We use cookies

We use cookies and other tracking technologies to improve your browsing experience on our website, to show you personalised content, to analyze our website traffic, and to understand where our visitors are coming from. To find out more, please visit our group privacy policy.

Accept:

General Data Protection Regulation (GDPR)

GDPR is the EU data protection regulation which has been effective across Europe since 25 May 2018. It strengthens individuals' data protection rights and is designed to create a culture of responsible data protection practices across all organisations. Accountability and evidencing good data protection policies and practices, on an ongoing basis, are key foundations of the GDPR.


1. Why are PAYA Group concerned about GDPR?

The GDPR applies to any organisations that provide goods or services to European residents and therefore as our services are available to cardholders globally it is important for us to comply with GDPR.


2. GDPR Preparations

At PAYA Group, our GDPR compliance is a priority for the business. The obligations created by GDPR provide a standard that puts data protection at the forefront of our business activities.

We have implemented a data protection programme with key stakeholders, designed to consolidate our approach to data protection, whilst identifying and mitigating any risk to the personal data that we are responsible for. This is a key focus of the PAYA senior management, who engage with external advisors and auditors to ensure the highest standards are being met.

Accountability is at the forefront of this programme with ongoing processes being developed to ensure that we are able to evidence our commitment to data protection, which includes mapping our data flows and understanding where data is shared, stored and accessed.

We are working to increase awareness at all levels within PAYA Group to embed a culture of responsible data protection throughout the business.


Sub-Processors

PAYA Group engages several Sub-Processors to assist us with data processing activities.

Last updated: June 2024


1. What is a Sub-processor?

When PAYA Group engages third party service providers in our capacity as a data processor for our customers personal data, the General Data Protection Regulation (“GDPR”) and a number of other global privacy frameworks call these third-party service providers Sub-Processors. Sub-processors are service providers who have or potentially will have, access to the personal data that PAYA Group processes on behalf of it's customers.

This page outlines which Sub-Processors we utilise, the type of data we send them, the function they provide to us, and their residency.


2. Updates to this list

Due to the nature of our international business, services providers may change from time to time.

We will periodically update this page to reflect the changes in our list of Sub-Processors and Affiliates.

Under the terms of our Data Processing Addendum (DPA), if you are a contracting party with PAYA Group, you may reasonably object, in writing, to the processing of your personal data by a new Sub-Processor within 14 days following the update of this page.

If you do not object during the 14 day time period, the appointment of the new Sub-Processor shall be deemed accepted.

For more information on PAYA Group privacy practices, you can view our Privacy Policy here. If you have any questions regarding this page, please contact us.


3. List of Sub-processors

Name Data Type Purpose Entity Residency
No Sub Processors Found

Version GGDPR-0624-AT

To find out more about generating additional revenue from referrals, co-branding or white labelling, call a member of our Business Development team.

Call 0333 123 1246 today