Terms and Conditions for the Processing of Personal Data. Effective as of 21 September 2026, replacing the version effective 15 July 2025.
1. Introductory Provisions
1.1 Tapaya s.r.o., Company ID (IČO): 234 76 541, having its registered office at Uralská 689/7, Bubeneč, 160 00 Prague 6, registered in the Commercial Register maintained by the Municipal Court in Prague, File No. C 427691 (hereinafter referred to as the “Company”), hereby provides information regarding the manner and scope of personal data processing, including rights associated with personal data processing.
1.2 The Company, acting as a data controller or data processor, collects, stores, and uses (or otherwise processes) personal data in connection with its business activities (the specific purposes for which personal data are processed are further detailed below).
1.3 The protection of privacy and the processing of personal data are a priority for the Company. The processing of personal data is considered strictly confidential and personal data are handled in accordance with applicable legal regulations on personal data protection, in particular Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter referred to as “GDPR”).
1.4 For the purposes of these Terms and Conditions for the Processing of Personal Data (hereinafter referred to as the “Terms”) and to clearly delineate responsibilities within the Company's payment ecosystem, the key roles and concepts regarding personal data processing are defined as follows:
- a) Controller: An entity that alone or jointly with others determines the purposes and means of personal data processing. It is primarily responsible for ensuring that the processing is lawful.
- b) Processor: An entity that processes personal data strictly on behalf of the Controller and based on its documented instructions.
- c) Partner Company / Acquirer: A licensed financial institution that provides authorisation and settlement of payment transactions. In relation to sensitive cardholder data and merchant representatives' identification (AML) data, the Acquirer acts as a Controller.
- d) Platform: A web application operated by the Company through which integrators and merchants register, manage their accounts, and obtain overviews of payments and devices.
- e) Application: A software solution provided by the Company (Tapaya Accept / Tapaya Tap to Pay), whether in the form of a standalone mobile application or an integrated SDK module, used to accept payment cards.
- f) PCI Standards: Security standards established by the Payment Card Industry Security Standards Council (PCI SSC) and all related standards applicable to the Company's services.
- g) User: A user means an integrator and/or merchant who has established a business relationship with the Company, uses the Application or Platform, and is subject to these Terms.
2. Legal Basis and Purposes of Personal Data Processing
2.1 The legal bases for the processing of personal data are the negotiation and performance of a contract, compliance with legal obligations imposed on the Company, and the legitimate interests of the Company.
2.2 As part of its operations, the Company collects, stores, and uses personal data, acting in two distinct legal capacities:
- a) As a Controller: When operating its web platform, managing user accounts (integrators and merchants), ensuring the cybersecurity of its infrastructure, and complying with PCI Standards.
- b) As a Processor: When processing cardholders' payment transactions and performing identification (KYC/AML) of merchant representatives, acting solely based on instructions and on behalf of the Partner Company, which acts as the Controller in this relationship.
2.3 The Company processes personal data primarily for the following purposes:
- a) Processing and settlement of payment transactions: In the role of Processor for the Partner Company, processing cardholder data to execute payments (contract performance, legitimate interest);
- b) Compliance with legal obligations (AML/KYC): In the role of Processor, conducting merchant onboarding and collecting identification data in accordance with the Partner Company's instructions in order to comply with anti-money laundering obligations;
- c) User account and platform management: In the role of Controller, processing data to grant merchants and integrators access to the web platform (performance of contractual relations); and
- d) Fraud prevention and cybersecurity: In the role of Controller, monitoring devices and IP addresses to protect the network, detect anomalies, and comply with PCI security standards (legitimate interest and contractual obligation).
2.4 We obtain personal data primarily from you (e.g., during registration on the Platform, completing an onboarding form, or communicating with us), or through a processor in the form of an integrator who collects data from the merchant via their own form in accordance with the table in Section 3.1 of these Terms. Where required by law (specifically anti-money laundering laws — AML), we also collect and verify data about merchant representatives from publicly accessible sources (e.g., commercial and trade registers, ARES) and specialised external databases (e.g., international sanctions lists and lists of politically exposed persons — PEP).
3. Processed Personal Data
3.1 The Company processes the following data exclusively as a Processor based on the instructions of the Partner Company:
| Data subject | Processed data | Purpose of processing |
|---|---|---|
| Cardholder | Card number (PAN), name on card, encrypted PIN block, and transaction cryptograms | Processing and settlement of payment transactions |
| Merchant Representative | First and last name, address, copy or scan of identification document, date of birth, email | Identification, AML and KYC processes, contract performance |
3.2 The Company processes the following data for its own purposes as a Controller:
| Data subject | Processed data | Purpose of processing |
|---|---|---|
| Platform User | User email, password, first and last name | Contract performance — account identification, securing access to the platform |
| Application User | Device identifier, IP address, device model and operating system, geolocation data (GPS position at the time of transaction) | Legitimate interest and contractual obligation — fraud prevention, security, PCI Standards compliance |
| Cardholder | Electronic transaction receipts | Legitimate interest and contractual obligation — providing proof of payment |
| Platform User, Application User, or Cardholder | Data provided voluntarily when contacting us, reaching out to support, by phone, email, including all inquiries and responses to questionnaires and business communications | Legitimate interest and contract performance — service quality assurance and handling requests |
| Platform and Application User | First and last name, email address, phone number, company name / business name | Legitimate interest — direct B2B marketing |
| Platform and Application User | Platform and Application usage data (e.g., system logs, interface interaction logs, error reports, and technical device parameters) | Legitimate interest — analytics and product development |
4. Recipients of Personal Data
4.1 Personal data are disclosed only to authorised employees of the Company or the Partner Company acting as Controller, strictly to the extent necessary to fulfil individual processing purposes.
4.2 Personal data may be transferred to:
- a) The Partner Company, to which the Company, as Processor, transfers transaction and identification data for payment authorisation and AML compliance purposes;
- b) Public Authorities, where the Company is required by law to transfer certain personal data under applicable legal regulations (e.g., law enforcement agencies or other public authorities); and
- c) Processors, providing server, web, cloud, or IT services to the Company.
4.3 An up-to-date list of entities acting as Processors for the Company and specific Partner Companies is available at tapaya.com/en/privacy/processors.
4.4 To operate the Application and Platform, the Company utilises verified infrastructure providers with servers located primarily within the European Union. In cases where data transfers to partners or service providers outside the European Economic Area (EEA) occur, the Company ensures the highest level of protection by applying appropriate safeguards, typically by entering into Standard Contractual Clauses (SCCs) approved by the European Commission.
5. Data Retention and Processing Period
5.1 The Company processes personal data for the time strictly necessary to fulfil all rights and obligations arising from the relevant contractual relationship, and further for the period during which the Company, as a data controller, is obligated to retain personal data pursuant to generally binding legal regulations.
- a) Performance of contractual relationship: Duration of the contractual relationship and 10 years following its termination.
- b) Compliance with legal obligations: Data processed for the purpose of complying with legal obligations, specifically identification (KYC) and transaction data for anti-money laundering (AML) and tax purposes, shall be retained for the period mandated by law. This standard period is 10 years following the termination of the contractual relationship or the execution of the relevant transaction.
- c) Legitimate interest of Controller: Up to a maximum of 3 years from data storage, unless special legal regulations mandate a longer period in specific cases, and/or a justified case requires longer storage in connection with a specific matter.
5.2 For personal data where the Company acts exclusively as a Processor, the retention period is governed entirely by the instructions of the respective Controller (Partner Company) and applicable payment regulation standards. After this period expires, the data are securely deleted. Except at the exact moment of the transaction, the Company does not permanently store Sensitive Authentication Data (SAD) in accordance with PCI Standards.
6. Rights of the Data Subject
6.1 Data subjects have statutory rights regarding the processing of their personal data, which they may exercise at any time. These include:
- (i) right of access to personal data;
- (ii) right to rectification of inaccurate and completion of incomplete data;
- (iii) right to erasure of personal data if no longer needed for the purposes collected or if processed unlawfully;
- (iv) right to restriction of processing;
- (v) right to data portability;
- (vi) right to object, after which processing will cease unless compelling legitimate grounds overriding the subject's interests, rights, and freedoms are demonstrated (e.g., legal claims enforcement); and
- (vii) right to lodge a complaint with a supervisory authority (see Section 6.7 below).
6.2 Because we operate in a highly regulated payments sector, please note that some rights (especially erasure or objection) may be limited by law. The Company cannot comply with erasure requests for data that must be retained under statutory obligations (e.g., AML or tax regulations) or data essential for defending legal claims.
6.3 For further information regarding personal data processing, contact dpo@tapaya.com. To exercise rights, write to the Company's registered office address or email dpo@tapaya.com.
6.4 To protect your data against unauthorised access, we must verify your identity prior to fulfilling any requests. Additional identification may be requested where justified. Requests submitted by third parties require proof of authorisation (e.g., power of attorney).
6.5 Requests will be addressed without undue delay, at most within one month. For complex or voluminous requests, this period may be extended by an additional two months with timely notification.
6.6 The exercising of these rights is free of charge. However, for manifestly unfounded or excessive requests (particularly repetitive ones), the Company reserves the right to charge a reasonable fee reflecting administrative costs or to refuse the request.
6.7 If you believe processing violates statutory regulations, you have the right to lodge a complaint. We encourage contacting us first to resolve matters promptly. You also retain the right to complain to a supervisory authority. In the Czech Republic, this is the Office for Personal Data Protection (www.uoou.cz). EU supervisory authorities are listed on the EDPB website.
7. Automated Decision-Making and Profiling
7.1 The Company itself does not engage in fully automated decision-making producing legal effects concerning you. However, to ensure payment ecosystem security, prevent fraud, and comply with statutory duties (e.g., AML), software tools involving profiling elements may be utilised by us or external partners (especially Partner Companies).
- a) Mechanism: Security systems continuously and automatically analyse transaction patterns, IP addresses, or unique device identifiers to detect anomalies or cyber threats in real time.
- b) Potential Impact: High-risk evaluations by the system may result in automated temporary transaction rejections or preventive restriction of device access to the Application.
- c) Human Review: If affected by such automated security measures and you disagree, you hold the right to contact us, present your point of view, and request manual human review.
8. Security of Personal Data
8.1 Given the sensitive nature of financial transactions, strict technical and organisational measures are enforced in full compliance with global PCI security standards. Sensitive cardholder data (PAN, PIN code) are immediately encrypted upon capture in the Application. Sensitive Authentication Data (SAD) are never stored in mobile local memory or permanently stored on servers after payment authorisation completes. Modern cryptographic protocols protect data transmissions and infrastructure.
9. Final Provisions
9.1 The Company reserves the right to unilaterally amend or supplement these Terms at any time. Revisions will be notified to Users in advance via the Platform, Application, or electronic communication. Amendments take effect upon publishing the revised Terms. Notifications will always be distributed via email or User accounts.
9.2 If you navigate to third-party websites via links provided on the Platform, the processing of your personal data shall be governed by their respective privacy policies. The Company assumes no responsibility for external websites or their processing practices; review their terms prior to use.
9.3 These Terms do not cover cookies or tracking technologies on the Company's web platform. Refer to the separate Cookie Policy.