Privacy Policy
What are the purposes of this Privacy Notice
This privacy notice explains, amongst other, what information/data we collect about you, how we use it and what are your rights and choices in relation to the personal information we hold about you under the national data protection law and Regulation (EU) 2016/679 on the Protection of Natural Persons with Regard to the Processing of Personal Data and on the Free Movement of Such Data [General Data Protection Regulation (“GDPR”)].
This policy is applying to the Data Subjects who are accessing or applying to use the services payabl. offers or may offer in the future, either on their own account or on behalf of a business, potential personnel, suppliers or other person that may interact with payabl.
Who we are
PAYABL. CY LIMITED (hereinafter referred to as “the company” “us”, “we”, “payabl.”) is a limited liability company duly registered under the laws of the Republic of Cyprus, with registration number HE 289380 having its registered address at Olympion 23, Libra Tower, 5h Floor, 3035, Limassol, Cyprus.
The Company is authorised by the Central Bank of Cyprus (“CBC”) under licence number 115.1.2.9/2018, to provide payment services in accordance with the provisions of the Provision and Use of Payment Services and Access to Payment Systems Laws of 2018, as amended (the “PI Law”).
payabl. is committed to protect your privacy and confidentiality by complying with the national Data protection regulations and protect its Data Subject’s (referred to as “Data Subject”, “You”, “Your”, “Yours”) by keeping their personal data secure against theft damage or any misuse either knowingly or unknowingly.
Here at payabl., we respect your privacy and how your personal data is used, that’s why we encourage you to read this policy carefully.
We have appointed a Data Protection Officer and the contact details are as follows for contact purposes: Libra Tower, Olympion 23-5th Floor, Limassol 3035, phone 25332590 and email address: dataprotection@payabl.com
What Personal data we collect about you
Depending on the way you interact with payabl. we collect your personal data when:
- You fill in our forms and applications;
- Communicate with us;
- Respond or complete any of our surveys;
- Use any of our services & products;
- Connect with any member of our team;
- Apply for a job position;
- Visit our premises;
- Participate in any event we organise;
- Contact us for any reason.
The information we collect are the following:
Information that you provide us directly: | |
---|---|
Personal identification data |
|
Contact details |
|
Identification documents |
|
Financial data |
|
Information collected from the use of our products, services and our website by You: | |
---|---|
Transaction data |
|
Technical data |
|
Usage Data |
|
Marketing data |
|
Information we collect from other sources: | |
---|---|
Information from Others | we collect personal data from third parties, such as credit reference agencies, fraud prevention agencies, sanctions and transaction risk information obtained about our customer such as:
|
Information from social media |
|
Information from publicly available sources | information and contact details from publicly available sources such as:
|
Information from our CCTV | a Closed-Circuit Television (CCTV) is installed at the entrance of our offices which may record videos of you for security purposes and prevention of crime in our offices. |
Records of our discussions |
|
Marketing activities and events
You may also provide Us with your personal information at a marketing event or through marketing activities organized by the Company. This personal information may include: first and last name, company name, job title, work email address, work address, phone number and the content of your request.
If you attend an in-person or virtual event or agree to be recorded in a telephone or video meeting, we may record some or all of that event or meeting. For events, we may also document the event by taking photos or interviewing you at the event. We use this information for business and marketing purposes and training purposes based on your consent.
Data we collect from potential candidates.
You may provide us with your personal data by filing forms online, corresponding with us by phone, email, through social media, in person, through a recruitment agency or otherwise when you apply for a job position at payabl..
The data we may collect in this case may include but its not limited to the following:
Personal identification data, contact details, education history, training and professional experience, current and previous employment history, information required to prepare your employment agreement with us including a clear criminal record certificate and reference letters, interview notes, information about your health such as any disability you may have, and you need to disclose with us.
We will keep your personal information along with your CV for a period of one (1) year for any future job positions that you may be considered for at payabl..
Our Legal Basis for using your personal data
For the purposes of the General Data Protection Regulation, we must always have a legal basis for processing your personal data.
The legal basis may vary from one of the following:
- the performance of a contract with you: we will need certain personal information to perform our contract and provide our services to you;
- compliance with our legal & regulatory obligations: we are subject to a number of such obligations emanating from laws and statutory obligations (AML - Anti-Money Laundering laws, KYC obligations);
- legitimate interest: in some cases, we may collect and use your personal data because we have a legitimate interest to do so and its reasonable when balanced with your rights and freedoms (initiating legal claims or preparing our defence in litigation procedures, CCTV systems in order to prevent crime or fraud);
- Consent: when you have given us your prior written consent to collect and use your data.
With whom we may share your personal data
In order for us to perform and comply with our contractual and statutory obligations your personal data may be provided to various service providers and third parties only in cases we have a legal basis to do so. Such service providers and third parties enter into contractual agreements with payabl. in order to ensure confidentiality of your personal data and compliance with the General Data Protection Regulations and local laws and regulations.
Recipients of your personal data may be:
Type of Recipients | Why we share your personal data |
---|---|
Supervisory authorities, law enforcement agencies without your prior consent e.g. Central Bank of Cyprus, the European Central Bank, tax authorities, Cyprus Security Exchange Commission (CySec), criminal prosecution authorities, police and others. | To comply with our legal and regulatory obligations, including fighting money laundering, terrorism financing, and all related predicate offenses as long as a statutory obligation exists |
With agencies that we deal with in order to perform a background check such as: credit reference agencies, fraud prevention agencies, third party background screening providers, credit reference agencies, sanction screening providers, criminal conviction screening agencies, commercial and credit information agencies. | To comply with Anti-Money Laundering regulations and requirements and fraud prevention |
Our banking and financial service partners such as correspondent banks, payment networks such as Visa and MasterCard, card associations. | To help us provide our services to you. |
Analytic providers and search information providers. | To help us analyse how you use our service in order to enhance/upgrade our services. To learn more or opt out from our analytic service, please visit our Cookie Policy (give website) |
Technology service providers, partners that help us store information, file storage and cloud storage parties. | To help us ensure security, ensure resilience of services, store information and facilitate us provide the services. |
Marketing service providers, social media and advertising service providers | To assist us run our campaigns, events and activities. |
Professional Advisors, lawyers, financial consultants, internal and external auditors | To help us comply with our regulatory obligations and legal obligations. |
Acquiring partners and alternative payment providers | To provide you with the payment service you have requested. |
Automated decision making and profiling
Depending on the products and service you use, we may use automated decision-making means to make decisions about you. This means that we may use technology that can evaluate your personal circumstances and other factors to predict risks and outcomes. This is known as profiling. We do this to fulfil a contract with you, to provide you with the best service possible and to provide you with marketing material we might think you are interested in. You have the right not to be subject to a decision based solely on automated means. If you want to exercise this right, you can contact us at dataprotection@payabl.com.
International Data transfer
Your personal data may be transferred to countries outside EU/EEA or UK or to international organisations if such transfer has a legal basis. Such transfers may be necessary to provide you our services based on our contractual obligations, to comply with a legal obligation or where you have given us your prior consent. These countries may have different data protection regulations. We take all appropriate technical and organisational measures to ensure that we always comply with the General Data Protection Legislation when transferring your data outside EU/EEA.
We always ensure that such third countries have been approved by the European Commission as having adequate data protection levels or in any other case they are required to provide us appropriate safeguards that meet the European Data Protection Standards. We use approved EU Standard Contractual Clauses for transfers of your personal data to third countries outside EU/EEA.
How we protect your data
Any personal data we process will be treated with the utmost care and security. The systems and facilities in which personal data is processed are protected by secure network architectures (technical and organizational measures) that safeguard and secure the information we process. We have detailed security and data protection policies in place which our staff are required to follow when they handle your personal data. Our staff receives data protection and information security training annually.
While we take all appropriate measures to ensure the security of your personal data the transmission of information via the internet, including emails, is not completely secure. Although we will do our best to protect your personal data, we cannot guarantee the security of your data transmitted to our site; and any transmission is at your own risk. Once we have received your personal data, we will use strict procedures and security features to try to prevent any unauthorized access.
Where you have access to our portals via user authentication means (e.g. user credentials), you are responsible for keeping your user credentials secure and confidential.
How long we keep your data
The period for which we retain information about you will vary depending on the type of information and the purposes we use it for.
We will keep your personal data for as long as we have a business relationship with you. Once our business relationship ends, we will keep your personal data for 7 (seven) years, or any other period as may be required by applicable local laws.
We may process your personal data for a longer period based on other lawful reasons which allow us such us complaints handling, legal disputes, regulatory and taxation purposes as well as money laundering and fraud prevention reasons or other legal reasons.
Your rights
You have the following rights in terms of your personal data we process about you:
Right of Access
You can request a copy of personal data retained by payabl. and a confirmation whether we process your personal data.
Right of Rectification
This enables you to request a correction of any incorrect, inaccurate, or incomplete data we hold about you. In such cases we might need to verify the accuracy of data you provide to us, before we proceed to the update of our records.
Right to erasure – right to be forgotten
You can request from payabl. to delete your personal data where:
- there is no good reason for us to continue holding it,
- you gave us your consent to use your personal data and now you withdrawn that consent,
- you have objected to the processing of your personal data,
- we have used your personal data unlawfully,
- the law requires us to delete your personal data.
Please note that we may not be able to agree to your request. As a regulated financial service provider, we may be obliged to keep your personal data even though you asked us to delete it. We’ll always let you know if we can’t delete your data.
Right to restrict processing
You have the right to request the restriction of processing of your Personal Data where the accuracy of the data is contested, when you consider the processing as unlawful but you do not wish the erasure of your data, when data are no longer needed for the purpose of processing but they are required by you for possible legal claims or when you have objected the processing pursuant to article 21(1) of GDPR. If you object to us using personal data which we need in order to provide our services, we may stop providing you that service.
Right to data portability
If you have provided personal data to payabl. under a contract or by giving your consent, then you have the right to instruct us to transmit that personal data to you or another data controller in a machine-readable format where technically feasible.
Withdraw of consent
If you give us the consent to process your personal data, you can withdraw it at any time. If such withdrawal affects the provision of service, we will inform you accordingly.
You can ask us to carry out a human review of an automated decision we make about you
If we make an automated decision about you that significantly affects you, you can ask us to carry out a manual review of this decision.
Opting out of receiving electronic or promotional communications
If you no longer want to receive marketing or promotional-related emails from us, you may opt-out via the unsubscribe link included in such emails or by contacting us directly. We will try to comply with your request(s) as soon as reasonably practicable.
How to exercise your rights
To exercise any of your rights set out in the previous section, you can contact us by sending us an email at dataprotection@payabl.com.
We may require proof of your identity before we can give effect to these rights. You should also be aware that some of these rights are not absolute; therefore, exemptions or limitations may apply. For example, we can refuse to provide information if fulfilling your request would reveal the personal information about another person, or if you request that we delete information which we are required to retain by law, have compelling legitimate interests to keep, or need access to fulfil our legal obligations.
Any request for access to your personal information must be in writing and we will endeavour to respond within a reasonable period and in any event within one month (three months for complex or numerous requests).
We reserve the right to charge a reasonable fee (reflecting the costs of providing the information) or to refuse to respond where requests are manifestly unfounded or excessive.
We will do our best to help but if you’re not satisfied with our response, you have the right to lodge a complaint with the supervisory authority, the Office of the Commissioner for Personal Data Protection, Kypranoros 15, Nicosia 1061, Cyprus, P.O. Box 23378, 1682 Nicosia, Cyprus, tel: +357 22818456, fax: +357 22304565, email: commissioner@dataprotection.gov.cy.
Children’s personal data
Our Services are general audience services and not directed at children under the age of 18 (eighteen). If we learn that any information, we collect has been provided by a child under the age of 18 (eighteen), we will promptly delete the information.
Cookies
When you visit our sites or use our services, we may place or read cookies on your device, subject always to obtaining your consent, where required and in accordance with applicable laws. We use cookies to provide you with a better user experience, record information about your device, browser and in some cases your preferences. To find out more about how we use cookies and similar technologies, please see our Cookies policy.
Links to other websites
Our sites may contain links to other websites, including via our social media buttons. While we try to link only to websites that share our high standards and respect for privacy, we are not responsible for the content, security, or privacy practices employed by other websites and a link does not constitute an endorsement of that website. Once you link to another website from our site you are subject to the terms and conditions of that website, including, but not limited to, its privacy policy and practices. Please check these policies before you submit any data to these websites.
Social media buttons
Social media buttons such as LinkedIn, Facebook, Instagram, X (Twitter), Spotify, and YouTube are used on our website and can be recognised by their logos. We also use buttons for the embedded videos on our website.
Our buttons will not collect personal data about you unless you click on these logos or videos. If you click on them, these buttons are activated and automatically transmit data to the button provider. We do not have any influence over which data these providers collect from you, and we are also not aware of the extent of their data processing. If you would like more information about their data processing, this can be found in the respective privacy policies on the websites of these providers.
Changes to this privacy statement
We may revise or update this privacy policy from time to time. In such case we will post the most recent privacy policy on our website (www.payabl.com). We do however encourage you to review this statement periodically by visiting our website, so you always stay informed about how we are processing and protecting your personal information.
Last Updated: 03/09/2024