1. Introduction
At ecoPayz, we are committed to protecting your privacy and ensuring the security of your personal data. This policy outlines how we collect, use, store, and share your personal information when you use our services. By using our services, you agree to the terms outlined in this policy.
2. Data We Collect
We may collect the following personal data:
- Personal Information: Name, contact details (email address, phone number), date of birth, identity verification documents, and government-issued identification.
- Transaction Information: Details of transactions made using our services, including the amounts, dates, and counterparties.
- Technical Information: IP addresses, browser types, geolocation data, and device details, including cookies and web beacons.
- Behavioural Data: Data about how you interact with our website and services, such as browsing behaviour, page views, and clicks.
- KYC Information: Data collected to comply with Anti-Money Laundering (AML) and Know Your Customer (KYC) regulations.
3. How We Use Your Data
Your data is used for the following purposes:
- Managing your account and providing services: To facilitate transactions, process payments, and deliver our services.
- Legal and regulatory compliance: To comply with AML/KYC requirements, fraud detection, and regulatory reporting.
- Marketing and personalised experiences: To send you relevant marketing communications and tailor our services to your preferences, where consent has been provided.
- Customer insights and analytics: To analyse customer usage patterns to improve service offerings and user experience.
- Fraud prevention and security: To monitor for suspicious activities and ensure the security of your data and our platform.
4. Legal Basis for Processing
We process your data based on the following legal grounds:
- Contractual necessity: To provide the services you have signed up for.
- Legal obligations: To comply with regulations and legal requirements, such as financial reporting and anti-fraud checks.
- Legitimate interests: To protect our business and users, improve our services, and conduct internal analysis.
- Consent: For marketing and analytics purposes where legally required.
5. Sharing Your Data
We may share your personal data with:
- Regulatory bodies and law enforcement: For compliance purposes, including fraud prevention and AML regulations.
- Service providers and partners: With payment processors, cloud service providers, and fraud prevention partners who are bound by contractual confidentiality agreements.
- International transfers: We transfer personal data outside of your country of residence, ensuring that appropriate safeguards are in place, such as EU standard contractual clauses.
6. Data Security
We implement advanced security measures to protect your data from unauthorised access, misuse, loss, or destruction. These include:
- Encryption (AES-256) of sensitive data both in transit and at rest.
- Secure data centres with limited access, firewalls, and intrusion detection systems.
- Multi-factor authentication and role-based access for authorised personnel.
7. International Data Transfers
Your personal data may be transferred to, stored in, or processed in countries outside of your country of residence. We ensure that adequate safeguards, such as standard contractual clauses or Binding Corporate Rules, are in place to protect your data in compliance with applicable data protection laws.
8. Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes outlined in this policy or as required by law. Following account closure, data may be retained for up to seven years for regulatory compliance and legal purposes.
9. Your Rights
You have the right to:
- Access: Request a copy of the personal data we hold about you.
- Correction: Correct inaccurate or incomplete personal data.
- Deletion: Request the deletion of your personal data under specific conditions.
- Restriction: Request that we limit how we process your data.
- Portability: Receive your personal data in a structured, machine-readable format.
- Withdraw Consent: Where processing is based on your consent, you may withdraw your consent at any time.
To exercise any of these rights, please contact us at destek@demoapps.dev.
10. Data Breach Notification
In the event of a data breach that compromises your personal data, we will notify you and the relevant authorities within the legally required timeframe and in accordance with applicable data protection laws.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Significant changes will be communicated via email or through a notice on our website. Please check this policy regularly for updates.
12. Governing Law and Jurisdiction
This Privacy Policy is governed by the laws of Georgia. Any disputes or claims arising from this policy will be subject to the exclusive jurisdiction of the Georgian courts, unless otherwise stipulated by mandatory legal provisions in your country of residence.
13. Contact Information
If you have any questions or concerns about this Privacy Policy or how your data is handled, please contact our Data Protection Officer, at legal@demoapps.dev or our customer support team at destek@demoapps.dev
Türkçe
English
日本語