Locations
Dinarak stores and processes personal data within a secure infrastructure located in the Hashemite Kingdom of Jordan and/or in other approved locations in accordance with business continuity and disaster recovery requirements, and in compliance with applicable legal and regulatory requirements. All storage media and hosting arrangements are subject to the prescribed technical and organizational measures to ensure data protection. Data is retained for the period necessary to achieve the purposes for which it was collected or as required by applicable laws and regulations, after which it is securely deleted or destroyed. For more information on data retention practices, please refer to the section ("How long we retain your personal data")
How Long We Retain Your Personal Data
We retain your personal data to provide our services, maintain communication with you, and comply with applicable laws, regulations, instructions, and professional obligations to which we are subject, including regulatory data retention requirements applicable to payment companies and electronic wallets. For example, customer identification data, such as identity documents and personal, employment, and financial information, may be retained for a period not less than that specified under applicable laws and regulations or from the date the relationship ends, as required by applicable legislation. In some cases, we may need to retain your data for a longer period for the following reasons:
1. To comply with applicable legal or regulatory requirements
2. To assist in detecting and preventing fraud and financial crimes
3. To respond to official requests from regulatory, supervisory, or judicial authorities
4. To protect, establish, or defend the Company's legal rights
5. Your personal data will be securely disposed of when it is no longer required for the above purposes
Notwithstanding the above, certain personal data may be retained for a longer period in the event of legal disputes, judicial proceedings, or investigations, to protect, establish, or defend the Company's rights. Once the data is no longer required, it will be securely deleted, destroyed, or anonymized in a manner that ensures it cannot be re-identified or linked back to the data subject. Any inquiries related to data retention should be directed to the Company's designated Personal Data Protection Officer via email at: data.protection@dinarak.com
Processing of Sensitive Personal Data
Personal data protection regulatory requirements define sensitive personal data as any data or information relating to a natural person that directly or indirectly reveals their origin or ethnicity, or indicates their opinions, political affiliations, or religious beliefs, or any data related to their financial status, health condition (physical, mental, or genetic), biometric data, or criminal record. Biometric data refers to unique characteristics, whether physical or behavioral, that are processed using specific technologies to accurately identify an individual or verify their identity. Dinarak ensures that the processing of sensitive personal data is based on a clear legal basis. For example:
Biometric Data: The Company may process your biometric data, such as a self-captured image (selfie) or biometric verification features, when used for identity verification, liveness detection, account protection, compliance with "Know Your Customer (KYC)" requirements, or other security and regulatory purposes
Financial Status Data: The Company processes data related to your financial status, source of funds, source of income, or nature of activity in line with KYC requirements, anti-money laundering (AML) and counter-terrorist financing (CFT) regulations, and applicable instructions
Records, Risk, or Screening Data: Data related to sanctions, national lists, regulatory classifications, or risk data may be processed in accordance with applicable legal and regulatory requirements
How We Protect and Safeguard Your Personal Data
We implement appropriate technical and organizational measures to prevent the loss, misuse, alteration, or unauthorized access to your personal data. We aim to ensure that access to your personal data is restricted only to authorized individuals who need such access, and that those individuals are bound by confidentiality obligations. The Company also uses appropriate encryption technologies, such as SSL or TLS protocols, to protect data during transmission over networks, in order to reduce the risks of unauthorized access. If you use the Company's services online, through the application, or via any digital channels, you remain responsible for maintaining the confidentiality of your username, passwords, security codes, and any other authentication or verification methods, without prejudice to the Company's obligations to protect your data
Who Has Access to Your Personal Data and to Whom It Is Disclosed
We maintain the confidentiality of your personal data. In order to serve your needs as effectively as possible, we may share your personal data with other parties under binding contractual agreements that require them to protect your data and process it strictly in accordance with our instructions, or where such disclosure is required or permitted by law. We may share data related to you and your transactions with us, to the extent permitted by law, with the following entities, either on a regular basis (as part of ongoing operations) or on a one-time basis (as needed or upon a specific request), depending on the nature of the relationship and the purpose of processing:
1. Regulatory authorities, government bodies, and competent authorities, including the Central Bank of Jordan, the Anti-Money Laundering and Counter Terrorist Financing Unit, and other relevant authorities
2. Banks, financial institutions, payment companies, payment service providers, settlement or transfer providers, or any entities involved in executing financial transactions
3. Entities involved in card processing, digital payments, electronic wallets, transfer, or settlement services
4. Third-party service providers, including cloud service providers, identity verification services, screening services, compliance services, and technical support providers, for legitimate purposes and in accordance with applicable laws and regulations. Such parties are obligated to implement appropriate data protection measures and to process the data only for specified purposes and in accordance with the Company's instructions
5. External auditors who are required to audit the Company in accordance with applicable laws and regulations, and who may request data samples for verification and review purposes
6. Entities responsible for preventing or managing fraud and financial crimes
7. Law firms, lawyers, or legal advisors, where necessary for legal consultation or litigation purposes
8. Debt collection agencies, where such parties are engaged to recover outstanding or unpaid amounts
9. Other parties to whom you have consented to share your data
10. Any other entity where disclosure is necessary for service execution, compliance with the law, or protection of the rights of the Company or its customers
Your Rights and How They Can Be Exercised
You may exercise the following rights in relation to your personal data:
1. The right to request access to your personal data and obtain a copy of it
2. The right to be informed about how your personal data is processed and the purposes of such processing
3. The right to withdraw the prior consent you have provided for the processing of your personal data, in cases where processing is based on consent, within the limits permitted by applicable laws and regulations
4. The right to correct, amend, update, or supplement your personal data
5. The right to restrict processing within a specific scope as permitted by law
6. The right to request the erasure, restriction, or anonymization of your personal data, within the limits permitted by applicable laws and regulations
7. The right to object to the processing of your personal data or to profiling, where such processing is not necessary or is disproportionate to the purpose for which the data was collected
8. The right to request the transfer of your personal data to another entity in a structured, commonly used, and machine-readable format, where permitted by law and subject to technical feasibility
9. The right to be notified of any breaches, violations, or incidents affecting the security and integrity of your personal data, in accordance with applicable legal and regulatory requirements
Please note that the Company will handle requests promptly and efficiently. However, responses to certain requests may be subject to limitations or exceptions imposed by applicable laws and regulations. For example, it may not be possible to fulfill a request to delete certain personal data retained by the Company where there is a legal or regulatory obligation to retain such data for a specified period
For More Information
If you have any questions regarding this Policy or wish to learn more about our security practices or how we handle your personal data, please contact us through our official channels:
1. Website: dinarak.com
2. Address: Mecca Street, Building No. 172, 3rd Floor, P.O. Box: 3436, Amman 11821, Jordan
3. Email: info@dinarak.com
4. Phone: 0795087640
Complaints
If you have any complaint regarding the processing of personal data by Dinarak, please submit it via email or through the Company's official approved channels. You also have the right, in accordance with applicable laws, to lodge a complaint with the competent authority or the Personal Data Protection Council established under the applicable legislation
Changes to the Policy
We reserve the right to update this Policy from time to time to reflect changes in our practices, legal and regulatory requirements, or personal data protection regulatory requirements. Any updates shall become effective upon publication of the updated notice on our website or through any other official channel adopted by the Company. In the event of any material changes to this Policy, the Company will notify customers accordingly using the available contact details. Your continued use of our services shall constitute implicit acceptance of such changes