When you visit the Paysto website hosted by Paysto and its group companies around the world (“we” or “us”), correspond with us or become (or are in the process of becoming) one of our merchants or partners, we process personal data about you as a data controller. It is important to us that the personal data of the users of the app, the visitors to our websites, our (prospective) merchants and our (future) partners (“you”) is treated with care and that you are well informed about the way we process your personal data. We have written this privacy statement to tell you which data we process, how, why and how long we do this and your rights.
Which types of personal data do we collect and why?
Data we collect when you use this app, our website and about how you use this app or our website
When you browse this app, our website, we process your IP address, Google Analytics ID, internet browser and device type, location data and your use of the app and our website, including which pages you visited, how you got to our website, the time and length of your visit and your language preferences. We use this data for our legitimate interests of making sure our website works properly, including debugging, to be able to deliver you content and for DDOS mitigation on our website, and improving our website and to perform statistical analyses for optimizing our website. We also use this information to provide you with personal offers tailored to your needs and tailoring what we show you to your preferences, with your prior consent.
When we collect information about how you use of this app or our website, for example which landing pages you visit and which items you look at and how long, to make a determination about what we could likely do for you. For example, if you read about our products and services on our website, we might classify you as user or a website visitor who is interested in our products and services and therefore as a potential merchant. Based on the audience we expect you belong to, we may act, for example by contacting you with offers about our products and services, if we have your consent for this.
In order to make the most accurate assessment about which audience you likely belong to, and as you can also read in our Cookies Policy, we also use tracking cookies. These cookies track information about how you use our website and which other websites you visit, for example to show you advertisements if our products and services we suspect you might be interested in. We only place these tracking/targeting cookies with your prior consent. For more information about these tracking cookies, please view our Cookies Policy.
Data we collect when you contact us or request us to contact you
Via our website, you can contact us or ask us to contact you regarding questions, queries, (support) requests, comments or complaints, fill out an application to become a merchant or a partner or sign up for a test account. When you do this, we collect the information that you fill out, including your name, company, contact details, the reason you are contacting us, verification that you are not a robot and other information you decide to provide us. You can also contact us by calling us or e-mailing us using for example the contact details listed on our website. If you do so, we will collect your name, company and any other information we need to be of further assistance to you and/or communicate with you.
We use this data above to answer your question, comment or complaint and respond to your queries and (support) requests and to assess your application to become a merchant or partner. As such, this data is used by us to establish or perform our (future) contract with you and for our legitimate interests in following up with you. We also use the data above for our legitimate interest of conducting business with you and managing our internal administration, for establishing and performing our contract with you, for our legitimate interest of conducting marketing research so we can improve our products and services and to be able to offer our (future) merchants tailored products and services.
Data we process for our newsletter and marketing purposes
You can sign up for our newsletter or receive invitations to events using your name and e-mail address via this app or the sign-up form on our website. When you fill out this form, you indicate your consent to receive our newsletter and invitations. You can at any time unsubscribe from receiving these e-mails by following the instructions provided in any of the newsletters.
If you already are one of our merchants, we may contact you in relation to relevant products or services, for our legitimate interest of developing our business. We can do this via e-mail or, if your e-mail is registered on LinkedIn, we connect to you on LinkedIn and/or to send you messages on LinkedIn. If you are not yet one of our merchants, we will only contact you, for example via e-mail or LinkedIn, with offers or about our products or services if you have given us your permission to do so. When we contact you in this context via e-mail, you always have an opportunity to opt out at any moment by following the instructions in the e-mail or by contacting us using the contact details below under (“Contacting us”).
You can also download content, for example white papers and research reports, from our website using the forms designed for this purpose. We collect the data you fill out on the form, including your name, company, country and e-mail address. We process the data you fill out on this form for our legitimate interest of keeping track of who downloads our content.
Data we process when you sign up to become a merchant
If you sign up to become one of our merchants, we collect information we need to establish and perform a contract with you, including your contact information, address and, order details, tax information and payment details. We use this information to set up our products and services for you, including to provide you with support, boarding, integration, installation, helping you with settings, POS terminal field services, installation of POS terminals in stores and to pick up old/damaged POS terminals, and other actions which need to be taken to establish or perform our contract with you. In addition, we use your information for our legitimate interest of managing our internal administration and for complying with our legal obligations, such as taxation obligations.
We also collect data about your use of our products and services and your customer area account, including your login details, and the questions, queries, comments and complaints you send us in relation to our business relationship. We process this data to be able to perform our contract with you by following up with you and providing you with support and for our legitimate interest of being able to optimize and improve our products and services, including our customer area.
We can also use your (company) e-mail address for keeping you up to date on our products and services and to make you offers tailored to your needs (meaning of similar products and services you have already purchased from us).
We have an obligation to act in compliance with national and international laws, regulations and sanctions and to prevent laundering proceeds of crime or financing terrorism. As we are active in the financial sector, we are not allowed to accept just any merchant without checking them and we have to determine and report when suspicious transactions take place. Therefore, if you are applying to become one of our merchants, we will often need to collect information and documents to:
- verify your identity;
- identify the ultimate beneficial owners of your business;
- identify the purpose and intended nature of your future business relationship with us;
- monitor your transactions using automated systems which detect risks and verify the origins of your capital/assets;
- check whether a natural person representing you is competent to do so (and verify the identity of this person); and
- check whether you act on behalf of yourself or on behalf of a third party.
To carry out the above checks, we process a copy of your identification document, the address of your legal representative and shareholders, your bank account number, your contact information, information contained in correspondence between us, bank statements, your signature and an extract of your company registration document. We use this data to ensure the safety and integrity of the financial sector by aiming to identify, prevent and counter illegal conduct and to comply with our legal know-your-customer and anti-money laundering obligations, for example under the Russia Money Laundering and Terrorist Financing Prevention Act (115-FZ).
If necessary, we can also process any of your information above for our legitimate interest of protecting our legal rights, for example in connection with legal claims, and when we have a legal obligation to process your information. We may also transfer your data in the event of a company reorganization, merger, or sale.
How long do we keep your information?
We will always only keep your data for as long as we reasonably need it for the purposes listed above.
For example, data about your use of this app or visits to our website will be retained until your use or browsing session ends, except where it concerns data collected for the analytical and marketing purposes specified above. In those cases, we will keep your information for 1 year after collection.
If you become one of our merchants, we will keep all data relating to our business relationship until 7 years after the end of your contract with us or until our rejection your application. Data we have collected in relation to our legal obligation to verify our merchants will be kept by us for as long as we are legally obligated to, which is generally at least 7 years after end of relationship.
We store the information that we process as a result of you describing to our newsletters or because you have consented to receive information about our products and services or about offers until you decide you would no longer like to receive these mailings.
Data about any questions, comments or (supports) requests you have made us if you are not a merchant, will be kept for 2 years.
The retention terms above can be longer if we are required to keep data longer on the basis of applicable law or to administer our business. If we need to keep any information longer for our legitimate interest of protecting our legal rights, we will keep the necessary information for this purpose until the relevant claim(s) has/have been settled.
Social media buttons
We use plugins on our website from social media networks such as VK, Facebook, LinkedIn and Twitter. You can recognize these plugins by their logos. We also use plugins for the embedded video players which can be found on our website. Our plugins will not collect personal data about you, unless you click on these logos or videos. If you click on them, these plugins are activated and automatically transmit data to the plugin provider.
We do not have any influence over which data these providers collect from you and we are also not aware of the extent of their data processing. If you would like more information about their data processing, this can be found in the respective privacy policies on the websites of these providers.
With whom do we share this information?
We need the help of third parties to be able to offer you our website and our products and services. Where necessary we will share your information with our service providers and professional advisers (e.g. IT providers, CRM providers, marketing support providers (such as agencies which manage our social media accounts), social media providers such as LinkedIn, analysts, customer service providers, business development providers and legal service providers). We have concluded agreements with our service providers to protect your personal data.
If our business is sold or integrated with another business, your details will be disclosed to our advisers and any prospective purchaser’s adviser and will be passed to the new owners of the business.
Otherwise we will not share your information with any third party, unless we have your permission (for example if we wish to share your details with another group company for their recruitment purposes), where this is necessary in connection with the purposes above or with legal claims or when we have a legal obligation to do so.
How do we protect your data?
We are committed securing your personal data and have taken steps in this regard. In order to prevent unauthorized people or parties from being able to access your data, we have put in place a range of technical and organizational measures to safeguard and secure the information we process from you.
Where do we transfer this information?
Some of the information you send us may be shared with other Paysto group companies outside of the European Economic Area (“EEA”), when this is necessary for the purposes mentioned above. These countries include the countries in which we have operations. It also includes the countries in which some of our service providers are located, such as the United States.
To protect your data when these are transferred to countries outside of the EEA, we have implemented appropriate safeguards. When we transfer data to our Paysto group companies, these transfers are protected by an intragroup agreement containing Standard Contractual Clauses. For United States services providers, we rely on their Privacy Shield certification to protect your data. For other service providers located outside of the EEA, we also rely on Standard Contractual Clauses. If you want to receive more information about these safeguards, you can contact us using the details below under (“Contacting us”).
You are entitled to object to us processing your personal data, including profiling. You may also ask us for an overview of your information or ask for a copy. You may also request us to correct or delete certain data, restrict processing of your data, or ask us to transfer some of this information to other organisations. In some cases you may object to the processing of your data and, where we have asked for your consent to process personal data, you can withdraw this consent at any time. Where we process your data for our legitimate interests, you can contact us if you want more information about these.
There are some exceptions to these rights, however. For example, it will not be possible for us to delete your data if we are required by law to keep it or if we hold it in connection with a contract with you. Similarly, access to your data may be refused if making the information available would reveal personal information about another person or if we are legally prevented from disclosing such information.
If you wish to exercise any of these rights, please contact us using the details below.
Contacting us, questions and complaints
Questions, comments, requests or complaints concerning this privacy notice and the way we process your personal data are welcomed and can be addressed to our compliance department at email@example.com or Moscow, Bagrationovsky proezd, 7k20B.
If you have a complaint about the way we handle your personal data, you also have the right to address this with the data protection authority of the country in which you live or work or the country in which we are located.