KONEK™ is currently in its commercial pilot release and is only available to select users if your financial institution sent you an invitation to sign up for KONEK. Stay tuned for more information as to when KONEK is available to all users.
Privacy Notice
When you use the Interac Direct or Interac Card-Based Payments services and associated sites (collectively, “KONEK”), Interac Corp. (referred to below as “Interac”, or “we”, “us” and similar terms) will need to collect, use and disclose your personal information to process your transactions and for certain related activities. For full information regarding how Interac handles your personal information, you can review our full KONEK Privacy Policy. This KONEK Privacy Notice (“KONEK Privacy Notice”) sets out certain key elements from the KONEK Privacy Policy, to assist you to make an informed decision about using KONEK.
1. Information We Collect
We collect information about you from a variety of sources in connection with KONEK, including information provided to us by Your Financial Institution (as defined below) and participating merchants and information collected directly from you and your devices which Interac’s service providers obtain from third parties. You can find a full description of information collected from each of these sources in the KONEK Privacy Policy , and we have provided a high-level overview with some illustrative examples below.
(i) From Your Financial Institution. When you use KONEK, you are choosing to pay for products and services using existing bank accounts and/or existing credit cards issued to you by one or more banks with which you have a relationship (collectively, “Your Financial Institution”). Your Financial Institution will provide us with information such as your client ID, contact information (full name, address, email address and phone number), a list of accounts that you are authorized to use for KONEK transactions (i.e., account type and last four digits of each eligible account number), and full account number or payment card details only for the account that you select to pay for your purchase. Your Financial Institution also provides us with information about your use of other Interac products and services (including Interac e-Transfer and Interac Online Payments), which we use for fraud detection and prevention purposes. Your Financial Institution may also provide us with information regarding complaints, disputes or other customer service issues related to a KONEK transaction.
(ii) From Merchants. We will also receive information about the products and services you purchase from participating merchants (for example, product type, quantity and price), together with certain information about the merchant and the type of transaction (e.g., a one-time purchase or a recurring payment). In some cases, the merchant may also provide us with other information, such as your name, your merchant customer ID, and/or a mailing address. Your Merchants may also provide us with information regarding complaints, disputes or other customer service issues related to a KONEK transaction.
(iii) From You Directly. You may provide us with certain information directly from time-to-time, such as when you update your KONEK profile, edit your contact information, add a shipping address, or choose a default payment option.
(iv) From Your Devices. When you use KONEK, certain information is collected automatically from the device you use for the transaction, including through cookies, web beacons and device fingerprinting, for identity verification, authentication, and fraud prevention purposes. Examples of such information include your device ID, operating system, browser information, device type, IP address, location, KONEK usage data (such as the date and time when you use KONEK), and confirmation of identity for return users that choose to enable biometric authentication . Some of this data may also be used to generate aggregate statistical data, for the purposes described below.
2. How We Use Your Information
We use your personal information for the purposes of processing your payments for goods and services from participating merchants and other transactions (such as refunds), and to carry out related activities such as to: authenticate you; create and maintain your KONEK profile (where applicable); detect and prevent fraud; provide authentication process recommendations to Your Financial Institution; communicate with you (including to email you regarding your KONEK profile, where applicable); investigate complaints, disputes, or other customer services issues; manage internal risks and business needs; comply with our legal obligations; and generate aggregate statistical data in order to evaluate, improve, market, and generate reports on KONEK. We may also use information collected in connection with KONEK to detect and prevent fraud across other Interac products and services (e.g., Interac e-Transfer), as well as to develop fraud detection models and countermeasure rules.
3. Sharing Your Information
All of the information that we collect about you will be shared with Your Financial Institution, which is ultimately responsible for deciding whether to approve each of your transactions. In addition, we will share some information with merchants from which you make purchases, such as your shipping address, email address and phone number, so that they can ship your products and communicate with you about your purchase.
In addition, if you choose to make a card-based payment, your payment card details (i.e., PAN and card expiry date) and associated information, and in some cases your email address, will be provided to token aggregators who will share your information with the relevant Payment Network – i.e., Mastercard, Visa or AMEX (“Payment Network”). The Payment Network will then share the information with the card issuer. The sharing of your information with these parties is required in order to tokenize your payment card details, for security purposes.
We may also share your information with Your Financial Institution, Merchants, or other third parties (such as Acquirers) for the purpose of assisting in the investigation and resolution of complaints, disputes or other customer service issues related to a KONEK transaction.
Once information is disclosed to merchants, a Payment Network or Your Financial Institution, it will no longer be within Interac’s control, and will be handled in accordance with the relevant merchant’s, Payment Network’s or Your Financial Institution’s own privacy policies and procedures, which may differ from Interac’s. If you have questions about how Your Financial Institution, a Payment Network or a merchant will handle your personal information, you should contact them directly.
We will also share your information with our service providers, for the same purposes that we use your information. We may otherwise disclose your personal information as required or permitted by applicable law, including for compliance with applicable legal obligations or court order, to investigate or prevent fraud, or in connection with the sale, transfer or reorganization of some or all of our business.
4. Other Important Information
Scope & Duration of Consent. Interac will obtain your consent to collect, use or disclose your personal information for any purpose that is not described in the KONEK Privacy Policy, unless your consent is not required by applicable law. If you choose to create a KONEK profile, your consent will remain valid until you withdraw your consent or until your data is deleted in accordance with the KONEK Privacy Policy (i.e., after 12 months of inactivity or 12 months after account deletion, as described under “How long we keep your personal information). Therefore, when you consent to Interac’s collection, use and disclosure of your personal information in accordance with this KONEK Privacy Notice, you are agreeing to allow Interac to collect, use and disclose your information on multiple occasions, over time, each time that you use KONEK to conduct a transaction. Each time you use KONEK, Interac will automatically obtain an up-to-date list of accounts from Your Financial Institutions (account types and last four digits) that qualify for use with this service, as well as full account details for the account you select to make your payment.
Cross-Border Transfers. You should also be aware that certain information may be collected, communicated or stored outside the jurisdiction where you are located, including outside Canada, and that information that is transferred or stored outside Canada may be accessible to courts, law enforcement and national authorities in other countries.
Fraud Modeling and Automated Processing. KONEK uses technology that includes functions that allow you to be identified, located and profiled for fraud purposes. This technology is activated when you consent to the collection, use and disclosure of your personal information in accordance with this KONEK Privacy Notice, and will then be active whenever you use KONEK unless and until you withdraw your consent. In addition, KONEK makes fraud and transaction approval decisions based exclusively on automated processing of information.
Risks. Although we take steps to protect your information, it is not entirely possible to eliminate all security risks, such as the risk of unauthorized transactions, especially if: (a) you use KONEK on a public, work or shared device, (b) you share your KONEK profile or financial account login credentials for Your Financial Institution (“Login Credentials”) with another person; or (c) an unauthorized person obtains access to your personal device or your Login Credentials. If you suspect unauthorized access to or use of your Login Credentials, you should notify Your Financial Institution immediately. You should also be aware that Interac relies on the accuracy of information provided to us by you, Your Financial Institution and merchants. You should take steps to ensure that such information is correct, including updating and verifying the information about you that is held by merchants and Your Financial Institution.
Rights. You have the right to access and rectify your personal information, subject to certain required and permitted exceptions under applicable law. You may access your KONEK profile yourself, at any time, or contact us (as described below) to submit a request to access or rectify your personal information. You can also withdraw your consent to our continued use and disclosure of your personal information by deleting your KONEK profile (where applicable) or contacting us, subject to any limitations under applicable law. Please note that such withdrawal of consent will not operate retroactively, and may result in you being unable to continue using KONEK (i.e., if you withdraw consent to a condition of service). You may also have other rights under applicable law in the jurisdiction where you are located.
Contacting Us. You may contact Conni Gibson, Chief Legal Officer and Corporate Secretary, at [email protected] or Interac Corp. Royal Bank Plaza, North Tower, P.O. Box 45, 200 Bay Street, Suite 2400, Toronto, Ontario, M5J 2J1, Canada, if you have questions about how we collect your personal information, or other questions or concerns about our privacy policies and practices, including if you have questions about the collection, use, disclosure or storage of your personal information by our service providers outside Canada (or want to obtain written information about such service providers).
Additional Notices For Quebec Users
Your information may be communicated outside Quebec. While most of your information will be kept in Ontario, if you choose Card-Based Payments, your payment card details will be transferred to the United States. Some of our service providers that collect information about you in connection with their services are also located in the United States.
Your information will be accessible to Interac’s customer service, fraud operations, and fraud analytics teams, who have a need to access such information to perform their duties. Certain insights derived from your information will also be available to other Interac personnel.
You may find more information regarding the roles and responsibilities of Interac personnel with respect to personal information at Roles and Responsibilities of Interac Personnel Throughout the Lifecycle of Personal Information.