Privacy Policy
Last updated: 15 August 2026
This policy describes the data Paytena actually handles today, written against the running product rather than from a template. The short version: we hold business and payment metadata, plus the onboarding documents you choose to upload. We never see card numbers, we set no tracking cookies, and we do not sell data.
It is not legal advice and has not yet been through external data-protection counsel. A counsel-reviewed version is issued with the commercial agreement before a workspace goes live.
1.Who we are and our role
Paytena is a payment orchestration and provider-connectivity platform used by merchants and by payment service providers (PSPs). Which hat we wear depends on the data:
- We are the controller for account data, sign-in records, security logs and sales enquiries - the data we need to run the platform itself.
- We are a processor for the data you put into your workspace: payment metadata, business records, and uploaded documents. We process it on your instructions to provide the Service.
- PSPs are separate controllers for anything you submit to them through the platform. Once an application or a document is shared with a PSP, that PSP handles it under its own privacy policy and its own regulatory duties.
2.Data we process
- Account and access data - your email address, your name if you give one, which workspaces you belong to and your role in each, the time you last signed in, and session records. Sign-in is by magic link; session tokens are stored hashed, never in the clear.
- Sales enquiries - name, email, company and message when you use the contact form on our home page.
- Business records - legal entity name, registered country and address, company registration number, VAT id, website, business vertical, regulator, licence status and number, and your expected transaction profile (volumes, average value, payment methods).
- Onboarding documents - PDF, PNG or JPEG files up to 10 MB that you upload to your document vault: certificates of incorporation, articles of association, UBO declarations, director identification, proof of address, licences, bank letters, processing statements and similar. These often contain personal data about directors and beneficial owners who are not users of the Service. You upload them and remain responsible for having a lawful basis to do so.
- Payment metadata - amount, currency, country, payment method, your own reference, the provider chosen, the routing decision and why it was made, attempt outcomes, decline category and the raw provider code, fees, and refund and dispute totals.
- Provider credentials and webhook secrets - the API keys you enter for your own payment providers and the signing secrets for your webhook endpoints. These are encrypted with AES-256-GCM before they are written to the database and are never displayed again after creation.
- Security and audit data - an audit trail of significant actions recording the acting user’s email, the action, its target, and the IP address it came from; rate-limiting counters keyed by IP address; and delivery logs for outbound webhooks.
3.Cardholder data: we do not handle it
No Paytena screen, API or SDK collects a card number. There are no card fields anywhere in the product. The hosted payment page we redirect to in build mode is a clearly labelled sandbox with outcome buttons, deliberately with no card inputs at all.
The redirect flow exists precisely so that card entry happens on your payment provider’s own hosted page, under that provider’s PCI DSS scope. As a result Paytena does not store, process or transmit primary account numbers, expiry dates, security codes or magnetic-stripe data, and holds no such data to lose.
4.How we use data
We use data to operate and secure the Service: authenticating you, routing payment traffic across your own providers, producing your analytics and reconciliation views, transmitting the applications and documents you send to PSPs, maintaining an audit trail, billing you, and preventing abuse.
Aggregated provider performance signals (approval rates, fees, latency) train the routing engine. That model works on payment and provider attributes, never on identified individuals.
We do not sell data and we do not use it for advertising.
5.Automated decisions
The routing engine automatically chooses which of your providers should attempt a payment, and may retry a decline on a backup provider. That is a decision about a transaction and a provider, not a profile of a person.
Decisions on PSP applications - approval, rejection, requests for more information, pricing - are made by the PSP’s own staff in their portal. Paytena does not underwrite applicants and does not decide them automatically.
8.How long we keep data
A daily job enforces these windows automatically. Anything not listed is kept for the life of the workspace.
| Data | Retention |
|---|---|
| Sign-in sessions | Deleted once expired |
| Magic-link tokens | 24 hours after expiry |
| API idempotency keys | 24 hours |
| Rate-limit counters | 1 hour after the window resets |
| Webhook delivery log | 90 days |
| Abandoned hosted payment sessions | 7 days after expiry |
| Payments, business records, documents, audit trail | Life of the workspace |
Deleting a workspace deletes its data - members, payments, providers, business records, documents and audit entries - permanently and by cascade. Export anything you need first.
9.Security
- Provider credentials, webhook signing secrets and every uploaded file are encrypted with AES-256-GCM by the application before they reach any storage backend, so the storage backend never holds plaintext.
- Documents are only ever served through routes that check your authorisation first; the underlying storage URL is unguessable and yields ciphertext even if it leaks.
- Session tokens and API keys are stored as hashes. API keys are shown once, at creation.
- Workspace isolation is enforced in the data layer, not only in the interface, and sensitive actions are written to an audit trail.
- Because we hold no cardholder data, the most sensitive category in payments is simply out of scope here.
10.Your rights
Subject to applicable law you may ask us to access, correct, export or delete your personal data, or object to a particular use. Workspace owners can export payment data and delete the workspace directly from the dashboard at any time.
Where we hold data on behalf of a merchant or a PSP - for example, personal data inside an uploaded document - we will pass your request to that organisation, which is the controller for it, rather than acting on it ourselves.
You also have the right to complain to your local data protection authority.
11.Changes and contact
If we change how we handle data we will update this page and its date, and tell workspace owners about material changes.
For privacy requests or questions, use the contact form on our home page.