{"id":16726,"date":"2025-10-02T10:00:32","date_gmt":"2025-10-02T08:00:32","guid":{"rendered":"https:\/\/docs.centralpay.com\/documentation\/trust-center\/privacy-policy\/faq-privacy-policy\/"},"modified":"2026-09-03T09:22:21","modified_gmt":"2026-09-03T07:22:21","slug":"faq-privacy-policy","status":"publish","type":"docs","link":"https:\/\/docs.centralpay.com\/en\/documentation\/general-information\/trust-center\/privacy-policy\/faq-privacy-policy\/","title":{"rendered":"FAQ &#8211; Privacy Policy"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\">Governance and Responsibilities<\/h2>\n\n<p class=\"wp-block-paragraph\"><strong>Data Controller and DPO Contact<\/strong><\/p>\n\n<p class=\"wp-block-paragraph\">CentralPay, an Electronic money Institution (EMI), is the data controller for its payment services.<br\/>DPO contact: dpo@centralpay.com (response within 30 days).<\/p>\n\n<h2 class=\"wp-block-heading\">Data Collected<\/h2>\n\n<p class=\"wp-block-paragraph\"><strong>What data do we collect?<\/strong><\/p>\n\n<p class=\"wp-block-paragraph\">As part of the provision of its payment services and in order to comply with its legal obligations, CentralPay collects only the data that is strictly necessary. This data varies depending on the type of transaction (payment, KYC verification, fraud prevention, customer support). It falls into several categories:  <\/p>\n\n<ul class=\"wp-block-list\">\n<li><strong>Identifying information<\/strong>: last name, first name, title, date and place of birth, nationality, and role (e.g., legal representative, executive, or Beneficial Owner\u2014UBO).<\/li>\n\n\n\n<li><strong>Contact information<\/strong>: email address, phone number, mailing address.<\/li>\n\n\n\n<li><strong>Payment information<\/strong>: bank account details (IBAN, BIC); card information processed exclusively in a PCI DSS-certified environment (full card number and CVC collected solely for tokenization and never exposed in plain text), expiration date, card brand (Visa, Mastercard, etc.), issuing country, and last 4 digits.<\/li>\n\n\n\n<li><strong>Transaction data<\/strong>: transaction ID (transactionId), date and time, amount, currency, status, order ID (orderId), transaction history (one-time payments, recurring payments, split payments, refunds).<\/li>\n\n\n\n<li><strong>Security and anti-fraud data<\/strong>: IP address, 3DS fingerprint (browser\/device), anti-fraud results and scores, and any technical monitoring status.<\/li>\n\n\n\n<li><strong>KYC\/AML-CFT compliance data<\/strong>: official identity documents, proof of address, legal documents pertaining to the company (e.g., Commercial register, Articles of association), information on ultimate Beneficial Owners (UBOs and ownership percentages).<\/li>\n\n\n\n<li><strong>Technical data<\/strong>: application logs (API logs), events sent to Merchants (webhooks), technical identifiers (customerId, eventId).<\/li>\n<\/ul>\n\n<p class=\"wp-block-paragraph\">CentralPay does not collect <strong>any sensitive data<\/strong> as defined in Article 9 of the GDPR (health, religion, political opinions, sexual orientation, etc.), unless required to do so by law in exceptional circumstances.<\/p>\n\n<h2 class=\"wp-block-heading\">Purposes<\/h2>\n\n<p class=\"wp-block-paragraph\"><strong>Why do we use your data?<\/strong><\/p>\n\n<p class=\"wp-block-paragraph\">CentralPay processes your personal data solely for specific, explicit, and legitimate purposes. This processing is carried out in connection with the provision of our payment services, compliance with our regulatory obligations, and the security of our systems. The main purposes are as follows:  <\/p>\n\n<ul class=\"wp-block-list\">\n<li>Payment Processing: processing payment transactions (SEPA, credit cards, recurring or installment payments), managing cash flows, issuing invoices, and tracking payments.<\/li>\n\n\n\n<li>Compliance with regulatory requirements: enforcement of anti-money laundering and counter-terrorism financing (AML\/CTF) rules, know-your-customer (KYC) verification, legal document retention, and supervision by the ACPR.<\/li>\n\n\n\n<li>Fraud prevention and detection: implementation of the security controls required by PSD2 (strong authentication, 3DS), calculation of anti-fraud scores, and alert management.<\/li>\n\n\n\n<li>Customer Relations and Support: communicating with customers and users (notifications, confirmations, sending payment links), handling support requests, and managing complaints and disputes.<\/li>\n\n\n\n<li>Accounting and tax obligations: retention of supporting documents; compliance with the provisions of the Commercial Code and the General Tax Code.<\/li>\n\n\n\n<li>Technical Improvement and Security: Monitoring the performance and availability of our services; strengthening operational resilience in accordance with the DORA regulation; and continuously improving the customer experience and the security of our systems.<\/li>\n<\/ul>\n\n<h2 class=\"wp-block-heading\">Legal Basis<\/h2>\n\n<p class=\"wp-block-paragraph\"><strong>What is the legal basis for our data processing?<\/strong><\/p>\n\n<p class=\"wp-block-paragraph\">CentralPay processes your personal data solely for specific, explicit, and legitimate purposes. This processing is carried out in connection with the provision of our payment services, compliance with our regulatory obligations, and the security of our systems. The main purposes are as follows:  <\/p>\n\n<ul class=\"wp-block-list\">\n<li><strong>Payment Processing<\/strong>: processing payment transactions (SEPA, credit cards, recurring or installment payments), managing cash flows, issuing invoices, and tracking payments.<\/li>\n\n\n\n<li><strong>Compliance with regulatory obligations<\/strong>: enforcement of anti-money laundering and counter-terrorism financing (AML\/CTF) rules, know-your-customer (KYC) verification, legal document retention, and supervision by the ACPR.<\/li>\n\n\n\n<li><strong>Fraud prevention and detection<\/strong>: implementation of the security controls required by PSD2 (strong authentication, 3DS), calculation of fraud scores, and alert management.<\/li>\n\n\n\n<li><strong>Customer Relations and Support<\/strong>: communicating with customers and users (notifications, confirmations, sending payment links), handling support requests, and managing complaints and Disputes.<\/li>\n\n\n\n<li><strong>Accounting and Tax Obligations<\/strong>: Retention of supporting documents; compliance with the provisions of the Commercial Code and the General Tax Code.<\/li>\n\n\n\n<li><strong>Technical Improvement and Security<\/strong>: Monitoring the performance and availability of our services, strengthening operational resilience in accordance with the DORA regulation, and continuously improving the customer experience and the security of our systems.<\/li>\n<\/ul>\n\n<p class=\"wp-block-paragraph\"><strong>How long do we retain your data?<\/strong><\/p>\n\n<p class=\"wp-block-paragraph\">CentralPay follows specific retention periods based on legal requirements and operational needs. At the end of these periods, the data is either deleted or irreversibly anonymized. <\/p>\n\n<ul class=\"wp-block-list\">\n<li>Financial transactions (supporting documents): retained for 10 years, in accordance with the Commercial Code.<\/li>\n\n\n\n<li>Personal data associated with transactions (email, phone number, IP address, 3DS fingerprints, masked PAN, card token, fraud scores): retained for a maximum of 24 months, then deleted or anonymized.<\/li>\n\n\n\n<li>Card data (token + metadata): retained for up to 24 months after the card&#8217;s expiration date. The full PAN and CVC are never stored in plain text. <\/li>\n\n\n\n<li>Payment Requests (emails\/text messages): Retained for up to 24 months.<\/li>\n\n\n\n<li>Subscriptions and installment payments: retained for the duration of the subscription plus 5 years.<\/li>\n\n\n\n<li>Bank Accounts (IBAN\/BIC) and SEPA direct debits: retained for the duration of the mandate plus 10 years (contractual evidence).<\/li>\n\n\n\n<li>KYC \/ AML-CFT: Data retained for 5 years after the end of the business relationship (Art. L561-12 of the French Monetary and Financial Code).<\/li>\n\n\n\n<li>Technical logs and webhooks: retained for 24 months.<\/li>\n<\/ul>\n\n<p class=\"wp-block-paragraph\">Beyond these time periods, CentralPay retains only anonymized data or data that is strictly necessary to comply with a legal obligation.<\/p>\n\n<h2 class=\"wp-block-heading\">Location and Transfers<\/h2>\n\n<p class=\"wp-block-paragraph\"><strong>Where is your data processed?<\/strong><\/p>\n\n<p class=\"wp-block-paragraph\">The data processed by CentralPay is primarily hosted in the European Union\u2014mainly in France\u2014in environments certified to PCI DSS and ISO 27001 standards.<\/p>\n\n<p class=\"wp-block-paragraph\">To date, CentralPay does not transfer personal data outside the European Union.<br\/>If a transfer outside the EU were to become necessary in the future (for example, to an SMS or email service provider), it would be governed by:<\/p>\n\n<ul class=\"wp-block-list\">\n<li>an impact analysis of the transfer,<\/li>\n\n\n\n<li>the implementation of the European Commission&#8217;s Standard Contractual Clauses (SCCs),<\/li>\n\n\n\n<li>additional technical measures (encryption, segmentation, access control),<\/li>\n\n\n\n<li>and transparent communication with our customers.<\/li>\n<\/ul>\n\n<p class=\"wp-block-paragraph\"><strong>Data Transfers Outside the EU: How Do We Handle Them?<\/strong><\/p>\n\n<p class=\"wp-block-paragraph\">To date, CentralPay does not transfer personal data outside the European Union.<br\/>All data is hosted and processed within the EU, primarily in France and within certified (PCI DSS) infrastructure.<\/p>\n\n<p class=\"wp-block-paragraph\">If, in the future, a transfer outside the EU were to be necessary (for example, to an SMS or email service provider), CentralPay undertakes to:<\/p>\n\n<ul class=\"wp-block-list\">\n<li>conduct an impact analysis of the transfer,<\/li>\n\n\n\n<li>apply the European Commission&#8217;s Standard Contractual Clauses (SCCs),<\/li>\n\n\n\n<li>implement additional technical measures (encryption, segmentation, access control),<\/li>\n\n\n\n<li>and keep its customers fully informed.<\/li>\n<\/ul>\n\n<h2 class=\"wp-block-heading\">Nature of the Data<\/h2>\n\n<p class=\"wp-block-paragraph\"><strong>Do we process sensitive data?<\/strong><\/p>\n\n<p class=\"wp-block-paragraph\">No. CentralPay does not process any sensitive data as defined in Article 9 of the GDPR (health, religion, political opinions, sexual orientation, etc.). <br\/>We collect only the information strictly necessary to process payments and comply with our legal obligations (anti-money laundering and counter-terrorism financing, ACPR supervision).<\/p>\n\n<p class=\"wp-block-paragraph\"><strong>Do we collect data from minors?<\/strong><\/p>\n\n<p class=\"wp-block-paragraph\">CentralPay provides its services exclusively to businesses (B2B). We therefore do not knowingly collect data from minors.<br\/>If, indirectly, a minor is required to make a payment, data processing is limited to the necessary payment information (e.g., bank or card details), and is always carried out under the responsibility of the minor\u2019s legal guardian when verification is required. <\/p>\n\n<h2 class=\"wp-block-heading\">GDPR Compliance<\/h2>\n\n<p class=\"wp-block-paragraph\"><strong>Do we conduct impact assessments (PIA)?<\/strong><\/p>\n\n<p class=\"wp-block-paragraph\">Yes, we conduct AIPDs (PIAs) for processing operations that may pose a high risk (e.g., KYC, anti-fraud\/3DS, card tokenization, longitudinal analyses). Residual risks and mitigation measures are documented. <\/p>\n\n<p class=\"wp-block-paragraph\"><strong>How do we ensure data minimization and privacy by design?<\/strong><\/p>\n\n<p class=\"wp-block-paragraph\">We collect only the fields necessary for each specific purpose, segregate environments (LIVE\/pre-production), do not use any real data in testing, limit webhook payloads to the minimum necessary, and automatically purge or anonymize data upon expiration.<\/p>\n\n<p class=\"wp-block-paragraph\"><strong>How does CentralPay document its GDPR compliance?<\/strong><\/p>\n\n<ul class=\"wp-block-list\">\n<li>Public GDPR Policy (website).<\/li>\n\n\n\n<li>Record of data processing (internal, up-to-date).<\/li>\n\n\n\n<li>PIA on High-Risk Processing (Internal).<\/li>\n\n\n\n<li>Policies\/procedures (security, data deletion, incidents, rights).<\/li>\n\n\n\n<li>Internal Control Reports (ACPR).<\/li>\n<\/ul>\n\n<h2 class=\"wp-block-heading\">Subcontractors<\/h2>\n\n<p class=\"wp-block-paragraph\"><strong>How do we supervise our service providers?<\/strong><\/p>\n\n<p class=\"wp-block-paragraph\">Each service provider is subject to contractual requirements (Art. 28): security measures, confidentiality, incident reporting, auditability, data location, and controlled sub-contracting. Initial due diligence + regular reassessment (security, SLA, compliance). <\/p>\n\n<p class=\"wp-block-paragraph\"><strong>Which service providers do we use?<\/strong><\/p>\n\n<p class=\"wp-block-paragraph\">Upon request and after signing an NDA, we can provide an up-to-date list of our service providers, organized by category (hosting\/cloud, KYC, email\/SMS delivery, fraud prevention, support), along with their geographic locations.<\/p>\n\n<p class=\"wp-block-paragraph\"><strong>How do we select our key service providers?<\/strong><\/p>\n\n<p class=\"wp-block-paragraph\">CentralPay has a policy for managing subcontractors that complies with both the GDPR (Article 28) and the DORA Regulation.<\/p>\n\n<p class=\"wp-block-paragraph\">During the selection process, we conduct a thorough due diligence review covering security (certifications, technical measures), regulatory compliance (GDPR, PSD2, AML\/CFT), data location and legal framework, the service provider\u2019s financial stability, and the service levels (SLAs) offered. For critical service providers, we examine in particular their integration into the payment services value chain and their role in ensuring operational resilience. <\/p>\n\n<p class=\"wp-block-paragraph\">Each contractual relationship includes clauses that comply with Article 28 of the GDPR (confidentiality, security, incident notification, and restrictions on cascading subcontracting) as well as, where applicable, Standard Contractual Clauses (SCCs) to govern transfers outside the European Union.<\/p>\n\n<p class=\"wp-block-paragraph\">In accordance with DORA, we maintain a registry of ICT service providers and identify those considered critical service providers. These service providers are subject to enhanced evaluation, with specific contractual requirements regarding availability, integrity, continuity, and resilience testing. <\/p>\n\n<p class=\"wp-block-paragraph\">Monitoring is conducted through regular reviews (inspections, audit reports, SOC\/ISO-type compliance certifications, security questionnaires), a contractual right to audit, and periodic reporting mechanisms. We perform integration of these assessments into our ICT risk mapping and our DORA monitoring committees. <\/p>\n\n<h2 class=\"wp-block-heading\">Security and Resilience<\/h2>\n\n<p class=\"wp-block-paragraph\"><strong>What technical safeguards do we use?<\/strong><\/p>\n\n<p class=\"wp-block-paragraph\">CentralPay protects data and systems by combining robust technical mechanisms that comply with the highest international standards.<br\/>Communications are secured through systematic encryption: TLS 1.2\/1.3 for data in transit and AES-256 for data at rest, with centralized key management.<br\/>Card data is processed exclusively in a PCI DSS Level 1 environment, with data collection in a dedicated area and irreversible tokenization to prevent any exposure of the full PAN.<br\/>Access to the systems is controlled by RBAC (role-based access control) mechanisms and protected by strong authentication (MFA), with regular reviews of access privileges.<br\/>All sensitive actions are logged with a timestamp and cannot be tampered with; this logging is integrated into an SIEM system that provides real-time detection and alerts.<br\/>The infrastructure is compartmentalized: network segmentation, strict separation of environments (production, testing, pre-production), and secure management of secrets.<br\/>Finally, CentralPay regularly tests its system through penetration tests, vulnerability scans, and independent external audits.<\/p>\n\n<p class=\"wp-block-paragraph\"><strong>How does our organization ensure safety<\/strong>?<\/p>\n\n<p class=\"wp-block-paragraph\">Security relies not only on technology but also on strong organization and governance.<br\/>CentralPay implements a risk management framework that includes detailed risk mapping, key performance indicators (KPIs), and a risk appetite policy approved by management.<br\/>Oversight is based on the recognized three lines of defense model: operations provide first-line controls, an independent compliance and ongoing monitoring function serves as the second line, and internal audit constitutes the third line.<br\/>A Security and Compliance Committee meets regularly to steer strategy and update key policies and procedures (access management, incident response, data purges, and the exercise of GDPR rights).<br\/>Finally, the security culture is reinforced through regular training for teams, covering cybersecurity, personal data protection, and AML\/CFT obligations.<\/p>\n\n<p class=\"wp-block-paragraph\"><strong>What should we do in the event of a security incident?<\/strong><\/p>\n\n<p class=\"wp-block-paragraph\">CentralPay has a formalized incident management procedure.<br\/>In the event of an incident, we quickly detect, assess, and immediately contain it, followed by remedial actions.<br\/>All events are fully logged and investigated (forensically) to identify the cause and prevent recurrence.<br\/>When required by regulation, we notify the CNIL within a maximum of 72 hours and inform the affected individuals in the event of a high-risk incident.<br\/>Each incident results in a lessons-learned review and the implementation of a corrective action plan, which is monitored until the issue is fully resolved.<\/p>\n\n<p class=\"wp-block-paragraph\"><strong>Our Security Audits<\/strong><\/p>\n\n<p class=\"wp-block-paragraph\">CentralPay is subject to multiple levels of security controls and testing, both internal and external:<\/p>\n\n<ul class=\"wp-block-list\">\n<li>Regular external audits:\n<ul class=\"wp-block-list\">\n<li>Annual PCI DSS Level 1 certification for the collection and processing of payment data,<\/li>\n\n\n\n<li>Independent cybersecurity audits,<\/li>\n\n\n\n<li>Penetration tests conducted by third-party service providers to identify and fix vulnerabilities.<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li>Ongoing internal controls (second line of defense): security clearance reviews, vulnerability scans, and monitoring of critical systems.<\/li>\n\n\n\n<li>Periodic independent audits (third line of defense): internal and external audits of the security framework and regulatory compliance (ACPR, DORA).<\/li>\n\n\n\n<li>Annual Policy Review: All of our policies regarding security, data purging, incidents, and vendor management are reviewed and approved annually by management.<\/li>\n\n\n\n<li>Resilience testing in accordance with DORA:\n<ul class=\"wp-block-list\">\n<li>Business Continuity and Disaster Recovery Plans (BCP\/DRP) that are regularly tested to verify the ability to maintain services in the event of a major incident,<\/li>\n\n\n\n<li>Crisis exercises simulating cyberattack scenarios or critical system outages,<\/li>\n\n\n\n<li>Load and performance testing of critical infrastructure,<\/li>\n\n\n\n<li>Failover and redundancy scenarios across environments to ensure availability,<\/li>\n\n\n\n<li>For critical functions, a gradual shift toward advanced resilience tests such as \u201cTLPT\u201d (Threat-Led Penetration Testing), as required by DORA for significant entities.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n<h2 class=\"wp-block-heading\">Human Rights<\/h2>\n\n<p class=\"wp-block-paragraph\"><strong>What are your rights, and how can you exercise them?<\/strong><\/p>\n\n<p class=\"wp-block-paragraph\">Pursuant to Articles 15 through 22 of the GDPR, you have the following rights regarding your personal data:<\/p>\n\n<ul class=\"wp-block-list\">\n<li>right of access,<\/li>\n\n\n\n<li>right to correction,<\/li>\n\n\n\n<li>right to erasure,<\/li>\n\n\n\n<li>right to restriction,<\/li>\n\n\n\n<li>right to object,<\/li>\n\n\n\n<li>right to data portability,<\/li>\n\n\n\n<li>right to withdraw consent.<\/li>\n<\/ul>\n\n<p class=\"wp-block-paragraph\">You can exercise your rights by sending a request to: dpo@centralpay.com.<br\/>We are committed to responding to you within a maximum of 30 days, except in exceptional cases that warrant an extension. If you encounter any difficulties, you may also file a complaint with the CNIL. <\/p>\n\n<p class=\"wp-block-paragraph\"><strong>How do we balance data erasure with legal obligations?<\/strong><\/p>\n\n<p class=\"wp-block-paragraph\">CentralPay respects the right to erasure as provided for by the GDPR, but certain data must be retained due to legal obligations.<br\/>We delete or anonymize all personal data that is no longer necessary.<br\/>However, when the law requires us to retain certain information (for example, accounting records for 10 years or KYC data for 5 years after the end of the relationship), this data is retained, but:<\/p>\n\n<ul class=\"wp-block-list\">\n<li>access to them is strictly limited,<\/li>\n\n\n\n<li>They are used only for purposes required by law (ACPR audits, TRACFIN, evidentiary obligations).<\/li>\n<\/ul>\n\n<p class=\"wp-block-paragraph\">In this way, we strike a balance between respecting people&#8217;s rights and meeting our regulatory obligations.<\/p>\n\n<h2 class=\"wp-block-heading\">Other Coverages<\/h2>\n\n<p class=\"wp-block-paragraph\"><strong>Do we use automated decisions or profiling?<\/strong><\/p>\n\n<p class=\"wp-block-paragraph\">CentralPay does not apply any fully automated decisions that produce legal or significant effects on individuals, as defined in Article 22 of the GDPR.<br\/>However, we do use anti-fraud scoring tools that calculate a risk level for transactions. These results are used solely as a decision-making aid: when a case is sensitive or high-risk, it is systematically reviewed and validated by a human reviewer. <\/p>\n\n<p class=\"wp-block-paragraph\"><strong>Do we use cookies or trackers for advertising purposes?<\/strong><\/p>\n\n<p class=\"wp-block-paragraph\">In payment flows and APIs, CentralPay does not use any advertising cookies or marketing trackers. Only cookies or trackers that are strictly necessary for the technical operation and security of the payment flows (e.g., session management, authentication) may be used. <br\/>At this point, no banner-based consent mechanism is necessary, since we do not use optional cookies.<\/p>\n\n<p class=\"wp-block-paragraph\"><strong>How do we ensure resilience and backups?<\/strong><\/p>\n\n<p class=\"wp-block-paragraph\">Yes. The infrastructure is redundant across two data centers located in France; backups are encrypted and stored off-site, tested regularly (restores), and are subject to the same access controls as the production environment. <\/p>\n\n<p class=\"wp-block-paragraph\"><strong>Do we have a documented policy for data purging and anonymization?<\/strong><\/p>\n\n<p class=\"wp-block-paragraph\">Yes, with retention periods by category (transactions\/personal data: 24 months; cards: up to 24 months after the expiration date; KYC: 5 years after the relationship ends, power of attorney: 10 years, logs: 24 months) and mechanisms (deletion vs. irreversible anonymization), plus records of data purging (execution logs).<\/p>\n\n<p class=\"wp-block-paragraph\"><strong>Do our test environments contain real data?<\/strong><\/p>\n\n<p class=\"wp-block-paragraph\">CentralPay never uses actual personal data in its test or pre-production environments. All of our internal datasets (e.g., cards, IBANs, Customer Profiles) are synthetic or fictitious and comply with PCI DSS standards. <\/p>\n\n<p class=\"wp-block-paragraph\">However, users of our test environments (e.g., Merchant integrators) can technically enter their own data. This practice is strictly prohibited and governed by our Terms of Use. <\/p>\n\n<p class=\"wp-block-paragraph\">If a user accidentally enters personal data into a test environment, that data:<\/p>\n\n<ul class=\"wp-block-list\">\n<li>are not used for actual payment processing,<\/li>\n\n\n\n<li>are not replicated in production,<\/li>\n\n\n\n<li>and are automatically or manually purged as soon as they are detected.<\/li>\n<\/ul>\n\n<p class=\"wp-block-paragraph\"><strong>How does CentralPay manage support teams&#8217; access to data?<\/strong><\/p>\n\n<p class=\"wp-block-paragraph\">CentralPay\u2019s support teams do not have direct, permanent access to personal data. Access is granted only when necessary for operational purposes (for example, to resolve an incident or assist a customer), and in accordance with the following principles: <\/p>\n\n<ul class=\"wp-block-list\">\n<li>Temporary and Justified Access: Each access request is granted for a limited period and must be supported by a ticket or an approved request.<\/li>\n\n\n\n<li>Principle of least privilege: The support agent sees only the data strictly necessary to process the request.<\/li>\n\n\n\n<li>Strong Authentication (MFA): All access is secured through multi-factor authentication.<\/li>\n\n\n\n<li>Full traceability: Every action performed by a support team member is logged and audited.<\/li>\n\n\n\n<li>Regular review of access permissions: Access rights are reviewed monthly to ensure they remain justified.<\/li>\n\n\n\n<li>Masking of Sensitive Data: Sensitive fields (e.g., full card number, CVV, full IBAN) are systematically masked in the interfaces so that support staff can never view them in plain text.<\/li>\n<\/ul>\n\n<p class=\"wp-block-paragraph\"><strong>Do we provide your customers with specific GDPR-compliant contract terms?<\/strong><\/p>\n\n<p class=\"wp-block-paragraph\">Our Terms of Service and contracts include the necessary provisions (confidentiality, security, incident response, subcontracting, data retention and deletion). GDPR addenda may be included depending on the specific use case. <\/p>\n\n<p class=\"wp-block-paragraph\"><strong>Do we share our internal policies and procedures?<\/strong><\/p>\n\n<p class=\"wp-block-paragraph\">The public GDPR policy is available online. Detailed internal policies (incident response, data retention, security) are not shared by default. <\/p>\n","protected":false},"excerpt":{"rendered":"<p>Governance and Responsibilities Data Controller and DPO Contact CentralPay, an Electronic money Institution (EMI), is the data controller for its payment services.DPO contact: dpo@centralpay.com (response within 30 days). Data Collected What data do we collect? As part of the provision of its payment services and in order to comply with its legal obligations, CentralPay collects [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":0,"parent":16722,"menu_order":5,"comment_status":"open","ping_status":"closed","template":"","doc_tag":[],"doc_badge":[154],"class_list":["post-16726","docs","type-docs","status-publish","hentry","doc_badge-gdpr","no-post-thumbnail"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>FAQ - Privacy Policy - CentralPay Documentation<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/docs.centralpay.com\/en\/documentation\/general-information\/trust-center\/privacy-policy\/faq-privacy-policy\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"FAQ - Privacy Policy - CentralPay Documentation\" \/>\n<meta property=\"og:description\" content=\"Governance and Responsibilities Data Controller and DPO Contact CentralPay, an Electronic money Institution (EMI), is the data controller for its payment services.DPO contact: dpo@centralpay.com (response within 30 days). Data Collected What data do we collect? As part of the provision of its payment services and in order to comply with its legal obligations, CentralPay collects [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/docs.centralpay.com\/en\/documentation\/general-information\/trust-center\/privacy-policy\/faq-privacy-policy\/\" \/>\n<meta property=\"og:site_name\" content=\"CentralPay Documentation\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-03T07:22:21+00:00\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"15 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/docs.centralpay.com\\\/en\\\/documentation\\\/general-information\\\/trust-center\\\/privacy-policy\\\/faq-privacy-policy\\\/\",\"url\":\"https:\\\/\\\/docs.centralpay.com\\\/en\\\/documentation\\\/general-information\\\/trust-center\\\/privacy-policy\\\/faq-privacy-policy\\\/\",\"name\":\"FAQ - Privacy Policy - CentralPay Documentation\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/docs.centralpay.com\\\/en\\\/#website\"},\"datePublished\":\"2025-10-02T08:00:32+00:00\",\"dateModified\":\"2026-09-03T07:22:21+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/docs.centralpay.com\\\/en\\\/documentation\\\/general-information\\\/trust-center\\\/privacy-policy\\\/faq-privacy-policy\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/docs.centralpay.com\\\/en\\\/documentation\\\/general-information\\\/trust-center\\\/privacy-policy\\\/faq-privacy-policy\\\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/docs.centralpay.com\\\/en\\\/documentation\\\/general-information\\\/trust-center\\\/privacy-policy\\\/faq-privacy-policy\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Accueil\",\"item\":\"https:\\\/\\\/docs.centralpay.com\\\/en\\\/home\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"General information\",\"item\":\"https:\\\/\\\/docs.centralpay.com\\\/en\\\/documentation\\\/general-information\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Trust Center\",\"item\":\"https:\\\/\\\/docs.centralpay.com\\\/en\\\/documentation\\\/general-information\\\/trust-center\\\/\"},{\"@type\":\"ListItem\",\"position\":4,\"name\":\"Privacy Policy\",\"item\":\"https:\\\/\\\/docs.centralpay.com\\\/en\\\/documentation\\\/general-information\\\/trust-center\\\/privacy-policy\\\/\"},{\"@type\":\"ListItem\",\"position\":5,\"name\":\"FAQ &#8211; Privacy Policy\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/docs.centralpay.com\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/docs.centralpay.com\\\/en\\\/\",\"name\":\"CentralPay Documentation\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/docs.centralpay.com\\\/en\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/docs.centralpay.com\\\/en\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/docs.centralpay.com\\\/en\\\/#organization\",\"name\":\"CentralPay Documentation\",\"url\":\"https:\\\/\\\/docs.centralpay.com\\\/en\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/docs.centralpay.com\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/docs.centralpay.com\\\/wp-content\\\/uploads\\\/2023\\\/07\\\/logo-centralpay-2023.png\",\"contentUrl\":\"https:\\\/\\\/docs.centralpay.com\\\/wp-content\\\/uploads\\\/2023\\\/07\\\/logo-centralpay-2023.png\",\"width\":2382,\"height\":370,\"caption\":\"CentralPay Documentation\"},\"image\":{\"@id\":\"https:\\\/\\\/docs.centralpay.com\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"FAQ - Privacy Policy - CentralPay Documentation","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/docs.centralpay.com\/en\/documentation\/general-information\/trust-center\/privacy-policy\/faq-privacy-policy\/","og_locale":"en_US","og_type":"article","og_title":"FAQ - Privacy Policy - CentralPay Documentation","og_description":"Governance and Responsibilities Data Controller and DPO Contact CentralPay, an Electronic money Institution (EMI), is the data controller for its payment services.DPO contact: dpo@centralpay.com (response within 30 days). Data Collected What data do we collect? As part of the provision of its payment services and in order to comply with its legal obligations, CentralPay collects [&hellip;]","og_url":"https:\/\/docs.centralpay.com\/en\/documentation\/general-information\/trust-center\/privacy-policy\/faq-privacy-policy\/","og_site_name":"CentralPay Documentation","article_modified_time":"2026-09-03T07:22:21+00:00","twitter_card":"summary_large_image","twitter_misc":{"Est. reading time":"15 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/docs.centralpay.com\/en\/documentation\/general-information\/trust-center\/privacy-policy\/faq-privacy-policy\/","url":"https:\/\/docs.centralpay.com\/en\/documentation\/general-information\/trust-center\/privacy-policy\/faq-privacy-policy\/","name":"FAQ - Privacy Policy - CentralPay Documentation","isPartOf":{"@id":"https:\/\/docs.centralpay.com\/en\/#website"},"datePublished":"2025-10-02T08:00:32+00:00","dateModified":"2026-09-03T07:22:21+00:00","breadcrumb":{"@id":"https:\/\/docs.centralpay.com\/en\/documentation\/general-information\/trust-center\/privacy-policy\/faq-privacy-policy\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/docs.centralpay.com\/en\/documentation\/general-information\/trust-center\/privacy-policy\/faq-privacy-policy\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/docs.centralpay.com\/en\/documentation\/general-information\/trust-center\/privacy-policy\/faq-privacy-policy\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Accueil","item":"https:\/\/docs.centralpay.com\/en\/home\/"},{"@type":"ListItem","position":2,"name":"General information","item":"https:\/\/docs.centralpay.com\/en\/documentation\/general-information\/"},{"@type":"ListItem","position":3,"name":"Trust Center","item":"https:\/\/docs.centralpay.com\/en\/documentation\/general-information\/trust-center\/"},{"@type":"ListItem","position":4,"name":"Privacy Policy","item":"https:\/\/docs.centralpay.com\/en\/documentation\/general-information\/trust-center\/privacy-policy\/"},{"@type":"ListItem","position":5,"name":"FAQ &#8211; Privacy Policy"}]},{"@type":"WebSite","@id":"https:\/\/docs.centralpay.com\/en\/#website","url":"https:\/\/docs.centralpay.com\/en\/","name":"CentralPay Documentation","description":"","publisher":{"@id":"https:\/\/docs.centralpay.com\/en\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/docs.centralpay.com\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/docs.centralpay.com\/en\/#organization","name":"CentralPay Documentation","url":"https:\/\/docs.centralpay.com\/en\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/docs.centralpay.com\/en\/#\/schema\/logo\/image\/","url":"https:\/\/docs.centralpay.com\/wp-content\/uploads\/2023\/07\/logo-centralpay-2023.png","contentUrl":"https:\/\/docs.centralpay.com\/wp-content\/uploads\/2023\/07\/logo-centralpay-2023.png","width":2382,"height":370,"caption":"CentralPay Documentation"},"image":{"@id":"https:\/\/docs.centralpay.com\/en\/#\/schema\/logo\/image\/"}}]}},"author_avatar":"https:\/\/secure.gravatar.com\/avatar\/f26ba73d1afc0520e4b1044ff088c0eda58eeaf8c325f16e76f4f944099091cc?s=96&d=mm&r=g","author_name":"Victor","_links":{"self":[{"href":"https:\/\/docs.centralpay.com\/en\/wp-json\/wp\/v2\/docs\/16726","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/docs.centralpay.com\/en\/wp-json\/wp\/v2\/docs"}],"about":[{"href":"https:\/\/docs.centralpay.com\/en\/wp-json\/wp\/v2\/types\/docs"}],"author":[{"embeddable":true,"href":"https:\/\/docs.centralpay.com\/en\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/docs.centralpay.com\/en\/wp-json\/wp\/v2\/comments?post=16726"}],"version-history":[{"count":1,"href":"https:\/\/docs.centralpay.com\/en\/wp-json\/wp\/v2\/docs\/16726\/revisions"}],"predecessor-version":[{"id":16727,"href":"https:\/\/docs.centralpay.com\/en\/wp-json\/wp\/v2\/docs\/16726\/revisions\/16727"}],"up":[{"embeddable":true,"href":"https:\/\/docs.centralpay.com\/en\/wp-json\/wp\/v2\/docs\/16722"}],"wp:attachment":[{"href":"https:\/\/docs.centralpay.com\/en\/wp-json\/wp\/v2\/media?parent=16726"}],"wp:term":[{"taxonomy":"doc_tag","embeddable":true,"href":"https:\/\/docs.centralpay.com\/en\/wp-json\/wp\/v2\/doc_tag?post=16726"},{"taxonomy":"doc_badge","embeddable":true,"href":"https:\/\/docs.centralpay.com\/en\/wp-json\/wp\/v2\/doc_badge?post=16726"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}