Privacy policy
Last updated: [DATE]
This policy will explain what personal data VRPay collects, why, who it is shared with, and what rights you have over it.
01Who we are
Name the legal entity acting as data controller, its registered address, company number, and the contact details of the data protection officer or privacy contact.
02What data we collect
List each category: identity and verification documents collected for KYC, contact details, financial and transaction data, device and log data, and anything gathered from third-party verification providers.
03How we use your data and our legal basis
Map each purpose to a lawful basis under GDPR Article 6 — contract performance for operating accounts, legal obligation for anti-money-laundering checks and record keeping, legitimate interests for fraud prevention, consent for marketing.
04Who we share it with
Name the categories of recipient: licensed partner institutions holding the funds, card issuers and processors, identity verification providers, cloud hosting, and regulators or law enforcement where legally required.
05International transfers
State which transfers leave the UK/EEA, and the safeguard relied on for each — adequacy decision, standard contractual clauses, or another Article 46 mechanism.
06How long we keep it
Give retention periods per category. Anti-money-laundering records typically carry a statutory minimum retention period that outlives account closure — state it explicitly.
07Your rights
Access, rectification, erasure, restriction, portability, objection, and withdrawal of consent. Explain how to exercise each, the response deadline, and that no fee applies in ordinary cases.
08Complaints and contact
Give the privacy contact address and name the supervisory authority a complaint can be raised with in each market VRPay operates in.