Trust, Security, Privacy & AI Governance
Anyway emphasizes “security, privacy, and responsible AI governance” with internal policies addressing data handling, secure operations, and ongoing oversight. These governance measures evolve alongside product development, customer needs, and regulatory changes.
01 Security
The company maintains a “secure and reliable environment” through organizational, technical, and operational safeguards across systems, personnel, and service providers.
Data Encryption in Transit and at Rest
Communications use “industry-standard encryption protocols in transit,” with stored data protected through encryption at rest where appropriate.
Access Control
Access follows “least-privilege principles” through role-based provisioning, approval workflows, periodic reviews, and access adjustments when responsibilities change.
Logging and Monitoring
Internal processes support “visibility into system operations, investigation of abnormal or unauthorized activity, incident response and forensic analysis.”
Incident Response
Procedures address “identification, escalation, management, and review of security incidents” with timely investigation and mitigation.
Third-Party Service Provider Management
Third-party providers undergo assessment for “security, confidentiality, and operational suitability” with appropriate contractual and operational measures.
Infrastructure Security
Technical practices support “security and resilience” through configuration controls, environment segregation, change handling, and vulnerability management.
Personnel Confidentiality and Access Management
Personnel with system access face “confidentiality, acceptable-use, and access-management requirements” with onboarding, offboarding, and role-based access limitations.
Continuous Review
Security practices evolve with services, technical environments, and regulatory expectations.
Security Contact
Security inquiries and vulnerability disclosures should use company-provided contact details.
02 Privacy
Anyway handles “personal data responsibly, transparently, and in a manner appropriate” to its service model, addressing collection, use, retention, protection, and management.
Privacy Governance
Internal measures support “privacy governance across services and operations,” including data handling review and responsibility allocation.
Categories of Data
The company may process identity/contact data, account/authentication data, transaction/financial data, technical/usage data, communications data, and KYC/identity verification data depending on service features.
Purposes of Processing
Data processing serves “defined and legitimate purposes” including service provision, security, support, maintenance, improvement, and regulatory compliance.
Access Limitation and Internal Use
Data access is “limited based on role, business need, and internal authorization procedures” with confidentiality requirements.
Data Retention and Deletion
Retention and deletion follow “internal rules and procedures” reflecting service requirements, operational needs, and legal obligations.
Privacy Requests and Communications
Requests concerning access, correction, deletion, restriction, objection, or portability may be directed to the Privacy Lead.
Third-Party Service Providers and Processors
Third parties including cloud providers, AI APIs, KYC/AML services, analytics, support tools, payment processors, and security vendors undergo “internal review procedures” for appropriate safeguards.
International Data Transfers
Transfers across jurisdictions implement “appropriate safeguards” including Standard Contractual Clauses, adequacy decisions, or other mechanisms recognized under data protection law.
Privacy Contact
The Privacy Lead handles “data protection and privacy matters” through company-provided contact details.
Ongoing Review
Privacy practices evolve with products, service models, customer requirements, and regulatory developments.
03 AI Governance
Anyway commits to “responsible development, procurement, deployment, and use of AI-enabled capabilities” with risk-based review, transparency, accountability, and compliance readiness.
Scope and Role Awareness
The company recognizes “AI-related obligations may vary” based on feature nature, development approach, and role in the service chain.
Risk-Based Assessment
A “risk-based approach” evaluates features considering user categories, context, and operational/security/privacy implications to determine whether restrictions, enhanced governance, or additional safeguards apply.
Prohibited and Sensitive Use Screening
Features undergo assessment for “manipulation or deception, exploitation of vulnerabilities, inappropriate profiling or social scoring, sensitive inference, unlawful biometric use, emotion recognition in restricted contexts.”
High-Risk Use Case Governance
High-impact scenarios receive “enhanced governance measures” including data handling review, documentation, logging, user information, human oversight, and strengthened controls for accuracy and robustness.
Transparency and User Information
Users receive information about “interacting with AI-enabled functionality” and AI-generated content may be labeled per legal requirements.
Human Oversight and Escalation
Appropriate oversight measures support “informed human review, operational intervention, suspension of use where necessary.”
Documentation, Traceability, and Internal Review Records
The company maintains “documentation, assessments, risk classification records, and internal review materials” supporting governance and accountability.
Third-Party Models, Tools, and Downstream Integration
External models, APIs, and infrastructure undergo assessment for “security, privacy, operational suitability, and service-related risk.”
AI Literacy and Internal Enablement
Internal guidance and training support “responsible design, deployment, oversight, and use of AI-enabled functionality.”
Monitoring, Incident Awareness, and Continuous Improvement
Governance practices evolve with “product updates, implementation experience, customer feedback, incident learnings, and evolving legal and regulatory developments.”
General-Purpose AI and Regulatory Developments
The company monitors developments regarding “general-purpose AI models, transparency expectations, copyright-related considerations, and safety and security issues.”