Legal

Privacy Policy

How we collect, use, share and protect personal data under the UK GDPR and EU GDPR — in both our controller and processor roles.

Last updated: 1 September 2026

1.Who we are

FinPayOne Ltd (company number 17473434), registered at 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom, is the data controller for personal data we collect about website visitors, business contacts and prospective clients. For personal data we process inside systems we build or host for clients, we act as a data processor on that client's instructions.

Privacy enquiries: contact@finpayone.com.

2.Personal data we collect as controller

  • Business contact details you submit through our contact form: full name, business email, company name, stated volume or requirement, and your message.
  • Correspondence with us, including emails, meeting notes and demo requests.
  • Contract and billing information for client organisations, including signatory details and invoicing contacts.
  • Technical data from your visit: IP address, browser and device type, pages viewed and referral source.
  • Cookie and consent records, as described in our Cookie Policy.

3.Why we process it and our lawful bases

  • To respond to enquiries and provide proposals — legitimate interests in responding to business contact, and steps prior to entering a contract.
  • To deliver contracted services and support — performance of a contract.
  • To invoice, keep accounting records and meet tax obligations — legal obligation.
  • To secure our systems, prevent fraud and investigate incidents — legitimate interests in protecting our infrastructure.
  • To conduct know-your-customer checks on business counterparties and screen against sanctions lists — legal obligation and legitimate interests.
  • To send occasional relevant business updates to existing contacts — legitimate interests, with an opt-out in every message.
  • For optional analytics and sales attribution cookies — your consent.

4.Personal data we process for clients

When we build, integrate or host systems for a client, those systems may process personal data about that client's own customers, merchants or staff. In that role FinPayOne is a processor: we act only on the client's documented instructions under a written data processing agreement, we do not use the data for our own purposes, and we do not decide what is collected or for how long it is kept. Individuals with questions about that data should contact the client organisation as controller.

5.Who we share data with

We do not sell personal data and we do not share it with advertising networks for cross-site profiling. Sub-processors used in client engagements are listed in the applicable data processing agreement, with advance notice of changes.

  • Cloud hosting and infrastructure providers operating our platforms and environments.
  • Business tooling providers for email, CRM, document signature, ticketing and accounting.
  • Professional advisers such as auditors, accountants and lawyers.
  • Identity, sanctions and screening providers used for counterparty checks.
  • Regulators, law enforcement or courts where we are legally required to disclose.

6.International transfers

We prefer UK and EEA data residency. Where a transfer outside the UK or EEA is necessary, we rely on an adequacy decision or on the UK International Data Transfer Addendum and the EU Standard Contractual Clauses, supported by a transfer risk assessment and additional technical measures such as encryption.

7.Retention

  • Enquiry and prospect contact data: 24 months from last meaningful contact.
  • Client contract, invoice and accounting records: 7 years from the end of the relationship, to meet statutory obligations.
  • Security and access logs: 12 months, unless retained longer for an active investigation.
  • Cookie consent records: 12 months.
  • Processor-role data: for the period defined in the client's data processing agreement, then deleted or returned.

8.Security measures

We enforce TLS 1.3 in transit and AES-256 encryption at rest, role-based least-privilege access with mandatory multi-factor authentication, segregated environments, audit logging, dependency and vulnerability scanning, annual penetration testing and a documented incident response procedure.

9.Your rights

To exercise a right, email contact@finpayone.com. We respond within one month and may ask for information to verify your identity. You also have the right to complain to the UK Information Commissioner's Office (ico.org.uk) or your local EU supervisory authority.

  • Access a copy of the personal data we hold about you.
  • Have inaccurate data corrected.
  • Request erasure where we no longer need the data and no legal obligation requires us to keep it.
  • Restrict or object to processing based on legitimate interests.
  • Receive data you provided in a portable, machine-readable format.
  • Withdraw consent at any time where processing is consent-based.
  • Object to direct marketing at any time.

10.Automated decision-making

FinPayOne does not make decisions producing legal or similarly significant effects about individuals through solely automated means. Risk-scoring or screening features we build for clients are configured and overseen by that client's compliance function, with human review of outcomes.

11.Changes to this policy

We review this policy at least annually and when our processing changes. Material changes are notified to active clients and reflected in the 'last updated' date on this page.