| Version | 1.0 |
| Effective date | 26 September 2026 |
| Controller | AYDAPAY SP. Z O.O., Aleja Armii Ludowej 6/164, 00-571 Warsaw, Poland (KRS 0001036277, NIP 5214021930, REGON 525460979) |
| Approved by | Management Board of AYDAPAY SP. Z O.O. |
| Review cycle | At least annually, and whenever the law, our services or our providers change |
| Legal framework | Regulation (EU) 2016/679 (GDPR); Polish Act of 10 May 2018 on the Protection of Personal Data; Polish Act of 19 August 2011 on Payment Services; Polish Act of 1 March 2018 on Counteracting Money Laundering and Terrorist Financing; Customer Account Agreement, clause 17 |
Protecting the personal and financial information of our customers is central to how AYDAPAY works. This Policy explains, in clear language, what personal data we hold, why we hold it, who we share it with, how long we keep it, how we keep it secure and what rights you have. It applies to Individual Customers, representatives, directors, beneficial owners and authorised users of Business Customers, payees, and anyone who contacts us.
This Policy should be read together with our Privacy Policy (which also covers cookies and our website) and clause 17 of the Customer Account Agreement. If there is any conflict, the Customer Account Agreement prevails.
AYDAPAY SP. Z O.O. is the controller of your personal data for the AYDAPAY App, website and AYDAPAY Services. For data protection questions or to exercise your rights, contact us:
Where a service in the App is provided by one of our regulated partners under its own licence ("Partner Services", Customer Account Agreement clause 1.4), that partner processes your data as an independent controller under its own privacy notice, which we provide on request. AYDAPAY remains your single point of contact for all data protection questions.
| Category | Examples | Source |
|---|---|---|
| Identity data | Full name, date of birth, nationality, identity document details and images | You; our identity verification provider |
| Biometric data | Selfie, liveness check and face match used to confirm that you are the holder of the identity document | You, with your explicit consent |
| Contact data | Address, email address, telephone number | You |
| Business data | Company registration details, directors, shareholders and beneficial owners, business activity | You; public registers |
| Financial and transaction data | Account details, balances, payments, payees, purpose of payment, source of funds and wealth | You; our payment partners |
| Compliance data | Sanctions, PEP and adverse-media screening results, risk rating, due diligence records | Screening providers; public sources |
| Technical and security data | Device identifiers, IP address, log-in history, App version, security logs | Your device and the App |
| Communications | Support messages, complaints, call notes and recordings | You |
| Payee data | Name, account or wallet details and country of the person you pay | You |
AYDAPAY services are for adults only. We do not knowingly collect data from anyone under 18.
| Purpose | Legal basis (GDPR) |
|---|---|
| Opening and operating your account, executing payments and international transfers, currency exchange, customer support | Performance of a contract – Art. 6(1)(b) |
| Customer due diligence (KYC/KYB), sanctions screening, transaction monitoring, reporting to the General Inspector of Financial Information (GIIF), record keeping, tax and accounting obligations, handling complaints, reporting to the KNF | Legal obligation – Art. 6(1)(c) |
| Biometric identity verification | Explicit consent – Art. 9(2)(a). You may refuse; we then offer an alternative verification method where available |
| Fraud and scam prevention beyond the legal minimum, securing our systems, establishing or defending legal claims | Legitimate interests – Art. 6(1)(f) |
| News and offers about our own services | Consent – Art. 6(1)(a), which you can withdraw at any time |
We share personal data only where necessary and only with:
Every service provider that processes data on our behalf is bound by a written data processing agreement under GDPR Art. 28, is subject to due diligence before appointment and may use the data only to provide its service to AYDAPAY.
Some recipients are located outside the European Economic Area (EEA). We transfer data outside the EEA only where:
You may request information about the safeguards applied to a transfer by contacting us.
| Data | Retention period |
|---|---|
| Customer due diligence and transaction records | 5 years from the end of the business relationship or the date of an occasional transaction (may be extended by up to a further 5 years at the request of the competent authority), as required by the Polish AML Act |
| Complaints records | At least 5 years |
| Accounting and tax records | 5 years from the end of the relevant tax year |
| Contract acceptance evidence and security logs | 5 years after the end of the relationship |
| Marketing preferences | Until you withdraw your consent |
| Biometric data | Only for as long as needed to complete verification |
At the end of the retention period, data is securely deleted or irreversibly anonymised.
We apply technical and organisational measures appropriate to the risks of a regulated payment service, including:
Under GDPR Art. 35 and the list of processing operations published by the President of UODO, we have carried out a Data Protection Impact Assessment for our highest-risk processing. It is approved by the Management Board and reviewed at least annually, and whenever our providers, models or monitoring rules change.
| Element | Summary |
|---|---|
| Processing assessed | (a) Onboarding identity verification: document capture, selfie / liveness check and face match; (b) sanctions, PEP and adverse-media screening; (c) ongoing transaction monitoring with rules and risk scoring; (d) fraud and scam detection using device, behavioural and payment signals |
| Purposes | Meeting obligations under the Polish AML Act and Regulation (EU) 2023/1113; preventing fraud; protecting customers; meeting regulated partner requirements |
| Data subjects | Individual Customers, representatives and beneficial owners of Business Customers, authorised users, payees |
| Special category data | Biometric data used to uniquely identify a person (GDPR Art. 9), processed only with explicit consent and with an alternative verification route |
| Necessity and proportionality | Legal obligation (Art. 6(1)(c)) for due diligence and monitoring; legitimate interest (Art. 6(1)(f)) for fraud prevention beyond the legal minimum, supported by a documented balancing test; only the data a provider needs is shared; raw video is not kept after the check |
| Automated decisions | No account is refused or closed and no payment permanently rejected solely by an automated system; alerts are reviewed by trained staff and customers can request human review |
| Risk to individuals | Main measures | Residual risk |
|---|---|---|
| Biometric data leaked or reused | Processor contract under Art. 28; encryption in transit and at rest; limited retention; no use for other purposes; audit rights | Low |
| False rejection at identity verification | Alternative verification route; manual review of every failed check | Low |
| Incorrect sanctions / PEP match blocks a customer | Four-eyes review of matches; release within 2 Business Days once a false positive is confirmed; customer informed where the law allows | Low |
| Over-blocking by monitoring rules | Quarterly rule tuning; human review; complaints route; time limits on holds | Low to medium |
| Transfer to a country without adequate protection | Adequacy decisions, Standard Contractual Clauses, transfer risk assessments, partner due diligence | Low |
| Misuse of data by staff | Role-based access, access logs, confidentiality undertakings, training | Low |
Outcome: with these measures in place the residual risk is acceptable, so prior consultation with the President of UODO under GDPR Art. 36 is not required. The full DPIA is available to the supervisory authority on request.
We maintain a documented Personal Data Breach Procedure. If a breach is likely to result in a risk to individuals, we notify the President of the Personal Data Protection Office (UODO) within 72 hours of becoming aware of it. If the risk to you is high, we tell you without undue delay, in clear language, what happened, what we have done and what you should do to protect yourself. Every breach, whether notified or not, is recorded and reviewed so that it does not happen again.
| Right | What it means |
|---|---|
| Access | Obtain a copy of your personal data and information about how we use it |
| Rectification | Have inaccurate or incomplete data corrected |
| Erasure | Have your data deleted where there is no legal reason for us to keep it |
| Restriction | Ask us to limit the use of your data in certain cases |
| Portability | Receive the data you gave us in a machine-readable format (CSV or JSON) |
| Objection | Object to processing based on legitimate interests, and at any time to direct marketing |
| Withdraw consent | Withdraw consent (for example, for marketing or biometrics) at any time, without affecting earlier processing |
| Human review | Ask for a person to review a decision made solely by automated means |
How to exercise your rights: contact us through the App or at help@aydapay.com. We will verify your identity using your App log-in or registered email address, and reply within one month (extendable by two further months for complex requests, in which case we will tell you why within the first month). Requests are free of charge unless they are manifestly unfounded or excessive.
Legal limits: some rights are limited where the law requires us to keep data – for example, anti-money laundering records must be kept for 5 years. The law may also prevent us from disclosing certain information connected with anti-money laundering reviews or reports to the authorities.
If you are unhappy with how we handle your data, please contact us first so that we can put it right. You also have the right to lodge a complaint with the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych – UODO), ul. Stawki 2, 00-193 Warsaw, Poland, www.uodo.gov.pl, or with the data protection authority in the EU/EEA country where you live or work.
We review this Policy at least once a year. If we make significant changes, we will inform you in the App or by email before they take effect. The current version is always available on our website and in the App.
AYDAPAY SP. Z O.O. · Aleja Armii Ludowej 6/164, 00-571 Warsaw, Poland · KRS 0001036277 · NIP 5214021930 · REGON 525460979 · help@aydapay.com
If you have any questions about our Data Protection Policy (GDPR) & DPIA Summary, please don't hesitate to contact us.
How can I contact customer support?