Privacy Policy

Effective Date: April 05, 2026

PURPOSE AND SCOPE

PAYRIZ is a Delaware C Corporation with its registered agent address at 8 The Green, Suite A, Dover, Delaware (DE) 19901, USA (referred to as “PAYRIZ”, “we”, or “us”). PAYRIZ operates its website and application (the “PAYRIZ App”).

We respect your privacy and are committed to processing and protecting your personal data in a lawful, fair, and transparent manner, in accordance with applicable laws, including the EU General Data Protection Regulation (GDPR) and other relevant data protection regulations.

This Privacy Policy outlines how and why we collect and process your personal data, including through our website and PAYRIZ App, and explains your rights regarding that data.

Our platform allows users to access payment and financial services provided by independent third-party providers. We do not store or retain your financial account details, as these are securely handled by third-party payment providers. These providers may collect and process your personal data independently, and we encourage you to review their privacy policies.


PRINCIPLES OF DATA PROCESSING

We are responsible for maintaining the security of your personal data and preventing unauthorized access.

We process personal data in line with the following principles:

  • Lawfulness, fairness, and transparency
  • Purpose limitation
  • Data minimisation
  • Accuracy
  • Storage limitation
  • Integrity and confidentiality

SOURCES OF PERSONAL DATA

3.1 Information You Provide
You provide personal data when creating an account or using our services.

3.2 Third-Party Sources
To improve and operate our services, we may receive data from trusted third-party partners who collect and process data lawfully.

3.3 Merchant VASPs
We may receive transaction-related data from third-party Merchant VASPs that support fiat transactions, including account details and transaction history.

3.4 API Integrations
With your consent, we may access financial data through third-party APIs, such as account balances, transaction history, or bank details, to enable certain features.

3.5 Public Databases
We may collect publicly available information, such as names, contact details, and regulatory or sanctions-related data, for compliance and fraud prevention purposes.

3.6 Identity Verification Providers
We work with identity verification partners who may provide personal data such as name, address, ID documents, photos, date of birth, and citizenship.

3.7 Financial Institutions
We may receive financial data from banks and financial institutions, including transaction history and account details, in line with legal requirements.

3.8 Google Single Sign-On (SSO)
If you use Google SSO, we may collect your email address to facilitate login. No additional data is accessed.

3.9 Blockchain Data
We may collect publicly available blockchain data, such as wallet addresses and transaction details, to monitor and prevent illegal activities.

3.10 Marketing and Analytics Partners
We may collect data from marketing and analytics partners to understand user behavior, improve our services, and optimise marketing performance. This may include interaction data, usage patterns, and campaign performance metrics.

PURPOSES, LEGAL BASIS, AND DATA RETENTION

Pre-contractual steps and account creation
We process your data to take steps at your request before entering into a contract, including account registration and acceptance of our Terms and Conditions.
Legal basis: Contractual necessity and applicable legal obligations, including AML regulations.
Retention: Up to 8 years, with a possible extension of up to 2 additional years if required by a competent authority.

Service delivery and contract performance
We use your data to provide and maintain our services, including app functionality, payment processing, and order execution.
Legal basis: Performance of a contract and applicable legal obligations.
Retention: Up to 8 years, with a possible 2-year extension if legally required.

Compliance with legal and regulatory obligations
We process personal data to comply with legal requirements, including AML, KYC, fraud prevention, and risk management obligations. These processes may be facilitated through our partners.
Legal basis: Legal obligations.
Retention: Up to 8 years after the end of the contractual relationship, extendable by up to 2 years upon request from authorities.

Identity verification
We process your data to verify your identity remotely as part of compliance procedures.
Legal basis: Legal obligations.
Retention: Up to 8 years after the end of the contractual relationship.

Fraud prevention and legal protection
We use your data to prevent misuse of our services, investigate suspicious activity, and establish or defend legal claims.
Legal basis: Contractual necessity, legitimate interest, and legal obligations.
Retention: Up to 8 years after the contractual relationship, with a possible 2-year extension.

Fraud prevention for rejected applications
If your onboarding is not approved, we may retain relevant data for future applications and fraud prevention.
Legal basis: Legal obligations.
Retention: Up to 5 years.

Internal business operations and analytics
We process data for internal purposes such as analytics, audits, market research, and improving our services.
Legal basis: Legitimate interest.
Retention: Data is anonymized where possible and retained only as long as necessary.

Product development and improvement
We use data to improve our services, develop new features, and enhance user experience.
Legal basis: Legitimate interest.
Retention: Data is anonymized and stored only as long as required.

Website and app optimization
We analyze usage trends and performance using cookies and similar technologies.
Legal basis: Legitimate interest.
Retention: Depends on the type of cookies used.

Marketing and communication
We may use your data for marketing, notifications, and customer support through various channels.
Legal basis: Consent and legitimate interest.
Retention: Until consent is withdrawn or no longer necessary.

DATA SHARED ABOUT OTHERS

If you provide personal data about other individuals (such as family members), or request us to share their data with third parties, you confirm that you have informed them about this Privacy Policy in advance.


IDENTIFICATION METHODS

We currently perform identity verification through physical processes. If we introduce remote verification methods, such as two-factor authentication or similar tools, we will notify you accordingly. Please note that identity verification is required to use our services.


DIRECT MARKETING

If you are an existing user, we may use your email address to send information about our services or similar offerings, unless you object.

In other cases, we will only use your personal data for marketing if you provide explicit consent. You may withdraw your consent at any time without any negative consequences.

We may also share offers from our partners or request your feedback, but only with your prior consent.

Every marketing email will include an option to unsubscribe, allowing you to easily opt out at any time.


AUTOMATED DECISION-MAKING

We do not use automated decision-making technologies.


HOW WE SHARE YOUR PERSONAL DATA

We may share your personal data with:

  • Public authorities or regulators when required by law
  • Service providers supporting our operations, such as legal, financial, hosting, analytics, and marketing partners
  • Third parties necessary to perform services you request
  • Parties involved in business transactions such as mergers or acquisitions
  • Other parties, only with your consent

All third-party providers are required to process your data securely and only as instructed.


INTERNATIONAL DATA TRANSFERS

If your data is transferred outside the European Economic Area (EEA), we ensure it is protected through appropriate safeguards, such as:

  • Transfers to countries approved by the European Commission
  • Standard contractual clauses
  • Approval from relevant authorities where required

DATA SECURITY

We implement appropriate technical and organizational measures to protect your personal data. While no system is completely secure, we use encryption, access controls, and security monitoring to reduce risks.

Our partners and service providers are also contractually required to maintain confidentiality and data protection standards.


YOUR RIGHTS

You have the right to:

  • Be informed about how your data is used
  • Access your personal data
  • Correct inaccurate or incomplete data
  • Request deletion of your data where applicable
  • Restrict or object to processing
  • Request data portability
  • Withdraw consent at any time
  • File a complaint with a relevant data protection authority

To exercise your rights, contact us at hello@payriz.app. We may request identity verification before processing your request.


COOKIES

We use cookies to improve your experience, including keeping you logged in and analyzing website usage.

Types of cookies we use:

  • Necessary cookies: required for basic website functionality
  • Functional cookies: remember your preferences (with consent)
  • Marketing cookies: used for advertising (with consent)

You can manage or disable cookies through your browser settings, but some features may not function properly without them.


THIRD-PARTY LINKS

Our website may contain links to third-party websites. We are not responsible for their content or privacy practices. We recommend reviewing their policies before using their services.


CHANGES TO THIS POLICY

We may update this Privacy Policy from time to time. Any significant changes will be communicated in advance.


CONTACT

For any questions or requests, contact us at:
hello@payriz.app