This Privacy Policy explains how ORBITRA PAYMENTS LTD. collects, uses, stores, processes and discloses personal data obtained through the Website or in connection with the provision and use of the Services.
It describes the categories of personal data that the Company may collect, the sources from which such data may be received, the purposes for which it may be processed, the circumstances in which it may be disclosed to third parties, and the periods during which it may be retained.
This Privacy Policy also outlines the rights available to Users in relation to their personal data and the general principles followed by the Company when handling and protecting such data.
We collect and process personal data to comply with applicable legal and regulatory requirements, to provide, operate and administer the Services, and to enhance the functionality, security and overall quality of the Website and Services.
Personal data may be obtained directly from you, collected automatically when you access or use the Website or Services, or, where applicable, received from third-party partners, service providers or verification sources involved in the provision of the Services.
The categories of personal data that we may collect include:
We may collect and process personal data for the following purposes:
Before entering into a business relationship with a prospective User, the Company may conduct know-your-customer and due diligence procedures for the purposes of verifying identity, assessing risk and complying with applicable legal and regulatory requirements.
These procedures form part of the measures implemented by the Company to identify, prevent and mitigate money laundering, terrorist financing, fraud and other unlawful or prohibited activities.
In connection with such procedures, we may collect and review identification documents and verification materials, including, without limitation, passports, national identity cards, proof of address and other supporting documents. Depending on the relevant circumstances, risk profile, jurisdiction and applicable legal requirements, we may also request additional information, documents or explanations.
The Company may engage third-party service providers, verification partners or other authorized counterparties to perform or assist with KYC, screening and due diligence procedures on the Company’s behalf.
We may disclose or otherwise make your personal data available to third parties that provide services to us or act on our behalf where such disclosure is necessary to provide the Services, comply with legal obligations, protect our legitimate interests or support the operation of our business.
Where personal data is disclosed to such third parties, access shall be limited to the information reasonably required for the relevant purpose. Such third parties are expected to process the disclosed data only for the specific services or functions for which they have been engaged and in accordance with applicable legal and contractual safeguards.
Where certain functions are outsourced or performed with the assistance of third-party service providers, we may take reasonable measures to oversee and monitor the relevant arrangements in order to ensure that the delegated functions are carried out appropriately and securely.
We may also disclose personal data without your prior consent where such disclosure is permitted or required by applicable law, including in the following circumstances:
Where personal data is disclosed without your prior consent, we will seek to limit the information disclosed to what is reasonably necessary for the relevant purpose.
The Company shall not be responsible for any unauthorized, improper or unlawful use of personal data resulting from your failure to maintain the confidentiality and security of your Account credentials, passwords or other access details, including where you disclose such information to third parties.
We may process certain personal data, including your e-mail address, location information and Transaction-related data, in order to send you information about news, updates, campaigns, research, products or Services that may be relevant to you.
We may use this information to better understand your interests, preferences and potential business needs and to provide communications and offers that are more closely related to your use of the Services.
We may also apply limited profiling methods involving the automated processing of certain personal data to identify general preferences, interests or patterns relevant to marketing communications concerning our Services. Any such profiling shall be carried out in accordance with applicable law.
You are not required to receive marketing communications from us and may opt out at any time by contacting User Support or using the unsubscribe or opt-out mechanism provided in the relevant communication.
Personal data is stored on secure servers and protected through appropriate technical and organizational measures intended to reduce the risk of unauthorized access, disclosure, alteration, misuse or loss. Where appropriate, we may use encryption, SSL and other security measures in connection with the storage and transmission of personal data.
We retain personal data for as long as reasonably necessary to fulfil the purposes for which it was collected, including for the duration of our business relationship with you and for any additional period required or permitted by applicable law, regulatory requirements, recordkeeping obligations or legitimate business needs.
Following the termination of the business relationship, we may continue to retain personal data for the period necessary to comply with the legal, regulatory and recordkeeping obligations applicable to the Company. Unless a longer retention period is required or permitted by applicable law, such period will generally not exceed 5 (five) years after the end of the relevant relationship.
Once the applicable retention period has expired, we may securely delete, destroy, anonymize or otherwise dispose of the relevant personal data in accordance with applicable law and the Company’s internal retention procedures.
We apply technical, organizational and administrative measures intended to protect personal data against unauthorized access, disclosure, misuse, loss, modification, destruction and other unlawful forms of processing, with particular care given to data that may be sensitive in nature.
However, no method of storage, transmission or electronic processing can be completely secure or entirely free from risk. Although we take reasonable measures to safeguard personal data, the Company cannot guarantee the absolute security of any information transmitted to us or stored by us. To the extent permitted by applicable law, information transmitted through the internet, including by e-mail, is transmitted at your own risk.
You also have an important role in protecting your personal data. You should use strong and unique passwords, maintain the confidentiality of your credentials, limit access to your Account and devices, log out where appropriate, and carefully manage your security and privacy settings.
Subject to applicable law, Users may have the following rights in relation to their personal data:
The availability and scope of these rights may vary depending on the type of personal data concerned, the purpose for which it is processed and the legal basis applicable to such processing.
If you have any questions, concerns or complaints regarding the manner in which we collect, use, store, process or disclose your personal data, you may contact us and submit the relevant request or complaint.
We are committed to handling personal data in good faith and in accordance with applicable legal, regulatory and internal data protection standards. Where you raise concerns regarding the security of your personal data, the lawfulness of its processing, the period for which it is retained or the circumstances in which it has been disclosed, we will review the matter and use reasonable efforts to address your concern appropriately.
The Company may decline, restrict or defer the handling of a request or complaint where there are reasonable grounds to believe that the request is fraudulent, manifestly unfounded, impracticable, excessive, contrary to applicable law, or may adversely affect the rights, freedoms or security of other Users or third parties.