These documents are published in English only.以下文件僅以英文發布。
Privacy Policy
Last updated: 6 September 2026
This Privacy Policy explains how Dynvora Global Technology Limited ("AnyItem", "we", "us") collects, uses, discloses and protects personal data in connection with the services offered through anyitem.cards.
We handle personal data in accordance with the Personal Data (Privacy) Ordinance (Cap. 486) of Hong Kong and with the data protection law applicable in your place of residence.
1. Data we collect
Identity and verification data. Full name, date of birth, nationality, residential address, government-issued identity document details and images, and a facial image or liveness capture where required for verification.
Contact data. Email address, and any other contact details you provide.
Financial and transaction data. Card balances, funding sources, transaction records, merchant details, amounts, currencies and timestamps.
Source of funds and wealth data. Where required under our AML / KYC Policy, information and documentation concerning the origin of funds.
Technical data. IP address, device identifiers, browser type, operating system, and log data generated when you access the Platform.
Communications. Records of your correspondence with our support channels, including interactions with our automated support assistant.
We collect this data directly from you, from your use of the Platform, and from third-party verification, screening and risk providers engaged by us or by the issuing institution.
2. Why we use it
| Purpose | Basis |
|---|---|
| Verifying your identity and eligibility | Legal obligation; performance of contract |
| Facilitating card issuance and account servicing | Performance of contract |
| Anti-money-laundering and sanctions screening | Legal obligation |
| Fraud detection and transaction risk scoring | Legitimate interest; legal obligation |
| Responding to support enquiries | Performance of contract |
| Record-keeping and regulatory reporting | Legal obligation |
| Improving and securing the Platform | Legitimate interest |
We do not sell personal data. We do not use personal data for third-party advertising.
3. Automated processing
Transaction risk assessment is performed using automated screening tools provided by a third-party risk service provider. These tools may flag, delay or decline a transaction based on patterns in transaction data.
Our support channel includes an automated assistant that handles routine enquiries. It does not make decisions about your account. Where an enquiry falls outside its scope, it is escalated to a human operator.
Automated screening does not by itself result in permanent account closure. Where a decision materially affects you, you may request human review by contacting info@anyitem.cards.
4. Who we share it with
- the issuing institution and its service providers, for card issuance, authorisation and settlement;
- identity verification and sanctions screening providers;
- card processing and payment infrastructure providers;
- regulators, law enforcement and tax authorities, where required by law or by lawful request;
- professional advisers (legal, audit, compliance) under duties of confidentiality;
- cloud hosting and IT service providers.
We require all processors to handle personal data under contract, only on our instructions, and with appropriate security measures.
5. International transfers
Personal data may be transferred to and processed in jurisdictions outside your country of residence. Where such transfers occur, we put in place appropriate safeguards, including contractual protections requiring a standard of protection comparable to that of your home jurisdiction.
6. Retention
We retain personal data for as long as your account is active and thereafter for the period required by applicable anti-money-laundering and record-keeping law — generally seven years after the end of the relationship. Data no longer required is deleted or irreversibly anonymised.
7. Security
We apply technical and organisational measures including encryption in transit and at rest, access control on a need-to-know basis, logging of administrative access, and periodic review of our security posture.
No system is perfectly secure. If a data breach occurs that is likely to result in significant harm, we will notify affected individuals and the relevant regulator in accordance with applicable law.
8. Your rights
Subject to applicable law, you may request access to the personal data we hold about you; request correction of inaccurate data; request erasure, where we are not required to retain the data; object to or request restriction of certain processing; withdraw consent where processing is based on consent; and request human review of an automated decision that materially affects you.
Requests may be sent to info@anyitem.cards. We will respond within the period required by applicable law, and may need to verify your identity before acting on a request.
Certain rights are limited where compliance would conflict with our anti-money-laundering obligations. In particular, we cannot delete records we are legally required to retain, and we cannot disclose the existence or content of a suspicious transaction report.
9. Cookies
The Platform uses cookies and similar technologies that are necessary for the site to function and to maintain session security.
10. Children
The services are not offered to persons under 18. We do not knowingly collect personal data from children.
11. Changes
We may update this Policy. Material changes will be notified through the Platform or by email before they take effect.
12. Contact
Data protection enquiries: info@anyitem.cards.
This document has been prepared in English. Where a translation is provided for convenience, the English version prevails in the event of any discrepancy. Questions may be sent to info@anyitem.cards.