NexliPay
← Back to nexlipay.com

Privacy Policy

What personal data NexliPay handles, why we hold it, who we share it with, and the rights you have over it.

Last updated: [[DATE]]

Draft — not yet legal advice

This document is a working draft written to give a qualified lawyer a strong starting point. Every highlighted value is a fact only NexliPay can supply — entity name, jurisdiction, registration and licence numbers, addresses, named contacts. Do not publish this page until a solicitor licensed in your operating jurisdiction has reviewed it and every placeholder is filled with a true value.

01Who we are

NexliPay is a payment orchestration platform operated by LEGAL ENTITY NAME, a company registered in JURISDICTION under company number COMPANY NUMBER, with its registered office at REGISTERED ADDRESS. In this policy, “NexliPay”, “we” and “us” mean that entity.

For the purposes of UK GDPR and EU GDPR, we act as data controller for the personal data described below. Where we process payment data on behalf of a merchant customer, we act as data processor and the merchant is the controller. Our data protection contact is DPO OR PRIVACY CONTACT NAME, reachable at privacy@nexlipay.com.

02What we collect

CategoryExamplesWhy we hold it
Account dataName, work email, phone, job title, password hashTo create and secure your NexliPay account
Business & verification dataLegal entity details, registration documents, beneficial ownership, identity documentsKYC, KYB and anti-money-laundering obligations
Connected processor dataProcessor account identifiers, API credentials, settlement configurationTo route transactions across accounts you own
Transaction metadataAmount, currency, timestamp, card network, BIN, last four digits, decline codes, routing decisionsTo route, retry, reconcile and report on payments
Usage & device dataIP address, browser and device type, pages viewed, session timestampsSecurity, fraud prevention and product improvement
CommunicationsEmails, support tickets, call notesTo support you and keep a record of what was agreed

We do not store full primary account numbers (PANs) or card verification values. Card data is handled by your connected processors within their own PCI DSS environments; NexliPay receives only tokenised references and the metadata listed above.

03Legal bases for processing

  • Performance of a contract — providing the orchestration service you signed up for, including routing, settlement reporting and support.
  • Legal obligation — identity verification, sanctions screening, AML monitoring, tax and record-keeping requirements.
  • Legitimate interests — securing the platform, preventing fraud and abuse, and improving the product, balanced against your rights.
  • Consent — marketing communications and non-essential cookies only. You can withdraw consent at any time without affecting the service.

04Who we share data with

We share personal data only where it is necessary to deliver the service or meet a legal duty. We do not sell personal data, and we do not share it for third-party advertising.

  • Payment processors and acquirers you have connected, for the purpose of routing your own transactions.
  • Identity, sanctions and AML screening providers: SCREENING PROVIDER(S).
  • Infrastructure and hosting providers: HOSTING PROVIDER, located in HOSTING REGION.
  • Professional advisers, auditors and insurers, under duties of confidentiality.
  • Regulators, law enforcement and courts, where we are legally required to disclose.

05International transfers

Where personal data leaves the UK or EEA, we rely on an adequacy decision where one exists, and otherwise on UK International Data Transfer Agreements or EU Standard Contractual Clauses together with a transfer risk assessment. Our current transfer destinations are TRANSFER DESTINATIONS. You can request a copy of the safeguards in place.

06How long we keep it

DataRetention period
Account and contract recordsDuration of the relationship plus 6 years
KYC, KYB and AML records5 years from the end of the business relationship, per APPLICABLE AML REGULATIONS
Transaction and settlement metadataRETENTION PERIOD, aligned to card scheme and audit requirements
Support communications3 years from last contact
Marketing consent recordsUntil withdrawn, plus 2 years as proof of consent

07Your rights

Subject to legal limits — AML records in particular cannot simply be deleted on request — you have the right to access your data, correct it, erase it, restrict or object to processing, receive it in a portable format, and withdraw consent. You may also object to automated decision-making that has a legal or similarly significant effect on you.

To exercise any right, contact privacy@nexlipay.com. We respond within one month. If you are unhappy with our response you can complain to the SUPERVISORY AUTHORITY, e.g. UK ICO at AUTHORITY CONTACT DETAILS.

08Automated routing decisions

NexliPay scores transactions and selects a processor account automatically. These decisions concern which of your own accounts handles a payment; they do not profile individual cardholders or determine whether a person may access credit or a service. Where a transaction is declined, the decline originates from the processor or issuer, not from NexliPay. You can request an explanation of a routing decision at any time.

09Cookies

We use strictly necessary cookies for authentication and security, and — only with your consent — analytics cookies to understand how the site is used. You can change your choices at any time through the cookie settings link in the footer. A full cookie inventory is maintained at COOKIE INVENTORY LOCATION.

10Changes to this policy

We will post any changes on this page and update the date above. Where a change materially affects your rights we will notify you by email at least NOTICE PERIOD before it takes effect.

Questions?

Write to legal@nexlipay.com or use the contact page.