The data, and why we need it.
We act as controller for merchant and website data, and as processor for cardholder data we handle on your instruction.
Merchant and owner data
Collected to review an application and meet our anti-financial-crime obligations.
- Names, contact details and role of applicants and beneficial owners
- Identity documents and proof of address
- Company records, ownership structure and processing statements
- Screening results from sanctions, PEP and adverse-media checks
Transaction data
Processed to authorise payments, prevent fraud and settle funds.
- Card token, issuing country, BIN range and authorisation result
- Amount, currency, merchant reference and dispute status
- Device, IP and session signals used for risk scoring
- Full card numbers only inside a PCI DSS compliant environment, tokenised at rest
Website data
Collected when you visit payluxpay.com or use the console.
- Log data: IP address, user agent, pages requested
- Console audit trail: who changed which setting and when
- Cookie data as described in the cookie policy
Purposes, sharing and retention.
Legal bases
We rely on contract performance for providing the service, legal obligation for financial-crime checks and record-keeping, and legitimate interests for fraud prevention and service improvement. Marketing email is sent on consent only.
Who we share with
Acquiring banks and card schemes to process your transactions; screening, identity and fraud providers; payout partners in the destination market; hosting and infrastructure providers; professional advisers and authorities where we are required to disclose.
International transfers
Where data moves outside its country of origin we rely on adequacy decisions or standard contractual clauses, with transfer risk assessed per provider.
How long we keep it
Onboarding and transaction records are retained for the statutory period after the relationship ends — generally five to seven years. Applications we decline are kept for two years so we can explain the decision. Log data is kept for twelve months.
What you can ask us to do.
Rights you can exercise
Write to privacy@payluxpay.com and we respond within one month.
- Access a copy of the personal data we hold
- Correct data that is inaccurate or incomplete
- Ask for erasure where no legal retention duty applies
- Object to or restrict processing based on legitimate interests
- Receive your data in a portable format
- Complain to your data protection authority
Security and sub-processors
Access is least-privilege and logged, data is encrypted in transit and at rest, and the current sub-processor list is issued with the agreement. We give notice before adding or replacing one.
Need a DPA or the sub-processor list?
Ask and we will send our data processing addendum and the current list of sub-processors.