This Privacy Policy explains how Absolute Technology Limited ("Company", "we", "us") collects, uses, shares, and protects Personal Data in connection with the AbsolutePay platform and all related services (the "Platform" or "Services"), including our merchant dashboard and branded checkout.
It applies to:
- Merchants — the businesses that register for and use the Platform ("you"); and
- Merchant's Customers / End Customers — individuals who pay a Merchant through the Platform.
Where a separate notice, contract, or data-processing agreement applies (for example, a data-processing agreement between us and a Merchant), that document governs the relationship it covers. This Policy is the general statement of our practices.
1. Who is responsible for your data (Controller)
The Controller of the Personal Data described in this Policy is:
- Absolute Technology Limited, a free-zone company incorporated in the RAK Digital Assets Oasis (RAK DAO), Ras Al Khaimah, UAE (Registration No. 01011131), licensed by RAK DAO for Embedded Finance Enablement (Licence No. 07011064)
- Registered office: Office A, Innovation City Business Centre, RAK BANK ROC Office, Ground Floor, Al Rifaa, Sheikh Mohammed Bin Zayed Road, Ras Al Khaimah, UAE
For privacy questions or to exercise your rights, contact our data-protection contact:
- Data-protection officer / contact: [email protected]
- Privacy email: [email protected]
2. The law that applies
- Default (Company seat): The Company is incorporated in the RAK Digital Assets Oasis (RAK DAO), Ras Al Khaimah, UAE. RAK free zones apply the UAE Federal Personal Data Protection Law (Federal Decree-Law No. 45 of 2021, "PDPL") — there is no separate free-zone data-protection law here — so this Policy is drafted on the basis of the PDPL, together with its implementing regulations and the guidance of the competent UAE data-protection authority.
- EU / EEA / UK data subjects: Because the Platform targets a global (ex-US) audience, individuals located in the EU, EEA, or UK are in scope. For those individuals we also apply the EU General Data Protection Regulation (GDPR) and the UK GDPR on an extraterritorial basis, and the additional rights and safeguards they require.
Defined terms — "Personal Data", "Processing", "Controller", "Processor" — have the meaning given by the applicable data-protection law above.
3. What data we collect and why
We distinguish between data about the Merchant (and its authorised users) and data about the Merchant's End Customers.
3.1 Data about the Merchant and its users
| Category | Examples | Why we process it |
|---|---|---|
| Account & contact data | Business name, workspace details, authorised-user names, email, phone, role, login credentials | Create and administer the account; authenticate users; communicate with you |
| KYB / KYC identity data | Business registration and ownership documents, information on directors, beneficial owners and controllers (UBOs), identity-document and verification data for the individuals we must verify | Meet our legal onboarding, identity-verification, and financial-crime obligations |
| Screening data | Sanctions, politically-exposed-person (PEP), and adverse-media screening results at onboarding and on an ongoing basis | Comply with sanctions and anti-money-laundering (AML) law |
| Transaction & settlement data | Payments, payouts, gift-card/voucher and subscription activity, amounts, assets, fees and markup, on-chain references, settlement and accrual records | Provide the Services, calculate fees, keep required records, prevent fraud |
| Device, usage & analytics data | IP address, device and browser information, log data, product-usage events, cookie and similar-technology identifiers (see the "Cookies & Tracking" section below) | Operate, secure, debug, and improve the Platform |
| Support communications | Messages, tickets, and correspondence with our support and compliance teams | Provide support; keep a record; investigate issues |
Identity verification (KYC for individuals and KYB for businesses) is performed with the assistance of our identity-verification provider, a specialist third-party vendor.
3.2 Data about the Merchant's End Customers
To operate branded checkout and settlement, we may Process data about the people who pay a Merchant through the Platform — for example transaction and settlement data, and, where required, identity or verification data connected to a payment. See Section 4 for our role in respect of this data.
3.3 How we obtain data
Most data comes directly from you or your authorised users, from End Customers at checkout, or is generated by your use of the Platform. Some data (for example screening results and certain verification outputs) is obtained from our identity-verification provider, from our upstream payments and settlement provider, and from sanctions/PEP/adverse-media data sources.
We do not knowingly collect more Personal Data than we need for the purposes in this Section.
4. Our role: Controller and Processor
- Merchant and authorised-user data (Section 3.1): we are generally the Controller — we decide why and how it is Processed (account administration, our own financial-crime controls, product operation and improvement).
- End-Customer data (Section 3.2): our role depends on the activity. Where we Process End-Customer data on a Merchant's behalf to deliver a payment the Merchant has initiated, we act as the Merchant's Processor. Where we Process the same or related data to meet our own legal and financial-crime obligations, or to protect the integrity of the Platform, we act as an independent Controller.
- In relation to our upstream payments and settlement provider: the Company is an independent Controller for the Personal Data it Processes for its own purposes. The Company is not a joint controller with, or a processor for, the upstream provider; each party independently determines the purposes and means of its own Processing.
The Merchant remains responsible for the legality of its own business and its own customers, including providing its End Customers with any privacy notice and legal basis the Merchant is required to provide.
5. Our legal bases for Processing
Where the GDPR / UK GDPR applies (and by analogy under the PDPL), we rely on the following legal bases:
- Performance of a contract — to provide the Services to you and administer your account.
- Compliance with a legal obligation — including anti-money-laundering (AML), counter-terrorist financing, sanctions, identity-verification (KYC/KYB), record-keeping, and tax obligations.
- Legitimate interests — to secure, operate, debug and improve the Platform, prevent fraud and abuse, and run our business — balanced against the rights and interests of the individuals concerned.
- Consent — where we rely on consent (for example certain analytics or non-essential cookies, or optional communications). Where consent is the basis, you may withdraw it at any time without affecting Processing already carried out.
Special-category data and any biometric elements of identity verification, where present, are Processed only where a valid lawful basis and appropriate condition apply.
6. Who we share data with
We share Personal Data only as needed for the purposes above, and only with recipients bound by appropriate confidentiality and data-protection obligations:
- Our upstream payments and settlement provider — a licensed third-party payments provider that holds the settlement sub-account for each Merchant and executes payment and settlement instructions we pass on the Merchant's behalf.
- Our identity-verification provider — for KYC/KYB verification and related screening.
- Service processors — email/communications, cloud hosting and object-storage, and analytics providers that operate the Platform on our behalf.
- Regulators, law enforcement, and authorities — where we are legally required to disclose, or where disclosure is necessary to comply with law, a lawful request, or our financial-crime obligations, or to establish, exercise, or defend legal claims.
- Professional advisers and corporate transactions — auditors and legal advisers, and counterparties in a merger, acquisition, financing, or reorganisation (subject to confidentiality).
We do not sell Personal Data.
Sub-processor list. A current list of the third-party processors and sub-processors we use (including the named identity-verification vendor and hosting/analytics providers) is maintained internally and provided to Merchants on request under our data-processing terms.
Consistent with our white-label model, our upstream payments and settlement provider is not named in customer- or public-facing materials.
7. International transfers
We operate globally, and Personal Data may be transferred to, stored in, or accessed from countries outside the region where it was collected (including outside the UAE, EEA, and UK). Where we make such a transfer, we rely on an appropriate legal transfer mechanism — for example a finding of adequacy, or Standard Contractual Clauses (and the UK International Data Transfer Addendum where relevant), plus any supplementary measures required. A copy of the relevant safeguards is available on request.
8. How long we keep data
We keep Personal Data only as long as we need it for the purposes in this Policy, and then delete or anonymise it, subject to:
- AML / financial-crime record-keeping — identity-verification, transaction, and screening records are typically retained for at least seven (7) years after the end of the business relationship or the relevant transaction, or longer where the law or a regulator requires.
- Account life — account and contact data is retained while your account is active and for a reasonable period afterwards.
- Legal claims — data may be retained where needed to establish, exercise, or defend legal claims.
9. Your rights
Subject to the applicable law and its conditions and exemptions, you have the right to:
- Access the Personal Data we hold about you;
- Rectify inaccurate or incomplete data;
- Erase data ("right to be forgotten"), where a valid ground applies;
- Restrict or object to certain Processing, including Processing based on legitimate interests;
- Data portability — receive certain data in a portable format, where applicable;
- Withdraw consent at any time, where we rely on consent; and
- Complain to a supervisory authority.
Some of these rights are limited where we must retain data to meet a legal obligation — in particular AML and identity-verification record-keeping — or to establish, exercise, or defend legal claims. We will explain any limitation we apply.
To exercise a right, contact [email protected]. We may need to verify your identity before acting. We will respond within the period required by the applicable law.
To complain to a regulator:
- UAE: the UAE Data Office (or the competent UAE data-protection authority under the PDPL).
- EU / EEA / UK: your local data-protection supervisory authority (in the UK, the ICO).
We would appreciate the chance to address your concern first — please contact [email protected].
10. Security
We use technical and organisational measures appropriate to the risk — including access controls, encryption in transit, log redaction of sensitive fields, network and infrastructure controls, and least-privilege internal access. No system is perfectly secure; we cannot guarantee absolute security.
Note on custody. The Company is not the custodian of funds. Crypto pay-ins settle into a sub-account held by our upstream payments and settlement provider; the Platform never holds a private key or a customer wallet. This limits the categories of sensitive financial data we hold.
11. Data breaches
If a Personal Data breach is likely to result in a risk to individuals, we will notify the relevant regulator, and affected individuals where required, within the timeframe and in the manner required by the applicable law (for example the GDPR's 72-hour regulator-notification standard). We keep an internal record of breaches.
12. Children
The Platform is for businesses and adults. It is not intended for anyone under 18, and we do not knowingly collect Personal Data from children. If you believe a child has provided us data, contact [email protected] and we will take appropriate steps.
13. Automated decisions
Certain checks (for example fraud, sanctions, and eligibility screening) may involve automated processing. Where a decision producing legal or similarly significant effects is made solely by automated means, you have the rights the applicable law provides, including the right to request human review.
14. Changes to this Policy
We may update this Policy from time to time. We will post the updated version with a new effective date and, where the change is material, provide additional notice. Continued use of the Platform after an update means the updated Policy applies to you.
15. Contact
- Data-protection contact / DPO: [email protected]
- Privacy email: [email protected]
- Complaints: [email protected]
- Legal / notices: [email protected]
- Cookie preferences: you can control or clear cookies through your browser settings — see the "Cookies & Tracking" section below.
- Postal: Absolute Technology Limited, Office A, Innovation City Business Centre, RAK BANK ROC Office, Ground Floor, Al Rifaa, Sheikh Mohammed Bin Zayed Road, Ras Al Khaimah, UAE
Related documents: Terms of Service; the Cookies & Tracking section below; and (for Merchants) our data-processing terms.
Cookies & Tracking
This section explains how we use cookies and similar technologies on the AbsolutePay merchant dashboard and branded checkout (together, the "Platform"). It supplements, and should be read with, the rest of this Privacy Policy.
1. What are cookies and similar technologies?
Cookies are small text files placed on your device when you visit a website. We also use similar technologies — such as local storage, session storage, software development kits (SDKs), pixels, and device or browser identifiers — which work in comparable ways. In this section, "cookies" covers all of these.
Cookies may be:
- First-party — set by us; or third-party — set by a provider we use (for example an analytics provider).
- Session — deleted when you close your browser; or persistent — remaining until they expire or you delete them.
2. Categories of cookies we use
2.1 Strictly necessary cookies
Required for the Platform to function — for example authentication and keeping you signed in, session management, security and fraud prevention, load balancing, and remembering choices needed to complete a checkout. These cannot be switched off through our controls without breaking core functionality, and they generally do not require consent.
2.2 Functional cookies
Enable enhancements and remember preferences — for example language, display settings, and dashboard choices. If blocked, some features may not work as intended.
2.3 Analytics cookies
Help us understand how the Platform is used — pages visited, features used, errors encountered — so we can operate, debug, and improve it. Where required by the applicable law, these are set only with your consent. We aim to use aggregated or pseudonymised analytics where practical.
We do not use advertising or cross-site marketing cookies on the Platform.
3. Cookies we use
We use strictly necessary cookies to keep you signed in and secure the Platform (session and authentication), and, where enabled, first-party privacy-preserving analytics to understand product usage. We do not use advertising or cross-site tracking cookies. You can control or clear cookies through your browser settings.
4. How to control cookies
- Our controls: where a consent mechanism is presented (see Section 5 below), you can accept or reject non-essential categories and change your choice at any time.
- Your browser: most browsers let you block or delete cookies through their settings. Blocking strictly necessary cookies may prevent parts of the Platform from working.
- Analytics opt-out: where an analytics provider offers its own opt-out, we will link to it in the table above once populated.
5. Consent approach
Strictly necessary cookies are set without consent. For non-essential cookies (functional and analytics), we apply prior opt-in consent: no non-essential cookie is set before you consent, you can reject as easily as accept, choices are granular by category, and you can withdraw consent at any time.
6. Changes to this section
We may update this section from time to time to reflect changes in the technologies we use or in the law. We will post the updated version with a new effective date for this Policy.