Privacy Policy
Version 1.0 | 12 August 2026
Legal entity
PayMaxis LTD
Registration number
HE 412503
Registered address
165, Spyrou Araouzou, Office 201A, 3036 Limassol, Cyprus
Hosting
Amazon Web Services (AWS), Ireland and Germany
Security
PCI DSS Level 1 compliant
1. Purpose and Scope
This Privacy Policy explains how PayMaxis processes personal data in connection with its Website, merchant onboarding, business relationships, payment gateway and orchestration services, support, security, compliance and related activities.
This Policy may apply to Website visitors; prospective and existing merchants; directors, officers, shareholders, beneficial owners, employees and representatives of merchants and business partners; portal or dashboard users; suppliers; professional advisers; and individuals whose payment or transaction data is transmitted through PayMaxis as part of a merchant payment flow.
2. Who We Are and Our Data-Protection Roles
PayMaxis LTD, registration number HE 412503, is established in Cyprus at 165, Spyrou Araouzou, Office 201A, 3036 Limassol, Cyprus.
PayMaxis may act in different data-protection roles depending on the processing activity:
- As a controller, PayMaxis determines the purposes and means of processing for activities such as Website operation, enquiries, merchant onboarding, account administration, security, fraud prevention, compliance, business communications, and management of its own legal and contractual obligations.
- As a processor, PayMaxis may process personal data, including transaction and cardholder data, on behalf of a merchant or other customer when providing gateway, routing, orchestration, hosted payment, tokenisation or related technical services, subject to the relevant agreement and documented instructions.
- In some transaction flows, another participant in the payment ecosystem — such as a merchant, acquirer, PSP, card scheme, fraud provider or wallet provider — may independently act as controller for its own processing purposes.
3. Personal Data We May Process
3.1Website and enquiry data
- name, business name, job title and contact details;
- information submitted through contact, demo or enquiry forms;
- correspondence and support communications;
- IP address, browser, device, operating system, language, approximate location derived from IP, referring pages, timestamps and Website usage information;
- cookie and similar-technology data, subject to your cookie choices.
3.2Merchant onboarding and business relationship data
- corporate registration and business information;
- names, roles and contact details of directors, shareholders, beneficial owners, authorised signatories and representatives;
- identity and verification information, including identification-document details and proof-of-address information where required;
- ownership and control information;
- licensing, regulatory and business-model information;
- banking or settlement-account information supplied for business and compliance purposes;
- risk, due-diligence, sanctions, politically exposed person, adverse-media and fraud-prevention information obtained from lawful internal or third-party sources;
- contracts, support records, account activity and service-use information.
3.3Payment and transaction data
- corporate registration and business information;
- names, roles and contact details of directors, shareholders, beneficial owners, authorised signatories and representatives;
- identity and verification information, including identification-document details and proof-of-address information where required;
- ownership and control information;
- licensing, regulatory and business-model information;
- banking or settlement-account information supplied for business and compliance purposes;
- risk, due-diligence, sanctions, politically exposed person, adverse-media and fraud-prevention information obtained from lawful internal or third-party sources;
- contracts, support records, account activity and service-use information.
We may obtain personal data directly from you; from merchants and their systems; from acquiring banks, PSPs, card schemes, payment partners and technology providers; from identity, screening, fraud or compliance providers; from public registers and publicly available sources; or from professional advisers and authorities where lawful and appropriate.
4. Sources of Personal Data
We may obtain personal data directly from you; from merchants and their systems; from acquiring banks, PSPs, card schemes, payment partners and technology providers; from identity, screening, fraud or compliance providers; from public registers and publicly available sources; or from professional advisers and authorities where lawful and appropriate.
5. Purposes and Legal Bases
Purpose
Examples
Typical legal basis
Provide and administer services
Account setup, authentication, gateway/orchestration delivery, routing, support, reporting
Contract; legitimate interests; processor instructions where applicable
Merchant onboarding and relationship management
KYB, ownership checks, risk assessment, contracting, account management
Contract; legitimate interests; legal obligations where applicable
Security and fraud prevention
Access control, logging, threat detection, abuse prevention, transaction-security controls
Legitimate interests; legal obligations; processor instructions where applicable
Compliance and legal obligations
Sanctions screening, regulatory requests, record keeping, investigations, disputes
Legal obligation; legitimate interests
Compliance and legal obligations
Sanctions screening, regulatory requests, record keeping, investigations, disputes
Legal obligation; legitimate interests
Website operation and improvement
Diagnostics, performance, security, necessary cookies, analytics where permitted
Legitimate interests; consent for non-essential cookies where required
Business communications and marketing
Responding to enquiries, product updates, events and relevant B2B communications
Consent or legitimate interests, as applicable
Establishing or defending legal claims
Contract enforcement, complaints, audits, litigation and investigations
Legitimate interests; legal obligation
The precise lawful basis depends on the processing context. Where we rely on legitimate interests, we consider the relevant interests, necessity of processing, and impact on individuals. Where consent is the legal basis, consent may be withdrawn at any time without affecting processing that was lawful before withdrawal.
6. Automated Processing and Fraud/Risk Signals
PayMaxis and its merchants or payment partners may use automated rules, fraud indicators, risk models, routing logic or transaction-security controls to assist with payment processing, fraud prevention, security and operational decision-making. PayMaxis does not intend to make decisions producing legal or similarly significant effects about an individual solely on the basis of automated processing unless this is lawful, appropriately disclosed and subject to applicable safeguards.
7. How We Share Personal Data
- merchants and their authorised users;
- acquiring banks, PSPs, card schemes, banks, payment-method providers and other payment participants involved in the relevant transaction;
- cloud, hosting, communications, analytics, security, customer-support and other technology service providers;
- identity-verification, sanctions-screening, fraud-prevention, risk and compliance providers;
- professional advisers, auditors, insurers and consultants;
- competent regulators, courts, law-enforcement bodies and public authorities where required or permitted by law;
- a prospective purchaser, investor or successor in connection with a legitimate corporate transaction, subject to appropriate confidentiality and data-protection safeguards.
- contracts, support records, account activity and service-use information.
We do not sell personal data as a commodity.
8. Hosting, Subprocessors and International Transfers
PayMaxis uses Amazon Web Services (AWS) infrastructure in Ireland and Germany for hosting relevant services and data infrastructure. We may also use other service providers or payment partners located inside or outside the European Economic Area (EEA), depending on the service, merchant configuration and transaction route.
Where personal data is transferred from the EEA to a country not recognised by the European Commission as providing an adequate level of protection, PayMaxis will use an applicable transfer mechanism and safeguards where required, such as the European Commission’s Standard Contractual Clauses, together with supplementary measures where appropriate.
Where PayMaxis acts as a processor, the engagement of subprocessors and international transfers are additionally governed by the relevant data processing agreement and documented instructions of the controller.
9. Retention
PayMaxis retains personal data only for as long as reasonably necessary for the purposes for which it was collected or processed, including contractual, operational, security, dispute-resolution and legal-compliance requirements. Retention periods vary by data category and context.
- Merchant onboarding, contractual and compliance records may be retained for the duration of the relationship and for an appropriate period afterwards to meet legal, audit, dispute and record-keeping requirements.
- Transaction and technical records are retained in accordance with service requirements, contractual commitments, security needs, PCI DSS obligations where applicable, and the instructions of the relevant controller where PayMaxis acts as processor.
- Security logs may be retained for periods proportionate to cyber-security, fraud-prevention, incident-response and evidential needs.
- Marketing data is retained until consent is withdrawn, an objection is made, or the data is no longer needed, subject to maintaining a minimal suppression record where necessary to honour an opt-out.
Data may be retained for longer where required by law, regulatory requirement, litigation hold, investigation, or to establish, exercise or defend legal claims. When no longer required, data is deleted, anonymised or otherwise securely disposed of in accordance with applicable requirements.
10. Security
PayMaxis applies technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data. These measures include controls appropriate to the nature and risk of the processing, such as access management, encryption, network and infrastructure security, monitoring, vulnerability management, secure development practices, incident management, business continuity, supplier controls and staff awareness.
PayMaxis maintains PCI DSS Level 1 compliance for the payment-card environment within the applicable scope. No internet transmission or storage system can be guaranteed to be completely secure, and PayMaxis continually reviews and improves its controls based on risk and evolving threats.
11. Personal-Data Breaches
PayMaxis maintains procedures for assessing, containing, investigating and remediating personal-data breaches. Where PayMaxis acts as controller, it will notify the competent supervisory authority and affected individuals where required by applicable law. Where PayMaxis acts as processor, it will notify the relevant controller without undue delay in accordance with applicable law and the governing data processing agreement.
12. Your Rights
Subject to the conditions and limitations of applicable data-protection law, individuals may have rights to:
- obtain information about processing and access personal data;
- correct inaccurate or incomplete personal data;
- request erasure of personal data;
- restrict processing;
- object to processing based on legitimate interests and object at any time to direct marketing;
- withdraw consent where processing is based on consent;
- receive certain personal data in a structured, commonly used and machine-readable format and request portability where applicable;
- not be subject to a decision based solely on automated processing that produces legal or similarly significant effects, subject to applicable exceptions and safeguards;
- lodge a complaint with a competent data-protection supervisory authority.
Requests may be sent to
legal@paymaxis.com. We may need to verify your identity and may request information reasonably necessary to locate and assess the relevant records. Where PayMaxis processes data solely as processor for a merchant, we may refer the request to the relevant controller or assist that controller as required.
13. Cyprus Supervisory Authority
Individuals may lodge a complaint with the Office of the Commissioner for Personal Data Protection of the Republic of Cyprus or, where applicable, another competent EEA supervisory authority. We encourage you to contact PayMaxis first so that we can try to address your concern.
14. Children
PayMaxis services are provided to businesses and are not directed to children. We do not knowingly use the Website to solicit personal data from children. Transaction data concerning a minor may nevertheless be processed where a merchant lawfully offers services to minors and submits such data through PayMaxis; in that context the merchant remains responsible for the lawfulness of the underlying collection and processing where it acts as controller.
15. Changes to this Privacy Policy
We may update this Privacy Policy to reflect changes in law, technology, services or business practices. The revised Policy will be published with an updated effective date. Material changes may be communicated through additional channels where appropriate.
Contact
Questions, requests or concerns regarding this policy may be addressed to:
PayMaxis LTD
165, Spyrou Araouzou, Office 201A, 3036 Limassol, Cyprus
Email: legal@paymaxis.com