Nuvei Accounts - Política de Privacidade
AVISO DE PRIVACIDADE
UAB Nuvei
Última revisão: 7 de fevereiro de 2023
- Quem somos nós?
A UAB Nuvei (Lituânia) ("Nuvei", "Empresa", "nós" ou "nos") respeita a privacidade dos usuários de nossa plataforma de processamento de pagamentos (a "Plataforma"), serviços bancários, bem como dos usuários de nossos sites disponíveis em: accounts.nuvei.com, e está comprometida em proteger os Dados Pessoais que os usuários compartilham conosco em relação ao uso de nossa Plataforma, serviços bancários e/ou Site (coletivamente - o "Serviço").
Nesta política de privacidade da Empresa (a "Política de Privacidade"), você ou Titular dos Dados significa qualquer pessoa cujos Dados Pessoais são processados por nós e o termo "Dados Pessoais" significa qualquer informação ou conjunto de informações pelo qual podemos identificá-lo direta ou indiretamente, como seu nome, endereço de e-mail, número de telefone, etc. Processamos os Dados Pessoais de acordo com as disposições do Regulamento Geral sobre a Proteção de Dados nº 2016/679 (UE) (o "GDPR"), os requisitos dos atos legais aplicáveis, bem como as instruções das autoridades ou a regulamentação interna.
Esta Política de Privacidade tem como objetivo descrever nossas práticas em relação às informações que coletamos de você quando visita nosso Site ("Visitantes do Site"), quando usa nosso Serviço ou qualquer parte dele ("Usuário"), inclusive por meio do site de uma bolsa de criptomoedas ou plataforma de negociação que transporta o Serviço ("Bolsa"), ou quando se registra como cliente ("Cliente"), quando visita nossa conta de mídia social no Facebook, Twitter, LinkedIn e Medium (as "Contas Sociais"), bem como as maneiras pelas quais usamos seus Dados Pessoais e as opções e direitos disponíveis para você.
Se você se registrar ou usar nossos Serviços nos EUA, o controlador dos seus Dados Pessoais (ou seu equivalente, conforme definido nas leis de proteção de dados aplicáveis) será a SimplexCC (US), Inc. Se você se registrar ou usar nossos serviços em outro lugar, os controladores de seus dados pessoais serão a UAB Nuvei e seus dados pessoais não serão compartilhados com a entidade dos EUA - SimplexCC (US). A SimplexCC Ltd. e a UAB Nuvei, enquanto processam os seus dados pessoais, agem como controladores conjuntos ou, às vezes, as entidades acima têm uma relação controlador-processador. A SimplexCC (US) compartilha dados de cidadãos dos EUA com a SimplexCC Ltd. e a UAB Nuvei apenas na relação controlador-processador (a SimplexCC (US) atua como controladora, enquanto a SimplexCC Ltd. e a UAB Nuvei - como processadoras). Além disso, a UAB Nuvei é uma subsidiária do grupo Nuvei (Canadá).
A Plataforma, o Site e as Contas Sociais podem conter links para sites externos, como sites de nossos parceiros, sites que promovem nosso Serviço, etc. Quando você seguir links para qualquer um desses sites, observe que esses sites e os serviços acessados por meio deles têm suas próprias políticas de privacidade separadas e que não assumimos nenhuma responsabilidade ou obrigação por essas políticas ou pela coleta de Dados Pessoais nesses sites. Antes de enviar Dados Pessoais para esses sites ou usar serviços relacionados, é importante que você analise suas políticas de privacidade.
Se você usar os Serviços, o Site, a Plataforma ou as Contas Sociais, assinar nossos boletins informativos ou entrar em contato conosco ou se dirigir a nós sobre qualquer outro assunto, presumimos que você leu e concordou com os termos desta Política de Privacidade e com as finalidades, os métodos e os procedimentos para o uso dos seus Dados Pessoais especificados nela. Se você não concordar com a Política de Privacidade, não poderá usar nossos Serviços nem interagir conosco de outra forma. Esta Política de Privacidade está sujeita a alterações, portanto, visite o Site periodicamente e leia a versão mais recente da Política de Privacidade disponível aqui. Garantimos a você que a UAB Nuvei não vende, aluga ou negocia quaisquer Dados Pessoais com terceiros para fins comerciais ou de marketing.
Esta Política de Privacidade é incorporada por esta referência e faz parte dos Termos de Uso disponíveis em nuvei.com/nuvei-accounts/terms-of-use (os "TOU"), dos Termos e Condições Gerais para a Prestação de Serviços de Pagamento e Dinheiro Eletrônico e de qualquer outro contrato ou aviso que faça referência a esta Política de Privacidade
- De quem coletamos os dados pessoais?
Esta Política de Privacidade se aplica à coleta, ao uso e à divulgação dos Dados Pessoais das seguintes categorias de indivíduos pela Empresa:
- Visitantes do site: Indivíduos que visitam nosso Site e que podem fornecer voluntariamente determinados dados de contato (como seu endereço de e-mail) para receber comunicações da Empresa ou se pré-registrar para receber nosso Serviço. Para fins de esclarecimento, o Site não inclui nenhum site de propriedade ou operado por nossos Clientes.
- Usuários: Indivíduos cujas informações processamos para:
- Fornecer o Serviço aos nossos Clientes de acordo com nossos contratos com eles; ou
- Fornecer o Serviço diretamente aos nossos Usuários por meio de uma conta de dinheiro eletrônico ou conta de serviço; isso inclui Usuários que se registram em nome de uma organização; ou
- Cumprir os objetivos regulatórios, evitar atividades ilegais e cumprir as leis aplicáveis.
- Clientes: Aqueles que se registram por conta própria ou em nome de uma entidade ou organização para usar o Serviço da Empresa, incluindo comerciantes e operadores das Bolsas. Para evitar dúvidas, Clientes não incluem Usuários.
- Outras pessoas, inclusive as que assinam materiais de marketing direto, candidatam-se a várias vagas de emprego oferecidas por nós, atuam como representantes de nossos parceiros, etc.
- Como usamos seus dados pessoais e quais princípios mantemos?
Coletamos e processamos somente os Dados Pessoais necessários para atingir as finalidades de processamento de Dados Pessoais que especificamos. Ao processar seus Dados Pessoais:
- Cumprimos os requisitos da legislação atual e aplicável, incluindo o GDPR;
- Processamos seus dados pessoais de maneira legal, justa e transparente;
- Coletamos seus Dados Pessoais para fins específicos, claramente definidos e legítimos e não os processamos de forma incompatível com esses fins, exceto na medida permitida por lei;
- Tomamos todas as medidas razoáveis para garantir que os Dados Pessoais imprecisos ou incompletos, de acordo com as finalidades para as quais são processados, sejam retificados, complementados, suspensos ou destruídos sem demora;
- Mantemos os Dados Pessoais de forma que sua identidade possa ser estabelecida por um período não superior ao necessário para as finalidades para as quais os Dados Pessoais são processados;
- Não fornecemos dados pessoais a terceiros nem os divulgamos, exceto conforme estabelecido na Política de Privacidade ou na legislação aplicável;
- Garantimos que seus Dados Pessoais sejam processados com segurança, que asseguremos medidas de segurança técnicas e organizacionais, bem como que forneçamos acesso aos Dados Pessoais somente aos nossos funcionários que precisem desse acesso devido às suas funções de trabalho.
- Como coletamos dados pessoais?
Usamos os seguintes métodos de coleta:
- Por meio do uso que você faz do Serviço e/ou das transações realizadas em conexão com o Serviço. Em outras palavras, quando você usa o Serviço, inclusive quando navega na(s) Bolsa(s), coletamos e registramos as informações relacionadas a esse uso, seja de forma independente ou com a ajuda de serviços de terceiros, conforme detalhado abaixo.
- De nossos parceiros comerciais - as Bolsas, nossos parceiros turnkey, carteiras de criptomoedas e corretores. Por exemplo, quando você retorna à Bolsa, essa Bolsa pode nos fornecer suas informações de contato (como nome, endereço e data de nascimento), bem como informações de uso relativas às suas visitas anteriores ao(s) site(s) dela (por exemplo, o saldo do Usuário, logins anteriores e transações anteriores).
- Por meio de fontes disponíveis publicamente. Por exemplo, coletamos determinadas informações sobre você por meio de suas informações de Conta(s) SN publicamente disponíveis, listas negras de cartões de crédito publicamente disponíveis e listas oficiais de contas bancárias limitadas, além de outras informações públicas on-line.
- De serviços de terceiros. Por exemplo, podemos coletar alguns dados quando usamos serviços de terceiros para fornecer nosso Serviço e evitar fraudes.
- Informações que você nos fornece. Por exemplo, coletamos os Dados Pessoais necessários para usar o Serviço que você nos fornece ao preencher o formulário de registro, o processo de integração (se você se registrar como Cliente) e/ou ao entrar em contato conosco diretamente.
- Quando seus Dados Pessoais, com o seu consentimento, são fornecidos a nós por outras pessoas, incluindo empresas que usam nossos Serviços. Por exemplo, quando essas empresas indicam seus contatos, referem-se a você como uma pessoa autorizada, etc.
A pessoa que nos fornece Dados Pessoais é responsável pela exatidão, integridade e relevância de tais Dados Pessoais, bem como pelo consentimento da pessoa cujos dados são fornecidos para nos enviar seus Dados Pessoais. Poderemos solicitar que você confirme que a pessoa tem o direito de nos fornecer Dados Pessoais (por exemplo, preenchendo formulários de ordem de serviço ou de registro). Se necessário (por exemplo, se uma pessoa nos perguntar sobre o recebimento de seus Dados Pessoais), indicaremos o provedor desses Dados Pessoais.
- Quais dados pessoais estamos processando?
Processamos seus dados pessoais para as seguintes finalidades e sob as seguintes condições:
Finalidade do processamento de dados pessoais
Dados pessoais que estão sendo processados
Período de processamento de dados pessoais
Base legal para o processamento de dados pessoais
Registration, use of account, user identification, provision of Service (individuals)
Name, surname, username, e-mail, password, phone number, , personal identity code, date of birth, country of birth, address, address for correspondence, nationality, citizenship, gender, passport/ID card copy and its details (e. g. type, number, issuance place and date, expiry date, MRZ code, signature), selfies, IP address, device geographical location, KYC questionnaire, details of user’s bank accounts and payments, Service and account usage history, monetary operations, information on sources of income, tax data, Wallet ID, information about the Services ordered and used and changes therein, data on PEP’s, other information required by law.
Personal data collected for the implementation of the obligations under the Law on Money Laundering and Terrorist Financing Prevention shall be stored in accordance with the Law on Prevention of Money Laundering and Terrorist Financing of the Republic of Lithuania up to 8 (eight) years as of the transaction/termination of the Company's relationship with the user. The retention period may be extended for a period not exceeding 2 (two) years, provided there is a reasoned request from a competent authority.
–
Data processing is necessary for the conclusion and performance of the contract (Article 6(1)(b) GDPR)
Consent of the data subject to the processing of such data (Article 6(1)(a) GDPR)
Legitimate interests of the data controller or a third party (Article 6(1)(f) GDPR)
Registration, use of account, user identification, provision of Service (corporate)
Name, former name (if changed), trading name or doing business as, name and surname of representative of the customer (if any), names and surnames of all directors of the customer, including board members, supervisory council, names and surnames of ultimate beneficial owners of the customer (if any), names and surnames of persons with access right to the customer’s account at the Company, titles of general and limited partners (in case of partnerships), names, surnames, titles of main partners, citizenship, date of birth, declaration on connection with politically exposed persons of all above mentioned persons, gender of all natural persons, business registration address, business operational address, registration number, incorporation date, extract of registration and its date of issue, company’s status, proof of address for each UBO and customer’s representative (who acts under PoA), ID/Passport of UBO and representative persons and authorized persons to account, records of remote identification and verification of legal entity’s representative, records of remote identification and verification of legal entity’s persons who have access to its account, power of attorney (if applicable), representatives personal code (if applicable); e-mail; phone number and residence address.
Information obtained via KYC questionnaire: number of employees, main business activities, business activities countries, authorized capital, last year turnover, planned turnover for next year, purpose of intended business relationship, source of incoming funds, anticipated monthly turnover, anticipated monthly count of transactions, any other document/ information on ad hoc basis.
Personal data collected for the implementation of the obligations under the Law on Money Laundering and Terrorist Financing Prevention shall be stored in accordance with the Law on Prevention of Money Laundering and Terrorist Financing of the Republic of Lithuania up to 8 (eight) years as of the transaction/termination of the Company's relationship with the user. The retention period may be extended for a period not exceeding 2 (two) years, provided there is a reasoned request from a competent authority.
Data processing is necessary for the conclusion and performance of the contract (Article 6(1)(b) GDPR)
Consent of the data subject to the processing of such data (Article 6(1)(a) GDPR)
Legitimate interests of the data controller or a third party (Article 6(1)(f) GDPR)
Other payments activity, Buy/Sell Crypto
Payments in fiat information: amounts and currency, external IBANs, purpose of transactions.
Payments in crypto information: amounts and currency, wallet address.
name and Surname;
Selfies, ID or passport, billing address, phone number, email address, IP address, device geographical location, credit/debit cards info: first 6 and last 4 digits, BIN country, BIN bank.
From 3 to 8 years from the date of execution of the payment transaction.
Data processing is necessary for the conclusion and performance of the contract (Article 6(1)(b) GDPR).
Legitimate interests of the data controller or a third party (risk assessment) (Article 6(1)(f) GDPR).
Branded Cards
First 4 and last 4 card digits, phone number for One Time Password, name and surname, payment history: amounts, currencies, fees, merchant name and address, linked internal account number.
8 years as of the transaction/termination of the Company's relationship with the customer.
Data processing is necessary for the conclusion and performance of the contract (Article 6(1)(b) GDPR).
Legitimate interests of the data controller or a third party (Article 6(1)(f) GDPR).
Chargeback
Name and surname, POID document, billing address, email, phone number, account number, IP address, device geographical location, wallet address, payment amount and currency, Zendesk tickets, device ID, chargeback request and other related information and proof.
The entire period of the dispute/claim and 5 years after the end of the out-of-court dispute /claim.
Data processing is necessary for the conclusion and performance of the contract (Article 6(1)(b) GDPR).
Consent of the data subject to the processing of such data (Article 6(1)(a) GDPR).
Execution of financial operations, accounting, debt management.
Name, surname, e-mail, phone number, position, place of work, address, relationship with the represented legal entity, account number, credit institution, payment information, debt information, data transferred by the company collecting the contributions and confirmations of payments.
According to the regulatory legal acts, as well as in accordance with the Index of General Document Storage Periods Approved by order No. V-100 of the Chief Archivist of the Republic of Lithuania of 9 March 2011.
When the data does not fall within the above-mentioned storage area – the period of validity of the contract/cooperation between the parties and 10 years after the end of the contract/relationship (last contact).
Data processing is necessary for the conclusion and performance of the contract (Article 6(1)(b) GDPR)
Data processing is necessary for to fulfil a legal obligation imposed on the data controller (Article 6(1)(c) GDPR)
Legitimate interests of the data controller or a third party (Article 6(1)(f) GDPR)
Evaluation and selection of candidates for the offered job.
Name, surname, e-mail, phone number, address, education and activity data, content of the CV, other information required for the selection/evaluation of the candidate or provided by the candidate.
The selection period and 3 months after the selection if the candidate's consent to the retention of data after the selection has been obtained.
When data are received not for a specific selection, they shall be stored for 3 months after the date of their receipt.
Consent of the data subject to the processing of such data (Article 6(1)(a) GDPR)
Legitimate interests of the data controller or a third party (Article 6(1)(f) GDPR)
Management of electronic information channels (Platform, Site, Social Accounts), conducting analysis of Platform to provide more relevant content, ensure functionality and security and improve quality of the Service.
IP address, data collected with the help of cookies and settings, browser used, date and time of login, mobile device model and manufacturer, mobile device operating system (iOS, Android), password, account, and Service usage information.
Data collected through the integration of Social Accounts.
Site, Platform data are stored as described in this Privacy Policy.
Site and Platform data that is not included in the cookie information is stored for a maximum of 1 year from the date of collection, unless the person revokes his/her consent (when the data are processed based on consent).
Information in Social Accounts is stored according to the conditions set by the owner of this network
Consent of the data subject to the processing of such data (Article 6(1)(a) GDPR)
Legitimate interests of the data controller or a third party (Article 6(1)(f) GDPR)
Sending news, conducting surveys, direct marketing, advertising.
Name, e-mail address, phone number, the data requested in the survey announcement/ questionnaire.
Data is processed for 1 year from the receipt of consent, unless you revoke your consent earlier.
Consent of the data subject to the processing of such data (Article 6(1)(a) GDPR).
Settlement of disputes and claims.
Name, surname, workplace address, workplace position, contact with the represented legal entity, phone number, e-mail, the content of the claim or other similar document, information/documents related to the dispute/claim.
The entire period of the dispute/claim and 5 years after the end of the out-of-court dispute /claim resolution and 10 years after the end of judicial proceedings.
Data processing is necessary for to fulfil a legal obligation imposed on the data controller (Article 6(1)(c) GDPR)
Legitimate interests of the data controller or a third party (Article 6(1)(f) GDPR)
In Social Accounts we can share information about ourselves, our content, events, news, surveys, as well as information about the employees we are looking for. Social accounts users are also subject to the privacy policies of the social networks owners. When you contact us on Social Accounts, depending on the privacy settings you choose, we may see certain user account information such as profile first name, surname, image, sex, e-mail address, location, etc. (the list is not exhaustive). If a user posts information by communicating with us on our Social Accounts (e. g. posts a comment in the comments section of our Social Account or posts a message on our Social Account profile), depending on the privacy settings chosen, the posted information may be made public (for example, visible on our Social Account to other users).
In some cases, we may send messages related to the ordering or provision of our Service through the contact data provided by you, for example, to inform you about the confirmation of the order for Services, the expiration date of the ordered Service, temporary or permanent changes to the Service, including, but not limited to, planned outages, new features offered, version updates, point releases, major releases, abuse warnings, and changes to our TOU, Privacy Policy and other documents and agreements. Such communications are necessary for the proper provision of our contractual obligations and Service and are not considered to be direct marketing communications.
When providing our Services, we may, in certain cases, apply automated data decision-making, for example to prevent fraud, to ensure compliance with AML/CTF policies, etc. Automated decision-making refers to the processing of Personal Data using, for example, a software code or algorithm that does not require human intervention. We regularly review the criteria and models used in automated decision-making to ensure their integrity, efficiency, and impartiality. You may always ask for a revision of such automated decisions as it is indicated in the section 11 of this Privacy Policy.
We may, in certain cases, process Personal Data longer than indicated in this Privacy Policy, e. g. when we are required to do so by law, when we are engaged in litigation, arbitration, pre-trial investigation, etc. Company assures that in such cases your Personal Data will be deleted immediately as soon as it becomes unnecessary for such purposes.
- Do we share your Personal Data?
Also, we might share your personal data with parent company (Nuvei group). However, we undertake to do so only according to this Privacy Policy. Such transfers may only take place if we will sign EU standard contractual clauses approved by the European Commission, have other legal basis for such transfer or anonymize your personal data.
Our business partners, suppliers, sub-contractors, or agents who perform services for it, or consultants such as auditors, lawyers, tax advisors, analytics and search engine providers that assist us in the improvement and optimization of the Platform, etc., as well as the Personal Data Processors we use, such as ancillary service providers, IT companies, advertising and marketing companies, accounting companies, etc. We require data processors to store, process and treat Personal Data as responsibly as we do and only in accordance with our instructions. We have such partners and data processors:
Marketing, Advertising Partners – TrustPilot (Denmark);
Payment partners – PAYBIS (UK), PAYBIS US (ZEROHASH), ELASTUM (LT, EE), H FINANCE (LT) (data is securely transmitted when the service provider signs EU standard contractual clauses approved by the European Commission for the transfer of data outside the European Economic Area)
Accounting, financial services – Hashavim, PWC Israel, Billbeez, Altshuler Shaham Benefits, Howden, Priority, Jonathan Lubik consultants \ Econpartners, IBI trustee, Financial immunities, Michpal, Made Finance, Liram, OvdimNet Ayalon, Kna'an, Hi Bob (USA), RMR Consultants, Sima Kedem Ltd, Yoram Zilberman insurance agency, Baker Tilly Baltics (LT), UAB Scandinavian Accounting and Consulting (LT), SIA Ernst & Young Baltic (LV), MK TAX, Cogency Global, Mazars (data is securely transmitted when the service provider signs EU standard contractual clauses approved by the European Commission for the transfer of data outside the European Economic Area);
IT solutions, IT security maintenance and technical services – 7CI (Israel), Ingenie (UK) Kyte Consultants Ltd (Malta) (data is securely transmitted when the service provider signs EU standard contractual clauses approved by the European Commission for the transfer of data outside the European Economic Area).
Cloud and hosting providers - Amazon Web Services, Inc. (USA) Google, Inc. (USA) (data is securely transmitted when the service provider signs EU standard contractual clauses approved by the European Commission for the transfer of data outside the European Economic Area).
To publish your content to Social Accounts, we provide data to these social media platform operators:
LinkedIn Ireland Unlimited Company (Ireland), LinkedIn Corporation (Ireland), Facebook Ireland Ltd. (Ireland), Facebook, Inc. (USA), YouTube, Inc. (USA), Twitter, Inc. (USA), Twitter International Company (Ireland), A Medium Corporation (USA) (data is securely transmitted when the service provider signs EU standard contractual clauses approved by the European Commission for the transfer of data outside the European Economic Area).
State or local government institutions and authorities, law enforcement and pre-trial investigation institutions, courts and other dispute resolution institutions, other persons performing functions assigned by law, in accordance with the procedure provided for by legislation of the Republic of Lithuania. We provide these entities with mandatory information required by law or specified by the entities themselves.
Other third parties, such as payment institutions, etc. If necessary, to companies that intend to buy or would buy the Company's business or would conduct joint activities with us or would cooperate in another form. To affiliates with whom, we are under common corporate control. In case such affiliate is established outside the EEA we will conduct such Personal Data transfer only following conditions of this Privacy Policy (e. g. will sign EU Standard Contractual Clauses Approved by the European Commission for the transfer of data outside the EEA with such Affiliate).
We normally process Personal Data within the EEA, but in some cases your Personal Data may be transferred outside the EEA. The Company will always take steps to ensure any transfer of such information to entities based outside the EEA is carefully managed to protect your rights and interests by implementing Appropriate safeguards to protect Personal Data.
Your Personal Data will only be transferred outside the EEA under the following conditions:
- Data are transferred only to our reliable partners who ensure the provision of our services to you;
- EU Standard Contractual Clauses Approved by the European Commission, which ensure the security of transfers of your Personal Data, have been signed with such partners;
- The Commission of the European Union has decided on the eligibility of the country in which our partner is established, i.e., an adequate level of security is ensured;
- You have given your consent to the transfer of your Personal Data outside the EEA; or
- A special permit of the State Data Protection Inspectorate of the Republic of Lithuania was obtained to carry out such transfer.
Please note that for the purposes of identity verification and required regulatory screenings, Nuvei utilizes certain third-party identity verification and authentication services, provided by Onfido. Onfido’s collection and use of the information, which includes a copy of a government-issued ID and a photo selfie for biometric comparison, is described in Onfido’s privacy policy https://onfido.com/privacy/ .
For the purposes of complaints handling, Nuvei uses customer support platform - Zendesk Inc., to answer queries via chat, email or online ticket form. You might have to identify yourself by giving your name, surname, email address. Zendesk Inc. collection and use of the information is described in Zendesk Inc. privacy policy https://www.zendesk.com/company/agreements-and-terms/privacy-notice/.
- Minors
To use the Service, you must be over the age of eighteen (18). Company does not knowingly process Personal Data from children under the age of eighteen (18) and does not wish to do so. We reserve the right to request proof of age at any stage so that we can verify that minors under the age of eighteen (18) are not using the Service. If it comes to our knowledge that a person under the age of eighteen (18) is using the Service, we will prohibit and block such User from accessing the Service and will take appropriate measures to prevent that User from making use of our Service.
- Tracking technologies
When you access or use the Service, Site or Platform, we may use (and authorize third parties to use) industry-wide technologies such as cookies or similar technologies, including web beacons, pixel tags, scripts, tags and other technologies that store certain information on your computer (“Local Storage”) and which will allow us to enable automatic activation of certain features, and make your Service experience much more convenient and effortless (collectively “Tracking Technologies”). These Tracking Technologies allow us and third parties to automatically collect information about you (such as your IP address, device unique identifiers and your online behavior), to enhance your navigation on our Site, improve our Site’s performance and customize your experience on our Site, as well as for advertising and fraud prevention purposes. We also use this information to collect statistics about the usage of our Site, perform analytics, deliver content which is tailored to your interests.
To learn more please visit our Cookie Policy, available here:
nuvei.com/nuvei-accounts/cookies-policy.
Direct marketing
With your consent (only), we may use your Personal Data for direct marketing purposes to provide you with newsletters, offers and information about our Service, as well as to inquire about the quality of our performance.
The above content can be sent by e-mail, messages to the phone number specified by you, as well as messages in your account in the Platform or Site. Your contacts may be transferred to our partners who provide us with news sending or quality assessment services.
After sending such content, we can collect information about the people who received it, for example, which message people opened, what links they clicked on, etc. Such information is collected to offer you relevant and more tailored news and content.
Even if you have given your consent to the processing of Personal Data for direct marketing purposes, you can easily withdraw this consent for all or part of the Personal Data processing activities at any time. To do this, you can:
- notify us of your withdrawal in the manner specified in the provided message (e. g. by clicking on the “unsubscribe” link in the newsletter, etc.); or
- send us a notification in a manner specified in this Privacy Policy. If you so request withdrawal of consent, we may ask you to verify your identity.
If you withdraw your consent, we will try to stop sending such content to you immediately.
Withdrawal of consent does not automatically oblige us to destroy your Personal Data or provide you with information about the Personal Data processed by us, therefore, for these actions you should submit a separate request.
- Your rights
As a data subject, you have the following rights regarding your Personal Data:
- To know (to be informed) about the processing of your Personal Data (right to know);
- To access your Personal Data and the way they are processed (right of access);
- To request the correction or, depending on the purposes of the processing of Personal Data, supplementation of incomplete Personal Data (right to rectification);
- To request the erasure of your Personal Data or the suspension of your Personal Data processing activities (excluding storage) (right to erase and right to “be forgotten”);
- To request us to restrict the processing of Personal Data for one of the legitimate reasons (right to restrict);
- The right to transfer data (right to transfer). This right may be exercised only if there are grounds for its exercise and appropriate technical measures to ensure that the transfer of the requested Personal Data does not pose a risk of security breach to the data of other Data Subjects;
- The right to object the processing of your Personal Data when we process Personal Data based on a legitimate interest of the Company or a third party, including profiling. If you object, we will only be able to further process your Personal Data for compelling legitimate reasons that take precedence over your interests, rights, and freedoms, or to make, enforce or defend legal claims;
- Revoke your consent to the processing of your Personal Data when this data is processed or intended to be processed for direct marketing purposes, including profiling as far as such direct marketing is concerned (based on the Personal Data you provide, profiling may be carried out for direct marketing purposes to offer you individually tailored solutions and proposals. You can revoke your consent to the processing of Personal Data by automated processing, including profiling, or object to it at any time).
We may refuse to exercise your rights listed above, except for refusal to process your Personal Data for direct marketing purposes, competitions or in other cases when Personal Data is processed with your consent, when your request is allowed to us not to comply with the provision of the GDPR, or when, in cases provided for by law, it is necessary to ensure the prevention, investigation and detection of crimes, violations of official or professional ethics, as well as the protection of the rights and freedoms of the Data Subject, us and other persons, or when the Company has a legitimate interest.
You can exercise part of your rights as a Data Subject by changing the user account settings in the Platform or Site and the information contained therein. You may submit any request or instruction related to the processing of Personal Data to us in writing via Company’s internal system for handling Data Subject’s request. Please go to the UAB Nuvei Privacy Center and choose Data subject’s request options here: accounts.nuvei.com/privacy-policy.
When submitting such a request, we may ask you to fill in the necessary forms, as well as provide an identification document or other information that will help us to verify your identity, to better understand the content of your request. You may also send Data Subject’s request together with authorized personal document (ID or passport) copy to our office - Lvivo g. 37, Vilnius, LT-09306, Lithuania, however, we encourage you to submit you requests via our internal system since that channel is dedicated specifically to handle Data Subject’s requests.
Upon receipt of your request or instruction regarding the processing of Personal Data, no later than within 1 month from the date of the request, we will provide a response and perform the actions specified in the request or inform you why we refuse to perform them. If necessary, the specified period may be extended by a further 2 months, considering the complexity and number of requests. In such a case, within 1 month from the date of receipt of the request, we will inform you of such extension.
If Personal Data is deleted upon your request, we will only store copies of information that are necessary to protect our legitimate interests and those of others, to comply with the obligations of law, to resolve disputes, to recognize interference or to comply with any agreements you have entered with us. Please note that these rights are not absolute, and requests are subject to any applicable legal requirements, including legal and ethical reporting or document retention obligations (such as AML/CTF regulations).
- How do we secure your Personal Data?
We take great care in implementing and maintaining the security of the Service and safeguarding any Personal Data we process. Personal Data, trusted to us, is hosted on Amazon Web Services and Google Cloud Services, which provides advanced security features. Company employs industry standard procedures and policies to ensure the safety of the Personal Data processed and to prevent unauthorized use of any such information. In addition, to safeguard the privacy expectation of the data subjects, Nuvei is Payment Card Industry Data Security Standards (“PCI DSS”) certified. Please note that while we take reasonable measures to safeguard your Personal Data, we cannot fully guarantee its absolute security.
- Changes to this Privacy Policy
Company reserves the right to change this Privacy Policy at any time, so please re-visit this page frequently. We will provide notice of substantial changes to this Privacy Policy on the Service and/or we will send you an email regarding such changes to the e-mail address that you volunteered. Such substantial changes will take effect seven (7) days after such notice was provided on any of the above-mentioned methods. Otherwise, all other changes to this Privacy Policy are effective as of the stated “Last Revised” date, and your continued use of the Service after the Last Revised date will constitute acceptance of, and agreement to be bound by, those changes.
- Our contacts:
If you have any questions (or comments) concerning this Privacy Policy, you are welcome to contact us through the following Accounts Privacy Center, available here:
https://nuvei.com/accounts-privacy-center/.
Or
Data Protection Officer: dpo@nuvei.com.
We will try to reply within a reasonable timeframe. Please feel free to reach out to us at any time. If you are unsatisfied with our response or decision, you can reach out to the applicable data protection authority:
The State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija in Lithuanian, website available at https://vdai.lrv.lt/).
On this page
Ready to grow everywhere?
Get started with Nuvei – the growth infrastructure for every payment, everywhere. One intelligent system, built to scale.