Legal

Privacy policy

This policy explains what personal data AxPay processes, why we process it, who we share it with, and the choices you have.

Last updated · Version 1.0

1. Who we are

AxPay is operated by [Company legal name], registered at [registered address], company number [number]. For the personal data described here we act as the data controller, unless we process data on behalf of a business customer, in which case that customer is the controller and we are a processor.

Questions about this policy can be sent to [privacy@axpay.com]. Where required, our data protection officer can be reached at the same address.

2. Data we collect

Account data

Your name, email address, phone number, organisation, role, and the credentials used to authenticate. Passwords are stored only as a salted hash.

Transaction data

Records of payments initiated, approved, or received through the service, including amounts, currencies, counterparties, timestamps, and reference information you supply.

Verification data

Where law requires us to verify identity, the documents and details needed for know-your-customer and anti-money-laundering checks.

Technical data

IP address, device and browser characteristics, approximate location derived from IP, sign-in timestamps, and security event logs. This data is what makes it possible to detect and stop account takeover.

Support data

The content of messages you send us and our replies, plus any attachments you choose to include.

3. Why we process it

  • To provide the service — authenticate you, execute and settle payments, and maintain your account.
  • To keep accounts secure — detect fraud, prevent abuse, rate-limit sign-in attempts, and alert you to unusual activity.
  • To meet legal duties — sanctions screening, anti-money-laundering obligations, tax and accounting records.
  • To support you — answer questions and investigate problems you report.
  • To improve the product — understand which features are used, using aggregated data wherever it is sufficient.

4. Legal bases

Where the GDPR or UK GDPR applies, we rely on: performance of a contract with you; compliance with a legal obligation; our legitimate interests in securing and improving the service, balanced against your rights; and your consent, where we ask for it. You may withdraw consent at any time without affecting processing that already took place.

5. Sharing your data

We share personal data only as described here, and we do not sell it:

  • Payment partners — banks, card networks, and payment processors needed to move funds.
  • Service providers — hosting, monitoring, email delivery, and fraud-prevention vendors, bound by contract to process data only on our instructions.
  • Your organisation — if your account belongs to a business, its administrators can see account and activity data.
  • Authorities — where we are legally required to disclose, or to establish and defend legal claims.
  • Corporate transactions — a successor entity in a merger or acquisition, subject to this policy.

6. International transfers

Data may be processed outside your country. Where we transfer personal data out of the European Economic Area or the United Kingdom, we use an adequacy decision or the appropriate standard contractual clauses, together with additional safeguards where needed.

7. How long we keep it

Account data is retained while your account is active. After closure we keep what financial-services and tax law requires us to keep — typically [retention period, e.g. five to seven years] for transaction and verification records — and then delete or irreversibly anonymise it. Security logs are kept on a shorter cycle of [log retention period].

8. Security

We encrypt data in transit and at rest, restrict internal access on a least-privilege basis, log administrative actions, and support multi-factor authentication on every account. No system is perfectly secure, so we also plan for incidents and will notify you and any relevant regulator where the law requires it. Our security page describes these controls in more detail.

9. Your rights

Depending on where you live, you may have the right to:

  • access the personal data we hold about you and receive a copy;
  • correct data that is inaccurate or incomplete;
  • delete data, where no legal obligation requires us to keep it;
  • restrict or object to certain processing, including profiling;
  • receive your data in a portable, machine-readable format;
  • withdraw consent you previously gave;
  • complain to your local data protection authority.

To exercise a right, contact us at [privacy@axpay.com]. We respond within one month and may need to verify your identity first — which is itself a protection against someone else requesting your data.

10. Cookies and similar technologies

We use strictly necessary cookies to keep you signed in, remember a trusted device, and protect against cross-site request forgery. These cannot be switched off without breaking sign-in. Any analytics or preference cookies are set only where you have agreed, and you can change that choice at any time.

11. Children

The service is not directed at children and we do not knowingly collect data from anyone under [age threshold]. If you believe a child has provided us with personal data, contact us and we will delete it.

12. Changes to this policy

We may update this policy as the product and the law change. Material changes will be announced by email or an in-product notice before they take effect, and the version and date at the top of this page will be updated.

13. Contact

Write to [privacy@axpay.com] or [registered address]. For account and sign-in questions, our support page is faster.