Security and responsibility boundaries

Control the workflow.
Keep custody where it belongs.

NextPayInc verifies service events and orchestrates payout instructions. It does not hold customer funds. This separation keeps the platform’s role explicit and lets the relevant licensed partner own money movement and its applicable controls.

No funds heldEvidence-backed decisionsExplicit payment states
Example verified session and payout flow
CONTROL · VERIFIED EVENT verified flow
01
Session deliveredPolicy checks passed · schedule matched
complete
02
Both parties confirmOne-time QR · time, place and identity checked
verified
03
Payout instructedCommission rule applied · audit record created
sent
Provider amount
after verified delivery
AED 120.00

Responsibility model

Three parties.
Three distinct responsibilities.

Clear boundaries reduce assumptions. The exact allocation is documented for each pilot and partner integration; this overview describes the intended operating model.

01 · Gym operator

Defines the commercial and operational policy

The gym owns its member and trainer relationships, confirms authorized users, approves commission rules and reviews exceptions.

  • Source schedule and identities
  • Commission and exception policy
  • Employment, accounting and regulatory obligations
02 · NextPayInc

Verifies and orchestrates

The platform evaluates the configured event evidence, calculates the approved rule and creates a traceable payout instruction.

  • Verification decision and evidence
  • Commission calculation record
  • Idempotent payout orchestration
03 · Payment partner

Onboards recipients and moves funds

The selected licensed provider executes the transfer and applies the onboarding, screening and payment controls relevant to its service.

  • Payment-account onboarding
  • Execution and settlement
  • Partner-specific payment compliance

Verification controls

Trust the evidence,
not a single signal.

No contextual check is perfect in isolation. The verification policy evaluates the available signals together and records the result used to advance or hold the service event.

01

Signed, time-limited confirmation

The confirmation payload is designed to resist alteration and expire after the configured service window.

02

One-time use and replay detection

A confirmation is associated with one service event. Reuse or an invalid reference can be rejected and recorded.

03

Schedule and contextual checks

The expected participants, time, location and available device signals can contribute to the verification decision.

04

Operator exception review

A mismatch does not disappear. The evidence is retained for an authorized operator to review under the gym’s policy.

Auditability

A complete sequence
from service to settlement.

Operational trust depends on being able to reconstruct the decision, not only seeing the final number.

Event history

Actor, action and time

Each significant confirmation, decision, calculation and payout-status change is attached to the service event.

Calculation history

Rule version and result

The commission record preserves the inputs and effective rule used when the session became payable.

Payment history

Reference, attempt and state

The instruction and partner status remain distinct from the verification decision while sharing the same payable-event reference.

Data handling

Minimise what the workflow needs

A production pilot defines data fields, access roles, retention and integration boundaries before personal data is processed.

Security claims should be tested against the actual pilot architecture.

Partner licensing, certifications, encryption implementation, data hosting and contractual controls are confirmed during diligence. This page does not replace that review or legal advice.

UAE pilot partners

Review the controls before you review the demo.

We can walk your operations, finance and technical stakeholders through the responsibility model and pilot data flow.

Request a pilot