LEGAL / PRIVACY POLICY

Privacy policy

Last updated 1 September 2026. This explains what personal data we handle, why we hold it, how long we keep it, and the rights you and your customers have. Questions go to privacy@payluxpay.com.

WHAT WE HOLD

The data, and why we need it.

We act as controller for merchant and website data, and as processor for cardholder data we handle on your instruction.

Merchant and owner data

Collected to review an application and meet our anti-financial-crime obligations.

  • Names, contact details and role of applicants and beneficial owners
  • Identity documents and proof of address
  • Company records, ownership structure and processing statements
  • Screening results from sanctions, PEP and adverse-media checks

Transaction data

Processed to authorise payments, prevent fraud and settle funds.

  • Card token, issuing country, BIN range and authorisation result
  • Amount, currency, merchant reference and dispute status
  • Device, IP and session signals used for risk scoring
  • Full card numbers only inside a PCI DSS compliant environment, tokenised at rest

Website data

Collected when you visit payluxpay.com or use the console.

  • Log data: IP address, user agent, pages requested
  • Console audit trail: who changed which setting and when
  • Cookie data as described in the cookie policy
HOW WE USE IT

Purposes, sharing and retention.

Legal bases

We rely on contract performance for providing the service, legal obligation for financial-crime checks and record-keeping, and legitimate interests for fraud prevention and service improvement. Marketing email is sent on consent only.

Who we share with

Acquiring banks and card schemes to process your transactions; screening, identity and fraud providers; payout partners in the destination market; hosting and infrastructure providers; professional advisers and authorities where we are required to disclose.

International transfers

Where data moves outside its country of origin we rely on adequacy decisions or standard contractual clauses, with transfer risk assessed per provider.

How long we keep it

Onboarding and transaction records are retained for the statutory period after the relationship ends — generally five to seven years. Applications we decline are kept for two years so we can explain the decision. Log data is kept for twelve months.

YOUR RIGHTS

What you can ask us to do.

Rights you can exercise

Write to privacy@payluxpay.com and we respond within one month.

  • Access a copy of the personal data we hold
  • Correct data that is inaccurate or incomplete
  • Ask for erasure where no legal retention duty applies
  • Object to or restrict processing based on legitimate interests
  • Receive your data in a portable format
  • Complain to your data protection authority

Security and sub-processors

Access is least-privilege and logged, data is encrypted in transit and at rest, and the current sub-processor list is issued with the agreement. We give notice before adding or replacing one.

DATA REQUESTS

Need a DPA or the sub-processor list?

Ask and we will send our data processing addendum and the current list of sub-processors.