CentralPay Documentation CentralPay Documentation
  • General information
  • Documentation
  • Developers
  • English
    • FrenchSwitch to French
CentralPay Documentation CentralPay Documentation
  • General information
  • Documentation
  • Developers
  • English
    • FrenchSwitch to French
General information
  • Folder icon closed Folder open iconContact CentralPay >
  • Folder icon closed Folder open iconCentralPay
    • Certifications and Approvals
    • Security and Hosting
    • Availability Commitments
    • Platform Development
    • CentralPay Glossary
  • Folder icon closed Folder open iconContract Templates
    • Standard Merchant
    • Partner Merchant
      • MOBSP (Orias) Declaration
    • Intermediary Merchant
      • PSP Agent Declaration (ACPR)
      • ME Distributor Declaration (ACPR)
  • Folder icon closed Folder open iconOpen a CentralPay account
    • Onboarding Path
    • Principles of Reserve
    • Terms and Conditions of Use
  • Folder icon closed Folder open iconUsing the CentralPay APIs
  • Folder icon closed Folder open iconMerchant Portal
    • Guide: My Accounts
  • Folder icon closed Folder open iconCustomer Portal
  • Folder icon closed Folder open iconOnboarding Portal
  • Folder icon closed Folder open iconRates
    • Sales Offers
    • Interchange Fees and Card Schemes
    • Support Packages
  • Folder icon closed Folder open iconLogos and visuals
    • CentralPay Logos
    • PaySecure Logos
    • Reinsurance Visuals (FR/EN)
  • Folder icon closed Folder open iconTrust Center
    • Compliance and Operational ResilienceDORA
      • FAQ – Compliance and ResilienceDORA
    • Privacy PolicyGDPR
      • Subcontractors
      • FAQ – Privacy PolicyGDPR

Privacy Policy

Estimated reading: 9 minutes

Last updated: September 15, 2025

At CentralPay, the protection of personal data is at the heart of our commitments. As an Electronic money Institution authorized by the ACPR (authorization No. 17138), we process personal data in accordance with the General Data Protection Regulation (GDPR – EU 2016/679) and applicable French law.

This policy clearly and transparently describes how we process personal data in connection with the provision of our payment services.

1. Who is the data controller?

The data controller is:
CentralPay – 19 rue Edouard VAILLANT – 37000 TOURS
DPO contact: dpo@centralpay.com

2. What data do we collect?

CentralPay collects only the data strictly necessary to provide its payment services and to comply with its legal and regulatory obligations.

Identification Information

  • Last name, first name, title.
  • Date and place of birth.
  • Nationality.
  • Position (executive, legal representative, UBO).

Contact Information

  • Email address.
  • Phone number (cell or landline).
  • Business or personal mailing address (as applicable).

Payment Information

  • Bank account information: IBAN and BIC.
  • Card data: card number (collected only in a PCI DSS-compliant environment and immediately tokenized), expiration date, card brand (Visa, Mastercard, etc.), issuing country, last 4 digits.
  • Important: CentralPay never discloses the full card number or the security code to the Merchant.

Transaction Data

  • Transaction ID, date, and time.
  • Amount, currency, payment status.
  • Order reference (orderId).
  • Transaction history (one-time payments, recurring payments, installment payments, refunds).

Security and Anti-Fraud Data

  • Connection IP address.
  • Technical profile of the device (browser, language, screen resolution) during 3DS authentication.
  • Internal anti-fraud results and scores.
  • Possible monitoring status (technical blacklist).

KYC/AML-CFT Compliance Data

  • Identity documents (NIC, Passport, Residence permit).
  • Proof of address (utility bill, receipt).
  • Company legal documents (Commercial register, Articles of association, Register of Beneficial Owners).
  • Information on UBOs (names, ownership percentages).

Technical Data (Service-Related)

  • Application and technical logs (API logs).
  • Processing events (webhooks sent to Merchants).
  • Technical tracking identifiers (transactionId, customerId, etc.).

3. For what purposes do we use your data?

CentralPay processes your personal data solely for specific, explicit, and legitimate purposes. Each processing activity is based on a legal basis that complies with the GDPR.

Payment Processing and Service Management

  • Purpose: To process your payment transactions (SEPA, credit cards, Direct Debit, Bank transfers, recurring or installment payments), handle billing, and manage cash flows.
  • Data involved: bank account information (IBAN, BIC), card data (token, schema, country, masked PAN), transaction IDs, amounts, currencies, order references.
  • Legal basis: performance of the contract (Art. 6.1.b of the GDPR).

Identity Verification and Regulatory Requirements (KYC/AML-CFT)

  • Purpose: To comply with legal obligations regarding the fight against money laundering and terrorist financing (AML/CFT) and with the supervisory requirements of the ACPR.
  • Data covered: identification data (last name, first name, date of birth, nationality), identity documents, Proof of address, legal documents of the company, information on UBOs.
  • Legal basis: legal obligation (Art. 6.1.c of the GDPR; Art. L561-1 et seq. of the Monetary and Financial Code).

Fraud Prevention and Detection

  • Purpose: to secure transactions, prevent unauthorized or fraudulent payments, and enforce strong authentication rules (PSD2/3DS).
  • Data involved: IP address, technical fingerprint of the browser/device, card scheme and issuing country, results of anti-fraud checks, and any monitoring status.
  • Legal basis: legal obligation (PSD2) and legitimate interest (payment security—Art. 6.1.f of the GDPR).

Customer Relationship Management and Support

  • Purpose: to communicate with customers and users (confirming transactions, sending payment links, sending notifications), respond to support requests, and follow up on complaints and Disputes.
  • Data involved: email, phone number, customer credentials, and associated transaction data.
  • Legal basis: performance of the contract (Art. 6.1.b GDPR) and legitimate interest (customer relationship management).

Compliance with accounting, tax, and reporting requirements

  • Purpose: to retain certain data in order to comply with legal retention requirements (Commercial Code, General Tax Code) and to produce accounting and evidentiary documentation.
  • Data in question: transactional data (amounts, currencies, dates, statuses, references), and bank account information related to transactions.
  • Legal basis: legal obligation (Art. 6.1.c GDPR).

Improving Our Services and Technical Security

  • Purpose: To analyze the use of our services, optimize performance, and ensure resilience and cybersecurity, in accordance with the DORA regulation.
  • Data in question: technical logs, events (webhooks), technical identifiers, and anonymized usage statistics.
  • Legal basis: legitimate interest (Art. 6.1.f of the GDPR).

4. What is the legal basis for this processing?

Each data processing activity is based on a clearly defined legal basis:

  • Contract performance (Art. 6.1.b of the GDPR): processing payments, account management, customer relations, and support.
  • Legal obligation (Art. 6.1.c of the GDPR): AML/CFT compliance (Art. L561 of the French Monetary and Financial Code), accounting and tax obligations (Commercial Code, General Tax Code), regulatory obligations (PSD2, ACPR).
  • Legitimate interest (Art. 6.1.f of the GDPR): fraud prevention, system security, dispute resolution, and service improvement.
  • Consent (Art. 6.1.a GDPR): only for certain optional marketing communications or as required by law.

5. How long do we retain your data?

CentralPay follows a strict data retention schedule that complies with the requirements of the GDPR, the Monetary and Financial Code, and the Commercial Code.

We distinguish between:

a) Financial Transactions (Accounting Entries and Supporting Documents)

  • Retained for 10 years in accordance with accounting and evidentiary requirements (Art. L123-22 of the Commercial Code).
  • Data involved: transaction IDs (transactionId), date, amount, currency, status, order ID (orderId).
  • This information is required for contractual purposes and accounting and is not anonymized.

(b) Personal data associated with transactions

  • Stored for a maximum of 24 months and then irreversibly anonymized.
  • Data in question:
    • Payer’s contact information (email, phone number),
    • IP address, browser/device fingerprint (3DS),
    • Card data (token, masked PAN, expiration date, schema, issuing country),
    • Anti-fraud results (score, blacklist status).
  • This information is no longer retained beyond 24 months because it is no longer required by law or under any contract.

(c) Payment card data

  • Stored for up to 24 months after the card’s expiration date, then deleted or anonymized.
  • CentralPay never discloses the full PAN or the CVC outside its PCI DSS environment.

d) Bank Account information (IBAN/BIC) and SEPA direct debits

  • Retained for the duration of the term of office plus 10 years (contractual evidence), then deleted or anonymized.

e) KYC / AML-CFT Data

  • Retained for 5 years after the end of the business relationship (Art. L561-12 CMF), then deleted or anonymized.
  • Data covered: identity documents, proof of address, company legal documents, and information on UBOs.

f) Subscriptions and installment payments

  • Retained for the duration of the subscription plus 5 years (for evidentiary purposes), then anonymized.
  • Data involved: subscription ID, payment schedule, link to payment method.

g) Technical logs and webhooks

  • Stored for up to 24 months, then anonymized.
  • Data involved: API logs, processing events, technical identifiers (customerId, eventId), statuses, timestamps.

6. Who are the recipients of your data?

Your data may be shared only with:

  • CentralPay internal services (operations, compliance, support, security).
  • Payment partners and financial institutions (acquirers, SEPA settlement systems, card schemes).
  • Technical service providers (cloud hosting, KYC provider, SMS/email delivery) that are subject to contractual terms compliant with the GDPR.
  • Competent authorities (ACPR, TRACFIN, Banque de France, judicial authorities).

We never sell your data to third parties.

7. Where is your data processed?

  • The data is hosted in the European Union, primarily in France.
  • In the event of a transfer outside the EU (e.g., SMS or email service provider), standard contractual clauses (SCCs) and additional measures are implemented to ensure an equivalent level of protection.

8. What are your rights?

In accordance with Articles 15 through 22 of the GDPR, you have the following rights:

  • Right of access, correction, and deletion.
  • Right to restriction, objection, and data portability.
  • Right to withdraw consent (if applicable).
  • The right to file a complaint with the CNIL.

You can exercise your rights by writing to: dpo@centralpay.com (response within 30 days).

9. Safety

CentralPay implements a security policy aligned with PCI DSS, ISO 27001/27005 standards, and the European DORA (Digital Operational Resilience Act) regulation. Our measures cover the entire lifecycle of data and payment services to ensure their confidentiality, integrity, and availability.

Security is primarily ensured through clear governance and proactive risk management. We have a risk management framework approved by senior management, which includes a risk appetite policy, a risk map aligned with ISO and DORA standards, and risk indicators that are monitored regularly. This framework is implemented through a three-lines-of-defense structure and overseen by a security and compliance committee.

Data protection is based on systematic encryption, both in transit (TLS 1.2/1.3) and at rest (AES-256), with centralized key management. Payment data is processed exclusively in a PCI DSS Level 1-certified environment and undergoes irreversible tokenization, which prevents any exposure of full card numbers or security codes. In addition, we enforce strict policies for the automatic deletion and anonymization of personal data once the retention periods specified by the GDPR have expired.

Access to systems is strictly controlled through centralized identity management based on the principle of least privilege. Every employee is required to undergo strong two-factor authentication (MFA), and access permissions are reviewed regularly to ensure they remain appropriate.

Our infrastructure is continuously monitored. Sensitive operations are comprehensively logged and time-stamped, and a real-time monitoring system, coupled with an SIEM, enables us to quickly detect security incidents.

Operational resilience is ensured by a business continuity framework aligned with DORA. CentralPay has implemented an Emergency and Business Continuity Plan (PUPA) that includes regularly tested disaster recovery (PCA) and business continuity (PRI) components. Penetration tests and crisis management exercises are conducted annually, while a strict ICT outsourcing policy ensures the ongoing evaluation of critical service providers and the maintenance of a regulatory information registry.

Incident management follows a formalized procedure for detection, classification, and resolution. In the event of a major incident, we comply with the regulatory reporting deadlines for the ACPR and the CNIL, and a systematic review is conducted to continuously improve our security measures.

Finally, CentralPay is committed to continuous improvement. Internal and external audits, including independent PCI DSS and cybersecurity audits, are conducted regularly. Our ongoing monitoring and periodic audit procedures are reviewed annually to ensure their effectiveness and compliance with international standards and regulatory requirements.

10. Policy Update

This policy may be amended to reflect changes in data processing practices and legal requirements. Any updates will be posted on our website and, if necessary, communicated to the affected customers.

Click the links below to access the detailed pages in this section.

  • Subcontractors
  • FAQ – Privacy PolicyGDPR
Privacy Policy - PreviousFAQ – Compliance and ResilienceNext - Privacy PolicySubcontractors
CONTENTS

Doc Contents

Doc Footnotes

Doc Elements

  • Legal notices
  • Privacy policy

© 2026 CentralPay

You must log in to continue.

Login to CentralPay Documentation

Forgotten account?

Reset your password

Enter your username or email address and we will send you a link to reset your password.

Back to login
  • French