Data Protection Policy (GDPR) & DPIA Summary

wave shape

Data Protection Policy (GDPR) & DPIA Summary

Last Updated September 26, 2026

Customer Data Protection Policy (GDPR) and DPIA Summary

Version1.0
Effective date26 September 2026
ControllerAYDAPAY SP. Z O.O., Aleja Armii Ludowej 6/164, 00-571 Warsaw, Poland (KRS 0001036277, NIP 5214021930, REGON 525460979)
Approved byManagement Board of AYDAPAY SP. Z O.O.
Review cycleAt least annually, and whenever the law, our services or our providers change
Legal frameworkRegulation (EU) 2016/679 (GDPR); Polish Act of 10 May 2018 on the Protection of Personal Data; Polish Act of 19 August 2011 on Payment Services; Polish Act of 1 March 2018 on Counteracting Money Laundering and Terrorist Financing; Customer Account Agreement, clause 17

Protecting the personal and financial information of our customers is central to how AYDAPAY works. This Policy explains, in clear language, what personal data we hold, why we hold it, who we share it with, how long we keep it, how we keep it secure and what rights you have. It applies to Individual Customers, representatives, directors, beneficial owners and authorised users of Business Customers, payees, and anyone who contacts us.

This Policy should be read together with our Privacy Policy (which also covers cookies and our website) and clause 17 of the Customer Account Agreement. If there is any conflict, the Customer Account Agreement prevails.

1. Our commitments to you

  • We never sell your personal data and never share it for other companies' marketing.
  • We collect only the data we need, and use it only for the purposes described in this Policy.
  • We keep your payment information confidential under the professional secrecy rules of the Polish Act on Payment Services.
  • We protect your data with technical and organisational security measures appropriate to a regulated financial service.
  • No account is refused or closed, and no payment is permanently rejected, solely by an automated system: a trained member of staff always reviews the decision.
  • We respond to data protection requests within one month, free of charge.

2. Who is responsible for your data

AYDAPAY SP. Z O.O. is the controller of your personal data for the AYDAPAY App, website and AYDAPAY Services. For data protection questions or to exercise your rights, contact us:

  • Email: help@aydapay.com (subject: "Data Protection")
  • In the App: Support / Help section
  • Post: AYDAPAY SP. Z O.O. – Data Protection, Aleja Armii Ludowej 6/164, 00-571 Warsaw, Poland

Where a service in the App is provided by one of our regulated partners under its own licence ("Partner Services", Customer Account Agreement clause 1.4), that partner processes your data as an independent controller under its own privacy notice, which we provide on request. AYDAPAY remains your single point of contact for all data protection questions.

3. What personal data we collect

CategoryExamplesSource
Identity dataFull name, date of birth, nationality, identity document details and imagesYou; our identity verification provider
Biometric dataSelfie, liveness check and face match used to confirm that you are the holder of the identity documentYou, with your explicit consent
Contact dataAddress, email address, telephone numberYou
Business dataCompany registration details, directors, shareholders and beneficial owners, business activityYou; public registers
Financial and transaction dataAccount details, balances, payments, payees, purpose of payment, source of funds and wealthYou; our payment partners
Compliance dataSanctions, PEP and adverse-media screening results, risk rating, due diligence recordsScreening providers; public sources
Technical and security dataDevice identifiers, IP address, log-in history, App version, security logsYour device and the App
CommunicationsSupport messages, complaints, call notes and recordingsYou
Payee dataName, account or wallet details and country of the person you payYou

AYDAPAY services are for adults only. We do not knowingly collect data from anyone under 18.

4. Why we use your data and our legal basis

PurposeLegal basis (GDPR)
Opening and operating your account, executing payments and international transfers, currency exchange, customer supportPerformance of a contract – Art. 6(1)(b)
Customer due diligence (KYC/KYB), sanctions screening, transaction monitoring, reporting to the General Inspector of Financial Information (GIIF), record keeping, tax and accounting obligations, handling complaints, reporting to the KNFLegal obligation – Art. 6(1)(c)
Biometric identity verificationExplicit consent – Art. 9(2)(a). You may refuse; we then offer an alternative verification method where available
Fraud and scam prevention beyond the legal minimum, securing our systems, establishing or defending legal claimsLegitimate interests – Art. 6(1)(f)
News and offers about our own servicesConsent – Art. 6(1)(a), which you can withdraw at any time

5. Identity verification, biometrics and automated decisions

  • We verify identity using a regulated-grade identity verification provider that checks your document and performs a liveness check and face match. Biometric data is used only to confirm your identity and is not used for any other purpose.
  • Biometric data is kept only for as long as needed to complete verification. We keep the verification result and the audit record, as required by anti-money laundering law.
  • We use automated systems, including AI-assisted tools, for identity verification, sanctions screening, fraud detection and transaction monitoring. Alerts are reviewed by trained staff.
  • If a decision based solely on automated processing has a legal or similarly significant effect on you, you can ask for human review, express your point of view and contest the decision (GDPR Art. 22).

6. Who we share your data with

We share personal data only where necessary and only with:

  • Regulated partners – our Banking Partner, Money Transfer Partner and licensed payout partners in the destination country, to provide and execute your payments;
  • Service providers acting on our instructions – identity verification, sanctions and PEP screening, fraud prevention, cloud hosting, communications and customer support tools;
  • Professional advisers – auditors and legal advisers, under confidentiality obligations;
  • Public authorities – including the Polish Financial Supervision Authority (KNF), the General Inspector of Financial Information (GIIF), tax authorities, courts and law enforcement, only where the law requires it.

Every service provider that processes data on our behalf is bound by a written data processing agreement under GDPR Art. 28, is subject to due diligence before appointment and may use the data only to provide its service to AYDAPAY.

7. International transfers

Some recipients are located outside the European Economic Area (EEA). We transfer data outside the EEA only where:

  • the European Commission has recognised the country as providing adequate protection (for example, the United Kingdom);
  • we have put in place the European Commission's Standard Contractual Clauses together with a transfer risk assessment; or
  • the transfer is necessary to perform a payment you have instructed to a recipient in that country (GDPR Art. 49(1)(b)).

You may request information about the safeguards applied to a transfer by contacting us.

8. How long we keep your data

DataRetention period
Customer due diligence and transaction records5 years from the end of the business relationship or the date of an occasional transaction (may be extended by up to a further 5 years at the request of the competent authority), as required by the Polish AML Act
Complaints recordsAt least 5 years
Accounting and tax records5 years from the end of the relevant tax year
Contract acceptance evidence and security logs5 years after the end of the relationship
Marketing preferencesUntil you withdraw your consent
Biometric dataOnly for as long as needed to complete verification

At the end of the retention period, data is securely deleted or irreversibly anonymised.

9. How we keep your data secure

We apply technical and organisational measures appropriate to the risks of a regulated payment service, including:

  • Encryption of data in transit and at rest;
  • Strong Customer Authentication for log-in and payments, device binding and automatic session timeout;
  • Role-based access control on a need-to-know basis, with access logs and restricted access to compliance records;
  • Tamper-evident logging and continuous monitoring of our systems for suspicious activity;
  • Data minimisation – we send providers only the data they need;
  • Data Protection Impact Assessments for high-risk processing, such as biometric verification and automated monitoring;
  • Staff confidentiality undertakings and regular data protection, security and AML training;
  • Vendor due diligence and contractual audit rights over our processors;
  • Regular security testing, including independent penetration testing, and business continuity arrangements.

9A. Data Protection Impact Assessment (DPIA) – public summary

Under GDPR Art. 35 and the list of processing operations published by the President of UODO, we have carried out a Data Protection Impact Assessment for our highest-risk processing. It is approved by the Management Board and reviewed at least annually, and whenever our providers, models or monitoring rules change.

ElementSummary
Processing assessed(a) Onboarding identity verification: document capture, selfie / liveness check and face match; (b) sanctions, PEP and adverse-media screening; (c) ongoing transaction monitoring with rules and risk scoring; (d) fraud and scam detection using device, behavioural and payment signals
PurposesMeeting obligations under the Polish AML Act and Regulation (EU) 2023/1113; preventing fraud; protecting customers; meeting regulated partner requirements
Data subjectsIndividual Customers, representatives and beneficial owners of Business Customers, authorised users, payees
Special category dataBiometric data used to uniquely identify a person (GDPR Art. 9), processed only with explicit consent and with an alternative verification route
Necessity and proportionalityLegal obligation (Art. 6(1)(c)) for due diligence and monitoring; legitimate interest (Art. 6(1)(f)) for fraud prevention beyond the legal minimum, supported by a documented balancing test; only the data a provider needs is shared; raw video is not kept after the check
Automated decisionsNo account is refused or closed and no payment permanently rejected solely by an automated system; alerts are reviewed by trained staff and customers can request human review
Risk to individualsMain measuresResidual risk
Biometric data leaked or reusedProcessor contract under Art. 28; encryption in transit and at rest; limited retention; no use for other purposes; audit rightsLow
False rejection at identity verificationAlternative verification route; manual review of every failed checkLow
Incorrect sanctions / PEP match blocks a customerFour-eyes review of matches; release within 2 Business Days once a false positive is confirmed; customer informed where the law allowsLow
Over-blocking by monitoring rulesQuarterly rule tuning; human review; complaints route; time limits on holdsLow to medium
Transfer to a country without adequate protectionAdequacy decisions, Standard Contractual Clauses, transfer risk assessments, partner due diligenceLow
Misuse of data by staffRole-based access, access logs, confidentiality undertakings, trainingLow

Outcome: with these measures in place the residual risk is acceptable, so prior consultation with the President of UODO under GDPR Art. 36 is not required. The full DPIA is available to the supervisory authority on request.

10. If a data breach happens

We maintain a documented Personal Data Breach Procedure. If a breach is likely to result in a risk to individuals, we notify the President of the Personal Data Protection Office (UODO) within 72 hours of becoming aware of it. If the risk to you is high, we tell you without undue delay, in clear language, what happened, what we have done and what you should do to protect yourself. Every breach, whether notified or not, is recorded and reviewed so that it does not happen again.

11. Your rights

RightWhat it means
AccessObtain a copy of your personal data and information about how we use it
RectificationHave inaccurate or incomplete data corrected
ErasureHave your data deleted where there is no legal reason for us to keep it
RestrictionAsk us to limit the use of your data in certain cases
PortabilityReceive the data you gave us in a machine-readable format (CSV or JSON)
ObjectionObject to processing based on legitimate interests, and at any time to direct marketing
Withdraw consentWithdraw consent (for example, for marketing or biometrics) at any time, without affecting earlier processing
Human reviewAsk for a person to review a decision made solely by automated means

How to exercise your rights: contact us through the App or at help@aydapay.com. We will verify your identity using your App log-in or registered email address, and reply within one month (extendable by two further months for complex requests, in which case we will tell you why within the first month). Requests are free of charge unless they are manifestly unfounded or excessive.

Legal limits: some rights are limited where the law requires us to keep data – for example, anti-money laundering records must be kept for 5 years. The law may also prevent us from disclosing certain information connected with anti-money laundering reviews or reports to the authorities.

12. How you can protect your data

  • AYDAPAY will never ask you for your password or one-time codes, ask you to move money to a "safe account", or ask you to install remote-access software.
  • We contact you only through the App, www.aydapay.com, emails from the aydapay.com domain and our official phone numbers.
  • Keep your device locked and your App updated, and report any suspicious contact or unrecognised activity immediately to help@aydapay.com or through the App.

13. Complaints to the supervisory authority

If you are unhappy with how we handle your data, please contact us first so that we can put it right. You also have the right to lodge a complaint with the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych – UODO), ul. Stawki 2, 00-193 Warsaw, Poland, www.uodo.gov.pl, or with the data protection authority in the EU/EEA country where you live or work.

14. Changes to this Policy

We review this Policy at least once a year. If we make significant changes, we will inform you in the App or by email before they take effect. The current version is always available on our website and in the App.

AYDAPAY SP. Z O.O. · Aleja Armii Ludowej 6/164, 00-571 Warsaw, Poland · KRS 0001036277 · NIP 5214021930 · REGON 525460979 · help@aydapay.com

Need Help?

If you have any questions about our Data Protection Policy (GDPR) & DPIA Summary, please don't hesitate to contact us.

How can I contact customer support?