Bank-grade encryption Accepted in 150+ countries Instant virtual cards

Privacy Policy

1. Introduction

1.1 Purpose of this policy

This policy explains how GPAYNOW LTD (“GPAYNOW”, “we”, “us”, “our”) collects, uses, shares, stores and protects personal data. It covers:

  • personal data we collect when you visit our website or contact us;

  • personal data we collect when you register for an account and use our services, including virtual prepaid card services, account services and SMS verification services; and

  • personal data we are required to collect and process for the purposes of preventing money laundering, terrorist financing and proliferation financing (“financial crime prevention”).

For all of the processing described in this policy, GPAYNOW LTD acts as a data controller. Where we act as a processor on behalf of another organisation, that organisation’s own privacy notice will apply to the relevant processing.

This policy is written to meet our obligations under the UK General Data Protection Regulation (“UK GDPR”) and the Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025, and to meet the specific customer notification requirement in regulation 41(6) of the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 (“MLR 2017”).

1.2 Important statement required by the Money Laundering Regulations

Statutory notice under regulation 41 of the MLR 2017

Before we establish a business relationship with you or carry out an occasional transaction for you, we are required by law to tell you the following:

Any personal data we obtain from you, or about you, for the purpose of customer due diligence and ongoing monitoring will be processed only for the purposes of preventing money laundering, terrorist financing and proliferation financing. We will not use that personal data for any other purpose unless:

  • the use is permitted by an enactment other than the MLR 2017 or the UK GDPR; or

  • you have given your express consent to the proposed use.

Providing this information is a legal requirement. If you do not provide the information we request, we will not be able to open an account for you, establish or continue a business relationship with you, or carry out a transaction for you, and we may be required to terminate an existing relationship.

Note for internal review: regulation 41(6) requires this statement to be provided to the customer before the business relationship or occasional transaction begins. Publishing it inside a linked privacy policy is unlikely on its own to discharge that duty. Surface the same wording as a distinct, acknowledged step in the onboarding flow, and keep a timestamped record of the acknowledgement.

1.3 Who to contact

Role

Contact details

Data controller

GPAYNOW LTD, 128 City Road, London, EC1V 2NX, United Kingdom

General privacy enquiries and data subject requests

[privacy@gpaynow.net]

Data Protection Officer / Privacy lead

[Name / job title], [email address], [postal address if different]

Money Laundering Reporting Officer (MLRO)

[Name / job title], [email address] — for AML matters only; do not send suspicious activity reports to general support

Customer support

[support@gpaynow.net]

Telephone

[+44 xxxx xxx xxx]

Note for internal review: appointing a statutory Data Protection Officer is mandatory only in the circumstances set out in Article 37 UK GDPR. If GPAYNOW LTD does not meet those criteria, delete the “Data Protection Officer” wording and name a privacy contact instead. Do not describe a person as a DPO unless the appointment has been formally made and, where applicable, notified to the ICO.


2. Scope and our regulatory position

This policy applies to:

  • visitors to our website;

  • registered users and account holders;

  • beneficial owners, directors and authorised representatives of business customers;

  • prospective customers whose applications are declined or withdrawn; and

  • individuals whose data we process as part of sanctions screening, fraud prevention and financial crime controls.

Note for internal review — regulatory status. Complete the following before publication and delete this box:

  • Is GPAYNOW LTD registered with the FCA as a payment institution, electronic money institution or cryptoasset business? [Yes / No — registration number …]

  • Is GPAYNOW LTD supervised for AML purposes by the FCA, HMRC or another supervisory authority? [Supervisor name / registration number]

  • Is GPAYNOW LTD registered as a data controller with the Information Commissioner’s Office? [ICO registration number]

The company’s registered nature of business at Companies House is currently recorded under SIC code 58290 (other software publishing). Do not state or imply that GPAYNOW LTD is authorised or regulated by the Financial Conduct Authority unless that is factually correct — falsely claiming to be authorised or exempt is a criminal offence under section 24 of the Financial Services and Markets Act 2000. Where cards, accounts or payment services are issued by a third-party licensed institution, name that institution in section 8.

This question decides how much of this policy is correct — resolve it before publication. The lawful bases in section 4 (rows 2, 3 and 4), the statutory notice in section 1.2, and the retention periods in section 10 all assume that GPAYNOW LTD is itself a “relevant person” under the MLR 2017. If it is not:

  • regulation 41(6) imposes no notice duty on GPAYNOW LTD, so the wording in section 1.2 is a contractual commitment rather than a statutory notice;

  • the deeming provision in regulation 41(7) is unavailable, so public task under Article 6(1)(e) cannot be relied on;

  • regulation 40 does not impose the five-year retention obligation on GPAYNOW LTD directly; and

  • Article 6(1)(c) legal obligation cannot be relied on for another organisation’s legal obligation. The processing would instead need to rest on contract (Article 6(1)(b)) with our partners’ requirements, and on legitimate interests (Article 6(1)(f)) — and the policy must be rewritten accordingly.

Do not leave this as an open bracket.


3. Personal data we collect

3.1 Data you give us

Account registration and profile data: full name, date of birth, nationality, residential address, email address, telephone number, username and password, and account preferences.

Identity verification (KYC) data: images or scans of government-issued identity documents (passport, national identity card, driving licence), the document number, issuing country and expiry date; a selfie or short video used for biometric liveness and face-match checks; proof of address documents (utility bill, bank statement, tenancy agreement); and, where applicable, tax identification numbers.

Business customer data: company name, registration number, registered and trading addresses, constitutional documents, ownership and control structure, and identification data for directors, beneficial owners and authorised signatories.

Source of funds and source of wealth data: information and supporting evidence explaining the origin of the funds you use, your occupation, employer, expected account activity and transaction volumes, and the intended purpose and nature of the business relationship.

Payment and transaction data: cryptocurrency deposit and withdrawal addresses and on-chain transaction hashes (including for BTC, ETH and USDT deposits), bank account or payment instrument details used for funding, card load and spend records, merchant names, amounts, currencies, dates and times.

Communications: the content of emails, support tickets, live chat transcripts, and enquiry forms, together with any attachments you send us.

3.2 Data we collect automatically

IP address and derived approximate location; device identifiers, device and browser type, operating system and language settings; login timestamps and session data; pages viewed and referring URLs; and behavioural signals used for fraud and bot detection (such as typing cadence and device fingerprinting). See section 12 for cookies.

3.3 Data we obtain from third parties

Source

Data obtained

Identity verification providers

Verification results, document authenticity checks, biometric face-match and liveness scores

Credit reference and identity data agencies

Electronic identity confirmation, address history, mortality and identity-fraud markers

Sanctions, PEP and adverse media screening providers

Matches against UK (OFSI), UN, EU, US (OFAC) and other sanctions lists; politically exposed person status; adverse media and law-enforcement watchlist entries

Blockchain analytics providers

Risk scoring of cryptocurrency wallet addresses and transaction chains, exposure to sanctioned or illicit addresses

Fraud prevention databases and card schemes

Fraud markers, chargeback and dispute records, device reputation

Companies House and other public registers

Company details, directorships, beneficial ownership

Card issuing, banking and payment partners

Transaction authorisations, declines, blocks and compliance findings

Our website and advertising partners

Analytics and campaign attribution data (subject to your cookie choices)

3.4 Special category and criminal offence data

We do not seek to collect special category data as a matter of course. However:

  • Biometric data (facial geometry derived from your identity document and selfie) is processed for the specific purpose of uniquely identifying you during onboarding, and is special category data under Article 9 UK GDPR.

  • Data revealing political exposure and data relating to criminal allegations, proceedings and convictions may be generated by PEP, adverse media and sanctions screening, and is criminal offence data under Article 10 UK GDPR.

  • Identity documents may incidentally reveal other special category information (for example, place of birth or nationality). We do not use that information for any purpose other than verifying your identity.

The conditions we rely on for this processing are set out in section 5.3.


4. How we use your personal data, and our lawful bases

#

What we do

Personal data used

Lawful basis (Article 6 UK GDPR)

1

Create and administer your account; provide virtual cards, account services and SMS verification services; process deposits, loads, spend and withdrawals; provide customer support

Registration, account, payment and transaction data, communications

Contract — Art. 6(1)(b): necessary to perform our contract with you or to take steps at your request before entering into it

2

Verify your identity and carry out customer due diligence, enhanced due diligence and ongoing monitoring

Identity, KYC, biometric, business, source of funds data

Legal obligation — Art. 6(1)(c) (MLR 2017) and public task — Art. 6(1)(e), as provided by regulation 41(7) MLR 2017

3

Screen you and your transactions against sanctions, PEP and adverse media lists

Name, date of birth, nationality, address, screening results

Legal obligation — Art. 6(1)(c) (including the Sanctions and Anti-Money Laundering Act 2018) and public task — Art. 6(1)(e)

4

Monitor transactions for suspicious activity; investigate alerts; make suspicious activity reports to the National Crime Agency

Transaction, account, device and screening data

Legal obligation — Art. 6(1)(c) (Proceeds of Crime Act 2002, Terrorism Act 2000, MLR 2017) and public task — Art. 6(1)(e)

5

Prevent, detect and investigate fraud, account takeover, abuse and misuse of our services

Device, behavioural, transaction and fraud-database data

Legitimate interests — Art. 6(1)(f): protecting our business, our customers and the wider payments system; and, where the processing is for the prevention or detection of crime, the recognised legitimate interest basis under Art. 6(1)(ea)

6

Maintain the security, availability and integrity of our systems; keep audit logs

Device, session, log and access data

Legitimate interests — Art. 6(1)(f): information security

7

Respond to enquiries submitted through our website or by email

Name, contact details, job title, company, enquiry content

Legitimate interests — Art. 6(1)(f): responding to people who contact us; or contract where the enquiry is pre-contractual

8

Send marketing communications about our services

Email address, name, marketing preferences, engagement data

Consent — Art. 6(1)(a), where required by PECR; or legitimate interests — Art. 6(1)(f) for existing customers receiving information about similar services (soft opt-in). You may withdraw consent or object at any time

9

Analytics and measurement of website and campaign performance

Cookie and analytics data

Consent where required — Art. 6(1)(a); see section 12 for cookies now exempt from consent

10

Comply with tax, accounting, corporate and regulatory reporting obligations

Account, transaction and financial records

Legal obligation — Art. 6(1)(c)

11

Establish, exercise or defend legal claims; handle complaints, chargebacks and disputes; respond to law enforcement and court orders

Any relevant data

Legal obligation — Art. 6(1)(c); legitimate interests — Art. 6(1)(f)

12

Improve our services, develop new features and produce aggregated statistics

Usage and transaction data, aggregated or pseudonymised wherever possible

Legitimate interests — Art. 6(1)(f): running and improving our business

13

Transfer data in connection with a merger, acquisition, restructuring or sale of assets

Any relevant data

Legitimate interests — Art. 6(1)(f): managing corporate transactions

Where we rely on legitimate interests, we have carried out a legitimate interests assessment balancing our interests against your rights and freedoms. You may request a summary of the relevant assessment using the contact details in section 1.3.


5. Financial crime prevention in detail

5.1 Customer due diligence and ongoing monitoring

We are required to identify you and verify your identity from reliable, independent sources before we establish a business relationship or carry out certain transactions. We must also:

  • identify and verify beneficial owners of corporate customers;

  • understand the purpose and intended nature of the business relationship;

  • establish your source of funds and, where risk requires, your source of wealth;

  • apply enhanced due diligence where the risk is higher — for example where you are a politically exposed person or a family member or close associate of one, where you are connected with a high-risk third country, where the relationship is conducted at a distance without adequate safeguards, or where transactions are unusually large, complex or lack an apparent economic purpose; and

  • conduct ongoing monitoring of the business relationship and scrutinise transactions throughout its life, keeping our records up to date.

We may re-verify your identity or ask for updated documents periodically, or when your activity changes.

5.2 Sanctions screening

We screen customers, beneficial owners and, where relevant, counterparties and cryptocurrency addresses against applicable sanctions lists. These include:

  • the UK Sanctions List, maintained and published by the Foreign, Commonwealth and Development Office under section 2 of the Sanctions and Anti-Money Laundering Act 2018;

  • the Consolidated List of Financial Sanctions Targets maintained by the Office of Financial Sanctions Implementation (OFSI), part of HM Treasury; and

  • United Nations, European Union and United States (OFAC) lists, where relevant to a transaction.

A screening match may result in the freezing or rejection of a transaction, the suspension or closure of your account, and a report to OFSI or another competent authority. We are prohibited from providing services to designated persons.

5.3 Conditions for special category and criminal offence data

Where our financial crime controls involve special category data (Article 9 UK GDPR) or criminal offence data (Article 10 UK GDPR), we rely on the following conditions in Schedule 1 to the Data Protection Act 2018:

Condition

Where we use it

Part 2, paragraph 10 — prevention, investigation or detection of unlawful acts

Sanctions, PEP and adverse media screening; transaction monitoring; investigating alerts; making suspicious activity reports

Part 2, paragraph 12 — regulatory requirements relating to unlawful acts and dishonesty

Complying with, and assisting our partners and supervisors to comply with, AML and financial crime regulatory requirements

Part 2, paragraph 14 — preventing fraud

Sharing data with, and receiving data from, anti-fraud organisations and fraud prevention databases

Part 2, paragraph 15 — suspicion of terrorist financing or money laundering

Voluntary information sharing with other regulated firms under section 21CA of the Terrorism Act 2000 and section 339ZB of the Proceeds of Crime Act 2002. Suspicious activity reports themselves rest on paragraphs 10 and 12

Part 2, paragraph 5, with Part 4 paragraph 39 — appropriate policy document

We maintain an Appropriate Policy Document describing our procedures for complying with the Article 5 principles and our retention and erasure policies for this data. A copy is available on request

For biometric processing during identity verification we rely on Article 9(2)(g) UK GDPR (substantial public interest), together with the Schedule 1 conditions above. We do not rely on your consent for this processing, because we could not honour a withdrawal of consent without failing our financial crime obligations — and consent that cannot be withdrawn is not valid consent. If you are unable or unwilling to complete an automated biometric check, contact us and we will attempt to verify your identity through an alternative manual process; we may be unable to proceed if that process does not satisfy our obligations.

5.4 Suspicious activity reports and the prohibition on “tipping off”

If we know or suspect, or have reasonable grounds to know or suspect, that a person is engaged in money laundering or terrorist financing, we are legally required to submit a suspicious activity report (SAR) to the National Crime Agency.

We are prohibited by law from telling you that a report has been made, or that an investigation is being or may be carried out. This is the “tipping off” offence under section 333A of the Proceeds of Crime Act 2002 and section 21D of the Terrorism Act 2000. It means that:

  • we may decline, delay, freeze or reverse a transaction without giving you a reason;

  • we may suspend or close your account without giving you a reason; and

  • we may be unable to respond fully to a request you make to exercise your data protection rights.

This is not a matter of our discretion. It is a legal restriction, and it applies to all UK firms in the same position.

5.5 Restrictions on your rights in the AML context

Schedule 2 to the Data Protection Act 2018 restricts certain data protection rights where their exercise would be likely to prejudice the prevention or detection of crime, the apprehension or prosecution of offenders, or the assessment or collection of tax. Where a restriction applies, we may withhold information from a subject access response, decline an erasure request, or decline to explain why. We apply restrictions on a case-by-case basis and only to the extent necessary; we do not apply them as a blanket policy.

Separately, regulation 40 of the MLR 2017 requires us to retain due diligence and transaction records for five years. During that period we cannot delete that data at your request.


6. Automated decision-making and profiling

We use automated tools as part of onboarding, screening and monitoring. These include automated document authentication and face-matching, automated sanctions and PEP screening, blockchain address risk scoring, and automated fraud and transaction monitoring rules.

These tools can result in an application being referred for manual review, a transaction being held or declined, or an account being suspended pending review.

Your safeguards. Where a significant decision about you — one producing legal effects, or similarly significantly affecting you — is taken based solely on automated processing, Articles 22A to 22D of the UK GDPR, as inserted by the Data (Use and Access) Act 2025, give you the right to:

  • be given information about the decision;

  • make representations about it;

  • obtain human intervention by a person with the authority and competence to review the decision; and

  • contest the decision.

To exercise these rights, contact us using the details in section 1.3. We will arrange a review by a member of our compliance team who was not responsible for the original automated outcome.

Decisions involving special category data. Under Article 22B, a significant decision taken solely by automated means and based wholly or partly on special category data — which includes the biometric data used in identity verification — is permitted only where you have given explicit consent, or where the processing is authorised by law and we have taken measures to safeguard your rights. [Confirm which of these gates applies to automated onboarding declines, and record the analysis in the relevant DPIA before publication.]

A limitation we should be upfront about. Where a decision arises from a sanctions match or a suspicion of financial crime, our ability to explain it to you is constrained by section 5.4. We will still arrange human review; we may not be able to tell you what the review considered or what it concluded.

We do not use your personal data for automated decision-making for advertising or credit-scoring purposes.


7. Marketing and how to unsubscribe

We send marketing communications only where we have your consent, or where you are an existing customer and the communication concerns similar services and you did not object when we collected your details.

You can opt out at any time by clicking the unsubscribe link in any marketing email, by changing your preferences in your account settings, or by emailing [privacy@gpaynow.net] with the subject line “Unsubscribe” and the email addresses concerned. We will action the request without undue delay and in any event within [10] working days.

Opting out of marketing does not stop service messages — for example transaction confirmations, security alerts, requests for updated due diligence documents, or notices about changes to our terms. We cannot switch those off while you hold an account with us.


8. Who we share your personal data with

Recipient category

Purpose

Examples / placeholders

Card issuing, banking and payment partners

Issuing and servicing cards and accounts; processing transactions

[Name of issuer(s) and BIN sponsor(s)]

Card schemes

Authorisation, settlement, dispute and fraud processes

Visa, Mastercard

Identity verification and KYC providers

Document authentication, biometric verification, electronic identity checks

[Provider name(s)]

Sanctions, PEP and adverse media screening providers

Screening and ongoing monitoring

[Provider name(s)]

Blockchain analytics providers

Cryptocurrency deposit and withdrawal risk assessment

[Provider name(s)]

Fraud prevention agencies and databases

Preventing and detecting fraud

[Provider name(s)]

Cloud hosting, IT and communications providers

Hosting, storage, backup, email, support ticketing, SMS delivery

[Hosting provider], [CRM/helpdesk], [email provider]

Analytics and marketing platforms

Website measurement and campaign reporting, subject to your cookie choices

[Analytics provider], [advertising platforms]

Professional advisers

Legal, audit, accounting and compliance advice

Law firms, auditors, AML consultants

Regulators, law enforcement and government bodies

Legal and regulatory obligations

National Crime Agency, HM Revenue & Customs, Financial Conduct Authority, Office of Financial Sanctions Implementation, Information Commissioner’s Office, police and courts, foreign equivalents where lawfully required

Acquirers, investors and their advisers

Corporate transactions, subject to confidentiality undertakings

As applicable

We require all service providers acting as processors to enter into written contracts meeting Article 28 UK GDPR, to process personal data only on our documented instructions, and to apply appropriate security measures. We do not sell your personal data.


9. International transfers

Some of our service providers and partners are located outside the United Kingdom. Where we transfer personal data outside the UK, we do so only where one of the following applies:

  • the destination is covered by UK adequacy regulations (assessed, since the Data (Use and Access) Act 2025, against the new “data protection test”);

  • the transfer is made under the International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, supported by a transfer risk assessment; or

  • another exception under Chapter V of the UK GDPR applies, for example where the transfer is necessary for the establishment, exercise or defence of legal claims.

Countries to which personal data is currently transferred: [list countries — e.g. European Economic Area, United States, …].

To request a copy of the safeguards we have put in place, email [privacy@gpaynow.net].

Note for internal review: complete the country list from your processor register before publication, and confirm that a transfer risk assessment exists for each non-adequate destination.


10. How long we keep your personal data

Data

Retention period

Reason

Customer due diligence records — identity documents, verification results, source of funds evidence

Five years from the end of the business relationship, or from completion of an occasional transaction

Regulation 40(3) MLR 2017

Transaction records — occasional transactions (no ongoing relationship)

Five years from the date the transaction was completed

Regulation 40(3)(a) MLR 2017

Transaction records — transactions within a business relationship

Five years from the end of the business relationship. We are not required to keep these records for more than ten years from the date the transaction was completed

Regulation 40(3)(b)(i) and 40(4) MLR 2017

Suspicious activity reports and related investigation files

[Five] years from the date of the report, or longer if instructed by the National Crime Agency or required for legal proceedings

POCA 2002; law enforcement requirements

Sanctions screening records and match dispositions

Five years

MLR 2017; OFSI expectations

Account and profile data for closed accounts

Five years from account closure, then deleted or anonymised

Aligns with MLR 2017

Accounting and tax records

Six years from the end of the relevant accounting period

HMRC record-keeping requirements. (Section 388 of the Companies Act 2006 sets a shorter three-year minimum for private companies, so the six-year figure is driven by tax law, not company law)

Complaint and dispute records

Six years from resolution

Limitation Act 1980

Website enquiry emails

[Two] years, then securely archived for a further [five] years and deleted

Business need and limitation periods

CRM records for prospects

[Three] years from last meaningful contact

Business need

Marketing consent records and suppression lists

Consent records for [two] years from withdrawal; suppression lists kept indefinitely

Demonstrating PECR compliance; honouring opt-outs

Website and security logs

[12] months

Security and incident investigation

CCTV, if any

[30] days

Premises security

At the end of the applicable period we delete or securely anonymise the data. Where regulation 40(5) MLR 2017 applies, we must delete personal data obtained for AML purposes once the retention period expires, unless we are required to keep it by another law, you consent to its retention, or we have reasonable grounds to keep it for legal proceedings.


11. Security

We apply technical and organisational measures appropriate to the risk, including encryption of personal data in transit and at rest, role-based access controls and least-privilege access, multi-factor authentication for administrative systems, segregation of production and test environments, logging and monitoring, secure backup and tested restoration, vendor due diligence, staff confidentiality obligations, and AML and data protection training. Access to identity documents and due diligence files is restricted to staff with a defined compliance role.

If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner’s Office within 72 hours of becoming aware of it, and will notify you without undue delay where the breach is likely to result in a high risk to you.

No system is completely secure. Please keep your account credentials confidential, use a unique password and enable any additional security features we offer.


12. Cookies and similar technologies

We use cookies and similar technologies on our website. Cookies fall into the following groups.

Strictly necessary cookies. These are required for the website and your account to function — session management, authentication, load balancing, security and bot protection. We do not ask for consent for these because the law does not require it.

Statistical and appearance cookies. Following the changes made by the Data (Use and Access) Act 2025, cookies used purely for low-risk statistical purposes — producing aggregate measurements of how the site is used, in order to improve it — and for remembering appearance preferences such as language or display settings no longer require your consent, provided we give you clear information and an easy way to object. You have the right to opt out, and you can do so at any time via our cookie settings panel at [link to cookie preference centre].

This exemption is narrow. It does not cover analytics that track individuals across sites, build profiles, or feed advertising measurement — those need your consent, even if you think of them as “just analytics”.

All other cookies, including advertising, cross-site tracking and marketing attribution cookies, are set only with your consent, which you give through our cookie banner and can withdraw at any time through the same settings panel.

You can also block or delete cookies through your browser settings, though this may affect how the site works.

Cookie / technology

Category

Purpose

Duration

[session_id]

Strictly necessary

Maintains your logged-in session

Session

[csrf_token]

Strictly necessary

Protects against cross-site request forgery

Session

[cookie_consent]

Strictly necessary

Records your cookie preferences

[6 months]

[__cf_bm]

Strictly necessary

Bot protection (CDN provider)

30 minutes

[_ga / ga*]

Analytics — consent required

Google Analytics. Sets a persistent client identifier and, in default configurations, feeds advertising features, so it falls outside the statistical exemption

[13 months]

[locale / theme]

Appearance (opt-out)

Remembers language and display preference

[12 months]

[_fbp]

Marketing (consent)

Meta advertising measurement

[90 days]

[li_fat_id]

Marketing (consent)

LinkedIn campaign measurement

[30 days]

Note for internal review: replace this table with the actual output of a cookie scan of [gpaynow.net]. The table must list every cookie actually set, its provider, purpose and lifetime. An inaccurate cookie table is one of the most commonly enforced failures under PECR, where maximum fines are now £17.5 million or 4% of global annual turnover.

When you complete the scan, categorise carefully. Treating an advertising or cross-site analytics cookie as consent-exempt “statistics” is the single easiest way to turn a compliant banner into an enforcement risk. If a cookie identifies a device or user persistently, assume it needs consent unless you can show otherwise.

12.1 Links to third-party websites

Our website may contain links to third-party sites, including those of our partners. Those sites are outside our control and are not covered by this policy. If you submit personal data to them, their own privacy notices apply. We encourage you to read them.


13. Your rights

Subject to the restrictions described in section 5.5, you have the following rights.

Right

What it means

Access

To be told whether we process your data and to receive a copy of it

Rectification

To have inaccurate data corrected and incomplete data completed

Erasure

To have your data deleted where we no longer have a lawful reason to keep it. This right does not apply to records we must retain under the MLR 2017 or other legal obligations

Restriction

To ask us to limit our use of your data in certain circumstances, for example while we check its accuracy

Objection

To object to processing based on legitimate interests or on a public task, on grounds relating to your particular situation. You have an absolute right to object to direct marketing

Portability

To receive data you provided to us, in a structured, commonly used, machine-readable format, and to have it transmitted to another controller, where processing is based on consent or contract and is carried out by automated means

Withdraw consent

To withdraw consent at any time where we rely on it. Withdrawal does not affect processing carried out before withdrawal

Automated decisions

The rights described in section 6

How to exercise your rights. Contact us using the details in section 1.3. We may need to verify your identity before responding — for security, not to obstruct your request.

Our response time. We will respond within one month. Where a request is complex, or where you have made a number of requests, we may extend this by up to a further two months and will tell you within the first month if we do. Following the Data (Use and Access) Act 2025, we are required to carry out a reasonable and proportionate search for your data, and the response clock may be paused where we reasonably need to confirm your identity or need further information from you to identify the data you want. The clock resumes when you provide it.

Cost. There is normally no fee. We may charge a reasonable fee, or refuse to act, where a request is manifestly unfounded or excessive — and we will explain why if we do.


14. Complaints

Complain to us first. If you are unhappy with how we have handled your personal data, please contact [privacy@gpaynow.net], marked for the attention of the [Data Protection Officer / privacy lead]. Under the Data (Use and Access) Act 2025 you have a statutory right to complain to us directly. We will acknowledge your complaint within 30 days and take appropriate steps to respond to it without undue delay.

Complain to the regulator. You also have the right to complain to the UK supervisory authority:

Information Commissioner’s Office Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, United Kingdom Helpline: 0303 123 1113 Website: ico.org.uk

If you live or work outside the UK, or the alleged infringement occurred elsewhere, you may instead complain to your local supervisory authority.

You may also seek a judicial remedy through the courts.


15. Children

Our services are not directed at, and are not available to, anyone under the age of 18. We do not knowingly collect personal data from children. If we become aware that we hold personal data relating to a child, we will delete it, subject to any overriding legal retention obligation. If you believe a child has provided us with personal data, contact [privacy@gpaynow.net].


16. Changes to this policy

We review this policy at least annually and whenever our services or our use of personal data changes. The current version is always available at [gpaynow.net/privacy-policy]. Where a change is material, we will notify registered users by email or through the service before it takes effect. If we ever wish to use your personal data for a purpose not described here, we will tell you and, where required, ask for your consent.


We may use cookies or any other tracking technologies when you visit our website, including any other media form, mobile website, or mobile application related or connected to help customize the Site and improve your experience.

Learn More Accept All