Effective Date: February 14, 2025
Last Updated: February 14, 2025
Controller:
GHPay International Ltd.
20-22 Wenlock Road, London N1 7GU, UK
EU Representative:
GHPay EU Representative Office
Amsterdam Science Park 602, 1098 XH Amsterdam
Data Protection Officer (DPO):
dpo@ghpay.com
We process personal data under the following GDPR Article 6 conditions:
✅ Contractual Necessity
For payment processing and service delivery
✅ Legal Obligation
Anti-money laundering (AML) and tax compliance
✅ Legitimate Interests
Fraud prevention and service optimization
✅ Consent
Marketing communications and cookies
Data Type | Processing Purpose | Retention Period |
---|---|---|
Identity Verification | KYC/AML compliance | 7 years post-account closure |
Transaction Records | Payment processing & dispute resolution | 10 years |
Device Fingerprinting | Fraud detection | 3 years |
Marketing Preferences | Targeted communication | Until consent withdrawal |
We implement safeguards per GDPR Chapter V:
🔒 Standard Contractual Clauses (SCCs)
Used with non-adequate jurisdiction partners
🔒 Binding Corporate Rules (BCRs)
For intra-group data transfers
🔒 Adequacy Decisions
Applicable for EU-US Data Privacy Framework participants
Access/Portability
Request your data in machine-readable format (JSON/CSV)
Rectification
Update inaccurate records via account dashboard
Erasure
Submit deletion requests through our Data Rights Portal
Restriction/Objection
Temporarily freeze processing during disputes
Technical Safeguards
Organizational Controls
We utilize AI/ML systems for:
🤖 Risk Scoring
Transaction fraud probability analysis
🤖 Payment Routing
Optimal gateway selection
You may request human intervention via support ticket
Policy Updates
Notify users 30 days prior to material changes
Complaint Channels