loading
Personal data

Personal data processing policy.

What we collect, why we are allowed to, how long we keep it, who else sees it, and how to make a request about your own data.

1. Scope

1.1. This Personal Data Processing Policy (the «Policy») governs how Zephira Technology Limited (the «Operator», «Zephira», «we») collects, stores, uses and protects information relating to identified or identifiable natural persons («Personal Data») obtained through its websites, software and services, and in the course of performing its contracts.

1.2. The Policy applies to Personal Data of the Merchants' representatives, of Traders, of Customers whose payments pass through the platform, and of visitors to the website.

1.3. The Operator processes Personal Data in order to provide and improve its services, and in compliance with the data-protection and financial-crime legislation applicable to it and to its Partners.

1.4. Where a Merchant determines the purposes for which its Customers' data is processed, that Merchant is the controller of that data and the Operator acts on its documented instructions in respect of it.

2. Definitions

  • Personal Data — any information relating to a directly or indirectly identified natural person.
  • Data subject — the natural person whose Personal Data is processed.
  • Operator — Zephira, which determines the purposes and means of processing and carries it out.
  • Processing — any operation performed on Personal Data, automated or not: collection, recording, storage, use, transfer, blocking, erasure.
  • Dissemination — disclosure of Personal Data to an indefinite group of persons.
  • Provision — disclosure of Personal Data to a defined person or group of persons.
  • Blocking — temporary suspension of processing, other than where processing is needed to correct the data.
  • Erasure — action that makes restoration of the Personal Data impossible.
  • Anonymisation — action after which the data subject cannot be identified without additional information.
  • Cross-border transfer — transfer of Personal Data to a foreign state or to a foreign person.

3. Rights and obligations of the Operator

The Operator undertakes to:

  • provide the data subject, on written request, with information about their Personal Data and its processing, without disclosing the data of third parties in the absence of a lawful basis;
  • correct, block or erase Personal Data on the data subject's request where it is incomplete, outdated, inaccurate or unlawfully obtained;
  • cease processing on the data subject's demand in the cases provided by this Policy and by law;
  • explain the consequences of a refusal to supply data that must be provided by law or by contract;
  • inform the data subject, where data was obtained from a source other than the data subject, of the corresponding particulars, save where the law provides otherwise;
  • process Personal Data only to the extent permitted by applicable law and by this Policy.

The Operator is entitled to:

  • process Personal Data to perform its contracts and to meet its legal and regulatory obligations;
  • use Personal Data to promote its services where the data subject has given consent, which may be withdrawn at any time;
  • require the data subject to comply with the applicable law and with the conditions of processing;
  • restrict access to data where disclosure would prejudice the prevention of money laundering, the investigation of fraud, or the rights of third parties.

4. Rights and obligations of the data subject

The data subject is entitled to:

  • obtain information about the fact and purposes of processing, the methods used, the retention period, and the third parties that have access to the data;
  • demand correction, blocking or erasure of the data where it is inaccurate, outdated or unlawfully processed;
  • withdraw consent where processing is based on it;
  • appeal the Operator's actions to the competent supervisory authority or to a court;
  • protect their rights and interests, including compensation for damage.

The data subject undertakes to:

  • supply accurate and current data and update it in good time;
  • comply with the Operator's requirements concerning the confidentiality of access credentials.

5. Submitting a request

5.1. Information is provided on written request, or on the data subject's appearance in person.

5.2. The request must contain particulars that identify the applicant and confirm their entitlement to the information requested.

5.3. Requests may be sent electronically to privacy@zephira.io, signed with an electronic signature where the law requires one.

5.4. A repeat request may be made no earlier than thirty days after the previous one, unless the information previously supplied was incomplete.

5.5. The Operator may refuse a repeat request that does not meet these conditions, stating its reasons.

5.6. Access to data may be restricted in the cases provided by law, including the countering of money laundering and the protection of the rights of third parties.

6. Purposes of processing

Personal Data is processed in order to:

  • perform contractual obligations and provide the services;
  • verify Merchants, their beneficial owners and Traders, as required by financial-crime legislation;
  • monitor operations for fraud, sanctions exposure and money laundering, and to answer requests from Partners, issuers and authorities;
  • maintain the security, quality and availability of the platform;
  • communicate with users, send service notices and handle requests;
  • carry out marketing communications where consent has been given;
  • protect the rights and interests of data subjects and of the Operator, including the establishment and defence of legal claims.

6.1. Processing is limited to what is necessary to achieve those specific, lawful purposes, and data is not processed in a manner incompatible with the purpose for which it was collected.

7. Categories of data and of data subjects

7.1. Categories of data subject: representatives and beneficial owners of Merchants; Traders; Customers who pay through the platform; website visitors.

7.2. For Customers the Operator processes: name, contact details, date of birth where required, masked payment credentials, transaction details, IP address, cookie identifiers, session and device data, and approximate location derived from the IP address.

7.3. For Merchant representatives, beneficial owners and Traders the Operator processes: name, position, identification-document data, contact details, ownership and control information, and the documents required for due diligence.

7.4. The Operator proceeds on the basis that the data supplied is accurate and is not liable for its inaccuracy or incompleteness where the data subject or the Merchant has not notified a change.

7.5. Data is collected only to the extent necessary for the stated purposes. The Operator does not collect special categories of data and does not ask for full card numbers or wallet private keys.

8. Collection, storage and retention

8.1. Data is collected at registration, in the course of using the services, at the conclusion and performance of contracts, and in other lawful cases.

8.2. Data is stored for as long as necessary to achieve the purposes of processing, and in any event for the period required by the financial-crime legislation applicable to the Operator and its Partners — ordinarily five years from the end of the relationship or from the date of the operation, whichever is later.

8.3. Processing includes automated processing for the provision of the services, for monitoring and for the improvement of the platform. Decisions with legal or similarly significant effect are not taken solely by automated means without human review.

8.4. Processing without consent is possible in the cases provided by law, including the performance of a contract to which the data subject is a party, compliance with a legal obligation, the execution of a judicial act, and the protection of vital or legitimate interests.

9. Disclosure and cross-border transfer

9.1. Personal Data is not disclosed to third parties without a lawful basis, save to the Partners that perform the regulated leg of an operation, to processors engaged for hosting, communication and screening, and to authorities acting within their powers.

9.2. Processors act under contracts that impose confidentiality and security obligations equivalent to those in this Policy, and process data only on the Operator's documented instructions. A current list of categories of processor is available on request.

9.3. Cross-border transfer is carried out only to jurisdictions that afford an adequate level of protection, or under appropriate safeguards where they do not, and the Operator remains responsible for the security of the data transferred.

9.4. The Operator does not sell Personal Data and does not disclose it for third-party advertising.

10. Security

10.1. Data is held on protected infrastructure with encryption in transit and at rest, segregation of environments, and access granted on a least-privilege basis with logging.

10.2. The Operator applies organisational and technical measures against unauthorised access, alteration, disclosure and destruction, and reviews them periodically.

10.3. In the event of a security incident affecting Personal Data, the Operator notifies the competent authority and the affected data subjects within the periods set by the applicable law.

11. Cookies and similar technologies

11.1. This website sets no cookies. It does not use local storage, it does not carry advertising or analytics tags, and it loads no resources from third parties — fonts, styles, scripts and images are all served from zephira.io. Nothing on these pages tracks a visitor between sessions or across other sites.

11.2. The web server keeps standard request logs — IP address, timestamp, requested address, user agent — which are used to operate the service and to investigate abuse, and are retained for the period stated in the retention clause of this Policy.

11.3. The merchant Console, once a visitor signs in, will set a strictly necessary session cookie whose only purpose is to keep that person signed in. It carries no profiling data and expires with the session. No consent is required for it and refusing it is not possible while remaining signed in.

11.4. If analytics is introduced later, this section will be updated before it goes live, and any technology that requires consent will be introduced together with a consent mechanism rather than switched on quietly.

12. Changes to this Policy

12.1. The Operator may amend this Policy, notifying data subjects through the website or by email. The version number and effective date are shown at the top of this page.

12.2. Continued use of the services after an amendment takes effect constitutes acknowledgement of the amended Policy.

13. Contacts

Questions about the processing of Personal Data, and requests under this Policy: privacy@zephira.io

Zephira Technology Limited
company number 3184627, business registration number 74928315-000, incorporated in the Hong Kong Special Administrative Region
Registered office: Unit 2504, 25/F, Tower 1, Enterprise Square, 9 Sheung Yuet Road, Kowloon Bay, Kowloon, Hong Kong SAR