Privacy Policy
Last updated: 12 January 2026
Overview
This PayDo Privacy Policy (hereinafter – “Policy”) sets out the basis on which We collect personal data (any information relating to an identified or identifiable natural person) from You and how We process such data.
This Policy sets out the manner in which We process Your personal data when You:
- access or use the website www.paydo.com (or any of its sub-domains) (Our “Website”) and services; and/or
- provide Us with Your personal data, regardless of how it is provided.
In the provision of PayDo services as well as in Our mission to make PayDo services better for everyone at PayDo, We collect and use the personal data of Our Customers, End-User Customers and authorized persons using PayDo services, visitors to PayDo Website, or anyone contacting PayDo Support Team.
All references to the PayDo services contained within this Policy shall be deemed references to the Services, being those provided by Ecommerce Technologies LTD pursuant to the applicable Terms of Use or any other agreement.
Please read this Policy carefully before using PayDo services and/or the Website and/or contacting Us. By using PayDo services and/or by continuing to visit the Website and/or by contacting Us, You acknowledge that You have been informed of how We handle Your personal data, as described in this Policy.
By clicking ‘I have read and agreed to the Terms’ in the relevant place on the Website, You enter into the Terms of Use with PayDo. This Privacy Policy does not form part of the contract but explains how We handle Your personal data in accordance with applicable data protection laws.
The terms used in this Policy shall be understood in accordance with the PayDo Terms of Use and the applicable laws.
In this Policy, “We”, “Us” or “Our” refers to PayDo. Your PayDo Account is operated by Ecommerce Technologies Ltd (registered number 10844998), Cambridge House, 16 High Street, Saffron Walden, Essex, England, CB10 1AX, United Kingdom, which is authorised by the Financial Conduct Authority (FCA) as an electronic money institution permitted to issue e-money and provide payment services (Register Reference 900916).
This Policy is used by Ecommerce Technologies Ltd. Your Account is operated by the PayDo entity with which You have entered into an agreement, which may not be Ecommerce Technologies Ltd and that entity may be responsible for processing of Your personal data in accordance with its respective privacy policy.
By providing Us with personal data, You acknowledge that We will process it as described in this Policy and give us explicit consent for the processing of Your personal data hereunder.
If You do not agree with the terms of this Policy, You may choose not to use Our services. However, the retention of certain Personal Data by PayDo may be required by applicable law or regulations.
This Privacy Policy supplements but does not supersede or replace any other consents You may have provided to Us or any other agreements or arrangements that You may have with Us, in respect of Your personal data.
1. What personal data we process and how we collect it
1.1. We process personal data that is relevant to Our business relationship with You. Depending on Your interactions with PayDo, this may include:
1.1.1. Information You provide directly – for example, when You complete onboarding forms, register an Account, submit identification documents, make a transaction, or contact Our support team. This may cover details such as Your:
1.1.1.1. name;
1.1.1.2. address;
1.1.1.3. phone number;
1.1.1.4. email address;
1.1.1.5. payment details;
1.1.1.6. other information that You share with Us for providing Our services to You.
1.1.2. Information collected automatically when You visit Our Website or use Our services – for example:
1.1.2.1. technical data such as IP address, login information, browser type and version, time zone, operating system, device identifiers, and
1.1.2.2. usage data such as pages visited, clickstream, response times, errors, and support interactions.
1.1.2.3. For more information about cookies and similar technologies, see the Cookies section in this Policy.
1.1.3. Information obtained from third parties – in certain cases, We receive personal data about You from external sources such as:
1.1.3.1. Identity verification providers and fraud-prevention agencies – results of KYC/AML checks, sanctions or watchlist matches;
1.1.3.2. Financial institutions and payment processors – transaction-related details;
1.1.3.3. Credit reference agencies – creditworthiness information;
1.1.3.4. Public sources – company registers, sanctions lists, or other government databases.
1.1.4. Information relating to other individuals – that You may provide to Us (for example, an authorised representative, family member, or beneficial owner). We process such data only for the purposes described in this Policy and on a lawful basis, and We will inform those individuals where required by law.
1.1.5. We only collect personal data that is necessary to provide Our services, comply with Our legal and regulatory obligations (including AML/KYC requirements), improve Our systems, and protect against fraud and misuse.
1.1.6. You are responsible for ensuring that the personal data You provide to Us is true, accurate, and complete, and for informing Us promptly of any changes. We also take reasonable steps to ensure that the personal data We hold is accurate and kept up to date. You may update or correct Your information at any time by contacting Our support team or, where available, through Your Account settings.
2. Purposes and legal bases for processing of Your personal data
We collect, use, disclose, and otherwise process Your personal data for the following purposes, each supported by an appropriate lawful basis. For each purpose, We indicate whether providing the relevant data is mandatory or voluntary, and the consequences of not providing it:
2.1. Carrying out transactions or taking steps as directed by You.
Legal basis: Necessary to perform Our contract with You.
Requirement: Mandatory – without this information We cannot process Your transactions.
2.2. Facilitating Your use of Our services, and providing, improving, and developing Our services.
Legal basis: Necessary to perform Our contract; in some cases, based on Our legitimate interests to improve and develop Our services.
Requirement: Mandatory for core service functions; voluntary for improvements and optional features.
2.3. Authenticating, operating, and maintaining Your Account.
Legal basis: Necessary to perform Our contract; in some cases, required by law (e.g. identity verification).
Requirement: Mandatory – without accurate identity and login information We cannot provide or maintain Your Account.
2.4. Researching, designing, and launching new features or products.
Legal basis: Based on Our legitimate interests.
Requirement: Voluntary – You may choose whether to participate in surveys or beta testing.
2.5. Presenting content and information on Our Website in the most effective manner for You and for the device You use.
Legal basis: Based on Our legitimate interests.
Requirement: Voluntary – refusal may limit personalization.
2.6. Providing You with service-related alerts and updates.
Legal basis: Necessary to perform Our contract where related to services You use.
Requirement: Mandatory – We must be able to send You essential information regarding Your Account and the services You use (for example, transaction confirmations, security alerts, or changes to Our Terms).
2.7. Direct marketing (where You have provided consent).
Legal basis: Your Consent.
Requirement: Voluntary – You may withdraw Your consent at any time, without affecting the lawfulness of processing before its withdrawal.
Details: With Your consent, We may use Your personal data to send You marketing communications, such as offers or information about Our services, events, or those of Our affiliates or business partners. Communications may be sent by email or SMS. You also have the right to object at any time to the use of Your personal data for direct marketing, and if You do so, We will immediately stop such processing. By emailing Us at support@paydo.com We will cease to send You marketing information without charge.
2.8. Administrative purposes, e.g. accounting, risk management and record keeping, business research, planning, statistical analysis, and staff training.
Legal basis: Required by law for record-keeping; in other cases, based on Our legitimate interests.
Requirement: Mandatory – We cannot provide services without required records.
2.9. Security purposes, e.g. protecting Our Website from unauthorised access or usage and monitoring for security threats.
Legal basis: Required by law in some cases; otherwise, based on Our legitimate interests.
Requirement: Mandatory – refusal may prevent access to services.
2.10. Using data analytics and related technologies to deliver relevant content and improve Our services.
Legal basis: Based on consent for non-essential analytics and cookies; in other cases, based on Our legitimate interests.
Requirement: Voluntary – You may refuse or withdraw Your consent without affecting core services.
2.11. Managing and engaging third parties or service providers that support Our operations, such as IT, analytics, messaging, marketing, and professional services.
Legal basis: Necessary for the performance of Our contract and based on Our legitimate interests; in some cases, required by law.
Requirement: Mandatory – without sharing data with essential providers, We cannot deliver services.
2.12. Complying with laws and regulations applicable to Us in or outside of the UK.
Legal basis: Required by law.
Requirement: Mandatory – We cannot provide services without compliance checks (e.g. AML/KYC)
2.13. Responding to or taking part in legal proceedings, including seeking professional advice.
Legal basis: Required by law or based on Our legitimate interests.
Requirement: Mandatory where required by law; otherwise incidental.
2.14. Communicating with You and responding to Your questions or requests.
Legal basis: Necessary to perform Our contract; in other cases, based on Our legitimate interests.
Requirement: Mandatory for account-related queries; voluntary for general inquiries.
2.15. Supporting Our broader business interests.
Legal basis: Based on Our legitimate interests, provided such interests do not override Your rights and freedoms.
Requirement: Voluntary – applies only where consistent with Your rights and freedoms.
Our legitimate interests in this context include, for example:
- managing Our business and relationship with Our customers and/or users;
- providing and improving Our services;
- responding to inquiries and feedback;
- understanding how Our services are used and developing new features;
- enforcing obligations owed to Us;
- protecting the security and integrity of Our systems;
- sharing data in connection with acquisitions or transfers of Our business.
Whenever We rely on legitimate interests, We balance those interests against Your rights and freedoms to ensure they are not overridden. You have the right to object to such processing at any time (see Your Rights section).
2.16. Other reasonable purposes related or incidental to the above.
Legal basis: The same lawful basis that applies to the main purpose.
Requirement: Determined by the related purpose.
3. Automated Tools and Profiling
3.1. We use automated tools, including profiling, to support certain compliance and risk management activities. For example, We may automatically compare the information You provide to Us against sanctions lists, fraud and risk databases, or internal risk rules to detect unusual or suspicious activity.
3.2. These automated checks are necessary to comply with legal and regulatory obligations (such as anti-money laundering and counter-terrorist financing requirements) and to protect Our services against misuse.
3.4. However, We do not make decisions that are based solely on automated processing. A qualified member of Our staff is always involved in reviewing the results of automated checks before a final decision is made (for example, whether to open an Account, block a transaction, or request additional verification). This means that You will not be subject to a decision based solely on automated processing within the meaning of applicable data protection laws.
4. Minors
4.1. Our services are not intended for and their usage by individuals under the age of 18 (or the minimum legal age of majority in Your country, if higher/lower) is prohibited. We do not knowingly collect personal data from children or minors.
4.2. If You are a parent or legal guardian and believe that a child under Your care has provided Us with personal data, please contact Us immediately. We will take steps to delete such personal data without undue delay, unless We are legally required to retain it.
5. Jurisdiction-specific rights
5.1. Laws in some countries or regions give You additional privacy rights or impose specific requirements. If You live in one of the jurisdictions listed below, those additional rights apply to You as well as the other terms of this Policy.
5.1.1. European Economic Area (EEA): If You are a resident of the EEA We process Your information in the scope of the General Data Protection Regulation (GDPR). In addition to the rights set out in this Policy, You have the right to lodge a complaint with Your local supervisory authority.
5.1.2. The United Kingdom: If You are a resident of the UK, We process Your personal data in accordance with the UK GDPR and the Data Protection Act 2018. You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO).
5.1.3. Brazil: If You are a resident of Brazil, We process Your personal data in accordance with the Lei Geral de Proteção de Dados Pessoais (LGPD).
5.1.4. Canada: If you are located in Canada, We process Your personal data in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA). You have the right under PIPEDA to contact the Office of the Privacy Commissioner of Canada (OPC) if You have relevant concerns.
6. Contacting you
6.1. We may contact You in connection with the purposes described in this Policy, including to provide service-related information, security alerts, and account notifications. Communication may take place by email, SMS, telephone, or other appropriate means.
6.2. We will only send You marketing communications where You have given Your consent (see Direct Marketing section above).
7. Disclosure of Your personal data
7.1. We may share Your personal data with trusted third parties, but only where this is necessary for the purposes described in this Policy and in compliance with applicable law. These categories of recipients include:
7.1.1. Regulators and authorities – such as financial intelligence units, supervisory authorities, tax authorities, or law enforcement, where disclosure is required by applicable law (for example, for AML/CTF reporting).
7.1.2. Payment service providers and financial institutions – including banks, card schemes, and payment processors, in order to execute and settle transactions.
7.1.3. Identity verification and fraud-prevention providers – such as KYC/AML vendors, sanctions and watchlist screening tools, and credit reference agencies.
7.1.4. IT and cloud service providers – that host Our systems, provide security, support, or communications infrastructure.
7.1.5. Professional advisers – such as lawyers, auditors, accountants, or consultants who advise Us on legal, regulatory, or business matters and are bound by confidentiality.
7.1.6. Group companies and affiliates – to the extent necessary for internal administration, compliance, and the provision of shared services.
7.1.7. Business partners and service providers – who help deliver features of Our services, such as analytics, communications, or marketing support (based on Your consent where required).
7.2. We require all third parties to protect Your personal data in accordance with applicable laws and to process it only on Our instructions where they act as service providers.
8. Cookies
8.1. Our Website uses cookies to distinguish You from other users of the website. This helps Us to provide You with a good experience when You browse Our Website and also allows Us to improve Our website.
8.2. A cookie is a small file of letters and numbers that We store on Your browser or the hard drive of Your computer if You agree to the use of cookies. Cookies contain information that is transferred to Your computer’s hard drive.
8.3. We use persistent cookies and session cookies. A persistent cookie stays in Your browser and will be read by Us when You return to Our Website or a partner Website that uses Our services. Session cookies only last for as long as the session (usually the current visit to a Website or a browser session).
8.4. We use the following cookies in connection with the purposes set out above:
8.4.1. strictly necessary cookies – these are cookies that are required for the operation of Our Website. They include, for example, cookies that enable You to log into secure areas of Our Website. These cookies don’t require Your consent.
8.4.2. analytical/performance cookies – they allow Us to recognise and count the number of visitors and to see how visitors move around Our Website when they are using it. This helps Us to improve the way Our Website works, for example, by ensuring that users are finding what they are looking for easily. These cookies are used only with Your consent.
8.4.3. Google Analytics
8.4.3.1. With Your consent, We use Google Analytics to collect information about how visitors use Our Website. Google Analytics sets cookies on Your device to help Us analyse traffic and usage patterns. The information generated by these cookies (including Your IP address) may be transmitted to and stored by Google on servers outside Your country, including in the United States.
8.4.3.2. We use Google Analytics only for statistical and analytical purposes to improve Our Website and services. Google will not combine the information collected through Google Analytics with other data it holds about You.
8.4.3.3. You can withdraw Your consent to Google Analytics at any time by adjusting Your cookie preferences in Our cookie banner or through Your browser settings. For more information on Google’s privacy practices, please visit: policies.google.com/privacy.
8.4.4. functionality cookies – these are used to recognise You when You return to Our Website. This enables Us to personalise Our content for You, greet You by name, and remember Your preferences (for example, Your choice of language or region). These cookies are used only with Your consent.
8.4.5. targeting cookies – these cookies record Your visit to Our Website, the pages You have visited, and the links You have followed. We will use this information to make Our Website and the information displayed on it more relevant to Your interests. These cookies are used only with Your consent.
8.5. You can block cookies by activating the setting on Your browser that allows You to refuse the setting of all or some cookies (however, if You do so, You may not be able to access all or parts of Our Website):
8.5.1. Google Chrome;
8.5.2. Safari;
8.5.3. Mozilla Firefox;
8.5.4. Opera
8.6. We may use third-party web services on Our Website. The service providers that administer these services use technologies such as cookies (which are likely to be analytical/performance cookies or targeting cookies), web server logs, and web beacons to help Us analyse how visitors use Our Website and make the information displayed on it more relevant to Your interests. the information collected through these means (including IP addresses) is disclosed to these service providers. These analytics services may use the data collected to contextualise and personalise the marketing materials of their own advertising network.
9. Third-party websites
9.1. Our Website and communications may contain links to third-party websites. These websites are operated independently from Us, and We do not control their content or privacy practices. If You choose to visit any third-party website, We encourage You to review its privacy policy to understand how Your personal data will be handled.
9.2. This Privacy Policy does not apply to any personal data that You choose to provide directly to third parties.
10. Security
10.1. All information You provide to Us is stored on Our secure servers.
10.2. Any payment transactions will be encrypted using TLS/SSL technology.
10.3. Where We have given You (or where You have chosen) a password that enables You to access the Account, You are responsible for keeping this password confidential. We ask You not to share a password with anyone.
10.4. We restrict access to personal data to Our employees, service providers, and contractors on a strictly need-to-know basis and ensure that those persons are subject to contractual confidentiality obligations.
10.5. Unauthorized access. While We take reasonable precautions to safeguard Your personal data in Our possession or under Our control, We cannot be held responsible for unauthorised or unintended access that is beyond Our control, such as hacking or cybercrimes.
10.6. Vulnerabilities. We review Our information collection, storage, and processing practices from time to time to guard against unauthorised access, processing, or use. Please note, however, that the transmission of information via the Internet is not completely secure. Although We will use reasonable security arrangements to protect Your personal data, We cannot guarantee that Our Website is invulnerable to security breaches, nor do We make any warranty, guarantee, or representation that Your use of Our Website is safe and protected from viruses, worms, trojan horses, and other vulnerabilities. We also do not guarantee the security of data that You choose to send Us electronically. Sending such data is entirely at Your own risk.
10.7. Period of retention. We only retain personal data for so long as We need the personal data to fulfill the purposes We collected it for and to satisfy Our business and/or legal purposes, including audit, accounting, or reporting requirements. In particular, We are required by financial services regulations to retain certain categories of data for minimum periods. For example, identity verification records and transaction data must be stored to comply with anti-money laundering (AML), counter-terrorist financing (CTF), and related regulatory obligations.
10.8. The criteria We use to determine retention periods include, for example:
10.8.1. the type of personal data and the purpose for which it was collected;
10.8.2. whether We are subject to a legal or regulatory obligation to keep the data (such as financial reporting, anti-money laundering, or record-keeping requirements);
10.8.3. the limitation periods under applicable laws, within which legal claims may be brought; and
10.8.4. whether the data is still necessary to provide You with services or to maintain an ongoing customer relationship.
10.9. Anonymized data. In some circumstances, We may anonymise Your personal data so that it can no longer be associated with You, in which case We are entitled to retain and use such data without restriction.
11. International data transfer
11.1. We may transfer Your personal data to countries outside of the country where You are located, including to members of the PayDo group and to service providers who support Our operations. These countries may not provide the same level of data protection as in Your home jurisdiction.
11.2. When We transfer personal data internationally, We take steps to ensure that an adequate level of protection is provided for Your personal data. Depending on the circumstances, these measures may include:
11.2.1. transfers to countries recognised as providing an adequate level of protection by applicable data protection authorities;
11.2.2. use of standard contractual clauses or equivalent safeguards approved for international transfers; or
11.2.3. reliance on other lawful transfer mechanisms, where appropriate.
11.3. The European Commission has recognised certain countries as providing an adequate level of protection for personal data. An up-to-date list of adequate jurisdictions is available on the European Commission’s website
11.4. You may obtain further information about the safeguards We apply to international transfers, or request a copy of them, by contacting Us using the details provided in this Policy.
12. Your rights
12.1. Depending on where You are located and subject to applicable law, You have the following rights in relation to Your personal data:
12.1.1. Access – You have the right to obtain confirmation as to whether We process personal data about You and, if so, to request a copy of the personal data We hold.
12.1.2. Rectification – You have the right to request correction of any inaccurate or incomplete personal data.
12.1.3. Erasure (“right to be forgotten”) – You may request the deletion of Your personal data in certain circumstances, for example where the data is no longer necessary for the purposes for which it was collected, or where You withdraw Your consent.
12.1.4. Restriction – You have the right to request that We restrict the processing of Your personal data in certain cases, such as while We verify its accuracy or consider an objection You have raised.
12.1.5. Objection – You may object at any time to the processing of Your personal data carried out on the basis of Our legitimate interests, and We will assess Your request. You also have an absolute right to object at any time to the use of Your personal data for direct marketing.
12.1.6. Portability – You have the right to request that We provide You with Your personal data in a structured, commonly used, and machine-readable format, and to request that We transfer this data to another controller where technically feasible.
12.1.7. Withdraw consent – Where processing is based on Your consent, You have the right to withdraw that consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
12.1.8. Lodge a complaint – You have the right to lodge a complaint with a data protection authority if You believe that Your rights have been infringed. For EU/EEA users this will be Your local supervisory authority, for UK users the Information Commissioner’s Office (ICO), and for Canadian users the Office of the Privacy Commissioner of Canada (OPC).
12.2. You may have additional rights under the data protection laws of Your jurisdiction. Nothing in this Policy limits or excludes any rights You are entitled to under applicable law.
12.3. To exercise any of Your rights, please contact Us using the details provided in this Policy. We may need to verify Your identity before responding to Your request.
13. Limitations
13.1. We may be permitted under applicable laws to refuse Your request. For example, We may refuse (1) a request for erasure where the personal data is required in connection with claims; or (2) an objection request and continue processing Your personal data based on compelling legitimate grounds for the processing.
14. Complaints
14.1. If You believe that We have not complied with this Policy or with applicable data protection laws, We encourage You to contact Us so that We can resolve Your concerns. You also have the right to lodge a complaint with the competent data protection authority.
15. Changes to our privacy policy
15.1. We may update this Privacy Policy from time to time. If We make material changes, such as changes to the purposes of processing, the identity of the controller, how You can exercise Your rights, or international data transfers, We will notify You in advance through Our Website, or by email, or via Your Account (where available).
15.2. We will provide such notice within a reasonable period before the changes take effect, so that You have the opportunity to review the updated terms. The updated Privacy Policy will clearly state the date from which it applies.
16. Contact Us
16.1. If You have any questions, comments, or requests regarding personal data, please address them to: support@paydo.com

