Skip to main content

Legal & safety

Privacy Policy

Last updated:

This Privacy Policy explains how FinDech UAB handles personal information in connection with Paym websites, Paym accounts, Paym IDs, payment pages and related Paym services that are currently available or being tested.

Paym is currently under development and has not yet completed its general commercial launch. Some account and identity features may already be available. Other products, payment methods and jurisdictions described by Paym are planned, in development or available only for controlled testing. Where a regulated financial service is made available, Paym will identify the entity providing that service, its regulatory status and the applicable terms before the customer uses it.

1. Who is responsible for your information

FinDech UAB is the controller for personal information processed to operate the Paym platform, including Paym websites, Paym accounts and Paym IDs, unless another controller is identified for a particular service.

FinDech UAB
Company code: 307632436
Architektų g. 56-101
Vilnius, LT-04111
Lithuania

Contact: legal@findech.com

A regulated payment, identity-verification or financial-service partner may separately act as an independent controller for information it receives in order to provide its service. Where this applies, the relevant partner and its terms or privacy information will be identified as part of that service.

The contractual role of a partner can differ. A partner is not always a processor, and is not always an independent controller.

2. Information we may collect

The information Paym collects depends on how you use the service. Paym does not collect every category below from every person.

Account and profile information

This may include name, email address, phone number where used, Paym ID, display name, profile type, account settings and linked profile information.

Identity and verification information

Where required for a product, jurisdiction or regulated partner, this may include legal name, date of birth, nationality, country of residence, address, identification document information, verification results, business details, beneficial ownership or control information, and compliance declarations.

The exact information depends on the product, jurisdiction and regulated partner involved.

Payment and transaction information

Where payment or related functionality is used, this may include payer and recipient details, amount, currency, payment purpose or message, payment method category, bank or payment destination information where needed, transaction identifiers, routing or provider information, status, fees, foreign-exchange information, timestamps, and refund or dispute information.

Paym is not designed to store raw full card numbers or card security codes on its own systems. Where card details are collected for a payment, they are typically entered in a payment partner’s hosted fields.

Device, technical and security information

This may include IP address, browser or device information, session data, request and log information, authentication events, security signals and fraud or risk signals.

Communications and support

This may include messages you send to Paym, support correspondence, complaints and feedback.

Public Paym profile information

Information you deliberately publish as part of a Paym payment profile may be publicly visible. That can include a Paym ID, display name, profile image and other user-selected public profile information. Private legal-identity fields are not published as part of a public Paym profile.

Paym uses cookies and similar browser storage as described in the Cookie Policy.

Information you need to provide

Some information is required so that we can create or secure an account, provide a requested Paym function, verify eligibility, comply with applicable legal requirements or enable a regulated partner to provide a service. If required information is not provided, we may be unable to create or maintain an account, complete verification or make the relevant feature available.

Not every field is legally mandatory. Depending on the feature:

  • some information is needed to enter into or perform a contract with you, such as an email address to create an account or a Paym ID you choose to claim
  • some information is required by law or by a regulated partner’s own legal duties, such as identity or verification details where those checks apply
  • some information is optional, such as a profile image or a payment note, and the core service can often still be used without it

Information we receive from other sources

Paym may receive personal information from sources other than you directly, where that is relevant to a feature you or another user is using. Depending on the circumstances, this may include:

  • other Paym users, for example when someone pays you, requests a payment from you, reports a profile or otherwise interacts with your Paym ID
  • payer and recipient details connected with a payment or payment request
  • banks and payment providers involved in a payment, payout, refund or similar request
  • identity, KYC or KYB providers, where verification is used
  • fraud, security or similar risk services
  • people who represent a business or organisation, such as an authorised representative supplying company or control information
  • public or company registers, where business details are checked
  • sanctions, PEP or similar compliance sources, where those checks apply
  • device, network or security services that supply technical or risk signals

Paym receives this information in order to operate the requested feature, secure accounts, prevent fraud or abuse, verify eligibility, or meet legal and partner requirements. The categories that apply depend on how the service is used. A technical integration in Paym’s systems does not mean that a named provider is currently customer-facing.

3. Why we use information

Provide the Paym platform

To create and operate Paym accounts, Paym IDs, payment pages and related features you request.

Legal basis: performance of a contract, or steps you request before entering into a contract, where applicable.

Protect Paym, users and transactions

To secure accounts, prevent fraud and abuse, and maintain the integrity of the service.

Legal basis: legitimate interests in security, fraud prevention, abuse prevention, service integrity and protecting users, subject to applicable balancing requirements.

To comply with law where a specific obligation applies. Regulated partners may also need information for their own identity, anti-money-laundering, sanctions or similar obligations.

Legal basis: legal obligation where a specific obligation applies.

Improve and operate Paym

To keep the service reliable, debug problems, understand how features are used in aggregate, and improve Paym.

Legal basis: legitimate interests in reliability, debugging, service improvement and aggregate analysis where appropriate. Legitimate interests are not used as a blanket justification for every processing activity.

Optional analytics or marketing

Paym does not currently use optional analytics or marketing cookies. If that changes, the Cookie Policy will be updated first and, where required, consent will be the legal basis.

Submitting or using Paym is not treated as consent to this Privacy Policy as a whole.

4. Identity, fraud and compliance checks

Paym and service providers may use information to verify identity, assess fraud or security risk, comply with sanctions or other legal requirements, or determine whether a particular payment or financial feature can be offered.

A risk signal does not necessarily mean wrongdoing. It may result in additional verification, a delay, a review, a limit or refusal of a particular action where appropriate.

Automated signals may support fraud detection, security review, eligibility checks and routing or security controls. Paym does not currently take solely automated decisions that produce legal effects or similarly significant effects about you. Meaningful human review or a regulated partner’s own processes may also apply.

5. Who we may share information with

We disclose only information reasonably required for the relevant purpose. Depending on the service, this may include:

  • payment and financial-service providers
  • banks and payment networks
  • identity, KYC and KYB providers
  • fraud and security providers
  • hosting, cloud and infrastructure providers
  • email, communications and support providers
  • professional advisers
  • auditors
  • authorities, courts or regulators where legally required
  • parties involved in a corporate restructuring or acquisition where legally permitted

6. International transfers

Paym is intended to operate internationally. Personal information may therefore be processed outside the country in which it was collected.

Where European data-protection law applies and personal information is transferred outside the EEA, Paym intends to use an applicable lawful transfer mechanism where required, which may include an adequacy decision, appropriate contractual safeguards or another mechanism permitted by law.

You can contact legal@findech.com for information about the type of safeguards applicable to relevant international transfers. We do not provide confidential vendor contracts.

7. How long we keep information

We retain personal information only for as long as reasonably necessary for the purpose for which it was collected, including account operation, security, dispute handling and applicable legal or regulatory requirements.

How long that is depends on factors such as the lifetime of the account, the transaction relationship, legal requirements, claims or disputes, fraud and security needs, and consent status where consent is the basis.

Some payment or verification records held by regulated partners may be subject to different statutory retention periods.

An activated Paym ID is treated as a permanent payment address. If an account or profile is closed, the ID is retired rather than made available to someone else. A limited record of that retired identifier may be retained so a saved Paym link does not later resolve to a different person.

8. Your rights

Where the GDPR or other EEA data-protection law applies, you may have rights of access, correction, deletion, restriction, objection, portability, withdrawal of consent, and the right to complain to a supervisory authority.

These rights are not absolute and can be limited where continued processing is required by law or necessary for legal claims, fraud prevention or other recognised grounds.

Contact legal@findech.com to make a request.

FinDech UAB is established in Lithuania. The Lithuanian supervisory authority is the State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija). Its official website is vdai.lrv.lt.

9. Cookies

Paym uses cookies and similar technologies as described in the Cookie Policy.

10. Children

Paym’s generally available account functionality is intended for adults unless a particular product expressly states that it is available to younger users under a legally compliant family or guardian arrangement.

11. Security

Security measures relating to Paym accounts and systems are described on the Security page.

12. Changes

We may update this Policy as Paym develops, partners change or legal requirements evolve. The current version and update date will always be published here. Where required by law, we will provide additional notice of material changes.

13. Contact

Questions about this Policy can be sent to legal@findech.com.