Back to home
Legal

Trust, Security, Privacy & AI Governance

Effective Date: March 25, 2026 · Last Updated: March 25, 2026

Anyway emphasizes “security, privacy, and responsible AI governance” with internal policies addressing data handling, secure operations, and ongoing oversight. These governance measures evolve alongside product development, customer needs, and regulatory changes.

01 Security

The company maintains a “secure and reliable environment” through organizational, technical, and operational safeguards across systems, personnel, and service providers.

Data Encryption in Transit and at Rest

Communications use “industry-standard encryption protocols in transit,” with stored data protected through encryption at rest where appropriate.

Access Control

Access follows “least-privilege principles” through role-based provisioning, approval workflows, periodic reviews, and access adjustments when responsibilities change.

Logging and Monitoring

Internal processes support “visibility into system operations, investigation of abnormal or unauthorized activity, incident response and forensic analysis.”

Incident Response

Procedures address “identification, escalation, management, and review of security incidents” with timely investigation and mitigation.

Third-Party Service Provider Management

Third-party providers undergo assessment for “security, confidentiality, and operational suitability” with appropriate contractual and operational measures.

Infrastructure Security

Technical practices support “security and resilience” through configuration controls, environment segregation, change handling, and vulnerability management.

Personnel Confidentiality and Access Management

Personnel with system access face “confidentiality, acceptable-use, and access-management requirements” with onboarding, offboarding, and role-based access limitations.

Continuous Review

Security practices evolve with services, technical environments, and regulatory expectations.

Security Contact

Security inquiries and vulnerability disclosures should use company-provided contact details.

02 Privacy

Anyway handles “personal data responsibly, transparently, and in a manner appropriate” to its service model, addressing collection, use, retention, protection, and management.

Privacy Governance

Internal measures support “privacy governance across services and operations,” including data handling review and responsibility allocation.

Categories of Data

The company may process identity/contact data, account/authentication data, transaction/financial data, technical/usage data, communications data, and KYC/identity verification data depending on service features.

Purposes of Processing

Data processing serves “defined and legitimate purposes” including service provision, security, support, maintenance, improvement, and regulatory compliance.

Access Limitation and Internal Use

Data access is “limited based on role, business need, and internal authorization procedures” with confidentiality requirements.

Data Retention and Deletion

Retention and deletion follow “internal rules and procedures” reflecting service requirements, operational needs, and legal obligations.

Privacy Requests and Communications

Requests concerning access, correction, deletion, restriction, objection, or portability may be directed to the Privacy Lead.

Third-Party Service Providers and Processors

Third parties including cloud providers, AI APIs, KYC/AML services, analytics, support tools, payment processors, and security vendors undergo “internal review procedures” for appropriate safeguards.

International Data Transfers

Transfers across jurisdictions implement “appropriate safeguards” including Standard Contractual Clauses, adequacy decisions, or other mechanisms recognized under data protection law.

Privacy Contact

The Privacy Lead handles “data protection and privacy matters” through company-provided contact details.

Ongoing Review

Privacy practices evolve with products, service models, customer requirements, and regulatory developments.

03 AI Governance

Anyway commits to “responsible development, procurement, deployment, and use of AI-enabled capabilities” with risk-based review, transparency, accountability, and compliance readiness.

Scope and Role Awareness

The company recognizes “AI-related obligations may vary” based on feature nature, development approach, and role in the service chain.

Risk-Based Assessment

A “risk-based approach” evaluates features considering user categories, context, and operational/security/privacy implications to determine whether restrictions, enhanced governance, or additional safeguards apply.

Prohibited and Sensitive Use Screening

Features undergo assessment for “manipulation or deception, exploitation of vulnerabilities, inappropriate profiling or social scoring, sensitive inference, unlawful biometric use, emotion recognition in restricted contexts.”

High-Risk Use Case Governance

High-impact scenarios receive “enhanced governance measures” including data handling review, documentation, logging, user information, human oversight, and strengthened controls for accuracy and robustness.

Transparency and User Information

Users receive information about “interacting with AI-enabled functionality” and AI-generated content may be labeled per legal requirements.

Human Oversight and Escalation

Appropriate oversight measures support “informed human review, operational intervention, suspension of use where necessary.”

Documentation, Traceability, and Internal Review Records

The company maintains “documentation, assessments, risk classification records, and internal review materials” supporting governance and accountability.

Third-Party Models, Tools, and Downstream Integration

External models, APIs, and infrastructure undergo assessment for “security, privacy, operational suitability, and service-related risk.”

AI Literacy and Internal Enablement

Internal guidance and training support “responsible design, deployment, oversight, and use of AI-enabled functionality.”

Monitoring, Incident Awareness, and Continuous Improvement

Governance practices evolve with “product updates, implementation experience, customer feedback, incident learnings, and evolving legal and regulatory developments.”

General-Purpose AI and Regulatory Developments

The company monitors developments regarding “general-purpose AI models, transparency expectations, copyright-related considerations, and safety and security issues.”