Who we are
Hashcode Next Fintech Limited (“Next Payment”, “we”, “us”) provides payment operations software. This notice explains how we collect, use, store, access and disclose personal data when you use our website, software and applications (the “Services”).
The law this notice is written against
“Personal data” means personal data as defined under the Personal Data (Privacy) Ordinance (Cap. 486) of the Hong Kong Special Administrative Region: any data relating directly or indirectly to a living individual from which it is practicable for the identity of the individual to be ascertained.
What we collect
To provide the Services or answer your enquiry, we may collect and hold some or all of the following about you and, where applicable, your beneficiaries or counterparties:
| Category | What it includes |
| Identity | name, date of birth, identification document type and number |
| Contact | address, telephone number, email address |
| Business | legal entity, registration number, registered address, business activity, website |
| Payment | bank account information, wallet or account identifiers, beneficiary details, payment instructions and references |
| Technical | session and device data required to operate the console, and the cryptographic result of a security-key challenge |
| Correspondence | your messages to us, and our replies |
Where you give us personal data about another individual, you confirm that you have given them a copy of this notice and that you have their consent.
What we do not collect
We do not store the FIDO security key, the biometric, or the private key material — the key signs a challenge on the device and we receive the result, never the secret. We do not ask for or store card numbers, because card issuing is not part of the Services. We do not sell personal data.
How we use it
To verify identity and eligibility; to prepare payment drafts and quotes; to route a payment for approval; to screen recipients and check instructions against policy; to keep the approval, partner status and reconciliation records; to answer you; and to meet our own legal and regulatory obligations.
Who we share it with
Personal data is shared only where necessary, and only with:
- the applicable licensed partner, which processes and settles payments under its own licence and may run its own identity, sanctions and anti-money-laundering checks;
- service providers acting on our instructions, such as hosting, email and support providers;
- authorities, where the law requires it or a lawful request is made;
- your own organisation, through the console, for the payments you are authorised to see.
Where it is held, and for how long
Onboarding records are kept for the life of the relationship plus the statutory period. Payment, approval and reconciliation records are kept for the period the applicable partner and the applicable law require. Unsuccessful applications and enquiries are kept for a shorter fixed period. Specific hosting regions and retention windows are provided on request.
How it is protected
Access is limited to people who need it. The console reads and drafts inside your workspace session and holds no API keys. Every release is approved by a named person using a FIDO security key, or released under a standing rule a named person approved. The MCP surface exposes no release verb to an agent.
Your rights
Subject to the applicable law, you may ask for a copy of the personal data we hold about you, ask us to correct it, ask us to stop using it for a particular purpose, or withdraw a consent you have given. Write to the address below and we will respond within the period the applicable law allows. You may also complain to the Office of the Privacy Commissioner for Personal Data (Hong Kong).
Changes
We will publish any change to this notice on this page and update the effective date below. If a change materially affects how we use personal data, we will tell account holders directly.
Contact
Questions about this notice go to hello@hashcode-next.com.
Effective 4 October 2026.