Privacy Policy
What personal data NexliPay handles, why we hold it, who we share it with, and the rights you have over it.
Last updated: [[DATE]]
Draft — not yet legal advice
This document is a working draft written to give a qualified lawyer a strong starting point. Every highlighted value is a fact only NexliPay can supply — entity name, jurisdiction, registration and licence numbers, addresses, named contacts. Do not publish this page until a solicitor licensed in your operating jurisdiction has reviewed it and every placeholder is filled with a true value.
01Who we are
NexliPay is a payment orchestration platform operated by LEGAL ENTITY NAME, a company registered in JURISDICTION under company number COMPANY NUMBER, with its registered office at REGISTERED ADDRESS. In this policy, “NexliPay”, “we” and “us” mean that entity.
For the purposes of UK GDPR and EU GDPR, we act as data controller for the personal data described below. Where we process payment data on behalf of a merchant customer, we act as data processor and the merchant is the controller. Our data protection contact is DPO OR PRIVACY CONTACT NAME, reachable at privacy@nexlipay.com.
02What we collect
| Category | Examples | Why we hold it |
|---|---|---|
| Account data | Name, work email, phone, job title, password hash | To create and secure your NexliPay account |
| Business & verification data | Legal entity details, registration documents, beneficial ownership, identity documents | KYC, KYB and anti-money-laundering obligations |
| Connected processor data | Processor account identifiers, API credentials, settlement configuration | To route transactions across accounts you own |
| Transaction metadata | Amount, currency, timestamp, card network, BIN, last four digits, decline codes, routing decisions | To route, retry, reconcile and report on payments |
| Usage & device data | IP address, browser and device type, pages viewed, session timestamps | Security, fraud prevention and product improvement |
| Communications | Emails, support tickets, call notes | To support you and keep a record of what was agreed |
We do not store full primary account numbers (PANs) or card verification values. Card data is handled by your connected processors within their own PCI DSS environments; NexliPay receives only tokenised references and the metadata listed above.
03Legal bases for processing
- Performance of a contract — providing the orchestration service you signed up for, including routing, settlement reporting and support.
- Legal obligation — identity verification, sanctions screening, AML monitoring, tax and record-keeping requirements.
- Legitimate interests — securing the platform, preventing fraud and abuse, and improving the product, balanced against your rights.
- Consent — marketing communications and non-essential cookies only. You can withdraw consent at any time without affecting the service.
04Who we share data with
We share personal data only where it is necessary to deliver the service or meet a legal duty. We do not sell personal data, and we do not share it for third-party advertising.
- Payment processors and acquirers you have connected, for the purpose of routing your own transactions.
- Identity, sanctions and AML screening providers: SCREENING PROVIDER(S).
- Infrastructure and hosting providers: HOSTING PROVIDER, located in HOSTING REGION.
- Professional advisers, auditors and insurers, under duties of confidentiality.
- Regulators, law enforcement and courts, where we are legally required to disclose.
05International transfers
Where personal data leaves the UK or EEA, we rely on an adequacy decision where one exists, and otherwise on UK International Data Transfer Agreements or EU Standard Contractual Clauses together with a transfer risk assessment. Our current transfer destinations are TRANSFER DESTINATIONS. You can request a copy of the safeguards in place.
06How long we keep it
| Data | Retention period |
|---|---|
| Account and contract records | Duration of the relationship plus 6 years |
| KYC, KYB and AML records | 5 years from the end of the business relationship, per APPLICABLE AML REGULATIONS |
| Transaction and settlement metadata | RETENTION PERIOD, aligned to card scheme and audit requirements |
| Support communications | 3 years from last contact |
| Marketing consent records | Until withdrawn, plus 2 years as proof of consent |
07Your rights
Subject to legal limits — AML records in particular cannot simply be deleted on request — you have the right to access your data, correct it, erase it, restrict or object to processing, receive it in a portable format, and withdraw consent. You may also object to automated decision-making that has a legal or similarly significant effect on you.
To exercise any right, contact privacy@nexlipay.com. We respond within one month. If you are unhappy with our response you can complain to the SUPERVISORY AUTHORITY, e.g. UK ICO at AUTHORITY CONTACT DETAILS.
08Automated routing decisions
NexliPay scores transactions and selects a processor account automatically. These decisions concern which of your own accounts handles a payment; they do not profile individual cardholders or determine whether a person may access credit or a service. Where a transaction is declined, the decline originates from the processor or issuer, not from NexliPay. You can request an explanation of a routing decision at any time.
09Cookies
We use strictly necessary cookies for authentication and security, and — only with your consent — analytics cookies to understand how the site is used. You can change your choices at any time through the cookie settings link in the footer. A full cookie inventory is maintained at COOKIE INVENTORY LOCATION.
10Changes to this policy
We will post any changes on this page and update the date above. Where a change materially affects your rights we will notify you by email at least NOTICE PERIOD before it takes effect.
Questions?
Write to legal@nexlipay.com or use the contact page.