PAYDA PRIVACY POLICY

Collection, Use, Processing, Sharing,
Retention and Protection of Personal Information

Effective Date: September 1, 2026

Last Updated: September 2, 2026

Bentix Global Solutions Inc. (“PAYDA,” “Company,” “we,” “us,” or “our”) respects your privacy and is committed to protecting your personal information.

This Privacy Policy explains how PAYDA collects, uses, processes, stores, shares, retains, and protects personal information when you use the PAYDA website, web application, electronic wallet, payment services, cash-in, cash-out, bank transfer, remittance, customer support, and other related services (collectively, the “PAYDA Services”).

PAYDA processes personal information in accordance with applicable Philippine laws and regulations, including the Data Privacy Act of 2012 (Republic Act No. 10173) and its Implementing Rules and Regulations, issuances of the National Privacy Commission (NPC), applicable Bangko Sentral ng Pilipinas (BSP) regulations, applicable anti-money laundering and counter-terrorist financing laws and regulations, and other applicable Philippine laws.

Certain PAYDA Services may be provided through or in cooperation with Netbank (A Rural Bank) Inc. (“Netbank”), including through Netbank's Banking-as-a-Service (“BaaS”) platform, APIs, payment infrastructure, and core banking system.

Where Netbank independently determines the purposes and means of processing personal information in connection with its regulated financial services, Netbank may act as a separate Personal Information Controller and its own privacy notice and terms may apply.

1. PERSONAL INFORMATION CONTROLLER

The entity responsible for personal information processing conducted by PAYDA is:

Company: Bentix Global Solutions Inc.

SEC Registration No.: [INSERT]

Principal Office: Unit 2908 One San Miguel Avenue Ortigas Center Pasig City

Customer Support: [INSERT]

Email: [INSERT]

Data Protection Officer: [INSERT NAME]

DPO Email: [INSERT EMAIL]

PAYDA may engage third-party Personal Information Processors to process personal information on its behalf.

Depending on the specific service, Netbank and other regulated financial institutions may independently act as Personal Information Controllers for processing activities that they determine and perform under their own legal and regulatory obligations.

2. PRIVACY PRINCIPLES

PAYDA is committed to processing personal information according to the principles of:

  • Transparency
  • Legitimate purpose
  • Proportionality
  • Data minimization
  • Accuracy
  • Security
  • Accountability

PAYDA collects and processes only information reasonably necessary for legitimate and lawful purposes.

3. PERSONAL INFORMATION WE COLLECT

The type of personal information collected depends on the PAYDA Service you use.

3.1 Account and Registration Information

PAYDA may collect:

  • Full name
  • Preferred name or nickname
  • Mobile phone number
  • Email address
  • Date of birth
  • Gender, where required
  • Residential or mailing address
  • Nationality
  • PAYDA Account ID
  • Internal Member ID
  • Profile information
  • Account status
  • Registration information

4. IDENTITY VERIFICATION AND KYC INFORMATION

For account registration, financial services, KYC, Customer Due Diligence (“CDD”), fraud prevention, AML/CFT compliance, and regulatory requirements, PAYDA and/or Netbank may collect:

  • Full legal name
  • Date of birth
  • Nationality
  • Residential address
  • Mobile phone number
  • Email address
  • Government-issued identification information
  • Identification document images
  • Identification verification results
  • Occupation
  • Employer information, where required
  • Source of funds
  • Source of income
  • Purpose of transaction
  • Beneficial ownership information
  • Tax or regulatory information where legally required
  • Risk classification
  • Customer due-diligence information
  • Enhanced due-diligence information

The information required may differ depending on the type of account, transaction, customer risk classification, applicable law, and requirements of Netbank or other regulated financial institutions.

5. FINANCIAL AND BANK ACCOUNT INFORMATION

When you use PAYDA's financial services, PAYDA may collect and process:

  • Bank name
  • Bank account number
  • Account holder name
  • Financial institution
  • Account verification information
  • Payment instrument information
  • Wallet/account information
  • Transaction amounts
  • Transaction dates and times
  • Transaction reference numbers
  • Payment references
  • Sender information
  • Recipient information
  • Merchant information
  • Cash-in transactions
  • Cash-out transactions
  • Bank transfer information
  • Remittance information
  • Refunds
  • Reversals
  • Transaction status
  • Fees and charges
  • Other information necessary to process financial transactions

Where the financial account is maintained by Netbank, Netbank may separately process and retain applicable information in accordance with its legal and regulatory obligations.

6. DEVICE AND TECHNICAL INFORMATION

When you use PAYDA, certain information may automatically be collected, including:

  • IP address
  • Device type
  • Operating system
  • Operating-system version
  • Application version
  • Browser type
  • Screen resolution
  • Device identifiers
  • Advertising identifiers, where applicable
  • Mobile network information
  • MCC/MNC information
  • LTE/Wi-Fi information
  • Network connection type
  • Date and time of access
  • Login records
  • Authentication records
  • Device registration information
  • Application crash information
  • Performance information
  • Security logs
  • Fraud indicators

PAYDA uses this information primarily for service operation, security, fraud prevention, troubleshooting, analytics, and regulatory purposes.

7. LOCATION INFORMATION

PAYDA may collect location information where:

  • you grant the applicable device permission;
  • the feature requires location information; or
  • collection is otherwise permitted or required by law.

Location information may be used for:

  • fraud prevention;
  • transaction-risk assessment;
  • account security;
  • service functionality;
  • regulatory compliance;
  • security investigations; and
  • other purposes disclosed at the time of collection.

You may disable location permission through your device settings. Certain services may not function when location permission is disabled.

8. APP PERMISSIONS

Depending on the features you use, PAYDA may request access to certain device functions.

Camera

May be used to:

  • scan QR codes;
  • scan payment information;
  • scan transfer information;
  • capture documents for identity verification; and
  • use other camera-based functions.

Location

May be used for:

  • security;
  • fraud prevention;
  • transaction-risk assessment; and
  • location-dependent functions.

Photos/Storage

May be used to:

  • save QR images;
  • upload documents;
  • select images;
  • attach files to customer-support requests; and
  • perform other functions requiring file access.

You may generally refuse optional permissions. However, functions requiring such permissions may become unavailable.

9. COOKIES AND SIMILAR TECHNOLOGIES

PAYDA may use cookies, SDKs, pixels, local storage, and similar technologies.

These technologies may be used for:

  • authentication;
  • session management;
  • security;
  • fraud prevention;
  • remembering preferences;
  • analytics;
  • application and website performance;
  • service improvement; and
  • relevant communications or advertising where permitted.

You may control cookies through your browser or device settings.

Disabling certain cookies may affect the functionality of some PAYDA Services.

10. HOW WE COLLECT PERSONAL INFORMATION

PAYDA may collect personal information:

  1. Directly from you during account registration;
  2. During identity verification and KYC;
  3. When you conduct transactions;
  4. When you register or link a bank account;
  5. Through the PAYDA website and web application;
  6. Through Netbank;
  7. Through banks and financial institutions;
  8. Through payment service providers;
  9. Through KYC and identity-verification providers;
  10. Through fraud-prevention and security providers;
  11. Through merchants and transaction counterparties;
  12. Through customer-support interactions;
  13. Through government or regulatory sources where lawfully available; and
  14. Automatically through your device and use of PAYDA Services.

11. PURPOSES OF PROCESSING PERSONAL INFORMATION

PAYDA may process personal information for the following purposes.

11.1 Account Management

  • Creating and maintaining PAYDA Accounts;
  • verifying account information;
  • authenticating Members;
  • maintaining account security;
  • providing account services; and
  • managing Member profiles.

11.2 Payment and Financial Services

  • Cash-in;
  • cash-out;
  • bank transfers;
  • remittance;
  • merchant payments;
  • QR payments;
  • refunds;
  • reversals;
  • settlement;
  • reconciliation;
  • transaction verification; and
  • fee calculation.

11.3 KYC and Customer Due Diligence

  • Identity verification;
  • customer identification;
  • customer due diligence;
  • enhanced due diligence;
  • account-risk assessment;
  • beneficial-owner identification;
  • source-of-funds verification;
  • source-of-income verification; and
  • compliance with financial regulations.

11.4 AML/CFT Compliance

PAYDA may process information to:

  • prevent money laundering;
  • prevent terrorist financing;
  • conduct transaction monitoring;
  • detect suspicious transactions;
  • perform sanctions screening;
  • investigate unusual transactions;
  • conduct enhanced due diligence;
  • comply with AMLC requirements; and
  • submit reports required by law.

11.5 Fraud and Security

Information may be processed to:

  • detect unauthorized transactions;
  • prevent account takeover;
  • detect fraudulent activity;
  • investigate scams;
  • detect abnormal transactions;
  • protect PAYDA systems;
  • protect Members; and
  • maintain payment-system security.

11.6 Customer Support

Information may be used to:

  • answer inquiries;
  • investigate complaints;
  • investigate unauthorized transactions;
  • resolve disputes;
  • provide technical support; and
  • maintain customer-support records.

11.7 Legal and Regulatory Compliance

PAYDA may process information to comply with:

  • Philippine laws;
  • BSP requirements;
  • AMLC requirements;
  • NPC requirements;
  • court orders;
  • lawful government requests;
  • tax requirements;
  • accounting requirements;
  • audit requirements; and
  • other regulatory obligations.

11.8 Service Improvement

PAYDA may use information to:

  • improve PAYDA Services;
  • analyze service usage;
  • improve security;
  • troubleshoot technical issues;
  • develop new features; and
  • conduct aggregated or de-identified analytics.

12. LAWFUL BASES FOR PROCESSING

Depending on the circumstances, PAYDA may process personal information based on:

Consent

Where consent is required and is the lawful basis relied upon.

Contract

Where processing is necessary to provide PAYDA Services requested by you or to perform contractual obligations.

Legal Obligation

Where processing is necessary to comply with Philippine law, regulation, court order, or regulatory requirement.

Legitimate Interests

Where processing is necessary for a legitimate interest and is permitted by applicable privacy law, taking into account the rights and interests of the data subject.

Other Lawful Bases

PAYDA may rely on other lawful bases recognized under Philippine law.

Where processing is required by law, withdrawal of consent may not prevent PAYDA from continuing such processing.

13. PAYDA AND NETBANK PROCESSING

PAYDA may use Netbank's BaaS infrastructure, APIs, payment systems, and core banking system.

Depending on the specific service, information may be provided to Netbank for:

  • account opening;
  • KYC;
  • identity verification;
  • customer due diligence;
  • bank-account maintenance;
  • transaction processing;
  • cash-in;
  • cash-out;
  • bank transfers;
  • settlement;
  • reconciliation;
  • fraud monitoring;
  • AML/CFT compliance;
  • regulatory reporting;
  • customer support; and
  • other financial-service purposes.

Netbank may independently process personal information as a regulated financial institution.

Where Netbank determines the purposes and means of processing, Netbank may act as a separate Personal Information Controller.

Members may therefore be required to review and accept applicable Netbank terms and privacy notices when using financial products or accounts provided by Netbank.

14. SHARING OF PERSONAL INFORMATION

PAYDA does not sell personal information.

Where lawful and necessary, PAYDA may disclose or share information with:

  • Netbank;
  • banks;
  • financial institutions;
  • payment service providers;
  • payment-system operators;
  • remittance providers;
  • merchants;
  • KYC providers;
  • identity-verification providers;
  • fraud-prevention providers;
  • cybersecurity providers;
  • cloud-service providers;
  • technology providers;
  • customer-support providers;
  • auditors;
  • professional advisers;
  • legal advisers;
  • regulators;
  • government agencies; and
  • other authorized service providers.

15. DISCLOSURE WITHOUT CONSENT

PAYDA may disclose personal information without separate consent where permitted or required by law, including:

  • compliance with a legal obligation;
  • compliance with a court order;
  • lawful regulatory requests;
  • AML/CFT obligations;
  • fraud prevention;
  • crime prevention or investigation;
  • cybersecurity;
  • protection of PAYDA, Members, or other persons; and
  • other circumstances authorized under Philippine law.

16. PERSONAL INFORMATION PROCESSORS

PAYDA may appoint third-party Personal Information Processors.

Processors may provide:

  • cloud hosting;
  • database services;
  • KYC;
  • identity verification;
  • SMS;
  • email;
  • push notifications;
  • fraud monitoring;
  • cybersecurity;
  • analytics;
  • customer support;
  • document processing; and
  • payment technology.

PAYDA shall take reasonable steps to ensure that its processors process information only for authorized purposes and maintain appropriate safeguards.

17. CROSS-BORDER PROCESSING

Certain PAYDA service providers may process personal information outside the Philippines.

Where personal information is transferred outside the Philippines, PAYDA shall implement appropriate safeguards and comply with applicable Philippine privacy requirements.

Such safeguards may include contractual, organizational, technical, and security measures appropriate to the nature of the information and processing.

18. SENSITIVE PERSONAL INFORMATION

PAYDA may process sensitive personal information where permitted or required by applicable law.

This may include information contained in:

  • government-issued identification;
  • KYC documents;
  • identity verification;
  • AML/CFT investigations;
  • regulatory records; and
  • other legally required documentation.

Appropriate safeguards shall be applied to sensitive personal information.

19. FINANCIAL INFORMATION CONFIDENTIALITY

PAYDA treats financial and transaction information as confidential.

Access shall be limited to authorized personnel, systems, institutions, and service providers with a legitimate and lawful need.

Financial information may be accessed or disclosed when necessary to:

  • process transactions;
  • provide financial services;
  • provide customer support;
  • prevent fraud;
  • perform AML/CFT monitoring;
  • comply with law;
  • comply with regulatory requirements; or
  • investigate disputes.

20. TRANSACTION MONITORING

PAYDA may monitor account and transaction activity to protect the PAYDA ecosystem and comply with legal and regulatory obligations.

Monitoring may consider:

  • transaction amount;
  • transaction frequency;
  • transaction velocity;
  • cash-in activity;
  • cash-out activity;
  • transfer activity;
  • recipient information;
  • sender information;
  • device information;
  • IP information;
  • account behavior;
  • geographic indicators; and
  • other lawful risk indicators.

Such monitoring may result in additional verification, temporary restrictions, transaction review, or other actions where permitted by law.

21. AML/CFT PROCESSING

PAYDA and/or Netbank may process personal information to comply with applicable Philippine AML/CFT requirements.

This may include:

  • customer identification;
  • customer due diligence;
  • enhanced due diligence;
  • beneficial-owner verification;
  • source-of-funds verification;
  • source-of-income verification;
  • transaction monitoring;
  • sanctions screening;
  • suspicious-transaction investigation;
  • regulatory reporting; and
  • recordkeeping.

Where applicable law prohibits disclosure of information relating to an AML/CFT report or investigation, PAYDA may be unable to provide details concerning the investigation.

22. RETENTION OF PERSONAL INFORMATION

PAYDA retains personal information only for as long as necessary or appropriate for:

  • providing PAYDA Services;
  • fulfilling the purpose for which the information was collected;
  • complying with legal obligations;
  • complying with BSP requirements;
  • complying with AML/CFT obligations;
  • tax and accounting requirements;
  • audit requirements;
  • dispute resolution;
  • fraud investigations;
  • legal claims; or
  • other lawful purposes.

Different categories of personal information may therefore have different retention periods.

PAYDA does not automatically delete all information immediately after account closure where applicable laws or legitimate legal requirements require continued retention.

23. RETENTION AFTER ACCOUNT CLOSURE

After account closure, PAYDA shall securely delete or anonymize information that is no longer necessary and is not required to be retained.

Information that must be retained under applicable law may continue to be stored securely for the required period.

Such retained information shall not be used for unrelated purposes.

24. SECURE DESTRUCTION

When personal information reaches the end of its applicable retention period, PAYDA shall take reasonable steps to securely dispose of it.

Electronic information may be securely deleted or rendered irretrievable.

Physical records may be shredded, destroyed, or otherwise disposed of using appropriate security procedures.

25. SECURITY MEASURES

PAYDA implements reasonable and appropriate organizational, physical, and technical measures to protect personal information.

These may include:

  • encryption in transit;
  • appropriate encryption or equivalent safeguards for sensitive information;
  • authentication;
  • role-based access controls;
  • access logging;
  • security monitoring;
  • vulnerability management;
  • security testing;
  • backup and recovery procedures;
  • incident-response procedures;
  • secure software-development practices;
  • confidentiality obligations;
  • employee security training;
  • vendor security assessments; and
  • periodic security reviews.

No electronic system can be guaranteed to be completely secure. PAYDA continuously evaluates and improves its security controls.

26. DATA BREACHES AND SECURITY INCIDENTS

PAYDA maintains procedures for identifying, investigating, containing, and responding to personal-data breaches and security incidents.

Where a breach is subject to mandatory notification, PAYDA shall comply with applicable notification requirements of the National Privacy Commission and other relevant Philippine regulators.

Where an incident affects a financial service provided through Netbank or another regulated financial institution, PAYDA may coordinate with the relevant institution and regulator as required.

27. YOUR RIGHTS UNDER THE DATA PRIVACY ACT

Subject to applicable law and lawful limitations, you may have the following rights:

Right to be informed

You have the right to know how your personal information is processed.

Right to access

You may request access to personal information concerning you.

Right to correct

You may request correction of inaccurate or outdated personal information.

Right to object

You may object to certain processing where permitted by law.

Right to withdraw consent

Where processing is based on consent, you may withdraw consent subject to applicable legal limitations.

Right to erasure or blocking

You may request deletion, removal, or blocking of personal information where permitted by law.

Right to data portability

Where applicable, you may request a copy or portability of personal information in accordance with Philippine law.

Right to lodge a complaint

You may lodge a complaint with the National Privacy Commission if you believe your privacy rights have been violated.

These rights are subject to exceptions and limitations under applicable law.

28. HOW TO EXERCISE YOUR PRIVACY RIGHTS

Privacy requests may be submitted through:

PAYDA Customer Support

Email: [INSERT PRIVACY EMAIL]

In-App Support: [INSERT PROCEDURE]

Telephone: [INSERT]

Address: [INSERT]

Requests may be subject to identity verification to protect against unauthorized access or disclosure.

PAYDA may request reasonable information necessary to verify the identity and authority of the requesting person.

PAYDA shall process valid requests in accordance with applicable Philippine law.

29. CHILDREN'S PERSONAL INFORMATION

PAYDA Services are intended only for persons who are legally eligible to use the applicable service.

PAYDA may apply age and identity verification requirements appropriate to the financial service.

Where personal information concerning children is processed, PAYDA shall comply with applicable Philippine privacy laws and requirements.

If PAYDA becomes aware that personal information has been collected contrary to applicable requirements, PAYDA shall take appropriate action.

30. MARKETING COMMUNICATIONS

PAYDA may send marketing or promotional communications where permitted by applicable law and where the appropriate lawful basis exists.

Members may opt out of marketing communications through available unsubscribe mechanisms or account settings.

Opting out of marketing communications does not prevent PAYDA from sending necessary service communications such as:

  • transaction confirmations;
  • security alerts;
  • fraud alerts;
  • account notices;
  • regulatory notices;
  • service interruptions; and
  • other necessary service communications.

31. PROFILING AND AUTOMATED PROCESSING

PAYDA may use automated systems, rules, analytics, and risk models for:

  • fraud detection;
  • transaction monitoring;
  • cybersecurity;
  • account security;
  • AML/CFT monitoring;
  • risk assessment; and
  • service improvement.

Where applicable law requires additional safeguards regarding decisions that significantly affect a Member, PAYDA shall comply with such requirements.

32. THIRD-PARTY INFORMATION

PAYDA may lawfully receive information from:

  • Netbank;
  • banks;
  • financial institutions;
  • KYC providers;
  • identity-verification providers;
  • payment providers;
  • fraud-prevention providers;
  • merchants;
  • regulators;
  • government agencies; and
  • transaction counterparties.

Such information may be used for identity verification, transaction processing, fraud prevention, security, regulatory compliance, and other lawful purposes.

33. DATA ACCURACY

Members must provide accurate and current information.

Members should promptly update information when it changes.

PAYDA may rely on information provided by Members unless PAYDA has reasonable grounds to believe that such information is inaccurate or incomplete.

34. ACCOUNT AND AUTHENTICATION SECURITY

Members must protect:

  • passwords;
  • PINs;
  • OTPs;
  • authentication codes;
  • registered devices;
  • SIM cards;
  • recovery information; and
  • other authentication credentials.

Members must immediately report suspected unauthorized access or compromised credentials.

PAYDA personnel will not request passwords, PINs, or OTPs through unsolicited communications.

35. PHISHING, SCAMS AND FRAUD

Members should remain alert to:

  • phishing;
  • fake PAYDA websites;
  • fake customer-support accounts;
  • fraudulent messages;
  • fraudulent links;
  • impersonation;
  • social engineering; and
  • unauthorized requests for OTPs or account credentials.

PAYDA will not request Members to disclose their passwords or OTPs through unsolicited communications.

Suspected fraud or unauthorized transactions should be reported immediately through official PAYDA support channels.

36. THIRD-PARTY SERVICES AND LINKS

PAYDA may provide links to third-party websites or services.

Third parties may have their own privacy policies.

PAYDA is not responsible for the privacy practices of independent third parties.

Members should review applicable third-party privacy notices before providing personal information.

37. NETBANK PRIVACY NOTICE

Where Netbank acts as the regulated financial institution, account provider, e-money issuer, banking service provider, or other financial-service provider, Netbank may independently process personal information.

Members may therefore be subject to Netbank's:

  • Privacy Notice;
  • Account Terms;
  • Financial Product Terms;
  • KYC requirements;
  • AML/CFT requirements;
  • complaint procedures; and
  • other applicable policies.

Where required, Members will be directed to or provided with the applicable Netbank documentation.

38. FINANCIAL CONSUMER PROTECTION

PAYDA and the relevant regulated financial institution shall comply with applicable financial consumer protection requirements.

For financial products or services provided by Netbank, complaints may be handled through Netbank's applicable complaint-resolution process and, where appropriate, escalated through applicable BSP consumer-assistance mechanisms.

39. CHANGES TO THIS PRIVACY POLICY

PAYDA may update this Privacy Policy when necessary because of:

  • changes in law;
  • regulatory requirements;
  • changes in PAYDA Services;
  • changes in Netbank integration;
  • changes in technology;
  • changes in data-processing practices; or
  • other legitimate operational requirements.

For material changes, PAYDA shall provide appropriate notice in accordance with applicable law.

The revised policy shall state its effective date.

40. DATA PROTECTION OFFICER

For privacy concerns, requests, complaints, or questions, please contact:

Data Protection Officer

Name: [INSERT DPO NAME]

Position: Data Protection Officer

Email: [INSERT DPO EMAIL]

Telephone: [INSERT]

Address: Unit 2908 One San Miguel Avenue Ortigas Center Pasig City

41. NATIONAL PRIVACY COMMISSION

If you believe your privacy rights have been violated, you may contact the National Privacy Commission of the Philippines or file a complaint in accordance with applicable procedures.

PAYDA encourages Members to contact the PAYDA Data Protection Officer first so that the concern can be investigated and resolved where possible.

42. BSP FINANCIAL CONSUMER CONCERNS

For concerns involving financial products or services provided by Netbank or another BSP-supervised institution, Members may first use the applicable financial institution's complaint-handling process.

Where appropriate and permitted, unresolved financial-consumer concerns may be elevated to the Bangko Sentral ng Pilipinas through its applicable consumer-assistance channels.

43. CONTACT INFORMATION

Bentix Global Solutions Inc.

Principal Office: Unit 2908 One San Miguel Avenue Ortigas Center Pasig City

Customer Support: [INSERT]

Privacy Email: [INSERT]

DPO Email: [INSERT]

Fraud / Unauthorized Transaction Reporting: [INSERT 24/7 CHANNEL]

Website: [INSERT]

44. EFFECTIVE DATE

This Privacy Policy takes effect on:

September 1, 2026

and remains effective until amended or replaced.

Last Updated: September 2, 2026