Privacy Policy
Last updated: 16 September 2026
This is a template. Replace the bracketed placeholders and have the text reviewed by your legal adviser before publishing. Nothing on this page is legal advice.
1. Controller
The controller responsible for personal data processed on this website and in the ePayX service is ePayX Ltd., [Street and number], [Postcode] [City], [Country] ("ePayX", "we"). You can reach our data protection contact at [email protected].
2. What this policy covers
This policy describes how we handle personal data of visitors to this website, of merchants who use ePayX as their Merchant of Record, and of end customers who buy a product sold by ePayX on behalf of a merchant.
3. Data we process and why
3.1 Website visitors
- Server logs. IP address, user agent, requested page, timestamp. Purpose: operating and securing the site. Legal basis: legitimate interest (Art. 6(1)(f) GDPR). Retention: [14] days.
- Contact form. Name, email, company, message and the data you choose to include. Purpose: answering your request. Legal basis: pre-contractual steps or legitimate interest (Art. 6(1)(b) and (f) GDPR). Retention: [12] months after the conversation ends.
- Fonts. This site loads web fonts from Google Fonts. Your browser sends its IP address to Google when fetching them. [If you self-host fonts, delete this item.]
- Cookies and analytics. This site sets no analytics or advertising cookies. [Update if you add analytics.]
3.2 Merchants
To provide the Merchant of Record service we process business contact details, account credentials, bank details for payouts, tax identification numbers, and transaction data related to your products. Legal basis: performance of the contract (Art. 6(1)(b) GDPR) and legal obligations such as anti-money-laundering and tax law (Art. 6(1)(c) GDPR).
3.3 End customers of our merchants
When ePayX sells a product as Merchant of Record we process the buyer's name, email, billing country and address, payment method data (handled by our PCI-certified payment partners; we do not store full card numbers), tax status, IP address and device signals for fraud prevention, and the purchase history. Legal basis: performance of the purchase contract, legal obligations (tax, accounting, consumer law) and legitimate interest in fraud prevention.
4. Recipients
We share data only where necessary with: payment service providers and acquiring banks; fraud-prevention services; tax authorities and tax-compliance providers; email and hosting providers; professional advisers; and the merchant whose product you bought (limited to what they need to deliver the product and provide support). All processors are bound by data processing agreements.
5. International transfers
Where data is transferred outside the EEA or the UK, we rely on adequacy decisions or the EU Standard Contractual Clauses with supplementary measures where needed.
6. Retention
Transaction and invoice data are retained for the statutory period under applicable tax and commercial law (typically [10] years in Germany). Fraud signals are retained for [24] months. Other data is deleted when no longer needed for the purpose it was collected.
7. Your rights
You have the right to access, rectify and erase your data, to restrict or object to processing, to data portability, and to withdraw consent where processing is based on consent. You may lodge a complaint with a supervisory authority, in particular in the member state of your residence. To exercise your rights write to [email protected].
8. Security
ePayX maintains technical and organisational measures appropriate to the risk, including encryption in transit and at rest, access controls, logging and regular testing. Card data is processed by PCI DSS Level 1 certified partners.
9. Changes
We will update this policy when our processing changes. The date at the top shows the current version.