Regulated, resilient,
and ready.
A licensed payment institution under direct supervision — with governance, resilience and risk controls built for the rules coming next.
A licensed Austrian payment institution
Compliance is not a page of certifications. It is the question a CRO, CFO or Compliance officer asks before signing a merchant agreement. The answer below is structured for that reader: who governs DaoPay, what the licence covers, how the operation stays running, how regulatory change is prepared for, how merchants are reviewed and safeguarded, and what happens when something goes wrong on the rails.
DaoPay is an EU-licensed payment institution. There is no separation between the website and the licence: the same legal person is named in both.
- Legal entity
- DaoPay GmbH
- Registered office
- Vienna, Austria
- Authorisation
- held under ZaDiG 2018
- Contracting party
- for all merchant services
- Supervisory relationship
- set out later on this page
Leadership
- Peter Krapfl
- Chief Executive Officer since 2001
- Oliver Jura
- Chief Operating Officer since 2005
Both have led the company across the full operational history this page refers to: the ZaDiG 2018 authorisation, the EU passporting footprint, the safeguarding regime, the 24/7 operating posture in Vienna, and the merchant qualification discipline described below.
Independently governed
DaoPay is privately held and independently governed. Ownership is not split across external investors, platform partners or resellers whose incentives might pull the operating model in different directions. DaoPay is advised by specialist EU payment law counsel on regulatory and licensing matters.
DaoPay carries the operational, regulatory and scheme-side exposure of the licensed payments it processes on a merchant's behalf. Risk is absorbed within the licensed payment institution, governed under the same ZaDiG 2018 authorisation that merchants contract under, and is not routed back to merchants through disclaimers, sub-processor clauses or acceptance-side terms. The same legal entity that holds the licence holds the scheme-side exposure and answers to the supervisory authority. Merchants do not accept that exposure onto themselves by signing.
How decisions are made
Merchant, scheme and counterparty decisions are taken by named operators and escalated through standing committees, not delegated to automated scoring alone.
- Onboarding Committee
- signs off on merchant fit decisions
- Risk Committee
- signs off on portfolio-level risk and scheme exposure
Both report into the management board. Cases outside standard policy carry an Information Security Officer and an executive escalation path. Committee membership is not surfaced publicly; the structure is disclosed, the individuals are not.
Why this matters before you read on
Everything on this page rests on the foundation just described. The licence, the regulatory outlook, the operational resilience, the merchant vetting and the dispute handling that follow all belong to one legal entity, under one licence, overseen by the same decision-makers named above.
Regulated under Austrian and EU law
DaoPay GmbH is an EU-licensed payment institution, authorised under the Austrian Payment Services Act 2018 (ZaDiG 2018), the national transposition of PSD2.
Licence scope
The authorisation covers all six ZaDiG service categories. The list is exhaustive: requests outside it are declined during qualification rather than absorbed informally.
- Payment business, execution of payment transactions
- Acquiring of payment transactions
- Issuing of payment instruments
- Money remittance
- Payment initiation services (PISP)
- Account information services (AISP)
Two footprints, two sets of rules
DaoPay's licence and its commercial footprint are two distinct things. Inside the EEA, the payment institution licence is passportable under PSD2 cross-border rules, and DaoPay answers directly to the competent Austrian financial market authority. Beyond the EEA, commercial reach across 72+ countries is delivered through DaoPay's acquiring network, where each local partner carries its own authorisation in its own jurisdiction.
For a merchant with customers on both sides, this is not a technicality. On the EEA leg, the regulatory weight sits with DaoPay's own licence. On the non-EEA leg, it sits with the local acquiring partner as principal. Neither leg is presented as the other, and the contract structure keeps that separation visible.
Supervisory relationship, what it actually means for your risk file
DaoPay GmbH is supervised by the competent Austrian financial market authority. For a merchant's own risk file, this confirms that the licence has an external counterparty: someone other than DaoPay has standing authority to examine the institution's safeguarding arrangements and operational resilience on an ongoing basis. The contracting decision sits inside a supervised perimeter rather than outside it. The underlying register entry remains available in the legal and reference surfaces of the site, where the statutory detail properly belongs.
Ahead of the regulatory calendar
DaoPay's regulatory readiness is structured around three reference points: the regulation already in operating obligation, the regulation whose high-risk obligations are approaching, and the regulations still being watched as they take shape.
Five regulatory tracks,
one integrated posture.
Each track is monitored against its own applicability date and integrated under the existing ZaDiG 2018 licence rather than treated as a separate compliance project.
- Already binding
DORA
DORA, Regulation (EU) 2022/2554, has applied to DaoPay since 17 January 2025 as a mid-sized payment service provider. ICT risk management and third-party oversight are embedded in the operating model.
DaoPay's third-party stack is overseen by the same supervisor that oversees its payments licence. A third-party outage at a downstream technology provider can no longer be siloed as that provider's problem alone; it lands on DaoPay's operating model and on the supervisor's visibility.
- Approaching
AI Act
The EU AI Act's high-risk obligations apply from 2 August 2026. DaoPay frames its use of AI within the licensed payment institution as decision support for human operators, not as a replacement for human underwriting.
Any AI system DaoPay deploys is treated under a Deployer posture, mapped onto the existing ZaDiG 2018 governance and risk-committee oversight rather than introduced as a separate compliance track.
- Watching
FIDA and Open Finance
DaoPay tracks the Financial Data Access negotiations and positions its data-access posture in line with emerging Open Finance standards.
No specific merchant-facing capability is marketed on the basis of FIDA while the regulation's final shape remains under negotiation. This is a deliberate readiness stance, not a gap: the contractual posture a merchant signs today will not need to be reopened once FIDA's final form lands.
- Not applicable
Crypto and MiCA
DaoPay does not currently provide crypto-asset services under MiCA, Regulation (EU) 2023/1114. Any future scope change would be made transparent.
For a merchant, this keeps settlement statements free of crypto-related exposure and keeps the supervisory perimeter already established under ZaDiG 2018 from being widened by a service the merchant's own compliance function would then need to assess separately.
- Ongoing by design
Staying current
DaoPay tracks EU-level regulatory change early and integrates it under its existing ZaDiG 2018 licence, so new regulation does not open a new governance track.
It folds into the same licence, the same supervisor and the same oversight committee structure named earlier on this page, and merchants are kept informed as it happens.
Operating around the clock
A dedicated Network Operations Centre (NOC), staffed from Vienna 24/7, runs over 17,000+ automated checks, backed by a dedicated NOC team and an Information Security Officer.
What the 17,000+ automated checks actually cover
These checks run continuously across DaoPay's servers, containers and supporting infrastructure, verifying system-level parameters and technical health rather than sampling individual transactions. They are designed to surface infrastructure anomalies before they can affect the merchant-visible transaction layer.
Business continuity
DaoPay maintains a Business Continuity and Disaster Recovery framework aligned with ZaDiG 2018 and EBA outsourcing guidelines, anchored to the same licence, the same supervisor and the same oversight structure named earlier on this page. A mandatory scheme release follows the scheme's own clock rather than an internal release window, and the rollout sits inside the same dual sign-off described under Operational philosophy below.
Infrastructure partners
DaoPay works with scheme-certified acquiring, tokenisation and alternative payment method partners across the EU. Each partner carries its own exposure:
- Acquiring
- sits with the acquiring partner as a scheme-certified principal
- Tokenisation
- sits with a purpose-built counterparty in its own regulatory perimeter
- Alternative payment methods
- sit with the local-method partner in its own jurisdiction
Nothing is routed back through the DaoPay licence as a grey-area extension.
Operational philosophy, in plain language
The operating philosophy behind these claims is conservative and documented rather than novel and advertised. No change that materially affects production resilience happens without dual sign-off across operations and risk. Any single-point-of-failure risk found by the NOC is treated as a structural work item, not a monitoring promise. The cadence and depth of internal drill practice is not disclosed publicly; the framework posture is what is publishable, the drill cadence is what is enforced operationally.
From the operating layer back to your onboarding ledger
The NOC, the framework, the partner stack and the operating philosophy above are not a separate workstream from a merchant's day-to-day. When a payment event, a scheme update or an infrastructure incident lands outside business hours, the response runs through the same committee-based oversight that signed off on the merchant's onboarding decision. It is the same institution, the same licence and the same supervisor answering out of hours what it qualified the merchant on months earlier.
Merchant fit, reviewed by people
Every merchant application is reviewed against three outcomes: Go, Review or No-Fit, each with reasoning provided. Review is a dialogue, not a rejection. A No-Fit decision arrives with a written reason, so the merchant understands what part of the fit assessment they would need to evidence differently if they come back.
Acceptance Policy
DaoPay reviews merchant fit on a case-by-case basis under its published Acceptance Policy. This is the document of record the Onboarding Committee refers to when signing off fit decisions, and the document a merchant can read in advance. The full restricted or prohibited industry list is held in the Acceptance Policy PDF rather than rendered on the page.
Regulatory checks during onboarding
DaoPay operates continuous transaction monitoring and customer due diligence as part of its regulatory obligations under ZaDiG 2018. These checks are not only a post-go-live concern; they are part of the qualification discipline itself. Customer due diligence is handled inside the licensed payment institution and not outsourced.
One counterparty across the scheme rails
As a direct member of the international card schemes that matter for the markets DaoPay serves, authorisation, clearing, settlement and scheme-level dispute routing run on DaoPay's own licence rather than through an aggregator intermediary. When a scheme query arrives, it arrives at the licensed entity directly.
Scheme-dispute interception
DaoPay operates scheme-aligned pre-dispute interception, reducing chargeback exposure before disputes mature. This interception is a function of the licensed counterparty relationship described above, not a third-party service added on top.
Safeguarding
Customer funds are safeguarded in segregated accounts at credit institutions, in accordance with § 17 ZaDiG 2018. The bank account structure is built so that customer funds cannot be commingled with operating funds, regardless of what happens elsewhere in the business.
Reach that scales with
your merchant footprint.
DaoPay processes payments in multiple major currencies through its acquiring network and supports 100+ payment methods across cards, wallets, account-to-account transfers and local schemes. Specific method and scheme names are covered on the Solutions and Integration Hub pages.
A merchant who reaches a Go outcome here enters an operating relationship in which the same governance, committees, supervisor relationship, NOC and safeguarding posture described earlier continue to apply for the life of the contract.
Risk Defence, the payoff of the trust claim above
The risk-defence posture at DaoPay is not a separate module added on top of the regulatory authorisation. It is the consequence of every earlier claim on this page playing out in a real merchant scenario.
- The legal entity
- holds the licence
- Regulatory readiness
- keeps that licence forward-looking
- Operational resilience
- keeps the underlying processing available
- Scheme membership plus § 17 ZaDiG 2018 safeguarding
- keeps the funds and rail-level dispute access structurally sound
When a dispute or chargeback arrives
A scheme dispute that reaches DaoPay is handled on the licensed counterparty's rails. It does not pass through an aggregator that would reroute or retranslate it, and the merchant does not deal with a different legal entity for the dispute than the one they signed the merchant agreement with. Where the case fits the conditions for scheme-aligned pre-dispute interception, the chargeback is addressed before it fully matures. Where interception is not available, the dispute moves through the standard scheme process with DaoPay acting as the licensed counterparty, providing the evidence and reasoning the scheme rules require.
The escalation path inside DaoPay follows the same committee-based structure described earlier. The Onboarding Committee and Risk Committee are both in scope for dispute-relevant decisions, and executive sign-off applies to any case outside standard policy.
The real test of this chain is whether, at three in the morning on a Saturday, a scheme query arrives at the same licensed entity that holds the merchant's segregated funds, is answered by the same NOC that keeps DaoPay's systems running around the clock, is escalated through the same committee that signed off on the original onboarding decision, and produces a documented outcome the merchant's own CRO can bring back to their board.
When a regulatory question arises
If a regulator, supervisory authority or a merchant's own compliance function raises a question about DaoPay's posture, the answer is grounded in the same ZaDiG 2018 framework repeated throughout this page. The supervisory relationship, the regulatory readiness, the safeguarding arrangements and the operational resilience framework are each a separate anchor in the merchant's risk file, all pointing to the same licensed entity and the same supervisor.
Where risk sits, resolved
Earlier on this page, DaoPay named the liability it carries: operational, regulatory and scheme-side exposure. This is what that means in practice. The exposure is carried on the licensed entity's rails, with the committee oversight already disclosed, the safeguarding already in segregated-account form, and the supervisor already in the picture. The contractual relationship between DaoPay and the merchant does not hand that exposure back. It stays with the licensed institution.
For CRO, CFO and Compliance readers who need a direct pathway to verify any specific item above, the standard pre-qualification contact route is the proper next step.