Legal

Privacy Policy

PREFLOOR LTD · Registration number HE496840 · Republic of Cyprus
Version 1.0 · Effective from 12 August 2026

This policy explains how PREFLOOR LTD handles personal data collected through this website and in the course of our business relationships.

Who we are. PREFLOOR LTD supplies payment orchestration technology and acts as an agent introducing merchants to licensed payment providers. We route transactions, provide reporting and support. We do not hold, safeguard or settle funds, we do not issue payment instruments, and we do not operate accounts for merchants or their customers. Settlement is carried out by licensed payment institutions, electronic money institutions and acquirers under their own agreements with the merchant.

1. Who is responsible for your data

PREFLOOR LTD, a company incorporated in the Republic of Cyprus under registration number HE496840, registered office at Giannou Kranidioti & Pargas 9, Floor 1, Flat/Office 102, 1065, Nicosia, Cyprus, is the controller of the personal data described in this policy.

For any question about this policy or about your personal data, write to business@prefloorltd.com.

2. Who this policy applies to

Our services are provided to businesses, not to consumers. This policy applies to:

We do not have a direct relationship with the customers of our merchants. Where transaction data reaches us in the course of routing a payment, we act on the instructions of the merchant and of the licensed payment partner, and we process it only as needed to provide the technical service.

3. What we collect

CategoryExamplesWhere it comes from
Contact dataName, business email, phone, company, positionYou, through our forms or by email
Onboarding dataIdentity documents, proof of address, ownership information, source of funds informationYou and your company, during due diligence
Screening dataSanctions, politically exposed person and adverse media check resultsThird-party screening providers and public registers
Relationship dataCorrespondence, support tickets, meeting notes, contractual recordsOur interaction with you
Technical dataIP address, browser and device type, pages viewed, time on site, consent recordAutomatically, through the website and cookies

Please do not send us special categories of personal data (health, religion, political opinions and similar). We do not request them and do not need them.

4. Why we process it, and on what legal basis

PurposeLegal basis
Responding to enquiries and preparing an agreementSteps at your request prior to entering a contract
Providing and supporting our servicesPerformance of a contract
Customer due diligence, sanctions screening, ongoing monitoringLegal obligation; and our legitimate interest in preventing financial crime
Introducing a merchant to a licensed payment partnerPerformance of a contract; legitimate interest in operating our agency business
Security, fraud prevention, keeping records of what was agreedLegitimate interest in protecting our business and our partners
Marketing communicationsYour consent, which you may withdraw at any time
Analytics cookiesYour consent, given through the cookie banner
Responding to regulators, courts and law enforcementLegal obligation

5. Who we share it with

We share personal data only where there is a reason to. Recipients fall into these groups:

We do not sell personal data, and we do not share it with third parties for their own marketing.

6. Transfers outside the EEA

Some of our partners and service providers are located outside the European Economic Area. Where personal data is transferred outside the EEA, we rely on an adequacy decision of the European Commission, or on the Standard Contractual Clauses, together with additional measures where the circumstances require them. You may ask us which mechanism applies to a specific transfer.

7. How long we keep it

DataRetention
Enquiries that do not lead to a relationship12 months from the last contact
Due diligence records and transaction records5 years after the end of the business relationship, as required by anti-money-laundering law, and longer where an authority requires it
Contracts and accounting records6 years after the end of the contract
Marketing consent and the record of itUntil you withdraw consent, plus 2 years to evidence the withdrawal
Cookie consent record182 days, then you are asked again
Website server logsUp to 12 months

8. Your rights

Subject to the conditions in the GDPR, you have the right to:

To exercise any of these rights write to business@prefloorltd.com. We answer within one month and may ask you to confirm your identity first. Where anti-money-laundering law requires us to keep records, we cannot delete them on request, and we will tell you when that is the case.

9. Security

We apply access control on a need-to-know basis, encryption in transit, logging of access to due diligence files, and confidentiality obligations on everyone who handles personal data for us. No system is completely secure, and we do not claim otherwise. If a breach is likely to result in a high risk to you, we will tell you.

10. Automated decision-making

We do not take decisions producing legal effects concerning you based solely on automated processing. Screening tools may flag a name for review, but the decision to accept or decline a business relationship is always taken by a person.

11. Changes

We may update this policy. The version number and effective date at the top of this page always show the current version. Material changes will be communicated to counterparties directly.