Privacy Policy

1. Definitions and Interpretation

  1. In this Privacy Policy, unless the context otherwise requires:
    1. "Applicable Data Protection Laws" means Regulation (EU) 2016/679 (the General Data Protection Regulation or "GDPR"), the Data Protection Acts 1988-2018, the ePrivacy Regulations, and all other applicable laws and regulations relating to the processing of Personal Data;
    2. "Controller", "Processor", "Data Subject", and "Personal Data" shall have the meanings given to them under Applicable Data Protection Laws;
    3. "Merchant" means any person or entity using the Services;
    4. "End Customer" means any individual or entity whose Personal Data is processed in connection with a Transaction;
    5. "Financial Services Provider" means any acquiring bank, payment institution, processor, card scheme, or other regulated entity involved in the processing, clearing or settlement of Transactions;
    6. "Platform" means the Splink hosted software platform;
    7. "Services" means the software, payment services, infrastructure and associated functionality provided by Splink;
    8. "Transaction" means any electronic payment initiated via the Platform;
  2. References to legislation shall include any amendment, re-enactment or replacement thereof.

2. Introduction and Scope

  1. This Privacy Policy is issued by Splink Limited, a company incorporated in Ireland under company number 647572, with its registered office at Two Haddington Buildings, 20 Haddington Road, Dublin D04 HE94, Ireland.
  2. Splink is committed to ensuring that Personal Data is processed lawfully, fairly and transparently and in accordance with Applicable Data Protection Laws.
  3. This Privacy Policy explains how Splink collects, uses, processes, stores, shares and protects Personal Data in connection with the Services.
  4. This Privacy Policy applies to:
    1. Merchants;
    2. End Customers;
    3. directors, shareholders and beneficial owners;
    4. authorised users and employees;
    5. website visitors and prospective customers.
  5. Splink shall ensure that all Personal Data is:
    1. processed fairly and lawfully;
    2. collected for specified, explicit and legitimate purposes;
    3. adequate, relevant and limited to what is necessary;
    4. accurate and kept up to date;
    5. retained only for as long as necessary; and
    6. processed in a manner that ensures appropriate security.
  6. This Privacy Policy should be read alongside the Platform Terms and Conditions, the Cookie Policy, any applicable Processor Terms, and any agreement entered into with Splink.

4. Categories of Personal Data

Splink may collect, use, store and process the following categories of Personal Data:

  • "Identity Data" including full name, date of birth, nationality, identification documentation, and verification data.
  • "Contact Data" including residential or business address, email address, and telephone number.
  • "Business Data" including company registration details, ownership and control structure, details of directors and beneficial owners, and business activities and trading information.
  • "Financial Data" including bank account details, and payout and settlement information.
  • "Transaction Data" including payment details including amount, date, method and currency; refunds, reversals and disputes; Chargebacks and associated data; and transaction patterns and activity.
  • "Technical Data" including IP address, device identifiers, browser and operating system, and usage logs and session data.
  • "Compliance and Risk Data" including AML/KYC verification results, sanctions screening results, politically exposed person (PEP) status, and fraud indicators and internal risk scores.
  • "Behavioural and Analytical Data" including usage patterns, transaction trends, and interaction with the Platform.

5. Sources of Personal Data

  1. Splink collects Personal Data from the following sources:
    1. direct interactions with Data Subjects;
    2. Transactions processed via the Platform;
    3. automated technologies including cookies, logs and analytics tools; and
    4. third parties, including Financial Services Providers, acquiring banks and payment processors, card networks, identity verification providers, fraud prevention and risk providers, credit reference agencies, and publicly available or regulatory databases.
  2. Splink may combine Personal Data obtained from different sources in order to enhance accuracy, prevent fraud and improve the Services.

6. Purposes of Processing

  1. Splink processes Personal Data for the following purposes:
    1. Provision of Services: To create and manage accounts; to provide access to the Platform; and to administer and operate the Services.
    2. Payment Processing: To facilitate and manage Transactions; to enable interaction with Financial Services Providers; and to route and process payments securely.
    3. Identity Verification and Underwriting: To verify identity; to assess eligibility for Services; to perform risk and credit assessments; and to determine ongoing suitability.
    4. Transaction Monitoring: To monitor activity for unusual or suspicious behaviour; and to identify potential fraud or misuse.
    5. Fraud Prevention and Risk Management: To detect and prevent fraud; to support the AML and CTF compliance obligations of Splink's Financial Services Providers; to support sanctions screening carried out by Financial Services Providers; and to conduct ongoing monitoring of risk.
    6. Legal and Contractual Compliance: To respond to lawful requests from courts, regulators and public authorities having jurisdiction over Splink; and to comply with Splink's obligations under applicable data protection, tax and commercial law.
    7. Service Improvement: To analyse performance and usage; to improve functionality and reliability; and to enhance user experience.
    8. Analytics and Value-Added Services: To generate insights and benchmarking data; to develop fraud and risk models; and to support value-added services including business financing offers, analytics and performance tools.

8. Data Sharing

  1. Splink may share Personal Data with the following categories of recipients, where necessary:
    1. Financial Services Providers, including acquiring banks, payment processors and card schemes, for the purposes of processing and settling Transactions;
    2. fraud prevention and risk management providers, for the purposes of fraud detection, risk scoring and supporting the AML and compliance obligations of Financial Services Providers;
    3. identity verification and KYC providers;
    4. technology and infrastructure service providers acting as processors on behalf of Splink;
    5. regulatory authorities, law enforcement agencies and courts, where disclosure is required by law or regulation; and
    6. group companies and professional advisers, including legal, financial and audit advisers, on a need-to-know basis.
  2. All sharing of Personal Data is subject to appropriate contractual, technical and organisational safeguards, including data processing agreements where required under Applicable Data Protection Laws. Splink does not sell Personal Data to third parties.

9. Anonymised and Aggregated Data

  1. Splink may generate aggregated and anonymised data derived from use of the Services. Such data does not identify individual Data Subjects, cannot reasonably be re-identified, and does not constitute Personal Data under Applicable Data Protection Laws.
  2. Splink may use and share anonymised and aggregated data with third parties for analytics and benchmarking, fraud detection and risk modelling, service improvement, and value-added services including business financing and analytics solutions, without restriction.

10. International Transfers

  1. Personal Data may be transferred to, and processed in, countries outside the European Economic Area (EEA), including where Splink's service providers or Financial Services Providers are located in such countries.
  2. Where such transfers occur, Splink shall ensure that appropriate safeguards are in place in accordance with Applicable Data Protection Laws. Such safeguards may include:
    1. transfers to countries recognised by the European Commission as providing an adequate level of protection;
    2. the execution of Standard Contractual Clauses (SCCs) approved by the European Commission; or
    3. other appropriate transfer mechanisms recognised under Applicable Data Protection Laws.
  3. Further information regarding international transfer safeguards may be requested by contacting Splink at [email protected].

11. Data Security

  1. Splink implements appropriate technical and organisational measures to protect Personal Data against unauthorised access, accidental loss, destruction, alteration or disclosure, including:
    1. encryption of Personal Data in transit and at rest;
    2. access controls and role-based permissions;
    3. network monitoring and intrusion detection;
    4. regular security testing and vulnerability assessments;
    5. staff training on data protection and security; and
    6. compliance with PCI-DSS requirements in relation to payment card data.
  2. Notwithstanding the above, no method of electronic transmission or storage is completely secure. While Splink takes reasonable precautions, it cannot guarantee absolute security and shall not be liable for any unauthorised access that occurs despite such measures, except where such access results from Splink's failure to implement appropriate safeguards.

12. Data Retention

  1. Splink retains Personal Data only for as long as is necessary for the purposes for which it was collected, or as required by applicable law or regulation. The following retention principles apply:
    1. Contractual and operational data is retained for the duration of the Merchant relationship and for a minimum of six (6) years following termination of that relationship.
    2. KYC, identity verification and risk records are retained for a minimum of five (5) years from the date of collection or the end of the business relationship.
    3. Transaction records are retained for a minimum of six (6) years for regulatory and audit purposes.
    4. Technical and analytical data is retained for a maximum period of three (3) years unless otherwise required by law.
  2. Upon expiry of the applicable retention period, Personal Data will be securely deleted or anonymised. Where data is anonymised, it may be retained indefinitely for analytical purposes.

13. Data Subject Rights

  1. Data Subjects have the following rights under Applicable Data Protection Laws, subject to applicable conditions and exemptions:
    1. Right of Access - the right to obtain confirmation as to whether Personal Data is being processed and, where so, to receive a copy of that Personal Data together with supplementary information;
    2. Right to Rectification - the right to require Splink to correct inaccurate or incomplete Personal Data without undue delay;
    3. Right to Erasure - the right to require Splink to erase Personal Data where it is no longer necessary for the purposes for which it was collected, where consent has been withdrawn, or where processing is unlawful, subject to applicable legal and regulatory retention obligations;
    4. Right to Restriction - the right to require Splink to restrict processing of Personal Data in certain circumstances;
    5. Right to Data Portability - the right to receive Personal Data in a structured, commonly used and machine-readable format and to transmit that data to another controller, where processing is based on consent or contractual necessity and is carried out by automated means;
    6. Right to Object - the right to object to processing based on legitimate interests, including profiling, unless Splink can demonstrate compelling legitimate grounds for the processing that override the interests, rights and freedoms of the Data Subject; and
    7. Rights in Automated Decision-Making - the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal or similarly significant effects.
  2. To exercise any of the above rights, Data Subjects should submit a written request to Splink at [email protected]. Splink will respond within one (1) month of receipt of a valid request. Splink may extend this period by a further two (2) months where the request is complex or where a number of requests have been received, in which case Splink will notify the Data Subject within one month of receipt. Splink may require verification of identity before processing any request.
  3. Where Splink is unable to comply with a request, Splink will inform the Data Subject of the reasons and of the right to lodge a complaint with the relevant supervisory authority.

14. Cookies

  1. Splink uses cookies and similar tracking technologies on the Platform for the following purposes:
    1. Strictly Necessary Cookies - essential for the operation of the Platform and the provision of the Services. These cookies cannot be disabled.
    2. Functional Cookies - used to remember user preferences and settings to enhance the experience of using the Platform.
    3. Analytical Cookies - used to collect information about how the Platform is used, including the pages visited and any errors encountered, in order to improve performance and functionality.
    4. Security Cookies - used to authenticate users, prevent fraudulent use of accounts, and protect both Splink and its Merchants.
  2. By continuing to use the Platform, you consent to the use of cookies in accordance with this Privacy Policy and Splink's Cookie Policy. You may withdraw consent to non-essential cookies at any time by adjusting your browser settings or through the cookie preference centre on the Platform. Please note that disabling certain cookies may affect the functionality of the Platform.
  3. Full details of the cookies used by Splink, including their names, purposes and retention periods, are set out in the Cookie Policy.

15. Data Breaches

  1. Splink maintains a data breach response procedure in accordance with its obligations under Applicable Data Protection Laws.
  2. In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of natural persons, Splink will:
    1. notify the relevant supervisory authority (the Data Protection Commission in Ireland) without undue delay and, where feasible, within 72 hours of becoming aware of the breach, in accordance with Article 33 GDPR;
    2. where the breach is likely to result in a high risk to the rights and freedoms of Data Subjects, notify the affected individuals without undue delay in accordance with Article 34 GDPR; and
    3. document all personal data breaches, including those which are not required to be notified, in accordance with Article 33(5) GDPR.
  3. Splink maintains an internal register of personal data breaches and will take appropriate remedial action following any breach. Merchants who become aware of a potential personal data breach involving data processed through the Platform should notify Splink immediately at [email protected].

16. Regulatory Disclosures

  1. Splink may be required to disclose Personal Data to regulatory authorities, law enforcement agencies, courts, supervisory bodies or other public authorities where such disclosure is required or permitted by applicable law or regulation, including:
    1. in response to a valid court order, subpoena or other legal process;
    2. where required by applicable data protection law, tax law or other legislation having direct application to Splink;
    3. where required by Payment Networks or Financial Services Providers in connection with the processing of Transactions; or
    4. where Splink reasonably determines that disclosure is necessary to protect the rights, property or safety of Splink, its Merchants, End Customers or others.
  2. Where permitted by law, Splink will endeavour to notify the relevant Merchant prior to any such disclosure. Splink shall not be liable for any loss or damage arising from disclosures made in good faith in response to lawful requests from authorities.

17. Complaints

  1. If you have a complaint or concern regarding the processing of your Personal Data by Splink, you may contact Splink in the first instance at [email protected]. Splink will acknowledge receipt of your complaint and will aim to investigate and respond within 14 working days. Where a complaint is complex or requires further investigation, Splink will notify you of this and provide a revised timeframe.
  2. Where a complaint relates to data processed by a Financial Services Provider, Splink may direct or escalate the complaint to the relevant provider as appropriate.
  3. If you are not satisfied with Splink's response, or if you consider that Splink is processing your Personal Data in a manner that is inconsistent with Applicable Data Protection Laws, you have the right to lodge a complaint with the relevant supervisory authority. In Ireland, the supervisory authority is:

    Data Protection Commission
    21 Fitzwilliam Square South
    Dublin 2, D02 RD28
    Ireland
    www.dataprotection.ie

18. Contact Details

  1. Questions, requests or concerns regarding this Privacy Policy or the processing of Personal Data by Splink should be directed to:
    Splink Limited
    Two Haddington Buildings, 20 Haddington Road, Dublin D04 HE94, Ireland
    Email: [email protected]
This Privacy Policy was last updated in April 2026. Splink reserves the right to update this Privacy Policy from time to time. The current version will always be available on the Platform. Where changes are material, Splink will notify Merchants by email or through the Platform.