Regulatory Status and Compliance Framework

wave shape

Regulatory Status and Compliance Framework

Last Updated September 26, 2026

Regulatory Status and Compliance Framework

Version1.0
Effective date26 September 2026
Approved byManagement Board of AYDAPAY SP. Z O.O.
Intended forCustomers, banking and payment partners, correspondent institutions, auditors and supervisory authorities

This page gives a transparent overview of who AYDAPAY is, how we are regulated, how our services are delivered and how we manage financial crime, customer protection and data protection risks. The legally binding terms for customers are set out in the Customer Account Agreement.

1. Corporate information

Legal nameAYDAPAY spółka z ograniczoną odpowiedzialnością (AYDAPAY SP. Z O.O.)
Legal formPolish limited liability company
Registered officeAleja Armii Ludowej 6/164, 00-571 Warsaw, Poland
KRS0001036277 (National Court Register)
NIP5214021930
REGON525460979
Share capitalPLN 230,000, fully paid up
Contacthelp@aydapay.com · +48 737 660 344 · www.aydapay.com

2. Regulatory status

  • AYDAPAY is entered in the register of payment service providers maintained by the Polish Financial Supervision Authority (Komisja Nadzoru Finansowego – KNF), ul. PiÄ™kna 20, 00-549 Warsaw, as a small payment institution under the Polish Act of 19 August 2011 on Payment Services. Our status can be verified in the public register at www.knf.gov.pl.
  • Our own authorisation permits us to provide payment services in the territory of Poland only. It does not permit us to provide payment services in other countries or cross-border payment services.
  • AYDAPAY is not a bank. We do not accept deposits, grant credit or pay interest. Customer balances are not covered by any deposit guarantee scheme; they are protected by safeguarding (see section 6).
  • We are an obligated institution under the Polish Act of 1 March 2018 on Counteracting Money Laundering and Terrorist Financing and report to the General Inspector of Financial Information (GIIF).
  • As a controller of personal data, we are supervised by the President of the Personal Data Protection Office (UODO).

3. How our services are delivered

ServiceProvided by
The AYDAPAY App and technology, customer onboarding and verification, customer support and complaints handling for all servicesAYDAPAY
Domestic payment services in Poland for customers resident or established in PolandAYDAPAY, under its own authorisation
Account Details (IBAN / account numbers), holding and safeguarding of customer funds, payments to and from accounts outside Poland, and all payment services for customers outside PolandOur Banking Partner – an electronic money institution authorised and supervised by the UK Financial Conduct Authority
International money transfers and related currency conversionOur Money Transfer Partner – a money remittance institution authorised in the UK and the EU – and licensed payout partners in the destination country
Card and Open Banking fundingAuthorised card acquirers and payment initiation service providers

For Partner Services, AYDAPAY acts as a technology and distribution partner of the regulated partner and does not itself provide those regulated payment services. Before a customer uses a Partner Service, and at any time on request, we provide the name, registered office, supervisory authority and licence number of the partner providing it. AYDAPAY never describes itself as holding a licence it does not hold, and never presents partner services as its own regulated services.

4. Governance

  • The Management Board is responsible for the compliance framework and approves all policies, which are reviewed at least annually and before any new product, partner or country is launched.
  • A Money Laundering Reporting Officer (MLRO) is appointed by the Management Board, with direct access to the Board, independence in reporting decisions and responsibility for the AML/CFT programme.
  • Our AML/CFT programme is subject to independent review by an external auditor.
  • We maintain a compliance calendar with daily, monthly, quarterly and annual controls, and keep evidence of every control performed.

5. Anti-money laundering, counter-terrorist financing and sanctions

We apply a risk-based approach in line with the Polish AML Act, EU anti-money laundering legislation (including Regulation (EU) 2023/1113 on information accompanying transfers of funds) and FATF Recommendations.

ControlHow it works
Business-wide risk assessmentDocumented and updated at least annually and whenever our products, partners or countries change
Customer due diligence – individualsValid passport, national ID card or residence document, with a live selfie (liveness check) and face match through our identity verification provider; proof of address and source of funds or wealth where required
Customer due diligence – businesses (KYB)Registration extract, articles of association, shareholder and director registers, proof of address, description of activity and expected transactions; identity verification of directors, authorised representatives, authorised users and beneficial owners
Sanctions, PEP and adverse-media screeningAt onboarding and on every payment, against UN, EU, Polish, UK, US (OFAC), Canadian and other applicable lists; potential matches are reviewed under the four-eyes principle
Enhanced due diligenceFor higher-risk customers, politically exposed persons, unusual activity and higher-risk corridors, including source of funds, source of wealth and purpose of payment, with supporting documents such as invoices and contracts
Ongoing monitoringContinuous rule-based and AI-assisted transaction monitoring, with every alert reviewed by trained staff; accounts with abnormal activity may be restricted pending review
Restricted jurisdictions and prohibited activitiesWe do not onboard customers from comprehensively sanctioned countries, FATF "call for action" countries or EU high-risk third countries, and we do not serve prohibited activities (for example unlicensed gambling, weapons, virtual assets, unlicensed financial services, shell companies and cash-intensive businesses). Money service businesses are reviewed individually and must hold a valid licence
LimitsTransaction and balance limits based on the customer's risk profile, partner requirements and the law
Suspicious activity reportingSuspicious transactions are reported to GIIF by the MLRO, in compliance with the prohibition on tipping off
Travel rulePayer and payee information accompanies transfers of funds as required by Regulation (EU) 2023/1113
Record keepingDue diligence and transaction records kept for 5 years after the end of the relationship or transaction
TrainingAnnual AML/CFT and sanctions training for all staff, with assessment and attendance records

Our services are provided online only; we do not accept or pay out cash.

6. Safeguarding of customer funds

  • Customer funds are kept separate from AYDAPAY's own money and are never used to run the business.
  • Funds received for Partner Services are held in segregated customer-funds accounts with our Banking Partner, which safeguards them under its regulatory obligations.
  • Funds received by AYDAPAY for its own services in Poland are deposited no later than the end of the next Business Day in a separate account with a bank, or protected in another way required by the Polish Act on Payment Services.
  • Safeguarded balances are reconciled daily, and partner balance statements are obtained and reviewed monthly.
  • Balances held on accounts maintained by AYDAPAY under its own authorisation are limited to the equivalent of EUR 2,000 per customer, as required for small payment institutions.

See our Safeguarding Statement for details.

7. Customer protection and fraud prevention

  • Strong Customer Authentication for log-in and payments.
  • Verification of Payee for euro transfers within the EU/EEA and Confirmation of Payee in the UK, where supported by the payment scheme.
  • Scam warnings at the time of payment for higher-risk payments, and holding periods for card and Open Banking funding to protect against fraud.
  • All fees, exchange rates, the amount the recipient will receive and delivery times are shown before every payment.
  • Refund of unauthorised payments by the end of the next Business Day, in line with the Polish Act on Payment Services.
  • A 14-day right of withdrawal for Individual Customers.

See our Customer Protection & Fraud Awareness Policy for details.

8. Data protection and information security

We comply with the GDPR and Polish data protection law. We carry out Data Protection Impact Assessments for high-risk processing, keep a Record of Processing Activities, bind every processor by a data processing agreement, apply encryption and role-based access controls, and maintain breach-notification and data-subject-request procedures. See our Customer Data Protection Policy and Privacy Policy.

9. Complaints

Complaints are acknowledged within 2 Business Days and answered within 15 Business Days (35 Business Days in particularly complex cases), in line with the Polish Act of 5 August 2015 on complaints handling by financial market entities. Customers may escalate to the Financial Ombudsman (Rzecznik Finansowy), the KNF or the courts. See our Complaints Policy.

10. Partner oversight and operational resilience

  • We verify each partner's licence in the official register at onboarding and quarterly.
  • Responsibilities for KYC, monitoring, sanctions, complaints and safeguarding are agreed in writing with each partner.
  • We review partner incidents, audit findings and complaint data regularly, and maintain an exit plan to protect customers if a partner stops providing a service.
  • We maintain business continuity and incident response arrangements, and notify the KNF, UODO and affected partners of significant incidents as required by law and contract.

11. Information for partners and due diligence requests

Banks, payment institutions and other partners conducting due diligence on AYDAPAY may request our corporate documents, ownership and management structure, AML/CFT policy and procedures, risk assessment summary, independent audit findings and completed due diligence questionnaires. Requests should be sent to help@aydapay.com with the subject "Partner Due Diligence". Confidential documents are shared under a non-disclosure agreement.

12. Related documents

  • Terms and Conditions (Customer Account Agreement)
  • Privacy Policy
  • Customer Data Protection Policy
  • Safeguarding Statement
  • Complaints Policy
  • Refund & Cancellation Policy
  • Customer Protection & Fraud Awareness Policy
  • Anti-Money Laundering, Fraud Prevention and Customer Protection Policy

AYDAPAY SP. Z O.O. · Aleja Armii Ludowej 6/164, 00-571 Warsaw, Poland · KRS 0001036277 · NIP 5214021930 · REGON 525460979 · help@aydapay.com

Need Help?

If you have any questions about our Regulatory Status and Compliance Framework, please don't hesitate to contact us.

How can I contact customer support?