Privacy Policy
WayToPay is committed to protecting your privacy and ensuring the security of your personal information.
Privacy Policy (GDPR)
WayToPay
Effective Date: August 6, 2025
1. General Provisions
This Privacy Policy (hereinafter referred to as the "Policy") explains what personal data is collected, used, and stored by WayToPay s.r.o. (hereinafter referred to as the "Company") when you use the website www.waytopay.io (the "Platform"), and how such data is processed in accordance with Regulation (EU) 2016/679 (GDPR).
2. Data We Collect
WayToPay may collect the following categories of personal data:
- Full name, email address, and phone number;
- Identification documents, selfies, video recordings;
- Device data, IP address, cookies;
- Transaction history and activity logs on the Platform.
3. Purposes of Processing
Your data is processed for the following purposes:
- Identity verification (KYC);
- Compliance with AML regulations;
- Provision and customization of services;
- Customer support and notifications;
- Platform optimization and improvement;
- Legal and regulatory compliance (e.g. MiCA, GDPR).
4. Legal Basis for Processing
Data processing is based on one or more of the following legal grounds:
- Performance of a contract (Platform access and services);
- Legal obligation (AML/KYC compliance);
- Legitimate interest (e.g. security, fraud prevention, analytics);
- Consent (for marketing, cookies, etc.).
5. Data Sharing with Third Parties
Personal data may be shared with:
- Verification providers (e.g., SumSub);
- AML/CTF tools (e.g., Crystal Blockchain);
- IT infrastructure and hosting providers;
- Legal and financial consultants;
- Governmental and supervisory authorities upon lawful request.
All third-party service providers are contractually bound to comply with GDPR and maintain strict confidentiality.
6. Cookies
We use cookies to improve functionality, security, analytics, and user experience.
You may disable cookies in your browser settings.
More info: www.aboutcookies.org
7. Data Retention Period
All data is retained for a minimum of 5 years following the termination of the business relationship, in compliance with AML obligations.
8. Your Rights under GDPR
You have the right to:
- Access, rectify, or delete your data;
- Restrict or object to data processing;
- Data portability;
- Withdraw consent at any time (where applicable);
- Lodge a complaint with a supervisory authority in the EU.
9. Data Security
WayToPay implements technical and organizational measures, including but not limited to:
- Data encryption;
- Access control systems;
- Activity audit trails;
- Secure backups.
However, absolute security cannot be guaranteed due to the nature of online systems.
10. Contact Information
For any inquiries regarding this Policy or your data rights, please contact:
Data Controller
WayToPay s.r.o.
Registered in: Czech Republic
Company Registration Number: 219 28 606
Withdrawal of Consent
You may withdraw your consent to data processing at any time by sending a request to [email protected].