Back to figopay

Legal

Privacy policy

FIGOPAY respects the privacy of Users and processes personal data in accordance with applicable data protection legislation, including Regulation (EU) 2016/679 on the protection of personal data — GDPR — and applicable national legislation.

In the course of using the Platform figopay.eu, FIGOPAY may process data necessary for creating and administering the Account, authentication, providing services, processing Transactions, communicating with the User, preventing fraud, ensuring the security of the Platform, complying with legal obligations, and improving services. Such data may include, as applicable, identification data, contact data, technical data, IP addresses, device identifiers, access logs, data regarding Transactions, the history of Platform use, and communications sent to FIGOPAY.

Data processing may be carried out, as applicable, on the basis of the performance of the contract with the User, the fulfilment of legal obligations, FIGOPAY's legitimate interest in ensuring the operation, security, and protection of the Platform, as well as, where necessary, on the basis of the User's consent.

FIGOPAY implements reasonable and appropriate technical and organizational security measures to protect the Platform, Accounts, and processed data, including access control measures, monitoring, logging, protection against unauthorized access, fraud prevention measures, and internal information security procedures.

However, the User understands that no digital system can be guaranteed to be completely immune to errors, vulnerabilities, cyberattacks, fraud attempts, technical unavailability, or security incidents. FIGOPAY makes reasonable efforts to prevent, detect, and remedy such situations, within the limits of available technology and applicable legal obligations.

The User is obliged to use the Platform with prudence, to keep authentication data confidential, not to disclose passwords, OTP codes, or other security elements, and to inform FIGOPAY without delay if the User notices unauthorized access, unknown Transactions, suspicious messages, phishing attempts, unauthorized use of the Account, security errors, or technical vulnerabilities.

FIGOPAY will never request, through unsecured channels, the complete password, OTP codes, complete card details, or other sensitive information that would allow unauthorized access to the User's Account. Any such request must be treated as suspicious and reported immediately to FIGOPAY.

Personal data may be transmitted to service providers, payment processors, technical infrastructure providers, security services, analytics services, consultants, public authorities, or other entities, only to the extent necessary for providing services, complying with legal obligations, protecting FIGOPAY's rights, or preventing fraud. Where providers processing data on behalf of FIGOPAY are used, they will be subject to appropriate contractual obligations regarding confidentiality and data protection.

Data is retained for the period necessary to fulfil the purposes for which it was collected, for the duration of the Account's existence, for the period required by applicable legislation, or for the period necessary to defend FIGOPAY's rights and legitimate interests. After the applicable periods expire, the data will be deleted, anonymized, or archived in accordance with the law.

The User benefits, under the conditions of the GDPR, from the right of access to data, the right to rectification, the right to erasure, the right to restriction of processing, the right to data portability, the right to object, the right to withdraw consent, where processing is based on consent, as well as the right to lodge a complaint with the competent data protection authority.

In the event of a security incident affecting personal data, FIGOPAY will assess the nature and impact of the incident and will take the necessary measures in accordance with applicable legislation, including, where applicable, notifying the competent authority and/or the affected Users.

To exercise data protection rights or to submit reports regarding the security of the Platform, the User may contact FIGOPAY at the contact address indicated on figopay.eu or through any other official channel made available by FIGOPAY.

This text is a good basis, but for final publication it should be supplemented with: the legal name of the controller, tax ID/registered office, dedicated GDPR email, a DPO if applicable, exact categories of data, main providers, transfers outside the EEA, and the specific retention period.

See also Terms and conditions