cookie

We use cookies to enhance your browsing experience, analyze site traffic, and serve targeted advertisements. By clicking 'Accept All', you consent to the use of all cookies. You can manage your preferences by clicking "Customize Preferences". Read our Cookie Policy for more information.

Logo
Menu Hamburger

Privacy policy

1. General Principles

For the purposes of Applicable Data Protection Laws, including, where applicable, the GDPR, the UK GDPR, PIPEDA and substantially similar legislation (hereinafter – “Applicable Data Protection Laws”), Alpha Payments Inc., operating under the Paycot brand ("Paycot", "we", "our" or "us"), acts as the data controller in relation to Personal Data processed for its own legal, regulatory and business purposes. Where Paycot processes Personal Data solely on behalf of a Client in connection with the provision of the Services, Paycot may act as a data processor or service provider, as applicable under the relevant law.

The Parties acknowledge that the collection, use, storage, disclosure and other processing of Personal Data may be necessary for the provision of the Services and compliance with Applicable Law.

Nothing in these Terms limits any mandatory rights or obligations arising under Applicable Data Protection Laws.

 


 

2. Contact for Privacy

Privacy-related requests may be submitted using the contact details published on the Website or by emailing [email protected].

 


 

3. Privacy Policy

The processing of Personal Data by Paycot is governed by these Terms and the Paycot Privacy Policy, as amended from time to time.

The Privacy Policy describes, among other matters:

  • the categories of Personal Data collected; 

  • the purposes of processing; 

  • the lawful bases for processing; 

  • categories of recipients; 

  • international transfers where applicable; 

  • retention periods; 

  • data subject rights; and 

  • contact details for privacy-related enquiries. 

The Client acknowledges that it has had the opportunity to review the Privacy Policy before using the Services.

Paycot has designated a Privacy Officer responsible for overseeing compliance with Applicable Data Protection Laws, responding to privacy-related enquiries and coordinating the Company's privacy governance programme. Contact details for privacy-related requests are available on the Website.

Paycot maintains policies, procedures and governance measures designed to ensure ongoing compliance with Applicable Data Protection Laws.

 


 

4. Collection of Personal Data

Paycot may collect Personal Data from:

  • the Client; 

  • Authorised Users; 

  • beneficial owners; 

  • directors; 

  • authorised representatives; 

  • payment counterparties; 

  • publicly available sources; 

  • regulatory databases; 

  • sanctions databases; 

  • identity verification providers; 

  • fraud prevention providers; and 

  • other lawful sources. 

The categories of Personal Data collected shall be limited to those reasonably necessary for the purposes described in the Privacy Policy and these Terms.

 


 

5. Purposes of Processing

Paycot may process Personal Data where reasonably necessary to:

  • provide the Services; 
  • verify eligibility to receive Services in accordance with applicable regulatory restrictions, including reverse solicitation requirements where applicable.

  • process Transactions; 

  • verify identity; 

  • perform KYC and KYB procedures; 

  • conduct sanctions screening; 

  • comply with anti-money laundering obligations; 

  • prevent fraud; 

  • maintain information security; 

  • comply with Applicable Law; 

  • communicate with the Client; 

  • resolve disputes; 

  • improve the Services; 

  • perform internal audits; 

  • manage operational risk; and 

  • protect Paycot's legitimate business interests where permitted by Applicable Law. 

 


6. Capacity in Which Paycot Processes Personal Data

 

Depending on the nature of the Services provided and the purpose for which Personal Data is processed, Paycot may act either as a data controller or as a data processor (or service provider, where recognised by Applicable Law).

Paycot generally acts as a data controller where it processes Personal Data for its own legitimate business purposes or in order to comply with legal and regulatory obligations, including, without limitation:

  • customer onboarding; 

  • Know Your Customer (KYC) and Know Your Business (KYB) procedures; 

  • anti-money laundering and counter-terrorist financing compliance; 

  • sanctions screening; 

  • fraud prevention; 

  • risk assessment; 

  • transaction monitoring; 

  • regulatory reporting; 

  • compliance with court orders or lawful requests issued by competent authorities; 

  • information security; 

  • record retention; and 

  • the establishment, exercise or defence of legal claims. 

Where Paycot processes Personal Data solely on behalf of a Client for the purpose of providing the Services in accordance with the Client's documented instructions, Paycot may act as a data processor (or equivalent role recognised under Applicable Law), while the Client remains responsible for determining the purposes and means of such processing.

Where Paycot acts as a data processor, it shall process Personal Data only:

  • in accordance with the documented instructions of the relevant Client, except where otherwise required by Applicable Law; 

  • for the purposes of providing the agreed Services; 

  • in compliance with Applicable Data Protection Laws; 

  • subject to appropriate technical and organisational security measures; and 

  • in accordance with any applicable data processing agreement or contractual arrangements between the Parties. 

Nothing in this Privacy Policy limits Paycot's ability to process Personal Data as a data controller where such processing is required to comply with Applicable Law, regulatory obligations or the legitimate interests of Paycot, provided that such legitimate interests are not overridden by the rights and freedoms of the relevant data subject where required by Applicable Data Protection Laws.

Where Applicable Data Protection Laws distinguish between different roles in relation to Personal Data, this Privacy Policy shall be interpreted accordingly.

 


 

7. Legitimate Interest

Where Paycot relies upon its legitimate interests as the lawful basis for processing Personal Data, such legitimate interests may include:

  • protecting the security and integrity of the Services; 

  • preventing fraud, financial crime and unauthorised access; 

  • improving the quality, functionality and performance of the Services; 

  • managing operational, legal and regulatory risks; 

  • exercising and defending legal claims; 

  • ensuring business continuity; 

  • developing and improving products and services; and 

  • protecting the legitimate interests of Paycot, its Clients and the integrity of the financial system, 

provided that such interests are not overridden by the rights and freedoms of the relevant data subject where required by Applicable Data Protection Laws.

 


 

8. Lawful Basis for Processing

Where required by Applicable Data Protection Laws, Paycot shall process Personal Data on one or more lawful bases under Article 6 GDPR (where applicable), including:

  • performance of a contract; 

  • compliance with legal obligations; 

  • legitimate interests; 

  • protection of vital interests; 

  • performance of tasks carried out in the public interest where applicable; or 

  • consent, where consent is required by Applicable Law. 

Where processing is based upon consent, the data subject may withdraw consent at any time, subject to Applicable Law.

 


 

9. Disclosure of Personal Data

Paycot may disclose Personal Data where reasonably necessary to:

  • affiliated companies; 

  • service providers; 

  • identity verification providers; 

  • payment system participants; 

  • financial institutions; 

  • foreign exchange providers; 

  • virtual currency service providers involved in the relevant Transaction; 

  • auditors; 

  • legal advisers; 

  • regulators; 

  • law enforcement agencies; 

  • courts; 

  • governmental authorities; or 

  • other third parties where required or permitted by Applicable Law. 

Paycot shall implement appropriate safeguards when engaging third-party service providers.

 


 

10. International Data Transfers

Where Personal Data is transferred outside the jurisdiction in which it was collected, Paycot shall implement appropriate safeguards where required under Applicable Data Protection Laws.

Such safeguards may include:

  • adequacy decisions; 

  • standard contractual clauses; 

  • legally recognised transfer mechanisms; or 

  • other safeguards recognised under Applicable Law. 

The Client acknowledges that certain international Transactions may necessarily involve cross-border transfers of Personal Data.

A copy of the applicable safeguards may be requested where required by Applicable Data Protection Laws, subject to the protection of confidential commercial information.


 

11. Data Security

Paycot shall implement commercially reasonable technical and organisational measures designed to protect Personal Data against:

  • unauthorised access; 

  • accidental loss; 

  • unlawful destruction; 

  • alteration; 

  • disclosure; 

  • misuse; 

  • cyberattacks; and 

  • other reasonably foreseeable security risks. 

Such measures may include encryption, access controls, authentication mechanisms, logging, monitoring, business continuity measures and other safeguards appropriate to the nature of the Personal Data processed.

No information system can guarantee absolute security, and Paycot does not warrant that unauthorised access will never occur.

 


 

12. Client Responsibilities

The Client shall ensure that any Personal Data provided to Paycot:

  • has been lawfully collected; 

  • may lawfully be disclosed to Paycot; 

  • is accurate; 

  • is updated where necessary; 

  • is limited to what is reasonably necessary; and 

  • is processed in accordance with Applicable Data Protection Laws. 

Where required by Applicable Law, the Client shall obtain all necessary notices, permissions or consents before providing Personal Data to Paycot.

The Services are intended exclusively for business clients and are not directed to minors.

 


 

13. Data Subject Rights

Where Applicable Data Protection Laws grant rights to data subjects, Paycot shall process requests relating to:

  • access; 

  • rectification; 

  • erasure; 

  • restriction of processing; 

  • data portability; 

  • objection to processing; 

  • withdrawal of consent where applicable; and 

  • other rights recognised under Applicable Law. 

Paycot may request reasonable evidence of identity before responding to such requests.

Individuals located in the EEA also have the right to lodge a complaint with the competent supervisory authority responsible for data protection.

 


 

14. Automated decision making

Paycot does not make decisions producing legal or similarly significant effects solely by automated means without appropriate human involvement, except where permitted or required by Applicable Law.

15. Data Retention

Paycot shall retain Personal Data only for the period required by Applicable Law or, where no statutory period applies, only for as long as reasonably necessary to:

  • provide the Services; 

  • comply with Applicable Law; 

  • satisfy regulatory record-keeping obligations; 

  • resolve disputes; 

  • establish, exercise or defend legal claims; 

  • prevent financial crime; or 

  • fulfil legitimate business purposes permitted by Applicable Law. 

Following expiry of the applicable retention period, Personal Data shall be securely deleted, anonymised or otherwise handled in accordance with Applicable Law.

 


 

16. Cookies and Similar Technologies

Paycot may use cookies, pixels, local storage objects, software development kits (SDKs) and similar technologies ("Cookies") in connection with the Website, Client Portal and other online Services.

Cookies are used to support the operation, security and functionality of the Services and, where permitted by Applicable Law, to improve user experience, analyse Website performance and maintain the security and integrity of Paycot's systems.

Depending on their purpose, Cookies may include:

  • strictly necessary Cookies required for the operation and security of the Website or Services; 

  • functional Cookies that remember user preferences and improve usability; 

  • performance and analytics Cookies that help Paycot understand how the Website and Services are used; 

  • security Cookies designed to detect fraud, prevent unauthorised access and protect the integrity of the Services; and 

  • other Cookies that may be permitted under Applicable Law. 

Where required by Applicable Law, including the GDPR, the ePrivacy Directive or equivalent legislation, Paycot shall obtain the user's consent before placing or accessing Cookies that are not strictly necessary for the operation of the Website or the provision of the requested Services.

Users may withdraw or modify their Cookie preferences at any time through the Cookie management tools made available on the Website or through their browser settings, subject to the technical limitations of the relevant browser or device.

Disabling certain Cookies may affect the availability, security or functionality of some features of the Website or Services.

Third-party analytics, security or service providers may place Cookies on behalf of Paycot where reasonably necessary for the operation of the Services. Such third parties process information in accordance with their own privacy notices and Applicable Data Protection Laws.

Additional information regarding the use of Cookies, including the categories of Cookies used, their purposes, retention periods and available user choices, may be provided in a separate Cookie Notice published on the Website.

Where required by Applicable Law, consent preferences shall be recorded and may be managed through the Cookie Preference Centre.

 


 

17. Marketing Communications

Where permitted by Applicable Law, Paycot may send the Client and its authorised representatives communications relating to the Services, including product updates, operational notices, service announcements, educational materials and marketing communications.

Marketing communications will be sent only where permitted under Applicable Data Protection Laws and, where required, on the basis of the recipient's consent or another lawful basis recognised by Applicable Law.

Recipients may opt out of receiving marketing communications at any time by using the unsubscribe mechanism included in the communication or by contacting Paycot using the contact details published on the Website.

The Client may also object to processing for direct marketing purposes at any time.

Withdrawal of consent or opting out of marketing communications shall not affect Paycot's ability to send communications that are necessary for:

  • providing the Services; 

  • administering Accounts; 

  • complying with Applicable Law; 

  • responding to security incidents; 

  • fulfilling contractual obligations; or 

  • communicating important operational or regulatory information relating to the Services.

 


 

18. Data Breaches

Where required by Applicable Data Protection Laws, Paycot shall respond to Personal Data breaches in accordance with its legal obligations without undue delay where required by Applicable Law.

Such measures may include:

  • investigation of the incident; 

  • containment measures; 

  • remediation; 

  • notifications to competent authorities where required; 

  • notifications to affected individuals where required; and 

  • implementation of corrective security measures. 

Nothing in these Terms creates additional notification obligations beyond those required by Applicable Law.

 


 

19. Confidentiality of Personal Data

Personal Data shall be treated as Confidential Information where applicable.

Nothing in these Terms prevents Paycot from disclosing Personal Data where such disclosure is:

  • required by Applicable Law; 

  • required by a competent authority; 

  • necessary to provide the Services; 

  • necessary to prevent fraud or financial crime; or 

  • otherwise permitted under Applicable Data Protection Laws. 

 


 

20. Limitation of Responsibility

Paycot shall not be responsible for:

  • inaccurate Personal Data supplied by the Client; 

  • the Client's failure to obtain required consents; 

  • unlawful instructions given by the Client; 

  • unauthorised disclosures made by the Client; or 

  • processing activities carried out independently by the Client. 

Each Party remains independently responsible for complying with Applicable Data Protection Laws in relation to its own processing activities.

 


 

21. Survival

The provisions of this Section shall survive suspension or termination of the Services to the extent necessary for:

  • compliance with Applicable Law; 

  • regulatory record retention; 

  • legal proceedings; 

  • dispute resolution; 

  • audit requirements; 

  • enforcement activities; or 

  • the protection of the rights and legitimate interests of either Party. 

 


 

22. Client Acknowledgement

By using the Services, the Client acknowledges and agrees that:

(a) Paycot may process Personal Data where reasonably necessary to provide the Services and comply with Applicable Law;

(b) Personal Data may be disclosed to regulators, financial institutions, service providers and other authorised recipients where required or permitted by Applicable Law;

(c) international Transactions may require cross-border transfers of Personal Data, subject to applicable legal safeguards;

(d) Paycot implements commercially reasonable technical and organisational measures to protect Personal Data but cannot guarantee absolute security;

(e) the Client remains responsible for ensuring that any Personal Data provided to Paycot has been lawfully collected and disclosed; and

(f) Personal Data may be retained after termination of the business relationship where required or permitted by Applicable Law.