02Data Protection

Privacy Policy

DaoPay GmbH (“DaoPay,” “we,” “us”) appreciates the trust you place in us by sharing your information. We are committed to protecting your personal data. The processing of your personal data takes place in accordance with applicable data protection law, in particular the General Data Protection Regulation (GDPR), the Austrian Data Protection Adaptation Act 2018, the Telecommunications Act (TKG), and the Austrian Payment Services Act (ZaDiG 2018). This Privacy Policy describes how DaoPay collects, uses and safeguards your personal data. We reserve the right to change this Privacy Policy at any time by publishing a revised version on this website; the revised version becomes effective upon publication. This policy is subject to annual review.

Terms used in this Privacy Policy have the same meaning as in our General Terms & Conditions, unless otherwise defined here.

Who is responsible for your data

DaoPay GmbH (“DaoPay” or “Controller”), with registered office at Hackhofergasse 5/14, 1190 Vienna, Austria, is a Licensed Austrian Payment Service Provider and Acquirer, supervised by the competent Austrian financial market authority.

Controller
DaoPay GmbH, Hackhofergasse 5/14, 1190 Vienna, Austria
Data protection contact
privacy@daopay.com
Data subject requests
gdpr@daopay.com

DaoPay’s Data Protection Officer

DaoPay has appointed a Data Protection Officer in line with Article 37 GDPR. The Data Protection Officer is responsible for the company’s data protection matters in accordance with legal and regulatory requirements and reports directly to the Managing Directors. The Data Protection Officer’s main functions are:

  • Monitoring compliance with data protection regulations and ensuring rule-compliant processes and guidelines within DaoPay.
  • Acting as contact person for data subject rights requests.
  • Acting as contact person and informant on data protection matters for DaoPay employees.
  • Providing comprehensive advice and support across all areas of DaoPay in the field of data protection.
  • Cooperating with the data protection authority.
  • Implementing and releasing data protection impact assessments.

What personal data means and how we use it

Personal data

Personal data means any data that may be linked to a specific, identifiable natural person.

How we use your information lawfully

Your personal data is only processed for specific, explicit and legitimate purposes, and always within the bounds of lawfulness, as described below.

Purposes of processing and legal grounds

Personal data shall be processed without consent, for the following purposes:

  • Complying with specific pre-contractual or contractual obligations undertaken by us to our customers.
  • Complying with national or EU laws and regulations, or executing orders or instructions given to DaoPay by judicial authorities, oversight authorities or professional bodies.
  • Exercising the rights of DaoPay, specifically defending itself in court proceedings.

On the basis of DaoPay’s legitimate interest in maintaining professional relationships with current and prospective customers:

  • Carrying out customer relationship management, including with the contacts of current and prospective customers and other persons or entities with whom our professionals have developed business relationships.
  • Complying with policies and procedures adopted by DaoPay to manage shared verification processes preliminary to accepting and correctly performing assignments, and quality control processes.

With your consent, which is optional and may be withdrawn at any time:

  • Sending you newsletters, publications, studies, survey results, market or industry analyses, and other professional information material of specific interest to you, published by DaoPay.

How we process personal data more broadly

On the basis of performing a contract between you and us, complying with applicable legal obligations, and providing you with good customer service, we process the information you provide to us for the following purposes:

  • To conclude and execute agreements with you and provide services to you.
  • To send you administrative information, for example about our website and changes to our Terms & Conditions.
  • To process transactions on your behalf.
  • To fulfil your order, arrange delivery, and communicate with you about the service and related customer service.
  • To respond to your inquiries and fulfil your requests, including questions and comments.
  • To contact you when we have an obligation to do so.
  • To offer and facilitate services at your request.
  • To improve our service and develop new services.
  • To resolve conflicts, manage litigation, resolve issues, and provide customer service, including troubleshooting.
  • To provide updates and announcements about our products, promotions and programmes, and to invite you to participate in special programmes (direct marketing), only with your unambiguous, active consent, which you may withhold or withdraw at any time without adverse effect.
  • To personalise your experience on the website by presenting tailored products and offers, on the basis of our legitimate interest.
  • For our business purposes, such as analysing and managing our business, mergers and acquisitions, market research, audits, developing new products, enhancing our website, identifying usage trends, and evaluating promotional campaigns and customer satisfaction, as we believe necessary or appropriate under applicable law, to comply with legal process, or to respond to requests from public and government authorities.

Website visitor, merchant and payer data

Website visitor data

This website uses Google Analytics 4, a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (“Google”). Google Analytics loads only after you accept optional analytics in our cookie banner; without that consent, no analytics script runs and no analytics cookies are set. The legal basis is your consent under Article 6(1)(a) GDPR and § 165 Abs. 3 TKG 2021, which you can withdraw at any time with effect for the future via the cookie settings link in the footer.

When enabled, Google Analytics uses cookies to distinguish visitors and measures how this website is used — for example which pages are visited, how long visits last, the type of device and browser, and the approximate region derived from your IP address. Google Analytics 4 does not log or store IP addresses. We have not activated Google Signals and we use no advertising or remarketing features; the data is used solely to understand and improve how this website performs.

Google may transfer the collected data to servers of Google LLC in the United States. Google LLC is certified under the EU-U.S. Data Privacy Framework; in addition, transfers are covered by the European Commission’s Standard Contractual Clauses under Article 46 GDPR. Analytics data is retained for a maximum of 14 months and then deleted automatically.

Beyond this, we process only the technical request data your browser sends, such as IP address and user agent, together with the strictly necessary cookies needed to operate the site and the consent mechanism itself. For the specific cookies Google Analytics sets, their durations, and how to give, refuse or withdraw consent, see our Cookie Policy & Consent (GDPR).

Merchant and business partner data

When you engage with us as a business partner, we process the information needed to assess and onboard your business, including contact details, business model, expected payment volume, and Identity & Verification data. This includes identifying directors and beneficial owners and performing required regulatory checks.

Payer and cardholder data

Payer data we handle is limited to transaction metadata such as amount, currency, timestamp and scheme reference. Card data is handled by our card scheme and processing partners under their own frameworks. We use this data to process payments and to manage fraud, chargebacks and disputes.

Recipients and third parties

We share personal data only where necessary, with categories of recipients including card scheme partners, payment processing partners and hosting providers. Where partners act as processors, they do so under contract and on our instructions. Supervisory authorities may access data where the law requires.

How we collect and protect your data generally

DaoPay processes information and personal data on its servers and protects it through physical, electronic and procedural measures, in accordance with applicable law. This helps prevent unauthorised access, maintains data accuracy and ensures the information is used correctly. Only employees who require access to perform their work are granted it.

DaoPay does not share personal data with any third party without your consent, unless DaoPay is obliged to do so by law or court order, or if passing on data is necessary to take legal action against fraudulent access to internet structures. We do not pass on data for any other reason, and only collect, store and process information to offer you high-standard service, individual information and communication. You are entitled to be informed of the purpose of the data storage; for information about your stored data, contact privacy@daopay.com.

The storage and processing of personal data transmitted or disclosed to us takes place only for the following purposes: processing, billing and controlling payment transactions, providing customer support, ensuring the best possible service, statistical evaluation (not profiling), and prevention of fraud and abuse.

Any personal data collected as part of a payment process to conduct business transactions is only transmitted to the extent necessary to the parties involved in the transaction (the merchant where the purchase was made, and the payment system operator used to make the payment). The legal basis for this processing is Article 6(1)(b) GDPR.

Downstream payment processing is performed by authorised payment system providers and our contracted business partners (typically banks, card scheme and telecommunication companies) that are authorised to carry out the relevant payment process and maintain appropriately secured systems. This is necessary to process distance-selling payments and to facilitate the use of DaoPay’s services.

International data transfers

We prefer to keep personal data within the European Economic Area. Where an international transfer is necessary, we rely on appropriate safeguards under Article 46 GDPR, such as the European Commission’s Standard Contractual Clauses, and assess each transfer before it takes place.

Where you have consented to analytics, usage data collected by Google Analytics may be processed by Google LLC in the United States on the basis of the EU-U.S. Data Privacy Framework and Standard Contractual Clauses, as described under “Website visitor, merchant and payer data” above.

How long we keep your data

We keep the data collected during our business relationship for 7 years after the end of your contract with us. Beyond this general period, our records are kept for the specific legal retention periods that apply to particular obligations under Austrian law (for example, accounting and tax record-keeping requirements under UGB/BAO, and payment-services-specific requirements under ZaDiG 2018 and applicable anti-money-laundering law).

Your rights as a data subject

You have the right to access, rectify and erase your personal data, to restrict processing, to data portability, to object to processing, and to withdraw your consent at any time. To exercise these rights, contact DaoPay GmbH, Hackhofergasse 5/14, 1190 Vienna, Austria, email privacy@daopay.com. We may need to confirm your identity before acting on a request.

If you believe the processing of your data breaches data protection law, or that your data protection rights have been violated in any other way, you have the right to lodge a complaint with the competent regulatory authority.

Authority
Datenschutzbehörde (Austrian Data Protection Authority)
Address
Barichgasse 40-42, 1030 Vienna, Austria

This right is without prejudice to any other administrative or judicial remedy available to you.

Automated decision-making and profiling

Our PreCheck uses a rule-based intake followed by a human-led review, so onboarding decisions are not based solely on automated processing. You can ask for human intervention and can contest a decision. If we introduce further automation in future, we will update this notice.

Source of personal data

Where we do not collect personal data directly from you, we obtain it from other sources. Business partner data is provided by you directly; payer data reaches us through our card scheme and processing partners as part of the payment flow.

Special cases

Right to correct inaccurate personal information

You have the right to request correction of inaccurate personal information processed by us.

Children’s privacy

Under no circumstances do we collect or process personal or identifiable information from or about children under 13 years of age.

Contact form

If you send us an inquiry via a contact form, we collect the data you provide, including your contact details, to respond to your inquiry and any follow-up questions. We never disclose these details without your permission.

Newsletter

If you wish to receive our newsletter, we require a valid email address and confirmation that you are the owner of that address and agree to receive the newsletter. We do not collect other data for this purpose and do not pass your data on to third parties. You may revoke your consent and unsubscribe at any time, for example via the “Unsubscribe” link in the newsletter.

Document governance

Responsibilities

Document Owner, creation and maintenance of this document
Head of Legal & Compliance
Legislative, statement of liability
Managing Directors
Implementation, execution
CISO
Administration, operations
CISO, IT
Inspection, audit of the company
Internal IT Revision
Risk analysis, evaluation of results
IT-Security Management Team