UKA Privacy Policy

UKA Privacy Policy

Effective Date: 7 September 2026
Last Updated: 7 September 2026

1. Introduction

This Privacy Policy explains how Device2 Pte. Ltd., operator of UKA, collects, uses, discloses, stores and protects personal data when you access or use the UKA mobile application, website or related services.

Device2 Pte. Ltd. is a Singapore company with UEN:

202511757D

References to “Device2”, “UKA”, “we”, “us” and “our” mean Device2 Pte. Ltd.

We are committed to handling personal data responsibly and in accordance with applicable data-protection laws, including the Singapore Personal Data Protection Act 2012 (“PDPA”).

This Privacy Policy applies to personal data processed by Device2 in connection with UKA.

Certain information relating to your card application, identity verification, card transactions and card account is independently processed by DCS Card Centre Pte. Ltd. (“DCS”) and its designated service providers.


2. Roles of UKA and DCS

UKA provides the customer-facing technology interface used to access the UKA co-branded card programme.

The card is issued by DCS.

DCS is responsible for card-related regulated services, including applicable identity verification, card issuance, transaction processing, settlement and card-account administration.

Device2 does not operate as the issuer of the card and does not hold customer funds.

Where UKA facilitates the transmission of information to DCS or a DCS-appointed provider, such information may pass through the UKA application interface without being retained by Device2.


3. Information Device2 Collects

The personal data collected by Device2 is limited to information reasonably necessary to provide, secure, maintain and support the UKA application.

Depending on how you use UKA, we may collect the following categories of information.

3.1 Account Information

When you create or use a UKA account, we may collect:

· email address;

· account identifier;

· account registration information;

· authentication status;

· account status;

· login information; and

· information necessary to maintain your UKA account.

If mobile-number registration is introduced in the future, we may also collect your mobile telephone number.


3.2 Authentication Information

UKA currently supports authentication methods that may include:

· email verification;

· password authentication;

· Google Sign-In; and

· Sign in with Apple.

Where you use Google or Apple authentication, Device2 may receive limited account information authorised by you and made available by the relevant authentication provider.


3.3 Device and Technical Information

For security, troubleshooting, technical support and service operation, Device2 may collect:

· IP address;

· device type;

· device model;

· operating system;

· operating-system version;

· application version;

· login timestamps;

· device identifiers where technically necessary;

· system logs;

· error information;

· crash information; and

· diagnostic information.

This information helps us identify technical issues affecting particular users, devices or application sessions.


3.4 Customer Support Information

When you contact UKA customer support or submit a support ticket, we may collect:

· your account information;

· email address;

· support-ticket content;

· communications with our support team;

· screenshots or information voluntarily provided by you;

· relevant device or technical information; and

· information reasonably necessary to investigate and resolve your request.

You should avoid voluntarily sending highly sensitive card, password or authentication information through customer-support communications unless specifically requested through a secure channel.


4. KYC and Identity Verification Information

Applicants for a UKA co-branded card are required to undergo identity verification and compliance screening administered through DCS.

DCS currently uses Sumsub as its designated third-party identity verification provider.

The verification process may involve information including:

· legal name;

· date of birth;

· nationality;

· residential address;

· identity-document details;

· passport or identification-card images;

· proof of address;

· photographs;

· facial verification or biometric-related information;

· source-of-funds information;

· source-of-wealth information; and

· other information required for regulatory or compliance purposes.

UKA may provide the user interface through which such information is submitted or transmitted.

However, Device2 does not retain copies of KYC documents, identity-document images, facial verification information or other KYC documentation processed as part of the DCS verification process.

Such information is processed by DCS and its designated providers in accordance with their own legal, regulatory and privacy obligations.


5. Card Information

Sensitive card information is processed through DCS systems.

Device2 does not independently retain complete sensitive card credentials such as:

· full card number;

· CVV or card security code; or

· equivalent card authentication credentials.

Card-related information shown within UKA is obtained through DCS interfaces where necessary to provide the requested functionality.


6. Transaction Information

Transaction information displayed within the UKA application is retrieved from DCS through APIs.

Device2 does not independently operate or maintain the underlying card transaction ledger.

The UKA application may display information supplied by DCS, such as:

· merchant information;

· transaction amounts;

· currencies;

· transaction dates;

· card status;

· transaction status; and

· other card-account information.

Such information is made available within UKA for the purpose of providing the user with access to their card-account information.


7. Digital Asset Information

UKA currently supports eligible funding functionality involving:

· USDT; and

· USDC.

Device2 does not hold user funds or digital assets and does not independently maintain a database of users' underlying digital-asset transaction data as part of the current UKA card programme.

Digital-asset transactions may nevertheless be processed or recorded by DCS, blockchain networks or other relevant service providers independently of Device2.

Information recorded on a public blockchain may remain publicly available independently of UKA.


8. Information We Do Not Currently Collect for Analytics or Advertising

UKA does not currently use third-party advertising, behavioural tracking or general-purpose analytics SDKs for the purpose of monitoring user behaviour for advertising or marketing.

In particular, UKA does not currently use third-party services such as advertising attribution SDKs for targeted advertising.

If this practice changes materially in the future, this Privacy Policy will be updated as appropriate.


9. How We Use Personal Data

Device2 may use personal data for the following purposes.

9.1 Providing UKA Services

We may process information to:

· create and maintain UKA accounts;

· authenticate users;

· provide access to UKA features;

· display card-related information;

· support card-application workflows;

· facilitate communications between users and relevant service providers;

· maintain application functionality; and

· respond to user requests.


9.2 Security and Fraud Prevention

We may use personal data to:

· protect UKA accounts;

· investigate suspicious login activity;

· detect unauthorised access;

· maintain application security;

· identify compromised devices or accounts;

· troubleshoot security incidents; and

· prevent abuse of UKA systems.


9.3 Technical Support and Troubleshooting

We may use device information, IP information, logs and diagnostic information to:

· identify application errors;

· reproduce technical issues;

· determine which users or devices are affected;

· investigate service interruptions;

· resolve customer-support requests; and

· improve application reliability.


9.4 Communications

We may use your contact information to send communications relating to:

· account registration;

· email verification;

· password reset;

· security notifications;

· account changes;

· service updates; and

· customer-support matters.

Authentication-related emails, such as login verification or password reset communications, may be sent using Alibaba Cloud infrastructure.

Card-related and sensitive transactional communications may be sent directly by DCS.


9.5 Compliance and Legal Obligations

Where applicable, we may use or disclose information where necessary to:

· comply with applicable law;

· respond to lawful regulatory requests;

· comply with court orders;

· protect legal rights;

· investigate unlawful conduct;

· cooperate with authorised law-enforcement authorities; or

· satisfy other legal obligations.


10. Push Notifications

UKA may send push notifications relating to matters such as:

· account activity;

· security;

· card status;

· transactions;

· application functionality; and

· important service information.

Push notifications may be delivered using platform services provided by Apple and Google.

Your device settings may allow you to manage whether you receive push notifications.

Disabling certain notifications may affect your ability to receive timely information regarding account or transaction activity.


11. Marketing Communications

UKA does not currently use user information for routine promotional push or email marketing.

UKA may introduce promotional, product or marketing communications in the future.

If such communications are introduced, Device2 will implement appropriate consent, preference or unsubscribe mechanisms where required by applicable law.


12. How We Share Personal Data

Device2 does not sell personal data.

We may disclose or make personal data available to third parties only where reasonably necessary for providing UKA Services, maintaining security, complying with legal obligations or supporting business operations.

Recipients may include the following.


12.1 DCS Card Centre Pte. Ltd.

Information may be transmitted to or received from DCS where necessary for:

· card applications;

· eligibility;

· card administration;

· KYC processes;

· transaction information;

· card status;

· dispute handling;

· account servicing; and

· other card-programme functions.

DCS may independently process personal data in accordance with its own legal and regulatory obligations.


12.2 Sumsub

Sumsub is currently used by DCS as a designated identity verification provider.

Identity and KYC information submitted during the card-application process may be processed by Sumsub on behalf of or in connection with DCS.

Device2 does not retain copies of the KYC documentation processed through this process.


12.3 Alibaba Cloud

Device2 uses Alibaba Cloud infrastructure located in Singapore to operate elements of the UKA technology platform.

Alibaba Cloud may be used for purposes including:

· hosting;

· application infrastructure;

· system operation;

· email authentication communications;

· logging;

· security; and

· technical support infrastructure.


12.4 Apple and Google

Device2 may interact with Apple and Google in connection with:

· authentication;

· application distribution;

· operating-system services; and

· push notifications.

Information processed by Apple or Google may also be subject to their respective privacy policies.


12.5 Professional Advisers

We may disclose personal data where reasonably necessary to:

· legal advisers;

· auditors;

· accountants;

· insurers;

· compliance advisers; or

· other professional advisers.


12.6 Government and Regulatory Authorities

We may disclose information where required or permitted by applicable law, including to:

· regulators;

· law-enforcement agencies;

· courts;

· government authorities; or

· other competent authorities.


12.7 Corporate Transactions

If Device2 is involved in a merger, acquisition, restructuring, financing, investment, transfer of business or similar corporate transaction, relevant personal data may be disclosed as reasonably necessary in connection with that transaction, subject to applicable confidentiality and data-protection requirements.


13. Data Location and International Transfers

Device2 currently operates its UKA server infrastructure through Alibaba Cloud in Singapore.

Device2's current UKA data processing is principally conducted in Singapore.

Certain third-party service providers, including DCS, Sumsub, Apple or Google, may independently operate systems or infrastructure in multiple jurisdictions in accordance with their respective operational structures and legal obligations.

Where Device2 transfers personal data outside Singapore, Device2 will take appropriate steps required by applicable law to ensure that the transferred personal data receives a standard of protection comparable to that required under Singapore's PDPA.


14. Data Retention

Device2 retains personal data only for as long as reasonably necessary for the purposes for which it was collected and in accordance with applicable legal and regulatory requirements.

Retention periods may vary depending on:

· the nature of the information;

· the purpose for which it is processed;

· account status;

· security requirements;

· dispute-resolution needs;

· legal obligations; and

· regulatory requirements.

Personal data will be retained in accordance with applicable legal and regulatory requirements.

Where personal data is no longer required for a legitimate legal or business purpose, Device2 will take reasonable steps to delete, anonymise or securely dispose of it.

DCS and other regulated service providers may be independently required to retain KYC, transaction or card-related records for periods required by applicable law and regulation.

Deletion of information held by Device2 does not necessarily result in deletion of information independently held by DCS or another service provider under its own legal obligations.


15. Account Deletion

UKA provides functionality allowing users to request deletion of their UKA account.

A deletion request may be initiated through the relevant account settings within the UKA application.

You may also contact UKA customer support where assistance is required.

Account deletion will result in deletion or deactivation of applicable Device2 account information, subject to information that must be retained for:

· applicable legal obligations;

· regulatory requirements;

· fraud prevention;

· security;

· dispute resolution; or

· other legitimate legal purposes.

Deleting a UKA account may not automatically terminate or erase records associated with your separate card relationship with DCS.


16. Data Security

Device2 uses reasonable administrative, organisational and technical safeguards designed to protect personal data against:

· unauthorised access;

· unauthorised disclosure;

· misuse;

· alteration;

· loss;

· destruction; and

· other similar risks.

Security controls may include, where appropriate:

· access controls;

· authentication;

· system monitoring;

· restricted access to production environments;

· logging;

· network-security controls; and

· other technical safeguards.

However, no electronic transmission or storage system can be guaranteed to be completely secure.

Users are responsible for maintaining the security of their own devices, passwords, email accounts and authentication credentials.


17. Data Breaches

Where Device2 becomes aware of a personal-data incident affecting information under its control, Device2 will assess and respond to the incident in accordance with applicable law.

Where legally required, Device2 will notify relevant authorities and affected individuals.

Incidents involving systems independently operated by DCS or another service provider may also be handled by the relevant service provider under its own legal obligations.


18. Your Rights

Subject to applicable law, you may have rights relating to personal data held by Device2, including rights to:

· request access to certain personal data;

· request correction of inaccurate or incomplete personal data;

· withdraw consent where processing is based on consent;

· request information regarding the use or disclosure of personal data;

· manage available communication preferences; and

· request account deletion.

Certain requests may be subject to exceptions, limitations or verification requirements under applicable law.


19. Withdrawal of Consent

Where Device2 relies on your consent to collect, use or disclose personal data, you may withdraw that consent by providing reasonable notice.

Withdrawal of consent may affect our ability to continue providing certain UKA Services.

Withdrawal of consent does not affect processing that was lawfully carried out before the withdrawal.

Certain information may continue to be processed or retained where Device2 is permitted or required to do so by applicable law.


20. Children's Privacy

UKA is intended only for users who are at least 18 years old.

We do not knowingly permit individuals below the age of 18 to open UKA accounts or apply for UKA cards.

If we become aware that an account has been created in violation of this requirement, appropriate steps may be taken to restrict or close the account.


21. Third-Party Privacy Practices

UKA integrates with services operated by third parties.

Those third parties may independently determine how they collect, use, disclose and retain information under their own privacy policies and legal obligations.

This includes, where applicable:

· DCS;

· Sumsub;

· Apple;

· Google; and

· other service providers.

We encourage users to review the applicable privacy notices presented during relevant third-party processes.


22. Changes to This Privacy Policy

Device2 may update this Privacy Policy from time to time to reflect:

· changes to UKA functionality;

· changes to service providers;

· changes to data-processing practices;

· regulatory developments; or

· legal requirements.

The updated Privacy Policy will be made available through the UKA application or website.

The effective or last-updated date will be shown at the top of the Privacy Policy.

Where required by law, additional notice may be provided regarding material changes.


23. Contact Us

For questions regarding UKA or general customer-support matters:

Device2 Pte. Ltd.
UEN: 202511757D

Website:
www.uka.global

Customer Support:
service@uka.global


24. Data Protection and Privacy Contact

For questions, requests or complaints relating specifically to privacy or personal data, contact:

Data Protection / Privacy Contact
Device2 Pte. Ltd.

Email:
privacy@uka.global

Website:
www.uka.global