External Privacy Policy Notice
This Privacy Policy constitutes part of and should be read in conjunction with the Luxon Terms and Conditions and Cookie Policy Notice. This policy explains how we may collect, create, process, store, protect, disclose, share and transfer your Personal Data as part providing our Services and/or otherwise as part of our business operations.
We have defined some terms that we use throughout the Privacy Policy. You can find the meaning of a capitalised term in Section (19) Definitions below or as otherwise may be defined in this agreement.
“Personal Data” means any information that identifies or is reasonably capable of identifying an individual, directly, or indirectly, such as a name or identification number, an online identifier or other identifiable characteristics and other information that is being associated with an identified or reasonably identifiable individual.
Luxon may also collect, create, process, store, protect, disclose, share and transfer your Non-Personal Data as part providing our Services and/or otherwise as part of our business operations. For example, Luxon may use anonymised and aggregated transactional information for commercial purposes such as reviewing or analysing transaction data and patterns.
Please note that Luxon provides services to both individual consumers and businesses and this Privacy Policy applies to both and should be read and interpreted accordingly.
Summary – The Summaries |
Any section summary boxes, such as this one, are provided for your convenience only, we encourage you to read the full sections so that you can fully understand and accept the terms of this Privacy Policy. |
Summary – This Notice |
This Notice explains how we Process Personal Data. This Notice may be amended or updated from time to time, so please check it regularly for updates. |
This Notice is issued by Luxon Pay Ltd (No. BC1360780), with its registered office at Suite #229, 6030 88ST NW, Edmonton, Alberta, T6E6G4, Canada. (“Luxon Pay“, “Luxon” “we”, “us” and “our”) and is addressed to individuals outside our organisation with whom we interact, including customers, visitors to our Sites, users of our Apps, other users of our Services, and visitors to our premises (together, “you”). For the purposes of this Notice, Luxon is the Controller.
As a Controller, Luxon is required to use appropriate security safeguards in order to protect Personal Information against loss or theft, as well as unauthorised access, disclosure, copying, use, or modification. This includes any Personal Information in our possession or custody and extends to Personal Information that has been transferred to a third party for Processing and we must ensure any third party process provides a comparable level of protection of Personal Data.
As a Controller, Luxon is required to use appropriate security safeguards in order to protect Personal Information against loss or theft, as well as unauthorised access, disclosure, copying, use, or modification. This includes any Personal Information in our possession or custody and extends to Personal Information that has been transferred to a third party for Processing and we must ensure any third party process provides a comparable level of protection of Personal Data.
This Notice may be amended or updated from time to time to reflect changes in our practices with respect to the Processing of Personal Data, or changes in Applicable Law. We encourage you to read this Notice carefully, and to regularly check this page to review any changes we might make in accordance with the terms of this Notice. You can always find the latest version of this Privacy Policy here on this page.
Our Services may be accessed by individuals without a Luxon eWallet account. We will collect Personal Data from you even if you are a non-account holder when you use our Services, such as when you use pay through Luxon’s Express Service, , or when you receive a payment through our Services from account holders (“Recipient”). We use the term “you” to apply to account and non-account holders. If you are a non-account holder, your Personal Data will be used to provide the Services and in accordance with this Privacy Policy and the relevant Luxon Terms and Conditions.
Summary – Collection of Personal Data |
We collect or obtain Personal Data: when those data are provided to us (e.g., where you contact us); in the course of our relationship with you (e.g., if you make a purchase); when you make Personal Data public (e.g., if you make a public post about us on social media); when you download, install, or use any of our Apps; when you visit our Sites; when you register to use any of our Sites, Apps, or Services; or when you interact with any third party content or advertising on our Site or in our App. We may also receive Personal Data about you from third parties (e.g., law enforcement authorities). |
We will only collect Personal Data relevant to the purpose for which it will be used, and which will be limited to what is necessary for that purpose.
Collection of Personal Data: We collect or obtain Personal Data about you from the following sources:
Please note that third parties you interact with may have their own privacy policies, and we are not responsible for their operations or their use of the data they may collect. Information collected by third parties is governed by their privacy practices and we are not responsible for unauthorized or unlawful third-party conduct. We encourage you to learn and understand the privacy practices of any relevant third parties you engage with.
Summary – Creation of Personal Data |
We create Personal Data about you (e.g., records of your interactions with us). |
We also create Personal Data about you in certain circumstances, such as records of your interactions with us, and details of your past interactions with us. We may also combine Personal Data from any of our Sites, Apps, or Services, including where those data are collected from different devices.
Summary – Categories of Personal Data we Process |
We Process: your personal details (e.g., your name); formal personal details (e.g., government ID); your contact details (e.g., your address); details of your contacts (e.g., the names and contact information in your address book); records of your consents; purchase details; payment details (e.g., your billing address); information about our Sites and Apps (e.g., the type of device you are using); details of your employer (where relevant); information about your interactions with our content or advertising; and any views or opinions you provide to us. |
We Process the following categories of Personal Data about you:
Summary – Sensitive Personal Data |
We do not seek to collect or otherwise Process Sensitive Personal Data. Where we need to Process Sensitive Personal Data for a legitimate purpose, we do so in accordance with Applicable Law. |
We do not seek to collect or otherwise Process Sensitive Personal Data in the ordinary course of our business. Where it becomes necessary to Process your Sensitive Personal Data for any reason, we rely on one of the following legal bases:
If you provide Sensitive Personal Data to us, you must ensure that it is lawful for you to disclose such data to us, and you must ensure a valid legal basis applies to the Processing of those Sensitive Personal Data.
Summary – Purposes of Processing and legal bases for Processing |
We Process Personal Data for the following purposes: providing our Sites, Apps, and Services to you; compliance checks; operating our business; communicating with you; managing our IT systems; health and safety; financial management; conducting surveys; ensuring the security of our premises and systems; conducting investigations where necessary; compliance with Applicable Law; improving our Sites, Apps, and Services; fraud prevention; and recruitment and job applications. |
The legal basis for the Processing of your Personal Data is dependent on the context in which we collect it and the purposes for which it is used. Subject to Applicable Law, the purposes for which we Process Personal Data, and the most common legal bases on which we perform such Processing, are as follows:
Processing Activity | Legal basis for Processing |
Provision of Sites, Apps, and Services: Providing our Sites, Apps, or Services; Providing promotional items upon request; and Communicating with you in relation to those Sites, Apps, or services. | The Processing is necessary for the performance of a contract We have a legitimate interest in carrying out the Processing for the purpose of providing our Sites, Apps, or Services We have obtained your prior consent to the Processing. |
Helping with social interactions: Helping with social interactions through our services; Adding extra functions in order to provide a better customer experience; For example, if you give us permission, we’ll use the contacts list on your phone so you can easily identify other Luxon users and make payments to your contacts using the Luxon App. We will not pass this information to any third parties. | We have a legitimate interest in carrying out the Processing for the purpose of providing our Sites, Apps, or Services We have obtained your prior consent to the Processing. |
Compliance checks: Fulfilling our legal, regulatory and/or compliance obligations; ‘Know Your Client’ checks and confirming and verifying your identity; Use of credit reference agencies; and; Screening against government and/or law enforcement agency sanctions lists and other legal restrictions. | The Processing is necessary for compliance with a legal obligation; The Processing is necessary for the performance of a contract; We have a legitimate interest in carrying out the Processing for the purpose of fulfilling our regulatory and compliance obligations; We have obtained your prior consent to the Processing. |
Operating our business: Operating and managing our Sites, our Apps, and our Services; Providing content to you; Displaying advertising and other information to you; Communicating and interacting with you via our Sites, our Apps, or our Services; and Notifying you of changes to any of our Sites, our Apps, or our Services. | The Processing is necessary for the performance of a contract; We have a legitimate interest in carrying out the Processing for the purpose of providing our Sites, our Apps, or our Services or other business operations to you; We have obtained your prior consent to the Processing. |
Communications and marketing: Communicating with you via any means (including via email, telephone, text message, social media, post or in person) to provide news items and other information in which you may be interested, subject always to obtaining your prior opt-in consent to the extent required under Applicable Law; Maintaining and updating your contact information where appropriate; and obtaining your prior, opt-in consent where required. | The Processing is necessary for the performance of a contract; We have a legitimate interest in carrying out the Processing for the purpose of contacting you, subject always to compliance with Applicable Law ; We have obtained your prior consent to the Processing |
Management of IT systems: Management and operation of our communications, IT and security systems; and audits (including security audits) and monitoring of such systems. | The Processing is necessary for compliance with a legal obligation; We have a legitimate interest in carrying out the Processing for the purpose of managing and maintaining our communications and IT systems. |
Health and safety Health and safety assessments and record keeping; Providing a safe and secure environment at our premises; Compliance with related legal obligations. | The Processing is necessary for compliance with a legal obligation; We have a legitimate interest in carrying out the Processing for the purpose of ensuring a safe environment at our premises; The Processing is necessary to protect the vital legitimate interests of any individual |
Financial management: Sales; Finance; Corporate audit; Vendor management | We have a legitimate interest in carrying out the Processing for the purpose of managing and operating the financial affairs of our business; We have obtained your prior consent to the Processing. |
Security Physical security of our premises (including records of visits to our premises); CCTV recordings; Electronic security (including login records and access details). | The Processing is necessary for compliance with a legal obligation; We have a legitimate interest in carrying out the Processing for the purpose of ensuring the physical and electronic security of our business and our premises. |
Investigations: Detecting, investigating and preventing breaches of policy, and criminal offences, in accordance with Applicable Law. | The Processing is necessary for compliance with a legal obligation; We have a legitimate interest in carrying out the Processing for the purpose of detecting, and protecting against, breaches of our policies and Applicable Laws. |
Legal proceedings: Establishing, exercising, and/or defending legal rights. | The Processing is necessary for compliance with a legal obligation; We have a legitimate interest in carrying out the Processing for the purpose of establishing, exercising or defending our legal rights. |
Legal compliance: Compliance with our legal and regulatory obligations under Applicable Law. | The Processing is necessary for compliance with a legal obligation. |
Improving our Sites, Apps, and services: Identifying issues with our Sites, our Apps, or our Services; Planning improvements to our Sites, our Apps, or our Services; Creating new Sites, Apps, or Services. | We have a legitimate interest in carrying out the Processing for the purpose of improving our Sites, our Apps, or our services; We have obtained your prior consent to the Processing |
Fraud prevention: Detecting, preventing and investigating fraud | The Processing is necessary for compliance with a legal obligation; We have a legitimate interest in carrying out the Processing for the purpose of detecting, and protecting against, fraud. |
Recruitment and job applications: Recruitment activities; Advertising of positions; Interview activities; Analysis of suitability for the relevant position; Records of hiring decisions; Offer details; Acceptance details. | The Processing is necessary for compliance with a legal obligation (especially in respect of applicable employment law); We have a legitimate interest in carrying out the Processing for the purpose of recruitment activities and handling job applications; We have obtained your prior consent to the Processing |
Where you consent: For any other purpose for which you provide your consent. | We have obtained your prior consent to the Processing |
Summary – Disclosure of Personal Data to third parties |
We disclose Personal Data to: legal and regulatory authorities; our external advisors; our Processors; any party as necessary in connection with legal proceedings; any party as necessary for investigating, detecting or preventing criminal offences; any purchaser of our business; and any third party providers of advertising, plugins or content used on our Sites or our Apps. |
We disclose Personal Data within Luxon, for legitimate business purposes and the operation of our Sites, Apps, or Services to you, in accordance with Applicable Law. In addition, we disclose Personal Data to:
If we engage a third-party Processor to Process your Personal Data, the Processor will be subject to binding contractual obligations to: (i) only Process the Personal Data in accordance with our prior written instructions; and (ii) use measures to protect the confidentiality and security of the Personal Data; together with any additional requirements under Applicable Law. Third party processors we use regularly, but which may change from time to time, include but are not limited to:
Summary – Profiling |
Personal Data are subject to automated decision-making and Profiling. |
We Process Personal Data for the purposes of automated decision-making and Profiling, which is defined in Section (19).
Automated decision-making and Profiling, are carried out for the following purposes:
Profiling Activity | Logic of the Profiling Activity | Consquences for You |
Credit Scoring | Where we engage a third party (e.g., a credit reference agency) to provide us with information about your credit score and/or credit history. This information is analysed to determine the most appropriate terms on which to offer you credit, where applicable. | This Profiling activity may affect whether you are able to obtain credit, and the interest rates applicable to any such credit. |
Transaction Monitoring | We engage a third party to analyse transactions to highlight suspicious behaviour and potentially block suspicious transactions. | This profiling activity may mean that transactions are rejected or delayed if the activity is suspicious we may also report suspicious activity to the relevant regulatory bodies or law enforcement agencies. |
KYC Identification | We engage a third party to collect information and analyse it for KYC purposes, this information is then removed from their system and stored on ours. | This profiling activity may mean that sign up is rejected or delayed if we may also need to provide this information relevant regulatory bodies or law enforcement agencies. |
You have a legal right to a meaningful explanation of and/or to contest, or reject being subject to automated decision making and Profiling and get human intervention on a decision as detailed further in (14) Your legal rights. However, these rights may not apply where the automated decision made, or Profiling is (i) Is necessary for entering into or performing a contract with you; (ii) Is authorised by law and there are suitable safeguards for your rights and freedoms; or (iii) Is based on your explicit consent. In these situations, you may still be able to obtain human intervention and express your point of view by contacting us using the details in (18) Complaints and contact details.
Summary – International transfer of Personal Data |
We transfer Personal Data to recipients in other countries. Where we transfer Personal Data from the EEA to a recipient outside the EEA that is not in an Adequate Jurisdiction, we do so on the basis of Standard Contractual Clauses. |
Because of the international nature of our business, we transfer Personal Data within Luxon and to third parties as noted in Section (7) above, in connection with the purposes set out in this Notice. For this reason, we may transfer Personal Data to other countries that may have different laws and data protection compliance requirements to those that apply in the country in which you are located.
Where we transfer your Personal Data from the EEA to recipients located outside the EEA who are not in Adequate Jurisdictions, we rely primarily on the European Commission’s Standard Contractual Clauses to facilitate the international and onward transfer of Personal Data. You are entitled to request a copy of our Standard Contractual Clauses using the contact details provided in Section (18) below.
Please note that when you transfer any Personal Data directly to a recipient outside the EEA, we are not responsible for that transfer of your Personal Data. We will nevertheless Process your Personal Data, from the point at which we receive those data, in accordance with the provisions of this Notice.
Summary – Data security |
We implement appropriate technical and organisational security measures to protect your Personal Data. Please ensure that any Personal Data that you send to us are sent securely. |
We have implemented appropriate technical and organisational security measures designed to protect your Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, unauthorised access, and other unlawful or unauthorised forms of Processing, in accordance with Applicable Law.
Because the internet is an open system, the transmission of information via the internet is not completely secure. Although we will implement all reasonable measures to protect your Personal Data, we cannot guarantee the security or confidentiality of your data transmitted to us using the internet – any such transmission is at your own risk and you are responsible for ensuring that any Personal Data that you send to us are sent securely.
In the event of a data breach by us or one of our Processors, we are obligated to:
Summary – Data accuracy |
We take every reasonable step to ensure that your Personal Data are kept accurate and up-to-date and are erased or rectified if we become aware of inaccuracies. |
We take every reasonable step to ensure that:
From time to time we may ask you to confirm the accuracy of your Personal Data.
Summary – Data minimisation |
We take every reasonable step to limit the volume of your Personal Data that we Process to what is necessary. |
We take every reasonable step to ensure that your Personal Data that we Process are limited to the Personal Data reasonably necessary in connection with the purposes set out in this Notice.
Summary – Data retention |
We take every reasonable step to ensure that your Personal Data are only retained for as long as they are needed in connection with a lawful purpose. |
We take every reasonable step to ensure that your Personal Data are only Processed for the minimum period necessary for the purposes set out in this Notice. The criteria for determining the duration for which we will retain your Personal Data are as follows:
(1) We will retain Personal Data in a form that permits identification only for as long as:
Plus (2) the duration of:
And (3) in addition, if any relevant legal claims are brought, we continue to Process Personal Data for such additional periods as are necessary in connection with that claim.
During the periods noted in paragraphs (2)(a) and (2)(b) above, we will restrict our Processing of your Personal Data to storage of, and maintaining the security of, those data, except to the extent that those data need to be reviewed in connection with any legal claim, or any obligation under Applicable Law.
Once the periods in paragraphs (1), (2) and (3) above, each to the extent applicable, have concluded, we will either:
Summary – Your legal rights |
Subject to Applicable Law, you may have a number of rights, including: the right not to provide your Personal Data to us; the right of access to your Personal Data; the right to request rectification of inaccuracies; the right to request the erasure, or restriction of Processing, of your Personal Data; the right to object to the Processing of your Personal Data; the right to have your Personal Data transferred to another Controller; the right to withdraw consent; and the right to lodge complaints with Data Protection Authorities. In some cases it will be necessary to provide evidence of your identity before we can give effect to these rights. |
You have many rights that you may be able to exercise in relation to your Personal Data. These rights may apply under a number of different regulations, for example, the General Data Protection Regulation (GDPR) which is generally applicable to EEA residents.
Subject to Applicable Law, you may have the following rights regarding the Processing of your Relevant Personal Data:
Subject to Applicable Law, you may also have the following additional rights regarding the Processing of your Relevant Personal Data: |
The right to object, on grounds relating to your particular situation, to the Processing of your Relevant Personal Data by us or on our behalf; and The right to object to the Processing of your Relevant Personal Data by us or on our behalf for direct marketing purposes. |
This does not affect your statutory rights.
To exercise one or more of these rights, or to ask a question about these rights or any other provision of this Notice, or about our Processing of your Personal Data, please use the contact details provided in Section (18) below. Please note that:
Summary – Cookies and similar technologies |
We Process Personal Data by using Cookies and similar technologies. For more information, please see our Cookie Policy. |
When you visit a Site or use an App we will typically place Cookies onto your device, or read Cookies already on your device, subject always to obtaining your consent, where required, in accordance with Applicable Law. We use Cookies to record information about your device, your browser and, in some cases, your preferences and browsing habits. We Process Personal Data through Cookies and similar technologies, in accordance with our Cookie Policy.
Summary – Terms and Conditions |
Our Terms and Conditions govern all use of our Sites, Apps and our Services. |
All use of our Sites, Apps, or Services is subject to our Terms and Conditions. We recommend that you review our Terms and Conditions regularly, in order to review any changes we might make from time to time.
Summary – Direct marketing |
We Process Personal Data to contact you with information regarding Sites, Apps, or Services that may be of interest to you. You may unsubscribe for free at any time. |
We Process Personal Data to contact you via email, telephone, direct mail or other communication formats to provide you with information regarding Sites, Apps, or Services that may be of interest to you. If we provide Sites, Apps, or Services to you, we may send information to you regarding our Sites, Apps, or Services, upcoming promotions and other information that may be of interest to you, using the contact details that you have provided to us, subject always to obtaining your prior opt-in consent to the extent required under Applicable Law.
You may unsubscribe from our promotional email list at any time by simply clicking on the unsubscribe link included in every promotional email we send. After you unsubscribe, we will not send you further promotional emails, but in some circumstances we will continue to contact you to the extent necessary for the purposes of any Sites, Apps, or Services you have requested.
If You wish to make a complaint about the Services or to exercise one of your legal rights outlined in Section 14, you can email us at support@luxon.com with brief details of your complaint or request and the phone number and email address associated with your eWallet or request our complaint form and send to our service email address on the form.
We will provide you a full response to your complaint or request by email within 15 Business Days after the date we receive your complaint. In exceptional circumstances where we are unable to respond in full to your complaint or request, we will inform you of this giving our reasons for the delay and the timeframe within which you will receive a full reply, which in any event shall be within 35 Business Days of the date we received your complaint or request.
Contact details for Luxon are as follows:
Luxon Pay Ltd, Suite #229, 6030 88ST NW, Edmonton, Alberta, T6E6G4, Canada. Email: support@luxon.com