This policy explains how GPAYNOW LTD (“GPAYNOW”, “we”, “us”, “our”) collects, uses, shares, stores and protects personal data. It covers:
personal data we collect when you visit our website or contact us;
personal data we collect when you register for an account and use our services, including virtual prepaid card services, account services and SMS verification services; and
personal data we are required to collect and process for the purposes of preventing money laundering, terrorist financing and proliferation financing (“financial crime prevention”).
For all of the processing described in this policy, GPAYNOW LTD acts as a data controller. Where we act as a processor on behalf of another organisation, that organisation’s own privacy notice will apply to the relevant processing.
This policy is written to meet our obligations under the UK General Data Protection Regulation (“UK GDPR”) and the Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025, and to meet the specific customer notification requirement in regulation 41(6) of the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 (“MLR 2017”).
Statutory notice under regulation 41 of the MLR 2017
Before we establish a business relationship with you or carry out an occasional transaction for you, we are required by law to tell you the following:
Any personal data we obtain from you, or about you, for the purpose of customer due diligence and ongoing monitoring will be processed only for the purposes of preventing money laundering, terrorist financing and proliferation financing. We will not use that personal data for any other purpose unless:
the use is permitted by an enactment other than the MLR 2017 or the UK GDPR; or
you have given your express consent to the proposed use.
Providing this information is a legal requirement. If you do not provide the information we request, we will not be able to open an account for you, establish or continue a business relationship with you, or carry out a transaction for you, and we may be required to terminate an existing relationship.
Note for internal review: regulation 41(6) requires this statement to be provided to the customer before the business relationship or occasional transaction begins. Publishing it inside a linked privacy policy is unlikely on its own to discharge that duty. Surface the same wording as a distinct, acknowledged step in the onboarding flow, and keep a timestamped record of the acknowledgement.
Role
Contact details
Data controller
GPAYNOW LTD, 128 City Road, London, EC1V 2NX, United Kingdom
General privacy enquiries and data subject requests
[privacy@gpaynow.net]
Data Protection Officer / Privacy lead
[Name / job title], [email address], [postal address if different]
Money Laundering Reporting Officer (MLRO)
[Name / job title], [email address] — for AML matters only; do not send suspicious activity reports to general support
Customer support
[support@gpaynow.net]
Telephone
[+44 xxxx xxx xxx]
Note for internal review: appointing a statutory Data Protection Officer is mandatory only in the circumstances set out in Article 37 UK GDPR. If GPAYNOW LTD does not meet those criteria, delete the “Data Protection Officer” wording and name a privacy contact instead. Do not describe a person as a DPO unless the appointment has been formally made and, where applicable, notified to the ICO.
This policy applies to:
visitors to our website;
registered users and account holders;
beneficial owners, directors and authorised representatives of business customers;
prospective customers whose applications are declined or withdrawn; and
individuals whose data we process as part of sanctions screening, fraud prevention and financial crime controls.
Note for internal review — regulatory status. Complete the following before publication and delete this box:
Is GPAYNOW LTD registered with the FCA as a payment institution, electronic money institution or cryptoasset business? [Yes / No — registration number …]
Is GPAYNOW LTD supervised for AML purposes by the FCA, HMRC or another supervisory authority? [Supervisor name / registration number]
Is GPAYNOW LTD registered as a data controller with the Information Commissioner’s Office? [ICO registration number]
The company’s registered nature of business at Companies House is currently recorded under SIC code 58290 (other software publishing). Do not state or imply that GPAYNOW LTD is authorised or regulated by the Financial Conduct Authority unless that is factually correct — falsely claiming to be authorised or exempt is a criminal offence under section 24 of the Financial Services and Markets Act 2000. Where cards, accounts or payment services are issued by a third-party licensed institution, name that institution in section 8.
This question decides how much of this policy is correct — resolve it before publication. The lawful bases in section 4 (rows 2, 3 and 4), the statutory notice in section 1.2, and the retention periods in section 10 all assume that GPAYNOW LTD is itself a “relevant person” under the MLR 2017. If it is not:
regulation 41(6) imposes no notice duty on GPAYNOW LTD, so the wording in section 1.2 is a contractual commitment rather than a statutory notice;
the deeming provision in regulation 41(7) is unavailable, so public task under Article 6(1)(e) cannot be relied on;
regulation 40 does not impose the five-year retention obligation on GPAYNOW LTD directly; and
Article 6(1)(c) legal obligation cannot be relied on for another organisation’s legal obligation. The processing would instead need to rest on contract (Article 6(1)(b)) with our partners’ requirements, and on legitimate interests (Article 6(1)(f)) — and the policy must be rewritten accordingly.
Do not leave this as an open bracket.
Account registration and profile data: full name, date of birth, nationality, residential address, email address, telephone number, username and password, and account preferences.
Identity verification (KYC) data: images or scans of government-issued identity documents (passport, national identity card, driving licence), the document number, issuing country and expiry date; a selfie or short video used for biometric liveness and face-match checks; proof of address documents (utility bill, bank statement, tenancy agreement); and, where applicable, tax identification numbers.
Business customer data: company name, registration number, registered and trading addresses, constitutional documents, ownership and control structure, and identification data for directors, beneficial owners and authorised signatories.
Source of funds and source of wealth data: information and supporting evidence explaining the origin of the funds you use, your occupation, employer, expected account activity and transaction volumes, and the intended purpose and nature of the business relationship.
Payment and transaction data: cryptocurrency deposit and withdrawal addresses and on-chain transaction hashes (including for BTC, ETH and USDT deposits), bank account or payment instrument details used for funding, card load and spend records, merchant names, amounts, currencies, dates and times.
Communications: the content of emails, support tickets, live chat transcripts, and enquiry forms, together with any attachments you send us.
IP address and derived approximate location; device identifiers, device and browser type, operating system and language settings; login timestamps and session data; pages viewed and referring URLs; and behavioural signals used for fraud and bot detection (such as typing cadence and device fingerprinting). See section 12 for cookies.
Source
Data obtained
Identity verification providers
Verification results, document authenticity checks, biometric face-match and liveness scores
Credit reference and identity data agencies
Electronic identity confirmation, address history, mortality and identity-fraud markers
Sanctions, PEP and adverse media screening providers
Matches against UK (OFSI), UN, EU, US (OFAC) and other sanctions lists; politically exposed person status; adverse media and law-enforcement watchlist entries
Blockchain analytics providers
Risk scoring of cryptocurrency wallet addresses and transaction chains, exposure to sanctioned or illicit addresses
Fraud prevention databases and card schemes
Fraud markers, chargeback and dispute records, device reputation
Companies House and other public registers
Company details, directorships, beneficial ownership
Card issuing, banking and payment partners
Transaction authorisations, declines, blocks and compliance findings
Our website and advertising partners
Analytics and campaign attribution data (subject to your cookie choices)
We do not seek to collect special category data as a matter of course. However:
Biometric data (facial geometry derived from your identity document and selfie) is processed for the specific purpose of uniquely identifying you during onboarding, and is special category data under Article 9 UK GDPR.
Data revealing political exposure and data relating to criminal allegations, proceedings and convictions may be generated by PEP, adverse media and sanctions screening, and is criminal offence data under Article 10 UK GDPR.
Identity documents may incidentally reveal other special category information (for example, place of birth or nationality). We do not use that information for any purpose other than verifying your identity.
The conditions we rely on for this processing are set out in section 5.3.
#
What we do
Personal data used
Lawful basis (Article 6 UK GDPR)
1
Create and administer your account; provide virtual cards, account services and SMS verification services; process deposits, loads, spend and withdrawals; provide customer support
Registration, account, payment and transaction data, communications
Contract — Art. 6(1)(b): necessary to perform our contract with you or to take steps at your request before entering into it
2
Verify your identity and carry out customer due diligence, enhanced due diligence and ongoing monitoring
Identity, KYC, biometric, business, source of funds data
Legal obligation — Art. 6(1)(c) (MLR 2017) and public task — Art. 6(1)(e), as provided by regulation 41(7) MLR 2017
3
Screen you and your transactions against sanctions, PEP and adverse media lists
Name, date of birth, nationality, address, screening results
Legal obligation — Art. 6(1)(c) (including the Sanctions and Anti-Money Laundering Act 2018) and public task — Art. 6(1)(e)
4
Monitor transactions for suspicious activity; investigate alerts; make suspicious activity reports to the National Crime Agency
Transaction, account, device and screening data
Legal obligation — Art. 6(1)(c) (Proceeds of Crime Act 2002, Terrorism Act 2000, MLR 2017) and public task — Art. 6(1)(e)
5
Prevent, detect and investigate fraud, account takeover, abuse and misuse of our services
Device, behavioural, transaction and fraud-database data
Legitimate interests — Art. 6(1)(f): protecting our business, our customers and the wider payments system; and, where the processing is for the prevention or detection of crime, the recognised legitimate interest basis under Art. 6(1)(ea)
6
Maintain the security, availability and integrity of our systems; keep audit logs
Device, session, log and access data
Legitimate interests — Art. 6(1)(f): information security
7
Respond to enquiries submitted through our website or by email
Name, contact details, job title, company, enquiry content
Legitimate interests — Art. 6(1)(f): responding to people who contact us; or contract where the enquiry is pre-contractual
8
Send marketing communications about our services
Email address, name, marketing preferences, engagement data
Consent — Art. 6(1)(a), where required by PECR; or legitimate interests — Art. 6(1)(f) for existing customers receiving information about similar services (soft opt-in). You may withdraw consent or object at any time
9
Analytics and measurement of website and campaign performance
Cookie and analytics data
Consent where required — Art. 6(1)(a); see section 12 for cookies now exempt from consent
10
Comply with tax, accounting, corporate and regulatory reporting obligations
Account, transaction and financial records
Legal obligation — Art. 6(1)(c)
11
Establish, exercise or defend legal claims; handle complaints, chargebacks and disputes; respond to law enforcement and court orders
Any relevant data
Legal obligation — Art. 6(1)(c); legitimate interests — Art. 6(1)(f)
12
Improve our services, develop new features and produce aggregated statistics
Usage and transaction data, aggregated or pseudonymised wherever possible
Legitimate interests — Art. 6(1)(f): running and improving our business
13
Transfer data in connection with a merger, acquisition, restructuring or sale of assets
Any relevant data
Legitimate interests — Art. 6(1)(f): managing corporate transactions
Where we rely on legitimate interests, we have carried out a legitimate interests assessment balancing our interests against your rights and freedoms. You may request a summary of the relevant assessment using the contact details in section 1.3.
We are required to identify you and verify your identity from reliable, independent sources before we establish a business relationship or carry out certain transactions. We must also:
identify and verify beneficial owners of corporate customers;
understand the purpose and intended nature of the business relationship;
establish your source of funds and, where risk requires, your source of wealth;
apply enhanced due diligence where the risk is higher — for example where you are a politically exposed person or a family member or close associate of one, where you are connected with a high-risk third country, where the relationship is conducted at a distance without adequate safeguards, or where transactions are unusually large, complex or lack an apparent economic purpose; and
conduct ongoing monitoring of the business relationship and scrutinise transactions throughout its life, keeping our records up to date.
We may re-verify your identity or ask for updated documents periodically, or when your activity changes.
We screen customers, beneficial owners and, where relevant, counterparties and cryptocurrency addresses against applicable sanctions lists. These include:
the UK Sanctions List, maintained and published by the Foreign, Commonwealth and Development Office under section 2 of the Sanctions and Anti-Money Laundering Act 2018;
the Consolidated List of Financial Sanctions Targets maintained by the Office of Financial Sanctions Implementation (OFSI), part of HM Treasury; and
United Nations, European Union and United States (OFAC) lists, where relevant to a transaction.
A screening match may result in the freezing or rejection of a transaction, the suspension or closure of your account, and a report to OFSI or another competent authority. We are prohibited from providing services to designated persons.
Where our financial crime controls involve special category data (Article 9 UK GDPR) or criminal offence data (Article 10 UK GDPR), we rely on the following conditions in Schedule 1 to the Data Protection Act 2018:
Condition | Where we use it |
|---|---|
Part 2, paragraph 10 — prevention, investigation or detection of unlawful acts | Sanctions, PEP and adverse media screening; transaction monitoring; investigating alerts; making suspicious activity reports |
Part 2, paragraph 12 — regulatory requirements relating to unlawful acts and dishonesty | Complying with, and assisting our partners and supervisors to comply with, AML and financial crime regulatory requirements |
Part 2, paragraph 14 — preventing fraud | Sharing data with, and receiving data from, anti-fraud organisations and fraud prevention databases |
Part 2, paragraph 15 — suspicion of terrorist financing or money laundering | Voluntary information sharing with other regulated firms under section 21CA of the Terrorism Act 2000 and section 339ZB of the Proceeds of Crime Act 2002. Suspicious activity reports themselves rest on paragraphs 10 and 12 |
Part 2, paragraph 5, with Part 4 paragraph 39 — appropriate policy document | We maintain an Appropriate Policy Document describing our procedures for complying with the Article 5 principles and our retention and erasure policies for this data. A copy is available on request |
For biometric processing during identity verification we rely on Article 9(2)(g) UK GDPR (substantial public interest), together with the Schedule 1 conditions above. We do not rely on your consent for this processing, because we could not honour a withdrawal of consent without failing our financial crime obligations — and consent that cannot be withdrawn is not valid consent. If you are unable or unwilling to complete an automated biometric check, contact us and we will attempt to verify your identity through an alternative manual process; we may be unable to proceed if that process does not satisfy our obligations.
If we know or suspect, or have reasonable grounds to know or suspect, that a person is engaged in money laundering or terrorist financing, we are legally required to submit a suspicious activity report (SAR) to the National Crime Agency.
We are prohibited by law from telling you that a report has been made, or that an investigation is being or may be carried out. This is the “tipping off” offence under section 333A of the Proceeds of Crime Act 2002 and section 21D of the Terrorism Act 2000. It means that:
we may decline, delay, freeze or reverse a transaction without giving you a reason;
we may suspend or close your account without giving you a reason; and
we may be unable to respond fully to a request you make to exercise your data protection rights.
This is not a matter of our discretion. It is a legal restriction, and it applies to all UK firms in the same position.
Schedule 2 to the Data Protection Act 2018 restricts certain data protection rights where their exercise would be likely to prejudice the prevention or detection of crime, the apprehension or prosecution of offenders, or the assessment or collection of tax. Where a restriction applies, we may withhold information from a subject access response, decline an erasure request, or decline to explain why. We apply restrictions on a case-by-case basis and only to the extent necessary; we do not apply them as a blanket policy.
Separately, regulation 40 of the MLR 2017 requires us to retain due diligence and transaction records for five years. During that period we cannot delete that data at your request.
We use automated tools as part of onboarding, screening and monitoring. These include automated document authentication and face-matching, automated sanctions and PEP screening, blockchain address risk scoring, and automated fraud and transaction monitoring rules.
These tools can result in an application being referred for manual review, a transaction being held or declined, or an account being suspended pending review.
Your safeguards. Where a significant decision about you — one producing legal effects, or similarly significantly affecting you — is taken based solely on automated processing, Articles 22A to 22D of the UK GDPR, as inserted by the Data (Use and Access) Act 2025, give you the right to:
be given information about the decision;
make representations about it;
obtain human intervention by a person with the authority and competence to review the decision; and
contest the decision.
To exercise these rights, contact us using the details in section 1.3. We will arrange a review by a member of our compliance team who was not responsible for the original automated outcome.
Decisions involving special category data. Under Article 22B, a significant decision taken solely by automated means and based wholly or partly on special category data — which includes the biometric data used in identity verification — is permitted only where you have given explicit consent, or where the processing is authorised by law and we have taken measures to safeguard your rights. [Confirm which of these gates applies to automated onboarding declines, and record the analysis in the relevant DPIA before publication.]
A limitation we should be upfront about. Where a decision arises from a sanctions match or a suspicion of financial crime, our ability to explain it to you is constrained by section 5.4. We will still arrange human review; we may not be able to tell you what the review considered or what it concluded.
We do not use your personal data for automated decision-making for advertising or credit-scoring purposes.
We send marketing communications only where we have your consent, or where you are an existing customer and the communication concerns similar services and you did not object when we collected your details.
You can opt out at any time by clicking the unsubscribe link in any marketing email, by changing your preferences in your account settings, or by emailing [privacy@gpaynow.net] with the subject line “Unsubscribe” and the email addresses concerned. We will action the request without undue delay and in any event within [10] working days.
Opting out of marketing does not stop service messages — for example transaction confirmations, security alerts, requests for updated due diligence documents, or notices about changes to our terms. We cannot switch those off while you hold an account with us.
Recipient category
Purpose
Examples / placeholders
Card issuing, banking and payment partners
Issuing and servicing cards and accounts; processing transactions
[Name of issuer(s) and BIN sponsor(s)]
Card schemes
Authorisation, settlement, dispute and fraud processes
Visa, Mastercard
Identity verification and KYC providers
Document authentication, biometric verification, electronic identity checks
[Provider name(s)]
Sanctions, PEP and adverse media screening providers
Screening and ongoing monitoring
[Provider name(s)]
Blockchain analytics providers
Cryptocurrency deposit and withdrawal risk assessment
[Provider name(s)]
Fraud prevention agencies and databases
Preventing and detecting fraud
[Provider name(s)]
Cloud hosting, IT and communications providers
Hosting, storage, backup, email, support ticketing, SMS delivery
[Hosting provider], [CRM/helpdesk], [email provider]
Analytics and marketing platforms
Website measurement and campaign reporting, subject to your cookie choices
[Analytics provider], [advertising platforms]
Professional advisers
Legal, audit, accounting and compliance advice
Law firms, auditors, AML consultants
Regulators, law enforcement and government bodies
Legal and regulatory obligations
National Crime Agency, HM Revenue & Customs, Financial Conduct Authority, Office of Financial Sanctions Implementation, Information Commissioner’s Office, police and courts, foreign equivalents where lawfully required
Acquirers, investors and their advisers
Corporate transactions, subject to confidentiality undertakings
As applicable
We require all service providers acting as processors to enter into written contracts meeting Article 28 UK GDPR, to process personal data only on our documented instructions, and to apply appropriate security measures. We do not sell your personal data.
Some of our service providers and partners are located outside the United Kingdom. Where we transfer personal data outside the UK, we do so only where one of the following applies:
the destination is covered by UK adequacy regulations (assessed, since the Data (Use and Access) Act 2025, against the new “data protection test”);
the transfer is made under the International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, supported by a transfer risk assessment; or
another exception under Chapter V of the UK GDPR applies, for example where the transfer is necessary for the establishment, exercise or defence of legal claims.
Countries to which personal data is currently transferred: [list countries — e.g. European Economic Area, United States, …].
To request a copy of the safeguards we have put in place, email [privacy@gpaynow.net].
Note for internal review: complete the country list from your processor register before publication, and confirm that a transfer risk assessment exists for each non-adequate destination.
Data
Retention period
Reason
Customer due diligence records — identity documents, verification results, source of funds evidence
Five years from the end of the business relationship, or from completion of an occasional transaction
Regulation 40(3) MLR 2017
Transaction records — occasional transactions (no ongoing relationship)
Five years from the date the transaction was completed
Regulation 40(3)(a) MLR 2017
Transaction records — transactions within a business relationship
Five years from the end of the business relationship. We are not required to keep these records for more than ten years from the date the transaction was completed
Regulation 40(3)(b)(i) and 40(4) MLR 2017
Suspicious activity reports and related investigation files
[Five] years from the date of the report, or longer if instructed by the National Crime Agency or required for legal proceedings
POCA 2002; law enforcement requirements
Sanctions screening records and match dispositions
Five years
MLR 2017; OFSI expectations
Account and profile data for closed accounts
Five years from account closure, then deleted or anonymised
Aligns with MLR 2017
Accounting and tax records
Six years from the end of the relevant accounting period
HMRC record-keeping requirements. (Section 388 of the Companies Act 2006 sets a shorter three-year minimum for private companies, so the six-year figure is driven by tax law, not company law)
Complaint and dispute records
Six years from resolution
Limitation Act 1980
Website enquiry emails
[Two] years, then securely archived for a further [five] years and deleted
Business need and limitation periods
CRM records for prospects
[Three] years from last meaningful contact
Business need
Marketing consent records and suppression lists
Consent records for [two] years from withdrawal; suppression lists kept indefinitely
Demonstrating PECR compliance; honouring opt-outs
Website and security logs
[12] months
Security and incident investigation
CCTV, if any
[30] days
Premises security
At the end of the applicable period we delete or securely anonymise the data. Where regulation 40(5) MLR 2017 applies, we must delete personal data obtained for AML purposes once the retention period expires, unless we are required to keep it by another law, you consent to its retention, or we have reasonable grounds to keep it for legal proceedings.
We apply technical and organisational measures appropriate to the risk, including encryption of personal data in transit and at rest, role-based access controls and least-privilege access, multi-factor authentication for administrative systems, segregation of production and test environments, logging and monitoring, secure backup and tested restoration, vendor due diligence, staff confidentiality obligations, and AML and data protection training. Access to identity documents and due diligence files is restricted to staff with a defined compliance role.
If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner’s Office within 72 hours of becoming aware of it, and will notify you without undue delay where the breach is likely to result in a high risk to you.
No system is completely secure. Please keep your account credentials confidential, use a unique password and enable any additional security features we offer.
We use cookies and similar technologies on our website. Cookies fall into the following groups.
Strictly necessary cookies. These are required for the website and your account to function — session management, authentication, load balancing, security and bot protection. We do not ask for consent for these because the law does not require it.
Statistical and appearance cookies. Following the changes made by the Data (Use and Access) Act 2025, cookies used purely for low-risk statistical purposes — producing aggregate measurements of how the site is used, in order to improve it — and for remembering appearance preferences such as language or display settings no longer require your consent, provided we give you clear information and an easy way to object. You have the right to opt out, and you can do so at any time via our cookie settings panel at [link to cookie preference centre].
This exemption is narrow. It does not cover analytics that track individuals across sites, build profiles, or feed advertising measurement — those need your consent, even if you think of them as “just analytics”.
All other cookies, including advertising, cross-site tracking and marketing attribution cookies, are set only with your consent, which you give through our cookie banner and can withdraw at any time through the same settings panel.
You can also block or delete cookies through your browser settings, though this may affect how the site works.
Cookie / technology | Category | Purpose | Duration |
|---|---|---|---|
[session_id] | Strictly necessary | Maintains your logged-in session | Session |
[csrf_token] | Strictly necessary | Protects against cross-site request forgery | Session |
[cookie_consent] | Strictly necessary | Records your cookie preferences | [6 months] |
[__cf_bm] | Strictly necessary | Bot protection (CDN provider) | 30 minutes |
[_ga / ga*] | Analytics — consent required | Google Analytics. Sets a persistent client identifier and, in default configurations, feeds advertising features, so it falls outside the statistical exemption | [13 months] |
[locale / theme] | Appearance (opt-out) | Remembers language and display preference | [12 months] |
[_fbp] | Marketing (consent) | Meta advertising measurement | [90 days] |
[li_fat_id] | Marketing (consent) | LinkedIn campaign measurement | [30 days] |
Note for internal review: replace this table with the actual output of a cookie scan of [gpaynow.net]. The table must list every cookie actually set, its provider, purpose and lifetime. An inaccurate cookie table is one of the most commonly enforced failures under PECR, where maximum fines are now £17.5 million or 4% of global annual turnover.
When you complete the scan, categorise carefully. Treating an advertising or cross-site analytics cookie as consent-exempt “statistics” is the single easiest way to turn a compliant banner into an enforcement risk. If a cookie identifies a device or user persistently, assume it needs consent unless you can show otherwise.
Our website may contain links to third-party sites, including those of our partners. Those sites are outside our control and are not covered by this policy. If you submit personal data to them, their own privacy notices apply. We encourage you to read them.
Subject to the restrictions described in section 5.5, you have the following rights.
Right | What it means |
|---|---|
Access | To be told whether we process your data and to receive a copy of it |
Rectification | To have inaccurate data corrected and incomplete data completed |
Erasure | To have your data deleted where we no longer have a lawful reason to keep it. This right does not apply to records we must retain under the MLR 2017 or other legal obligations |
Restriction | To ask us to limit our use of your data in certain circumstances, for example while we check its accuracy |
Objection | To object to processing based on legitimate interests or on a public task, on grounds relating to your particular situation. You have an absolute right to object to direct marketing |
Portability | To receive data you provided to us, in a structured, commonly used, machine-readable format, and to have it transmitted to another controller, where processing is based on consent or contract and is carried out by automated means |
Withdraw consent | To withdraw consent at any time where we rely on it. Withdrawal does not affect processing carried out before withdrawal |
Automated decisions | The rights described in section 6 |
How to exercise your rights. Contact us using the details in section 1.3. We may need to verify your identity before responding — for security, not to obstruct your request.
Our response time. We will respond within one month. Where a request is complex, or where you have made a number of requests, we may extend this by up to a further two months and will tell you within the first month if we do. Following the Data (Use and Access) Act 2025, we are required to carry out a reasonable and proportionate search for your data, and the response clock may be paused where we reasonably need to confirm your identity or need further information from you to identify the data you want. The clock resumes when you provide it.
Cost. There is normally no fee. We may charge a reasonable fee, or refuse to act, where a request is manifestly unfounded or excessive — and we will explain why if we do.
Complain to us first. If you are unhappy with how we have handled your personal data, please contact [privacy@gpaynow.net], marked for the attention of the [Data Protection Officer / privacy lead]. Under the Data (Use and Access) Act 2025 you have a statutory right to complain to us directly. We will acknowledge your complaint within 30 days and take appropriate steps to respond to it without undue delay.
Complain to the regulator. You also have the right to complain to the UK supervisory authority:
Information Commissioner’s Office Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, United Kingdom Helpline: 0303 123 1113 Website: ico.org.uk
If you live or work outside the UK, or the alleged infringement occurred elsewhere, you may instead complain to your local supervisory authority.
You may also seek a judicial remedy through the courts.
Our services are not directed at, and are not available to, anyone under the age of 18. We do not knowingly collect personal data from children. If we become aware that we hold personal data relating to a child, we will delete it, subject to any overriding legal retention obligation. If you believe a child has provided us with personal data, contact [privacy@gpaynow.net].
We review this policy at least annually and whenever our services or our use of personal data changes. The current version is always available at [gpaynow.net/privacy-policy]. Where a change is material, we will notify registered users by email or through the service before it takes effect. If we ever wish to use your personal data for a purpose not described here, we will tell you and, where required, ask for your consent.