Privacy Policy
This policy explains how PREFLOOR LTD handles personal data collected through this website and in the course of our business relationships.
Who we are. PREFLOOR LTD supplies payment orchestration technology and acts as an agent introducing merchants to licensed payment providers. We route transactions, provide reporting and support. We do not hold, safeguard or settle funds, we do not issue payment instruments, and we do not operate accounts for merchants or their customers. Settlement is carried out by licensed payment institutions, electronic money institutions and acquirers under their own agreements with the merchant.
1. Who is responsible for your data
PREFLOOR LTD, a company incorporated in the Republic of Cyprus under registration number HE496840, registered office at Giannou Kranidioti & Pargas 9, Floor 1, Flat/Office 102, 1065, Nicosia, Cyprus, is the controller of the personal data described in this policy.
For any question about this policy or about your personal data, write to business@prefloorltd.com.
2. Who this policy applies to
Our services are provided to businesses, not to consumers. This policy applies to:
- visitors to this website;
- people who contact us through the forms on this website or by email;
- representatives, directors, shareholders and beneficial owners of merchants, partners and suppliers, whose data we process during onboarding and throughout the relationship;
- candidates who apply to work with us.
We do not have a direct relationship with the customers of our merchants. Where transaction data reaches us in the course of routing a payment, we act on the instructions of the merchant and of the licensed payment partner, and we process it only as needed to provide the technical service.
3. What we collect
| Category | Examples | Where it comes from |
|---|---|---|
| Contact data | Name, business email, phone, company, position | You, through our forms or by email |
| Onboarding data | Identity documents, proof of address, ownership information, source of funds information | You and your company, during due diligence |
| Screening data | Sanctions, politically exposed person and adverse media check results | Third-party screening providers and public registers |
| Relationship data | Correspondence, support tickets, meeting notes, contractual records | Our interaction with you |
| Technical data | IP address, browser and device type, pages viewed, time on site, consent record | Automatically, through the website and cookies |
Please do not send us special categories of personal data (health, religion, political opinions and similar). We do not request them and do not need them.
4. Why we process it, and on what legal basis
| Purpose | Legal basis |
|---|---|
| Responding to enquiries and preparing an agreement | Steps at your request prior to entering a contract |
| Providing and supporting our services | Performance of a contract |
| Customer due diligence, sanctions screening, ongoing monitoring | Legal obligation; and our legitimate interest in preventing financial crime |
| Introducing a merchant to a licensed payment partner | Performance of a contract; legitimate interest in operating our agency business |
| Security, fraud prevention, keeping records of what was agreed | Legitimate interest in protecting our business and our partners |
| Marketing communications | Your consent, which you may withdraw at any time |
| Analytics cookies | Your consent, given through the cookie banner |
| Responding to regulators, courts and law enforcement | Legal obligation |
5. Who we share it with
We share personal data only where there is a reason to. Recipients fall into these groups:
- Licensed payment partners - payment institutions, electronic money institutions, acquirers and payment providers to whom we introduce you or through whom your transactions are routed. They receive onboarding and transaction data because they, not we, are the regulated party settling the funds. They act as independent controllers under their own privacy notices.
- Screening and verification providers - for sanctions, PEP and adverse media checks.
- Service providers - hosting, email, storage, support tooling, acting on our instructions under written terms.
- Professional advisers - lawyers, auditors and accountants, bound by professional confidentiality.
- Authorities - regulators, courts and law enforcement, where we are legally required to disclose.
We do not sell personal data, and we do not share it with third parties for their own marketing.
6. Transfers outside the EEA
Some of our partners and service providers are located outside the European Economic Area. Where personal data is transferred outside the EEA, we rely on an adequacy decision of the European Commission, or on the Standard Contractual Clauses, together with additional measures where the circumstances require them. You may ask us which mechanism applies to a specific transfer.
7. How long we keep it
| Data | Retention |
|---|---|
| Enquiries that do not lead to a relationship | 12 months from the last contact |
| Due diligence records and transaction records | 5 years after the end of the business relationship, as required by anti-money-laundering law, and longer where an authority requires it |
| Contracts and accounting records | 6 years after the end of the contract |
| Marketing consent and the record of it | Until you withdraw consent, plus 2 years to evidence the withdrawal |
| Cookie consent record | 182 days, then you are asked again |
| Website server logs | Up to 12 months |
8. Your rights
Subject to the conditions in the GDPR, you have the right to:
- be told what personal data we hold about you and receive a copy of it;
- have inaccurate data corrected;
- have data erased, where we have no continuing legal reason to keep it;
- restrict or object to processing, including profiling based on legitimate interest;
- receive data you gave us in a portable format;
- withdraw consent at any time, without affecting processing carried out before the withdrawal;
- lodge a complaint with a supervisory authority. In Cyprus this is the Office of the Commissioner for Personal Data Protection.
To exercise any of these rights write to business@prefloorltd.com. We answer within one month and may ask you to confirm your identity first. Where anti-money-laundering law requires us to keep records, we cannot delete them on request, and we will tell you when that is the case.
9. Security
We apply access control on a need-to-know basis, encryption in transit, logging of access to due diligence files, and confidentiality obligations on everyone who handles personal data for us. No system is completely secure, and we do not claim otherwise. If a breach is likely to result in a high risk to you, we will tell you.
10. Automated decision-making
We do not take decisions producing legal effects concerning you based solely on automated processing. Screening tools may flag a name for review, but the decision to accept or decline a business relationship is always taken by a person.
11. Changes
We may update this policy. The version number and effective date at the top of this page always show the current version. Material changes will be communicated to counterparties directly.