Skip to content

Privacy Notice

Last updated on 26-06-2026

At Paymentology, we value your privacy and aim to be transparent about the Personal Data we Process when you interact with us. This Privacy Notice explains how we Process and protect Personal Data when you visit our website, contact us, use our services, act as a client, prospect, supplier, business partner, office or event visitor, or where we Process Personal Data in connection with services provided to our clients. Recruitment, candidate, employee, independent contractor and other staff members Personal Data is addressed in separate privacy notices and is referenced here only where necessary.

As a global company, we are committed to managing and Processing Personal Data in compliance with applicable privacy and data protection laws relevant to the Paymentology entity involved and the Processing activity.

This Privacy Notice describes:

1. Who's Your Data Controller

2. Why We Collect and Process Personal Data

3. Personal Data We Process

4. Lawful Processing of Personal Data

5. Consequences of Your Refusal to Provide Personal Data

6. Persons who will Access Your Personal Data

7. Disclosures of Your Personal Data and Transfers to Third-Party Countries

8. Protection and Retention of Your Personal Data

9. Marketing Activities

10. Receipt of Your Information from a Third-Party

11. Laws Authorising or Requiring the Collection of Personal Data

12. Automated Decision Making

13. Your Rights

14. Data Protection Officer

15. Personal Data Regulators

16. Changes to this Privacy Notice

17. Third-party Website Links

18. Definitions

19. Enquiries, Requests, Complaints and/ or Concerns

20. Regional and Local Law Information

 

1. Who Controls Your Personal Data

Paymentology is the Data Controller for Personal Data Processed in connection with this Privacy Notice unless we explain otherwise. The responsible Paymentology entity may depend on your location, the services involved, your relationship with us and the entity that determines the relevant purposes and means of Processing.

When we provide services to clients, we usually act as Data Processor. This means we Process Personal Data on behalf of our clients and under their documented instructions. In those cases, our client is typically the Data Controller because it determines the main purposes and means of Processing. Where needed, we document our role through contracts, Data Processing Agreements or other privacy terms.

 

2. Why We Collect and Process Personal Data

In operating our business and providing services as a global card payments technology provider, we collect and Process Personal Data for several reasons. We mainly do this to provide services enabling our clients to issue payment cards and process card transactions, manage supplier and service provider relationships, manage business stakeholders, operate and secure our corporate environment, and meet legal, regulatory, security and risk-management obligations. Recruitment, candidate, employee, worker and contractor Processing is covered by separate notices and is referenced here only where necessary.

  • Provide our services to clients and partners enabling the issue of payment cards, card payment processing, card programme support, platform operation, security, risk, reporting, client support and service-management activities.
  • Manage our client, prospect, partner, vendor and supplier relationships, including onboarding, due diligence, contracting, account management, support, billing, procurement, audit and relationship governance.
  • Check that clients, vendors, partners and relevant individuals associated with them are eligible for our services, assess identity, perform business onboarding and due diligence, and carry out sanctions, financial crime, UBO, director, representative, fraud and risk checks where required or justified by law, contract, regulatory expectation, industry standards, financial partner requirements or legitimate business risk management.
  • Manage B2B sales, marketing, events, campaigns, lead generation, business-contact verification, CRM, email campaign analytics, opt-out and suppression lists, including limited use of sales-intelligence providers as described in this Privacy Notice.
  • Operate, administer, secure, monitor, test and improve our systems, networks, website, products, applications and corporate IT environment. Where permitted by applicable law, we may also use Personal Data, aggregated data and/or anonymised information to analyse, maintain, develop and improve our website, services, products, support operations, security controls and related research and development activities. Where we act as Data Processor for client services, any product-improvement or research activity involving Personal Data will be carried out only where contractually permitted, on documented instructions, using appropriately minimised data, or on anonymised information, as applicable.
  • Recruitment, candidate, employee, worker and independent contractor Processing is covered by separate privacy notices. Candidates should refer to the Recruitment Privacy Notice; employees, workers, independent contractors and other members of staff should refer to the applicable employee privacy notice.
  • Detect, monitor and prevent fraud, unauthorised payment transactions, security incidents, data loss, misuse of systems, vulnerabilities and other risks to Paymentology, its clients, cardholders, partners and services.
  • Report to, cooperate with and respond to requests from relevant authorities, regulators, professional bodies, supervisory authorities, statutory bodies, law enforcement, payment associations, auditors, insurers and courts where required or justified.

3. Personal Data We Process

The Personal Data we collect and/or Process may differ depending on the purpose for collecting and Processing it. The examples below are not exhaustive and are grouped at a higher level to keep this Privacy Notice clear. Specific fields and checks will depend on the relevant relationship, jurisdiction, role allocation, client instructions, applicable legal or regulatory requirements and the context in which the information is provided.

We may collect and/or Process Personal Data that you provide directly to us, that is provided to us by our clients or partners, that we receive from third parties, or that is generated automatically through our website, systems, products, support channels, security tools, cookies and similar technologies. We apply data minimisation and seek to Process only Personal Data that is adequate, relevant and necessary for the relevant purpose.

This table explains the main types of Personal Data we may Process, who the data relates to, where it may come from and why we may use it. The categories are not collected in every case and will depend on the relevant relationship, jurisdiction, role allocation, service model, legal or regulatory requirement, client instructions, contractual necessity or legitimate business risk management.

Data subjects

Data categories

Sources

Main purposes

Website visitors and online users

Device and browser data, IP address, cookie IDs, usage data, pages viewed, links clicked, referral URLs, approximate location, marketing preferences, form submissions and communications, contact data.

Directly from you; automatically from your device/ browser; cookies and similar technologies, as described in our Cookie Policy; analytics and advertising partners where permitted.

Website operation, analytics, security, preference management, marketing, lead generation, responding to enquiries.

Business prospects, leads, client contacts and partner contacts

Name, business email, business phone, company, role/ title, seniority, department, workplace, business location, professional profile URL, CRM history, event participation, marketing preferences, opt-outs, engagement metrics and source/ provenance metadata.

Directly from you; business communications; events; website forms; CRM; public/professional sources; business directories; social/professional networks; sales-intelligence providers.

B2B relationship management, lead generation, sales outreach, campaign management, enrichment, verification, database quality, suppression/ rights management and service communications.

Clients, vendors, partners, directors, representatives, ultimate beneficial owners (UBOs) and other relevant business relationship parties

Business identification, relationship and due diligence data, such as contact details, role or authority, corporate registration and ownership/ control information, UBO, director and representative details, identity or verification information, and, where required by law, regulation, financial partner requirements, client instructions or the relevant onboarding model, date of birth, nationality and location where required, relevant documents, screening and risk indicators, compliance status, audit trail and relationship records.

Directly from you or your organisation; clients, vendors and partners; public and corporate registers; official records; screening, compliance, fraud and risk providers; financial partners; public or professional sources; internal records.

Business onboarding and relationship due diligence, financial crime and sanctions compliance, fraud and risk controls, supplier and client risk management, audit and regulatory compliance, and ongoing relationship governance.

Cardholders and client end users

Card or account identifiers, tokenised identifiers, primary account number (PAN) where applicable, expiry date, transaction amount/date/time/currency, merchant data, authorisation response, authentication and security data, device and fraud signals, chargeback/dispute data, support data, onboarding or verification data where instructed by clients, audit logs and operational metadata.

Clients, issuers, programme managers, cardholders, payment schemes, processors, fraud/ risk providers, support channels and system-generated data.

Usually processed on client instructions for payment and platform services, including cardholder onboarding or verification where applicable, transaction processing, authorisation, fraud controls, disputes, settlement, reporting, support and regulatory or network compliance.

Recruitment, candidate, employee, worker and contractor records

Handled under separate recruitment and employee privacy notices.

See the applicable separate notice.

Recruitment and workforce administration are outside the main scope of this Privacy Notice unless expressly stated.

Client support contacts and other business correspondents

Name, contact details, employer, role, ticket content, emails, chat messages, call/ meeting notes, attachments, issue metadata, screenshots, system logs and escalation history.

Directly from you; clients; support tools; product systems; internal teams.

Support, troubleshooting, incident management, client service, quality assurance, audit and legal defence.

Visitors to offices/ events

Registration data, business contact details, access requirements, attendance records, CCTV or access logs where used, dietary/ accessibility information where necessary.

Directly from you; event forms/ platforms; building/ security systems.

Event administration, physical security, health and safety, access control and relationship management.



Sensitive and special-category Personal Data: we generally do not collect and/or Process sensitive or special-category Personal Data when providing our services, unless this is required or justified for a specific lawful purpose and appropriate safeguards apply. This may include accessibility requests, sanctions or background screening where lawful, biometric authentication where specifically approved, health and safety, legal claims, compliance obligations or client-directed Processing. Recruitment and employee special-category data is addressed in the applicable separate privacy notice.

Children: Paymentology services are generally business and payment infrastructure services and are not directed at children. We may Process children's Personal Data only where necessary for a client-directed card programme, legal compliance, or another specific lawful purpose with appropriate safeguards. Employment-related dependant or emergency contact Processing is addressed in the applicable employee privacy notice.

 

4. Lawful Processing of Personal Data

We only Process Personal Data where we have a lawful basis or legal ground to do so. Depending on the Processing activity and jurisdiction, this may include Processing necessary to take steps before entering into a contract or to perform a contract, Processing required to comply with a legal obligation, Processing necessary for our or a third party's legitimate interests, Processing based on your consent, the establishment, exercise or defence of legal claims, or another basis available under local law. The lawful basis for a particular activity depends on the relevant Paymentology entity, jurisdiction, relationship, processing purpose and whether Paymentology acts as Data Controller or Data Processor. Employment-law grounds are addressed in the applicable employee privacy notice. In exceptional circumstances, we may also Process Personal Data where necessary to protect someone's vital interests, such as in an emergency.

Where allowed under relevant national laws, we may Process Personal Data on the basis of legitimate interests. When we do so, we balance our legitimate interests against the interests and rights of the individuals whose Personal Data we Process and apply safeguards such as data minimisation, opt-outs, access controls, suppression lists, security controls, retention limits and human review where appropriate.

Where Paymentology acts as Data Processor, the client (as the Data Controller) is usually responsible for identifying the lawful basis for the underlying Processing. Paymentology Processes the Personal Data on documented instructions, subject to applicable law and contract terms.

Processing context

Applicable lawful bases / legal grounds

Payment and platform services

Client instructions; contract; legitimate interests; legal obligations; fraud prevention; network/ scheme obligations.

B2B marketing and sales outreach

Legitimate interests; consent where required by electronic marketing or local law; opt-out/ suppression rights.

Business onboarding, due diligence, screening and financial crime controls

Legal obligation, compliance with regulatory and financial-partner requirements, contract or pre-contractual steps; legitimate interests; contract; consent where required or appropriate under applicable law; client instructions where Paymentology acts as Data Processor; and additional conditions for sensitive or criminal-offence data where applicable.

Recruitment, candidate and employment records

Covered by separate privacy notices. Candidates should refer to the Recruitment Privacy Notice; employees, workers, contractors and other members of staff should refer to the applicable employee privacy notice.

Security, data loss prevention (DLP), monitoring and incident response

Legitimate interests; legal obligation; contract; security and fraud-prevention obligations.

Cookies, pixels and similar technologies

Strictly necessary cookies are used where required for website operation, security, integrity and storage of cookie preferences; functional, analytics and advertising/marketing cookies are used only where permitted by law and, where required, on the basis of consent.

 

 

5. Consequences of Your Refusal to Provide Personal Data

If you do not provide Personal Data that is necessary for a contractual, legal, regulatory, security or service purpose, we may be unable to provide or continue the relevant service, respond to your request, enter into or perform a contract, onboard you or your organisation, process payments, complete screening, provide support, comply with legal obligations or maintain access to our systems.

Where the Processing is optional, such as certain marketing communications or non-essential cookies, refusal or withdrawal should not prevent you from using unrelated services, although some features, personalisation, communications or analytics may be unavailable.

 

6. Who May Access Your Personal Data

Our personnel, group companies and third parties contracted by us as Data Processors or sub-processors may have access to Personal Data where they need it to administer and manage our services and stakeholder relationships. Access is limited to authorised persons and organisations with a legitimate need to access the Personal Data for the relevant purpose, and is subject to role-based permissions, confidentiality duties, security controls and contractual or legal restrictions.

This may include authorised Paymentology teams and group users involved in relevant business activities, as well as clients, issuers, programme managers, card networks, payment schemes, acquirers, banks, processors and other parties involved in payment execution, support, risk, disputes, settlement and compliance.

We may also give access to approved service providers that support our business and services. Depending on the context, these third parties may act as our Data Processors, Data Sub-processors or, in limited cases, independent Data Controllers. Where they act as Data Processors or Data Sub-processors, we use appropriate contractual controls and maintain Data Sub-processor information where required, including through the relevant client contract, Data Sub-processor notice or other applicable disclosure route. Where a third-party acts as an independent Data Controller, its own privacy notice and legal obligations may also apply.

 

7. Disclosures of Your Personal Data and Transfers to Third-Party Countries

We may disclose Personal Data to third parties where this is necessary or justified for the purposes described in this Privacy Notice. This may include disclosures to Paymentology group entities, clients, payment ecosystem participants, service providers, professional advisers, regulators, authorities, payment networks, banks, issuers, acquirers, programme managers, financial partners, fraud and compliance partners, auditors, insurers, transaction counterparties, prospective purchasers or investors, and other parties where permitted or required by law.

We may also disclose Personal Data where needed for corporate transactions, business transfers, restructuring, sale or purchase of assets, due diligence, or to enforce or apply our terms of use, contracts and other legal agreements.

Paymentology operates globally. Depending on the relationship, service model, support structure, vendor locations and legal requirements, Personal Data may be transferred, stored, accessed or otherwise Processed in countries other than the country in which it was originally collected. Where required by applicable law, we implement appropriate safeguards and rely on lawful transfer mechanisms to ensure that Personal Data remains protected.

Paymentology uses appropriate transfer mechanisms such as adequacy decisions, standard contractual clauses, UK international transfer mechanisms, intra-group transfer agreements, transfer risk assessments, supplementary technical and organisational measures, encryption, access controls, data minimisation and regional hosting or localisation controls where required.

Where Paymentology acts as Data Processor, international transfers are also governed by the relevant client contract, Data Processing Agreement, transfer schedule, sub-processing terms and documented client instructions.

Paymentology may disclose limited B2B professional contact data to sales intelligence providers where they act as independent Data Controllers for business contact verification, enrichment, database quality, suppression, rights-management and sales-intelligence ecosystem integrity purposes. This may include business contact details, role and company information, professional profile information, source or provenance information and opt-out or suppression status. You may object to this Processing, including B2B outreach or sales-intelligence enrichment, and may ask us to access, correct, delete, restrict or suppress your professional contact record, subject to applicable law. We may retain a minimal suppression record to respect your preferences. More information about relevant providers may be made available through our Trust Center or other applicable vendor disclosures.

 

8. Protection and Retention of Your Personal Data

Data security is extremely important to us. We take appropriate technical and organisational measures to protect Personal Data in our possession or under our control against accidental loss, damage, unauthorised access, misuse, alteration, disclosure or unlawful Processing. These measures may include role-based access controls, multi-factor authentication, encryption, tokenisation, pseudonymisation, confidentiality obligations, log-in records, network monitoring, vulnerability testing, data loss prevention (DLP), secure email transmission, endpoint protection, backups, supplier due diligence, incident response and staff training.

We limit access to Personal Data to employees, agents, contractors, service providers and other third parties who have a legitimate business need to know and who are subject to appropriate confidentiality, security, contractual or legal obligations.

We retain Personal Data only for as long as necessary for the purposes for which it was collected or otherwise Processed, unless a longer period is required or permitted by law, regulation, contract, payment-network rules, tax or audit obligations, legal hold, dispute, investigation, security requirements or client instructions. Retention periods or criteria may vary depending on the relevant data category, relationship, service model and applicable records-management schedule, and may be further described in contracts, supplementary notices or internal retention schedules where appropriate. When retention expires, we securely delete, return, archive, anonymise or de-identify Personal Data in accordance with applicable law, contract, client instructions and internal retention schedules.

We have procedures and incident management policies to deal with suspected Personal Data breaches and will notify affected individuals and applicable regulators where we are legally required to do so.

Where appropriate, we may create and use anonymised information for analytics, reporting, security, product improvement, research and development, and service-improvement purposes. Anonymised information does not identify you.

 

9. Marketing Activities

We may contact you periodically to provide information regarding our services, events, insights and content that may be of interest to you. Depending on the jurisdiction and communication channel, we may rely on consent, legitimate interests, an existing business relationship or another permitted legal basis. Where relevant national law requires that we receive your consent before sending certain types of marketing communications, we will only send those communications after receiving your consent.

We may use CRM, email campaign, sales intelligence and analytics tools to manage recipient lists, segment audiences, send business communications, measure delivery, open, click and engagement metrics where permitted, manage preferences and suppress contacts who opt out or object.

If you do not wish to receive further marketing communications from us, you can use the unsubscribe link in the marketing communication or contact privacy@paymentology.com. Withdrawal of consent does not affect the lawfulness of Processing based on consent before its withdrawal. We may retain a minimal suppression record to ensure your opt-out is respected.

 

10. When We Receive Personal Data from Third Parties

In some instances, we may receive Personal Data from third parties, including clients, issuers, programme managers, payment networks, vendors, screening providers, fraud and risk providers, public registers, corporate websites, professional networks, business directories, event partners, advertising platforms and sales-intelligence providers. Recruitment-related sources, such as recruiters, referees and candidate background screening providers, are addressed in the separate Recruitment Privacy Notice.

Where Personal Data has not been obtained directly from you and Paymentology acts as Data Controller, we will provide transparency information within the timeframe required by applicable law, unless an exemption applies, such as where you already have the information, providing it would involve disproportionate effort, disclosure is required by law, or confidentiality obligations apply.

 

11. Laws Authorising or Requiring the Collection of Personal Data

Under certain circumstances, we are authorised or required for legal reasons to collect, verify, retain, disclose or otherwise Process Personal Data. We will only collect and Process such Personal Data as required or justified by those legal reasons and will do so in compliance with relevant national laws regulating the Processing of Personal Data.

We use Personal Data to verify identity, perform business onboarding and due diligence, comply with fraud monitoring, prevention and detection obligations, meet anti-money laundering, counter-terrorist financing, Know Your Customer, Know Your Business, sanctions and other financial crime obligations, prevent unauthorised payment transactions, maintain audit trails, cooperate with regulators, authorities and payment associations, and comply with financial reporting, tax, security, corporate and contractual obligations. Employment law obligations are addressed in the applicable employee privacy notice. These obligations may be imposed by law, industry standards, payment-network rules, financial partners or contractual commitments and may require us to report compliance to third parties or submit to third-party verification audits.

 

12. Automated Decision Making

We may use automated systems, tools or models to support decisions, improve our services and help protect Paymentology, our clients and users. These tools may support activities such as payment processing, fraud and financial crime controls, business onboarding, security monitoring, support routing, marketing segmentation and service improvement.

Where Paymentology acts as Data Controller and uses solely automated decision-making that produces legal or similarly significant effects, we will provide the information and safeguards required by applicable law. This may include the right to request human intervention, express your point of view and contest the decision.

We do not intend to use AI or automated tools to make unrestricted decisions about individuals without appropriate governance. Where Personal Data is involved, AI-assisted outputs will be subject to appropriate controls, such as human review, access controls, logging, data minimisation and contractual safeguards.

 

13. Your Rights

You may have certain rights depending on your jurisdiction and the role in which Paymentology Processes your Personal Data. These may include rights to access, correct, delete or erase Personal Data, restrict or object to Processing, object to direct marketing, withdraw consent, receive a portable copy of your data, request review of certain automated decisions, and lodge a complaint with a regulator. Some laws may also give you rights to be notified of collection or of unauthorised access to your Personal Data.

Where Paymentology acts as Data Processor for a client/ Data Controller, a rights request relating to cardholder or end-user data should usually be directed to that client or Data Controller first, although Paymentology may assist in accordance with applicable contract, law or documented instructions. Where Paymentology acts as Data Controller, we will respond within the timeframe required by applicable law and may ask for specific information to verify your identity and ensure that you have the right to access the Personal Data or exercise the relevant right.

You can exercise your rights by contacting privacy@paymentology.com.

No fee is usually required to access your Personal Data or to exercise your other rights. However, where permitted by law, we may charge a reasonable fee or refuse to comply if a request is clearly unfounded, repetitive or excessive. We may also retain information where required or permitted by law, such as for legal claims, fraud prevention, regulatory compliance, security, audit or suppression purposes.

 

Data protection complaints

If you have concerns about how we handle your Personal Data, you can raise a data protection complaint with us at privacy@paymentology.com. We will review complaints received through this channel, may ask for information to confirm your identity or authority, investigate the matter, and provide an outcome without undue delay and within 30 days or such other time frame as required by applicable law. If you are not satisfied with our response, you may have the right to contact the data protection regulator or supervisory authority in your jurisdiction. For individuals in the UK, this is the UK Information Commissioner’s Office.
 

14. Data Protection Officer

Data Protection Officer: Pavel Zhelyazkov
Email address: privacy@paymentology.com

 

15. Personal Data Regulators

Should you believe that the Processing of your Personal Data contravenes applicable data protection law, you may lodge a complaint with the competent data protection regulator in your country, region, place of work, habitual residence or place of alleged infringement, depending on applicable law. We encourage you to contact us first at privacy@paymentology.com so we can try to address your concern.

  • United Kingdom: You may contact the Information Commissioner’s Office (ICO) using the ICO “Make a complaint” route on the ICO website.
  • South Africa: You may contact the Information Regulator (South Africa). General enquiries can be sent to enquiries@inforegulator.org.za and POPIA complaints to POPIAComplaints@inforegulator.org.za.
  • Norway: You may contact the Norwegian Data Protection Authority / Datatilsynet. Complaints should be submitted in writing through Datatilsynet’s complaints route.
  • Latvia: You may contact the Data State Inspectorate / Datu valsts inspekcija at pasts@dvi.gov.lv.
  • United Arab Emirates: You may contact the competent UAE federal or financial free-zone data protection authority, depending on the applicable entity, sector and location. This may include the UAE Data Office, DIFC Commissioner of Data Protection or ADGM Office of Data Protection, where applicable.
  • EU/EEA, LATAM and APAC: You may contact the competent national, regional or local data protection authority, consumer/privacy regulator or supervisory authority in the relevant country, including the authority where you live, work or where the alleged infringement occurred. Please use the relevant regulator’s official complaint or contact route.
  • Nepal: You may contact the competent national, sectoral or other authority responsible for privacy or data protection matters in Nepal, where applicable, using the relevant local or sectoral complaint route applicable to the processing activity.

 

16. Changes to this Privacy Notice

We will review this Privacy Notice and may amend or supplement it from time to time following regulatory changes, business strategies, new technology introduced into our operations, changes in products or systems, vendors, international transfers, data uses or regulator guidance. We will publish an updated version on our website when amendments or supplements are made.

 

17. Third-party Website Links

Our websites, emails, portals and documents may include links to third-party websites, plug-ins, integrations or applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control third-party websites and are not responsible for their privacy statements or practices unless we specifically control the relevant Processing. When you leave our website, you are encouraged to read the privacy notice of every website you visit.

Please also refer to our Cookie Policy, which explains the use of cookies on our website.

 

18. Definitions

Term

Meaning

Data Controller

A person or organisation that determines why and how Personal Data is Processed.

Data Processor

A person or organisation that Processes Personal Data on behalf of a Data Controller and according to instructions.

Data Subject

An identified or identifiable natural person to whom Personal Data relates; where a local law also protects juristic persons or similar entities, equivalent rights may apply to those entities under that local law.

Data Sub-Processor

A person or organisation engaged by a Data Processor to Process Personal Data on the Data Processor's behalf in accordance with documented instructions and applicable contractual obligations.

Personal Data

Any information relating to an identified or identifiable natural person, including identifiers, contact details, online identifiers, transaction data, location data, professional information and inferences.

Processing / Process

Any operation performed on Personal Data, including collection, recording, organisation, structuring, storage, adaptation, retrieval, consultation, use, disclosure, transfer, restriction, erasure or destruction.

Sensitive / special-category Personal Data

Data subject to enhanced protection under applicable law, such as health data, biometric data used for identification, criminal-offence data, racial or ethnic origin, political opinions, religious beliefs, trade-union membership, sexual orientation or similar sensitive categories under local law.

Paymentology (“we”, “our”, or “us”)

Depending on the context, means any one of Paymentology Ltd. (registered in the United Kingdom), Paymentology FZCO (registered in the United Arab Emirates), Paymentology (Pty) Ltd (registered in South Africa), Paymentology Latvia SIA (registered in Latvia), MeaWallet AS (registered in Norway), Paymentology Holdings Limited (registered in Mauritius), Paymentology KSA (registered in Saudi Arabia), Flexpay (Pty) Ltd (registered in South Africa), Paymentology Nepal Private Limited (registered in Nepal) being Paymentology group entities that may be involved in the relevant Processing.

 

 

19. Enquiries, Requests, Complaints and Concerns

To address any enquiries, requests, complaints and/or concerns regarding this Privacy Notice, the Processing of your Personal Data, or to exercise the rights stated in this Privacy Notice, please contact privacy@paymentology.com.

Please include enough information for us to understand your request, verify your identity where required, identify the relevant Paymentology entity, product, client relationship or Processing activity, and respond within the applicable timeframe.

Where your request concerns Personal Data that we Process as Data Processor for a client, we may redirect you to the relevant client/Data Controller or coordinate with that client in accordance with the applicable Data Processing Agreement. Where your request concerns recruitment, candidate or employment/work records, we may handle it under the separate Recruitment Privacy Notice or applicable employee privacy notice.

 

20. Regional and Local Law Information

This section explains how local data protection laws may supplement this Privacy Notice. Where local law gives individuals additional rights or requires additional disclosures, Paymentology will apply those requirements where relevant to the Paymentology entity, Processing activity and jurisdiction involved.

  • Depending on your location, the Paymentology entity involved, and the nature of the Processing, additional rights, disclosures or requirements may apply under local data protection laws. In some jurisdictions, we may use locally recognised terms, such as Personal Information, where required by applicable law.
  • The availability and scope of rights may vary depending on the applicable law, the country or region, the relevant Paymentology entity, whether Paymentology acts as Data Controller or Data Processor, and the specific Processing activity involved. Certain rights may be subject to limitations, exemptions or conditions under applicable law.
  • Where required by applicable law, Paymentology will provide any additional disclosures, implement appropriate safeguards, and facilitate the exercise of applicable rights in accordance with the relevant legal requirements.