Privacy
Policy
How we collect, use, and protect your personal data. Your privacy is our priority.
Privacy Focused
Your Data, Protected
Introduction
Overview of our data protection practices
This Privacy Policy explains how Paysolo O.O.D. ("Paysolo", "we", "us", "our"), a company incorporated in Bulgaria with company registration number 207268330, collects, uses, stores, and protects your personal data when you use our website (www.paysolo.io) and services.
We are committed to protecting your personal data and complying with the General Data Protection Regulation (GDPR) and all applicable Bulgarian and European data protection laws. This policy applies to all users of our platform, including individuals and businesses.
Data Controller
The data controller for your personal data is Paysolo O.O.D., registered at George Washington 24, fl. 3, office 6, Sofia, Bulgaria. You can contact us regarding data protection matters at contact@paysolo.io
Our Data Protection Officer can be reached at support@paysolo.io
Scope of Data Collection
3. Sources of Data
Purpose & Legal Basis
Why and how we process your data
We process your personal data for the following purposes, each supported by a specific legal basis under the GDPR:
Service Delivery (Contractual Necessity)
We process your data to provide our services, including account management, payment processing, crypto asset exchange, customer support, and communication about your account and transactions.
Regulatory Compliance (Legal Obligation)
We are legally required to process certain personal data to comply with anti-money laundering (AML) regulations, know-your-customer (KYC) requirements, tax reporting obligations, and other applicable laws.
This includes:
- Identity verification and ongoing monitoring
- Sanctions and PEP screening
- Transaction monitoring for suspicious activity
- Reporting to Financial Intelligence Units as required
- Record-keeping for the legally mandated retention period
Analytics & Improvement (Legitimate Interest)
We use aggregated and anonymized data to analyze usage patterns, improve our platform and services, develop new features, and ensure the security and stability of our systems.
Marketing Communications (Consent)
With your consent, we may send you marketing communications about our products, services, and promotions. You can withdraw your consent at any time by clicking the unsubscribe link in our emails or contacting us.
Legal Claims (Legitimate Interest)
We may process your personal data to establish, exercise, or defend legal claims, and to protect the rights, property, or safety of Paysolo, our users, or the public.
Data Sharing with Partners (Contractual Necessity)
We share necessary personal data with our licensed payment partners and service providers to facilitate the services you have requested, subject to appropriate data processing agreements.
Risk Assessment (Legitimate Interest / Legal Obligation)
We conduct risk assessments and profiling as required by AML regulations and to protect our platform against fraud. This may include automated processing of your transaction data to detect unusual patterns.
Complaints Handling (Legal Obligation / Legitimate Interest)
We process personal data to handle and resolve complaints, respond to inquiries from regulatory authorities, and maintain records of our complaint resolution processes.
Your Rights
6. Our Obligations
7. Your GDPR Rights
Under the GDPR, you have the following rights:
- Right of Access — You have the right to request a copy of the personal data we hold about you.
- Right to Rectification — You have the right to request correction of inaccurate or incomplete personal data.
- Right to Erasure — You have the right to request deletion of your personal data, subject to our legal retention obligations.
- Right to Data Portability — You have the right to receive your personal data in a structured, commonly used, and machine-readable format.
- Right to Object — You have the right to object to the processing of your personal data for direct marketing purposes or on grounds relating to your particular situation.
Commission for Personal Data Protection
If you believe that your data protection rights have been violated, you have the right to lodge a complaint with the Commission for Personal Data Protection of Bulgaria, 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592, Bulgaria.
Data Recipients
Data Retention
Specific retention periods apply depending on the type of data:
- Account and transaction data: retained for a minimum of 5 years after account closure, as required by AML regulations.
- KYC documentation: retained for a minimum of 5 years after the end of the business relationship.
- Marketing consent records: retained for the duration of the consent plus 3 years.
10. Co-Administration
In such cases, we ensure that:
- A joint controller agreement is in place that defines each party's responsibilities
- You are informed about the joint processing and your rights
- You can exercise your rights with either controller
11. International Transfers
12. Security Measures
We implement appropriate technical and organizational security measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These include encryption of data in transit and at rest, access controls, regular security audits, and employee training. However, no method of transmission over the internet or electronic storage is 100% secure.
Automated Decision-Making
How we use automated processing
We may use automated decision-making processes in the following contexts:
- Transaction monitoring: Automated systems analyze transactions in real-time to detect patterns that may indicate fraudulent activity, money laundering, or other suspicious behavior.
- Risk assessment: Automated risk scoring may be applied during onboarding and ongoing monitoring to comply with AML/KYC requirements.
Policy Updates
Contact & Inquiries
Data Controller
Paysolo O.O.D.
UIC: 207268330
Sofia, Bulgaria
General Contact
contact@paysolo.io
Data Protection Officer
support@paysolo.io
