Privacy Policy
General provisions
ABFPAY.COM LTD. (the “Company”) respects it’s Customer’s privacy and is committed to protecting Customer’s personal data. This Privacy Notice will inform you as to how the Company, being an administrator of personal data, looks after your personal data when you visit our website or use our services and tell you about your privacy rights and how the normative regulations protect you. The Company gives you information on how ABFPAY.COM collects and processes your personal data through your use of the Company’s website or services, including any data you may provide through this website or in other manner, when you sign up to our services. Specific details and information on the processing of personal data may also be described in agreements, on websites and in other documents related to the services of the Company.
- The Company ensures, within the framework of data protection legislation, the confidentiality of personal data and has implemented appropriate technical and organisational measures to safeguard personal data from unauthorized access, unlawful disclosure, accidental loss, modification, destruction or any other unlawful processing.
- The Company may use approved data processors for processing personal data. In such cases, the Company takes necessary steps to ensure that data processors process personal data under documented instructions of the Company, in accordance with the required and adequate security measures and otherwise in compliance with Data Protection Legislation.
- Every person should read and familiarize themselves with cookies policy in our website: https://abfpay.com/en/cookie-policy.
- Providing personal data is a required condition for using our services. If you wish to be a Customer of our services you need to be registered as a user of the website and give the Company permission to collect and process your personal data and agree with the rules of this Privacy Notice. Refusal to provide the personal data, necessary for performance of services, prevents the conclusion of the agreement with the Company.
Processing of personal data, collection of personal data and categories of data subjects
- Personal data may be collected from the Customer directly, from the Customer’s use of the services and from external sources such as public and private registers or other providers of databases (third parties). The Company may also record telephone calls, images and/or audio, save e-mail communication or otherwise document the Customer’s interaction and communication with the Company.
- The Company primarily collects from and processes personal data about natural persons who have entered into or wishes to enter into an agreement with the Company. The Company also collects and processes personal data from Customer’s legal representatives, shareholders, stakeholders, contact persons, beneficial owners and others.
-
Categories of personal data. Categories of personal data that the Company collects and processes are
for example:
- identification data such as – Customer’s first name and surname, middle name, gender, date of birth, place of birth, personal identity number, place of tax residence, tax ID, information form proof of identity document, copy of an identity document, proof of residence, a photograph of the Customer’s profile and a video recording of the verification session;
- contact data such as - the Customer’s residence address or address for communication purposes, postal address, country of residence, email address and phone number, language of communication;
- financial data such as – monthly salary and other regular or irregular income, financial liabilities, source/origin of income (funds), data about transactions, property, bank account;
- occupation (employment) data such as – data about employer / previous employer, occupation, position grade, area of work, working experience, education;
- correspondence records such as - the Customer’s communication with the Company through the communication channels, via email and/or by phone, or other tools which could be introduced, as well as information from surveys and polls,
- location data such as – IP address, login place, transaction place;
- family data such as marital status, dependants and / or family members;
- special category data (data about criminal convictions, legal capacity (in special cases));
-
Other data:
- risk profiling and classification (risk type, risk class) and other information gained from risk assessment-based activities, data about trustworthiness and due diligence such as payment behaviour, data that enables the Company to perform its due diligence measures regarding money laundering and terrorist financing prevention and to ensure the compliance with international sanctions, including the purpose of the business relationship and whether the Customer is a politically exposed person, as well as data on origin of assets or wealth such as data regarding the Customer’s transaction partners and business activities;
- voice and / or video recording data such as phone voice recordings;
- data concerning the applicability of any sanctions, including data regarding any relevant business dealings or activities, including any adverse media coverage that is available;
- data about the participation in companies and other types of legal entities, data about managers and other persons having decisive votes or representatives of the companies using or intending to use the Company’s services, as well as their ultimate beneficiary owners’ information and contact details of the representatives of the companies using or intending to use the Company’s services.
- information on the purpose and intended nature of the business relationship, investment objectives;
- information on the Customer’s knowledge and experience in financial technology services;
- transaction data, including the Customers transactions, incoming payments, claimed disbursements of money, information regarding the concluded assignment agreements, net annual return, selected currency, available funds, accountancy accounts;
- The Company does not process sensitive data related to Customer’s health, ethnicity, religious or political beliefs unless required by law or in specific circumstances where, for example, Customer reveals such data while using the Company’s services.
Legal basis and purposes of processing personal data.
The Company must have a legal basis for using the Customer’s personal data. The legal basis are one of the following:
-
Performance of agreements. The Company must have certain personal data to provide the services and
it cannot provide them without the Customer’s personal data. The main purpose of the processing of
the Customer’s data by the Company is to document, execute and administer agreements with a
Customer. Examples of purposes for processing include, but are not limited to:
- to take steps at the request of the Customers prior to entering into an agreement, as well as to conclude, execute and terminate an agreement with the Customer;
- to conduct national and international transactions via credit institutions, settlement and payment systems;
- for managing Customer relations, providing and administering access to the services;
- to authorize and control access to the services;
- for managing client relations and administrating access to the services;
- to authorize and control access to the services;
- to identify the Customer when accessing the Company’s services.
-
Legal obligations. In order to fulfil legal obligations under applicable regulations, the Company is
required to process the Customer’s data in accordance with regulatory legislation and Data
Protection Legislation. Examples of purposes for processing are:
- before the Customer may use the services and during the cooperation with the Customer under the agreement, the Company performs the due diligence of the Customer, to check and verify the Customer’s identity and to keep the Customer’s data updated and correct by verifying and enriching data through external and internal registers (KYC needs);
- to prevent, discover, investigate and report money laundering, terrorist financing, violation of sanctions;
- to comply with rules and regulations related to accounting, tax information exchange and risk management;
- to comply with regulations governing Money Services Businesses, financial technology services;
-
Legitimate interests. The Company sometimes collects and uses the Customer’s personal data, or
shares it with other organisations, because the Company has a legitimate reason to use it and this
is reasonable when balanced against the Customer’s right to privacy. Examples of purposes for
processing are:
- to provide to the Customer additional services;
- to develop, examine and improve the Company’s business, the services and the client experience by performing surveys, analyses, and/ or statistics;
- to organize campaigns for the Customer;
- to protect the interests of the Customer and/or the Company or its employees;
- to manage the relationships with the Customer;
- to prevent, limit and investigate any misuse or unlawful use or disturbance of the services;
- to ensure adequate provisions of the services, the safety of information within the services, as well as to improve, develop and maintain technical systems and IT infrastructure;
- to establish, exercise and defend legal claims and to handle complaints;
- to send verification reminders to Customers, who have not completed the verification process.
- Consent. If the Customer signs up to the Company services, and where allowed by law, the Company may contact the Customer via post, email and SMS text message with information about Company products, services, offers and promotions. The Company may use the personal data the Company has collected about the Customer in order to tailor the Company’s offers to Customer.
- The Customer can adjust his/ her preferences or inform the Company if the Customer doesn't want to receive any information regarding service, offer and promotions from the Company, at any time. Just use the privacy settings in Customer’s profile or click on the unsubscribe links on any marketing message the Company sends the Customer.
- The Company will not pass the Customer’s details on to any organisations outside the Company for their marketing purposes without the Customer’s permission.
-
Ways of obtaining personas data (collection). The Company usually obtains personal data directly
from Customer, for example, in the cases, when:
- Customer fills in applications and other forms to apply for services;
- Customer submits certain documents to the Company;
- Customer contacts the Company via telephone (the Company will inform you if the respective telephone call will be recorded);
- Customer uses the Company’s website or services;
- Customer participates in advertising campaigns or surveys organised by the Company.
- performing an obligation arising from regulations such as that the Company may be required to report to authorities, such as tax authorities, courts, law enforcement agencies including details of income, credit commitments, property holdings, remarks, and debt balances.
-
Transfer of information to third parties. The Company may share the Customer’s data with recipients
such as authorities, suppliers, payment service providers and business partners. The Company will
not disclose more of the Customer’s personal data than is necessary for the purpose of disclosure
and with respect to data protection regulation.
- Recipients may process the Customer personal data acting as data processors and/or as data controllers. When a recipient is processing the Customer’s personal data on its own behalf as a data controller, the recipient is responsible for providing information on such processing of the Customer’s personal data. The Company undertakes to guarantee appropriate technical and organizational security measures to ensure that the personal data processor upholds security standards that are not lower than the security standards set by the Company.
-
The Company discloses personal data to recipients such as:
- authorities, such as law enforcement agencies, bailiffs, notaries, tax authorities, supervisory authorities
- credit and financial institutions, correspondent banks, custodian banks, insurance providers and intermediaries of services, third parties participating in the trade execution, settlement and reporting cycle;
- financial and legal consultants, auditors or any other data processors of the Company, insofar as such information is necessary for the performance of functions delegated to them;
- providers of databases and registers, according to the normative regulation.
-
Profiling and automated decision making
- The Company may use Customers personal data for automated processing in order to, inter alia, offer services that meet Customer needs, to prevent money laundering, to set prices for financial services, to detect fraud and the risk of fraud, to assess Customer’s ability to meet obligations, and for marketing purposes.
- The Company uses information technology to make automated decisions based on the data about Customer’s availability to the Company. The Company can use automated decision-making, for example, to prevent fraud. Automated decision-making helps the Company to ensure fast, objective and efficient decision making based on the information at its disposal.
- Geographical area of Processing.
-
The Customer’s personal data is processed in accordance with this Privacy Notice and applicable
legal provisions.
- In the event of personal data transferring the purpose of processing the personal data is local legal basis and appropriate safeguards which are in place. The Company must ensure appropriate safeguards and verify if the country where recipient of data is located has adequate level of data protection as decided by the authorities.
- Upon request, the Customer can receive further details on personal data transfers to other countries.
-
Retention period
- Personal data will not be retained longer than necessary for the purposes for which the personal data is processed or required by Data Protection Legislation. For example, after the contractual relationship has expired, the Company will process personal data for the establishment, exercise or defense of legal claims. Personal data is also retained for pursuing the Company’s legitimate interest. Data retention requirements in regulatory legislation may be subject to national law and therefore may differ depending on the country. In the case of consent, personal data may be retained until implementation of the purpose of consent or its revocation, whichever occurs first.
- Rights as a data subject
-
The Customer has rights as a data subject in regard to the Company’s processing of personal data
under Data Protection Legislation. Such rights are, in general:
- to require the Customer’s personal data to be corrected if it is inadequate, incomplete or incorrect;
- to object to processing of the Customer’s personal data, such as for direct marketing purposes;
- to require the erasure of the Customer’s personal data;
- to restrict the processing of the Customer’s personal data, e.g. where the accuracy of the personal data is contested by the data subject.
- to receive information if the Customer’s personal data is being processed by the Company and if so then to access it;
- to receive the personal data that is provided by the Customer and is being processed based on consent or performance of an agreement in written or commonly used electronic format and were feasible transmit such data to another service provider (so called “data portability”);
- to withdraw the consent to process the Customer’s personal data;
- to request not to be subject to fully automated decision-making, including profiling, if such decision-making has legal effects or similarly significantly affects the Customer. This right does not apply if the decision-making is necessary in order to enter into or to perform an agreement with the Customer, if the decision-making is permitted under Data Protection Legislation or if the Customer has provided explicit consent. As a Customer you can lodge complaints pertaining to the Company’s processing of personal data to the Canadian authority (The Office of the Privacy Commissioner of Canada) if you consider that processing infringes on your rights and interests under Data Protection Legislation.
Contact details
- Customer may contact the Company with enquiries, requests for register extracts, withdrawal of consent or to exercise other data subject rights, including complaints regarding the processing of your personal data.
- For personal offers and marketing-based profiling, which is done according to the Company’s legitimate interest, the Company enables choices and the usage of a convenient tool for you to manage privacy settings.
- Customer may change certain information, approvals and choices in the Customer cabinet. Contact details of the Company: email: dataprotection@abfpay.com