XPAYE — Privacy policy

Privacy policy – XPAYE

1. Introduction

Introduction

This Privacy Policy describes how XPAYE collects, uses, processes and protects personal data in the context of its payment orchestration and processing services.

XPAYE applies high standards of data protection in accordance with the requirements of the competent African regulators and applicable international frameworks.

2. Data controller

Data controller

Depending on the nature of the service and the jurisdiction concerned:

The applicable contracting entity depends on the service used and the merchant's location.

3. Data collected

Data collected

XPAYE may collect and process in particular:

XPAYE does not store complete bank card data.

Card payments are processed via certified partners using hosted secure payment pages.

4. Purpose of processing

Purpose of processing

Data is collected in order to:

5. Legal basis for processing

Legal basis for processing

Processing is based on:

6. Data sharing

Data sharing

Data may be shared with:

Data is never sold to third parties.

7. International transfers

International transfers

Data is hosted in secure infrastructures located in jurisdictions offering a high level of data protection, notably in Europe, with secure replication mechanisms in Africa to ensure operational continuity and service resilience.

8. Retention period

Retention period

Personal data is retained for the period necessary for the performance of services and compliance with applicable legal and regulatory obligations.

Certain data, in particular that relating to customer identification (KYC), financial transactions and accounting or anti-money laundering obligations, may be retained for a period of up to ten (10) years from the end of the contractual relationship, in accordance with applicable regulatory requirements.

Other data is retained for a period proportionate to its purpose.

9. Data security

Data security

XPAYE implements appropriate technical and organisational measures to protect data against unauthorised access, loss, alteration or disclosure.

10. Data subject rights

Data subject rights

In accordance with applicable data protection regulations in the jurisdictions concerned, data subjects have in particular the following rights:

The exercise of these rights may be limited when the retention of data is necessary to comply with legal or regulatory obligations, in particular in the financial sector or anti-money laundering.

Requests may be sent to:

privacy@xpaye.africa

11. Cookies

Cookies

The use of cookies is described in the Cookie policy accessible on the site.

12. Contact

Contact

For any questions regarding data protection:

privacy@xpaye.africa