Privacy notice

Last updated: 6 August 2026

This notice explains what personal data PUS Payments processes through this portal, why, for how long, and who we share it with. It applies to anyone who creates an account here, goes through a verification, or visits the site.

Who we are

PUS Payments is the data controller for the personal data collected through this portal. For questions or requests about your data, see Contact below.

What data we process

What data we process depends on how you use the portal:

  • Account data: name, email address, phone number, password (stored encrypted) and, if enabled, your two-factor authentication.
  • Company data: Chamber of Commerce number, company name, legal form, industry, and registered address of the company you represent.
  • Identification data of ultimate beneficial owners (UBOs) and authorised signatories: name, date of birth, nationality, document number, ownership percentage, PEP status, and a copy of the identity document. This is mandatory customer due diligence and is used solely to assess your application.
  • Bank details: account number (IBAN) and a bank statement for verification.
  • During identity verification we ask for a short series of photos (a "liveness check") to confirm there is a live person in front of the camera, not a photo or video of a photo. This runs using facial-recognition technology that operates on your own device.
  • Visit data: only with your consent, via cookies — see our cookie policy.

Why we process this data

We process this data to: (1) meet our legal obligation to perform customer due diligence and ongoing monitoring under applicable anti-money-laundering rules; (2) manage and secure your account; (3) provide the payment service; (4) with your consent, improve the site and show relevant advertising.

Who we share data with

We don’t process your data on our own servers; we use specialised parties (processors) that do so on our behalf. For every processor, we work towards a data processing agreement under GDPR Art. 28.

  • Supabase — database, account management (login, passwords) and file storage for all data in this portal, including your uploaded documents. Runs on Amazon Web Services (AWS) infrastructure as a sub-processor.
  • Cloudflare — hosting of this application and handling all traffic to the site.
  • GitHub — storage of our source code and automated deployment of updates. Processes no customer data, but does process technical access data.
  • Anthropic — reads, only after you submit your verification and only when this feature is active, part of your uploaded documents (ID, bank statement, Chamber of Commerce extract) to check whether they match what you typed. This check is advisory; a human reviewer always makes the final call.
  • Google (Tag Manager, Analytics, Ads) — only with your consent, for site statistics and measuring/showing ads. Never loads on the pages where you fill in your verification or where we review case files.
  • Meta (Facebook, Instagram, WhatsApp) — possibly in the future, also only with your consent and only for advertising purposes. Never loads on the pages where you fill in your verification or where we review case files.

How long we keep data

This depends on the type of data: a phone-scan link code expires after 10 minutes; documents from a rejected application are kept for 90 days and then deleted; data from an accepted customer relationship is kept for the duration of that relationship plus the statutory period that applies afterwards (typically 5 years under applicable anti-money-laundering rules).

Your rights

You have the right to access, rectify, erase, restrict, and object to the processing of your data, and to data portability, and the right to lodge a complaint with the competent supervisory authority. For data we are legally required to retain (customer due diligence), we may have to refuse an erasure request for as long as that obligation applies. To exercise any of these rights, contact us at the address below. None of your applications, incidentally, is ever assessed in a fully automated way: every decision is made by two independent human reviewers.

Security

We secure your data through measures including two-factor authentication for reviewers, a four-eyes principle for every decision (two independent reviewers must agree), encrypted password storage, and an audit log of who viewed or decided on which case file, and when.

Changes to this notice

We may update this notice; the date at the top shows when that last happened.

Contact

Questions about this notice, or a request about your data? privacy@pus-payments.com

We use cookies to make this site work properly and, with your consent, for analytics. Learn more