Privacy

Privacy


1 Introduction

1.1 Let us formally introduce ourselves. We are ThePay, a.s. – a company registered under the identification business number 281 35 261, whose registered office is at Masarykovo nám. 102/65, Jihlava, Czechia. We can also be reached at our website at www.thepay.eu where you can find our telephone number and email address. We are supervised and regulated by the Czech National Bank.

1.2 Our privacy policy describes how we collect and process your personal information. It is based on the General Data Protection Regulation (GDPR) of the European Union (Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons) and Czech Data Protection Act No. 110/2019. Our privacy policy is effective from 1 October 2020 and may be updated from time to time, of which we will notify you.

1.3 In simpler terms, the privacy policy explains what personal information we collect, why we collect it, how we protect it and what privacy rights you have.

2 Terms and definitions

2.1 There are lots of terms used in this privacy policy – here is a summary of what they all mean. Any expressions used but not defined in this privacy policy, but which are defined in the Terms of business have the meaning as defined in the Terms of business.

2.2 ThePay: A smart, online, secure system solution that enables you to accept online payments from your customers and make e-money transactions. In ThePay, you can see your ThePay account linked to your user account.

2.3 ThePay account: An account where e-money is held in the form of current and available balance. You can have more than one account. It can be thought of as a regular bank account.

2.4 GDPR: Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (GDPR) effective from 25 May 2018.

2.5 Newcomer: You – a self-employed person or body corporate interested in using our services who has provided us with their email address and telephone number and entered the same on our website, along with the password they have created for this purpose. Although no contract yet exists between us at this stage, you have given us consent to the processing of your personal information and we make ThePay available to you.

2.6 Our customer (Client): You after you have entered into a contract with us. You are our customer and we are happy to have you on board.

2.7 Your customer (Customer): A private individual or body corporate who makes, or is interested in making, a payment to you using the payment gateway.

2.8 Newcomer's personal information: email address, phone number, password created to access ThePay, IP address and time of connection, browser and OS information, and any other information you provide to us.

2.9 Our customer's personal information: name, surname, title, business registration number, tax registration number, business name, trade name, registered office address, email address, project's website address, phone number, copy of ID, copy of driving licence, copy of passport, copy of shot gun certificate, bank account number, bank statement, IP address and time of connection, browser and OS information, information on whether you are a politically exposed person, communications made, e-money transaction details, details of transactions made via the project, masked information about your customer's payment card (debit, credit,... ), amount of transaction made by your customer, your customer's email address, your customer's bank account number, information about products used, product prices, ThePay account status, and any other information you provide to us.

2.10 Your customer's personal information: name, surname, title, business registration number, tax registration number, business name, trade name, registered office, residential address, correspondence address, email address, phone number, order ID and price, communications between your customer and our customer.

3 Lawfulness of processing

3.1 If you are a prospect requesting access to ThePay, you give us consent to the processing of your personal information. The purpose of processing the personal information on the basis of this consent is to create and send to you commercial, promotional, advertising and marketing communications, i.e. offers for our services, and to create customer profiles for target marketing communications. Your consent lasts for three (3) years from the date you give your consent. You have the right to withdraw your consent at any time [Article 6(1)(a) of the GDPR].

3.2 Where we enter into a contract with you and provide you with our payment gateway services, we will be processing your personal information for the conclusion and performance of the contract [Article 6(1)(b) of the GDPR]. As this relationship is subject to other legal obligations imposed in particular by Czech AML/CFT Act No. 253/2008, we will be processing your personal information also for compliance with the legal obligation to which we are subject [Article 6(1)(c) of the GDPR]. In addition, we will be processing your personal information for the purpose of our legitimate interests [Article 6(1)(f) of the GDPR] which include: establishing compliance with contractual obligations with our customers, establishing compliance with the law, protecting our reputation, protecting our intellectual property and other rights, and establishing, exercising or defending legal claims.

4 How we treat your personal information

4.1 We understand that your personal information is private to you and we will always treat it with the utmost care and attention. We take all measures to prevent unauthorised or unlawful processing of personal information. Any leakage of personal information is absolutely unacceptable to us.

4.2 We process personal information electronically, by automated means. We may use personal information for marketing profiling or automated decision-making, for covering risks or for establishing compliance with contracted obligations with our suppliers (banks, card associations). We analyse the behaviour of users on our website and in ThePay and use profiling to determine where risks may be and to determine business activity categories and turnover categories.

4.3 We will process the personal information for as long as we discuss the terms and conditions of the contemplated contract, amendments to the contract or other agreements with you and for an additional period of ten years after we enter into a business relationship with you, as provided for by Czech AML Act No. 253/2008. We will destroy the personal information after that period ends.

4.4 If and when we transfer the personal information to third parties, we will do it only in accordance with the laws of the Czech Republic. We may share the personal information with the competent public authorities (Financial Analytical Unit, Police of the Czech Republic, Czech National Bank) and cooperating entities, including suppliers of certain services, and only to the extent necessary. For instance, if your customer makes a card payment, the information will naturally flow through various information channels to card acquirers, banks and other financial institutions. We may also share the personal information with our consultants such as accountants, tax advisors, lawyers or eCommerce solution providers hosting your project. We do not transfer the personal information outside the EU or to any international organisation.

4.5 We store the personal information on secure servers managed by VSHosting s.r.o., an ISO 27001 (information security management standard) certified company seated at Sodomkova 1579/5, 102 00 Praha 10 under business registration number 61505455. We also use GDPR compliant services such as G Suite (Google LLC) and Basecamp.

5 Your privacy rights

5.1 Where we process the personal information that we have collected based on your consent to the processing of the personal information, you have the right to withdraw your consent at any time except where we process the personal information to the extent and for the purposes of fulfilling our legal obligation. Withdrawal of your consent does not affect the lawfulness of processing based on such consent before its withdrawal and neither does it affect the processing carried out on a legal basis other than consent (particularly where the processing is necessary for the performance of a contract, for compliance with a legal obligation or for reasons other than specified by applicable laws). You can withdraw your consent directly in your ThePay account (My profile – Marketing communications) or by writing to our registered address or by sending us an email to podpora@thepay.cz.

5.2 You can request information from us as to whether we process your personal information. Where we process your personal information, you have the right to request information regarding, in particular: our contact details and the contact details of our representatives and data protection officer, why we process the personal information, what types of personal information we collect, who we share the personal information with, what our legitimate interests are, what rights you have, how to contact the data protection authority, where we have received your personal information from, if and why the personal information is processed by automated means (including profiling) and what the envisaged consequences are and, if applicable, how we ensure the protection of the personal information which has been transferred to a third-country or international organisation. You also have the right to request a copy of the personal information we process about you, without prejudice to the rights and freedoms of other data subjects.

5.3 Should we process the personal information for a purpose other than for which it was originally collected, we will provide you with information on that purpose and any other relevant information.

5.4 If you have, for example, moved address or changed your telephone number or if any of your personal information has changed, you have the right to request rectification of the personal information held by us. You also have the right to request completion of incomplete information, by contacting us in writing or by updating the information directly in your ThePay account.

5.5 In certain circumstances, you have the right to request that we delete your personal information, for example, where the information is no longer needed for the purpose for which it was originally collected. We will assess you request on an individual basis and inform you accordingly.

5.6 We process the personal information only to the extent necessary. If you believe that we process the personal information for any purposes other than specified purposes, you may request that we process the personal information solely for the statutory purposes. We will assess you request on an individual basis and inform you accordingly.

5.7 You have the right to receive your personal information, which you have provided to us, in a structured, commonly used and machine-readable format. You also have the right to request that we transmit your personal information to another controller where this is technically feasible and where there are no legal or other major constraints.

5.8 If you believe that we process the personal information in breach of your right to privacy or in breach of applicable laws, particularly where the personal information is inaccurate with regard to the purpose for which it being processed, you have the right to request an explanation from us by sending us an email to podpora@thepay.eu or by writing to our registered address. You also have the right to object to data processing and demand that we remedy this situation (for example, by blocking, correcting, supplementing or deleting your personal information). We will assess you request on an individual basis and inform you accordingly.

5.9 You have the right to raise a concern or file a complaint with the supervisory authority: Personal Data Protection Office, Pplk. Sochora 27, 170 00 Praha 7, https://www.uoou.cz/.

5.10 Where you request us for information about how or to what extent we process your personal information, we will supply this information without undue delay, an in any event within one month of your request.

5.11 Where you exercise your right to access your personal information and make your request electronically, we will provide the information in electronic format unless you request otherwise.

5.12 Where you request further copies of personal information we hold about you and your request is manifestly unfounded or excessive, we can charge you a reasonable fee for the administrative costs of complying with your request.

5.13 Should you have any concerns about how your information is managed at ThePay, you have the right to contact our data protection officer (DPO) whose identity will be disclosed to you in response to your request sent to podpora@thepay.eu.

Did not find what you were looking for?
Let us help you!

If you cannot find an answer to your question,
feel free to reach out to us and we will look for a solution.

Nastavení cookies: Aby web fungoval, tak jak ho znáte

Aby naše webové stránky fungovaly správně, našli jste na nich, co hledáte, ušetřili spoustu času a nezobrazovaly se vám věci, které vás nezajímají, potřebujeme od vás souhlas se zpracováním souborů cookies, tj. malých souborů, které se ukládají ve vašem prohlížeči.

Upravit nastavení Povolit vše

Tyto cookies jsou nutné pro správné fungování našich webových stránek. Vždy aktivní.

Čím víc lidí má statistické cookies zapnuté, tím lépe můžeme naše stránky vyladit. Tyto cookies shromažďují informace o tom, jak lidé web používají, které stránky navštívili, na co klikají. a na které odkazy jsi klikla. Všechny informace, které soubory cookie shromažďují, jsou souhrnné a anonymní.

Díky marketingovým cookies třetích stran vám můžeme připomenout nabídky, které jste si prohlíželi na našich stránkách, i jinde na internetu. Když tyto cookies zakážete, reklam bude pořád stejně. Ovšem na věci, které vás nezajímají.

Zavřít