Capital Financial Services S.A. (or " Twispay", "we", "us", "our") is an e-money institution authorised to issue electronic money and to provide payment services under National Bank of Romania authorisation number IEME-RO-0001 of 25 April 2013. See our registration here (NBR Register – E-money Institution).
Together with our partners and affiliates/group companies, we are offering payment services to online merchants, in order for them to accept payments through different payment instruments (like credit or debit cards, or other alternative payment methods) on their websites and to enable their customers to pay for products or services by using such payment instruments.
1. Personal data we collect
We process your personal data when you use our Twispay payment page (e.g., www.secure.twipay.com), our payment services or our websites (collectively the " Services") and whenever we interact in connection with the Services. The Services provided by Twispay to our Merchants include card acquiring services, payment gateway services, handling of funds services, funds remittances, fraud control services and other related services such as customer support
The personal data may be collected in different ways, such as when a Merchant registers for a Twispay merchant account by filling in the applicable registration forms, a Customer of a Merchant makes payments or conducts transactions on one of our Merchants' website/platform or application through our Twispay payment page, a partner of a Merchant enrolled in the marketplace platform of the Merchant is approved by Twispay for receiving payments, a prospective client is interested in our Services and/or promotional offers, a person responds to our emails, telephones, questionnaires or surveys or when a Customer uses a recurring payments or pay by click feature of Twispay payment page. We also may receive information from other sources, such as our Merchants, our third-party partners, our financial and payment services providers, identity verification services, fraud and AML/CFT screening agencies and publicly available sources.
Whenever we use your personal data, we will have a legal basis to do this. For example, you have asked us to provide our Services, we have a legal obligation to do so or a legitimate interest in using your personal data, and/or the processing is necessary for the performance of a task carried out in the public interest.
The personal data that we may collect includes:
I. Customer contact details , such as name, e-mail, phone number, address (such data may be collected through our payment page or received from the Merchant from whom you buy goods or services);
II. Customer financial data , such as card number, name on the card, expiration date, card verification value (CVV) (such data is collected through our payment page or, where applicable, merchant's payment page), data in relation to other alternative payment methods and transaction data, such as transaction date, transaction value and a short description of the transaction;
III. Merchant personal data , such as name, address, telephone number, e-mail address, ID/Passport details regarding the Merchant's legal representatives, shareholders, ultimate beneficial owners - natural persons (such data is collected before entering in a contractual relationship with us and during such relationship);
IV. The personal data of the Merchant's partners offering marketplace services, such as, name, address, telephone number, e-mail address, details of ID/passport of the legal representatives, shareholders, ultimate beneficial owners - natural persons of the partners or such personal data of the partner natural person and other financial data such as bank account details for making payments, transaction data, such as the date of the transaction, the value of the transaction and a brief description of the transaction (these data may be collected directly or indirectly from the Merchant).
2. How we use information we collect
These are examples of how we may use personal data:
- process payment transactions, funds remittance and provide our Services;
- verify identity for compliance with the applicable laws regarding the prevention of money laundering and the prevention of terrorist financing;
- evaluate an application from a prospective Merchant to use our Services;
- manage risk, or to detect, prevent, and/or mitigate fraud or other potentially illegal or prohibited activities;
- respond to inquiries and provide customer support (for example in relation to payment refunds/chargebacks);
- for audits, regulatory purposes, and compliance with industry standards;
- to send communications regarding new services or products, events, offers and other news regarding our products and services;
- to develop new products and to improve or modify our Services.
Note that we may process your personal data for more than one lawful ground depending on the specific purpose for which we are using your data, like: pubic interest; legal obligation (necessary for compliance with a legal or regulatory obligation); performance of a contract (necessary for the performance of a contract to which you are a party or to take steps at your request prior to entering into a contract); and our legitimate interest.
3. Disclosure of information
Generally, we collect, store and process personal data on servers located in the European Union.
We share your personal data with our partners, including:
I. Twispay group companies/affiliated entities that we control or are under common control, to provide our Services and/or who help us with things like, website hosting, information technology and related infrastructure, customer service, CRM (customer relationship management), marketing services, email delivery, electronic signature, fraud, money laundering, terrorist financing prevention and risk mitigation;
II. Services providers who help us to provide the Services, with things like payment processing and funds settlement (such as, financial institutions, payment method providers, card scheme processors, acquiring banks), website hosting, information technology and related infrastructure, customer service, CRM (customer relationship management), email delivery, electronic signature, fraud, money laundering, terrorist financing prevention and risk mitigation;
III. Card Schemes (e.g., Visa or MasterCard) to provide our Services under the Card Schemes' rules and regulations and entities administering MATCH (MasterCard) and VMAS (Visa) databases where you misuse the Services for payment card transactions or engage in activity the Card Schemes identify as damaging to their brand, or if we required to do so by Card Schemes' rules and regulations; and
IV. Our Merchants , as necessary to process payments or provide the Services (for example transaction information about the purchases made by Customers through our payment processing Services or payments made to the partners of our Merchants providing marketplace services).
We may also disclose your personal data to third parties if we are under a duty to disclose or share your personal data in order to comply with a legal obligation or a court order.
4. Cross-Border transfer
We and our partners maintain appropriate administrative, technical and physical safeguards to protect personal information against accidental or unlawful destruction, accidental loss, alteration, unauthorized disclosure or access, use, and all other unlawful forms of processing of the personal data in our possession. When card data is processed, such data will only be processed in accordance with the strict Payment Card Industry Data Security Standards requirements ("PCI-DSS") in an encrypted form. Only by complying with the PCI-DSS requirements we are permitted to provide debit or credit card payment services. For more details please visit: https://www.pcisecuritystandards.org.
6. Data retention period
When you access our websites or use our Services, we or our authorised services providers may place small data files on your computer or other device. These data files may be cookies, pixel tags or "flash cookies" (collectively "cookies"). The cookies set may obtain information about you, your computer or device, your use of our website and your general internet usage. These technologies help to make it easier for you to log on and use the websites, to recognize you as a customer, provide feedback to us as to which parts of the website you visit, so we can assess the effectiveness of the site and provide a better, faster, and safer experience, advertising purposes, measure promotional effectiveness, help ensure that your account security is not compromised, mitigate risk and prevent fraud.
The types of cookies that we use generally fall into one of four usage categories:
Strictly Necessary cookies
These cookies are essential and are required for the operation of our website. They enable you to navigate around the website and use its features. They include, for example, cookies that enable users to log into secure areas of our websites.
These cookies collect information about how you use the website, including which pages you go to most often and if you get error messages from certain pages. This assists us to improve the way in which our website works, for example, by ensuring that you can find what you are looking for easily.
These cookies allow a website to remember your preferences (for example, your choice of language or region). They are used to recognize you when you return to our website.
These cookies record your visit to our website, the individual pages visited and the links followed. These cookies are used to tailor marketing to you and your interests. Information collected by tracking cookies is commonly used to target online advertising. They are also used to limit the number of times you see an advertisement as well as help measure the effectiveness of the advertising campaign.
We may use third parties, such as advertising networks and exchanges, to allow us to serve you advertisements. These third-party ad networks and exchange providers may use third-party cookies, web beacons, or similar technologies to collect information about your visit to our site and elsewhere on the Internet. The information that these third parties collect may be used to provide you with more relevant advertising on our sites or elsewhere on the web. Third party cookies are covered by the third-parties' privacy policies.
(i) Pixel tags, also known as Web Beacons and clear GIFs, may be used in connection with some Services to, among other things, track the actions of website users (such as email recipients), measure the success of our marketing campaigns and compile statistics about usage of the Services and response rates.
(iii) Flash Cookies - we may use Adobe Flash and other technologies to, among other things, collect and store information about your use of the Services. If you want to block or control flash cookies, you can adjust your settings.
Cookie management and control
Cookies can normally be disabled or deleted from the cookie folder of your browser. You may be able to configure your browser not to accept cookies, although please note that this may affect your ability to use the Services we provide and affect the website's functionality.
8. Third party websites
Our websites may, from time to time, contain links to and from the websites of third parties. If you follow a link to any of these websites, please note that these websites have their own privacy policies and that we do not accept any responsibility or liability for these policies. Please check these policies before you submit any personal data to these third-party websites.
9. Your choices and rights
Generally, you have certain rights under the applicable data protection legislation in respect to your personal data:
|Your rights||What does this mean?|
|The right of access||You have the right to access any personal data we hold about you (subject to certain restrictions). In exceptional circumstances we may charge a reasonable fee for providing such access but only where permitted by law (e.g. where your request is manifestly unfounded or excessive).|
|The right to rectification||You have the right to have your personal data rectified if it is incorrect or outdated and/or completed if it is incomplete.|
|The right to erasure/right to be forgotten||In some cases, you have the right to have your personal data erased or deleted. Note this is not an absolute right, as we may have legal or legitimate grounds for retaining your personal data.|
|The right to object to direct marketing, including profiling||You can unsubscribe or opt out of our direct marketing communication at any time. The easiest way to do this is by clicking on the "unsubscribe" link in any email or communication we send you or follow any other opt-out instructions communicated to you. Please note that if you opt-out of receiving marketing-related emails from us, we may still send you important administrative messages that are required to provide you with our Services.|
|The right to withdraw consent at any time for and personal data processing based on consent||You can withdraw your consent to our processing of your personal data when such processing is based on consent. Where you withdraw your consent, this does not affect the lawfulness of our processing before your withdrawal.|
|The right to object to processing based on legitimate interests||You may object at any time to our processing of your personal data when such processing is based on our legitimate interests.|
|The right not to be subject to a decision based solely on automated decision-making which produces legal effects or similarly significant effects||You may have the right not to be subject to such type of automated decision-making about you, unless: (i) you gave us your explicit consent to use your personal data to make our decision; (ii) we are allowed by law to make our decision; or (iii) our automated decision was necessary to enable us to enter into a contract with you.|
|The right to lodge a complaint with a supervisory authority||You have the right to contact the data protection authority of your country in order to lodge a complaint against our data protection and privacy practices. Do not hesitate to contact us at the details below before lodging any complaint with the competent data protection authority as we will always seek to resolve your complaint in the first instance.|
|The right to data portability||You have the right to move, copy or transfer personal data from our database to another. This only applies to personal data that you have provided, where processing is based on a contract or your consent, and the processing is carried out by automated means.|
|The right to restriction||This right means that our processing of your personal data is restricted, so we can store it, but not use nor process it further.It applies in the following limited circumstances set out in the EU General Data Protection Regulation:• the accuracy of the personal data is contested by you, for a period enabling us to verify the accuracy of the personal data;• the processing is unlawful and you object to the erasure of your personal data and request us to restrict the ways in which we processe your personal data;• We no longer need your personal data for the purposes of its processing, but you require the personal data for the establishment, exercise or defence of legal claims;• You object to our processing of your personal data based on our legitimate interests, pending the verification whether our legitimate grounds override your rights and freedoms.|
|The right to turn on/off cookies||The settings from the Internet browsers are usually programmed by default to accept cookies, but you can easily adjust it by changing the settings of your browser or, where available, by using the tools on our websites.Many cookies are used to enhance the usability or functionality of a website; therefore disabling some types of cookies may prevent you from using certain parts of our websites.If you wish to manage your preferences regarding the cookies which are set by our websites, please use the tool available on the particular website (if applicable), or refer to the Help function within your browser to learn how to manage your settings within your browser. For more information please consult the following links:http://www.aboutcookies.org/.|
To answer your request, we may require proof of your identity.
If you have any questions or concerns about how we treat and use your personal data or wish to exercise any of your rights above, please contact us at email@example.com, or in writing at the following address : Gara Herastrau no. 4C, Building B, 11th floor, Bucharest, Romania.
10. Use of services by minors
The Services are not directed to children we request that they not provide personal data through the Services. We do not knowingly collect information, including personal data, from children or other individuals who are not legally able to use our Services, including our sites.
11. Data processor
We process personal data about Customers and/or partners of Merchants offering marketplace services, when acting as the Merchant's payment service provider. Our Merchants are responsible for making sure that their Customer's and partner's privacy rights are respected, including ensuring appropriate disclosures about third party data collection and use. To the extent that we are acting as a Merchant's data processor, we will process personal data in accordance with the terms of our agreement with the Merchant, the Merchant's lawful instructions and applicable data protection legislation and rules.
Latest updated 07.04.2020