Cuentas Nuvei - Política de privacidad
AVISO DE PRIVACIDAD
UAB Nuvei
Última revisión: 7 de febrero de 2023
- ¿Quiénes somos?
UAB Nuvei (Lituania) ("Nuvei", "Empresa", "nosotros" o "nos") respeta la privacidad de los usuarios de nuestra plataforma de procesamiento de pagos (la "Plataforma"), servicios bancarios, así como de los usuarios de nuestros sitios web disponibles en: accounts.nuvei.com, y se compromete a proteger los Datos Personales que los usuarios comparten con nosotros en relación con el uso de nuestra Plataforma, servicios bancarios y/o Sitio web (colectivamente, el "Servicio").
En esta política de privacidad de la Empresa (la "Política de Privacidad"), tú o el Sujeto de los Datos significa cualquier persona cuyos Datos Personales son procesados por nosotros y el término "DatosPersonales" significa cualquier información o conjunto de información por la que podamos identificarte directa o indirectamente, como tu nombre, dirección de correo electrónico, número de teléfono, etc. Tratamos los Datos Personales de conformidad con las disposiciones del Reglamento General de Protección de Datos nº 2016/679 (UE) (el "RGPD"), los requisitos de los actos jurídicos aplicables, así como las instrucciones de las autoridades o la normativa interna.
Esta Política de Privacidad pretende describir nuestras prácticas en relación con la información que recopilamos de ti cuando visitas nuestro Sitio ("Visitantes del Sitio"), cuando utilizas nuestro Servicio o cualquier parte del mismo ("Usuario"), incluso a través del sitio web de una bolsa de criptomonedas o de una plataforma de negociación que lleve el Servicio ("Bolsa"), o cuando te registras como cliente ("Cliente"), cuando visitas nuestra cuenta de redes sociales en Facebook, Twitter, LinkedIn y Medium (las "Cuentas Sociales"), así como las formas en que utilizamos tus Datos Personales, y las opciones y derechos de que dispones.
Si te registras o utilizas nuestros Servicios en EE.UU., el responsable del tratamiento de tus Datos Personales (o su equivalente, tal y como se define en las leyes de protección de datos aplicables) será SimplexCC (US), Inc. Si te registras o utilizas nuestros Servicios en otro lugar, los responsables del tratamiento de tus Datos Personales serán UAB Nuvei y tus Datos Personales no se compartirán con la entidad estadounidense - SimplexCC (US). SimplexCC Ltd. y UAB Nuvei, al procesar tus Datos Personales, por regla general, actúan como controladores conjuntos, o a veces las entidades mencionadas tienen una relación de controlador-procesador. SimplexCC (EE.UU.) comparte datos de ciudadanos estadounidenses con SimplexCC Ltd. y UAB Nuvei sólo en relación de controlador-procesador (SimplexCC (EE.UU.) actúa como controlador, mientras que SimplexCC Ltd. y UAB Nuvei - como procesadores). Además, UAB Nuvei es una filial del grupo Nuvei (Canadá).
La Plataforma, el Sitio y las Cuentas Sociales pueden contener enlaces a sitios web externos, como nuestros sitios web asociados, sitios web que promocionan nuestro Servicio, etc. Cuando sigas los enlaces a cualquiera de estos sitios web, ten en cuenta que estos sitios y los servicios a los que se accede a través de ellos tienen sus propias políticas de privacidad independientes y que no asumimos ninguna responsabilidad ni obligación por estas políticas ni por la recogida de Datos Personales en estos sitios. Antes de enviar Datos Personales a ellos o de utilizar servicios relacionados, es importante que revises sus políticas de privacidad.
Si utilizas los Servicios, el Sitio, la Plataforma o las Cuentas Sociales, te suscribes a nuestros boletines, o te pones en contacto con nosotros o te diriges a nosotros para cualquier otra cuestión, asumimos que has leído y aceptado los términos de esta Política de Privacidad y los fines, métodos y procedimientos para el uso de tus Datos Personales especificados en ella. Si no estás de acuerdo con la Política de Privacidad, no puedes utilizar nuestros Servicios ni interactuar de otro modo con nosotros. Esta Política de Privacidad está sujeta a cambios, por lo que te rogamos que visites el Sitio de vez en cuando y leas la última versión de la Política de Privacidad disponible en el mismo. Te aseguramos que UAB Nuvei no vende, alquila ni intercambia Datos Personales con terceros para sus fines comerciales o de marketing.
Esta Política de privacidad se incorpora por esta referencia a, y forma parte de, las Condiciones de uso disponibles en nuvei.com/nuvei-accounts/terms-of-use (las "CDU"), las Condiciones generales para la prestación de servicios de pago y dinero electrónico, y cualquier otro acuerdo o aviso que haga referencia a esta Política de privacidad.
- ¿De quién recogemos Datos Personales?
Esta Política de Privacidad se aplica a la recogida, uso y divulgación por parte de la Empresa de los Datos Personales de las siguientes categorías de individuos:
- Visitantes del Sitio: Personas que visitan nuestro Sitio y que pueden ofrecer voluntariamente ciertos datos de contacto (como su dirección de correo electrónico) para recibir comunicaciones de la Empresa o registrarse previamente para recibir nuestro Servicio. Para mayor claridad, el Sitio no incluye ningún sitio propiedad de nuestros Clientes o gestionado por ellos.
- Usuarios: Personas cuya información tratamos:
- Prestar el Servicio a nuestros Clientes en virtud de nuestros acuerdos con ellos; o
- Proporcionar el Servicio directamente a nuestros Usuarios a través de una cuenta de dinero electrónico o una cuenta de servicio; esto incluye a los Usuarios que se registren en nombre de una organización; o
- Cumplir objetivos normativos, impedir actividades ilegales y cumplir la legislación aplicable.
- Clientes: Aquellos que se registran por su cuenta o en nombre de una entidad u organización para utilizar el Servicio de la Empresa, incluidos los comerciantes y los operadores de las Bolsas. Para evitar dudas, los Clientes no incluyen a los Usuarios.
- Otras personas, incluidas las que se suscriben a materiales de marketing directo, solicitan diversos puestos de trabajo ofrecidos por nosotros, actúan como representantes de nuestros socios, etc.
- ¿Cómo utilizamos tus Datos Personales y qué principios conservamos?
Recogemos y procesamos únicamente los Datos Personales que son necesarios para lograr los fines de procesamiento de Datos Personales que hemos especificado. Al procesar tus Datos Personales:
- Cumplimos los requisitos de la legislación vigente y aplicable, incluido el GDPR;
- Procesamos tus Datos Personales de forma lícita, justa y transparente;
- Recogemos tus Datos Personales con fines específicos, claramente definidos y legítimos, y no los tratamos de forma incompatible con dichos fines, salvo en la medida en que lo permita la ley;
- Tomamos todas las medidas razonables para garantizar que los Datos Personales que sean inexactos o incompletos, de acuerdo con los fines para los que se tratan, se rectifiquen, completen, suspendan o destruyan sin demora;
- Conservamos los Datos Personales de forma que pueda establecerse tu identidad durante un período no superior al necesario para los fines para los que se tratan los Datos Personales;
- No proporcionamos Datos Personales a terceros ni los revelamos, salvo en los casos establecidos en la Política de Privacidad o en la legislación aplicable;
- Garantizamos que tus Datos Personales se procesan de forma segura, que garantizamos medidas de seguridad técnicas y organizativas, así como que proporcionamos acceso a los Datos Personales sólo a aquellos de nuestros empleados que necesitan dicho acceso debido a sus funciones laborales.
- ¿Cómo recogemos los datos personales?
Utilizamos los siguientes métodos de recogida:
- A través de tu uso del Servicio y/o de las transacciones realizadas en relación con el Servicio. En otras palabras, cuando utilizas el Servicio, incluso cuando navegas por la(s) Bolsa(s), recopilamos y registramos la información relativa a dicho uso, ya sea de forma independiente o con la ayuda de servicios de terceros, como se detalla a continuación.
- De nuestros socios comerciales: las Bolsas, nuestros socios llave en mano, carteras de criptomonedas y corredores. Por ejemplo, cuando vuelves a la Bolsa, dicha Bolsa puede proporcionarnos tu información de contacto (como nombre, dirección y fecha de nacimiento), así como información de uso relativa a tus visitas anteriores a su(s) sitio(s) web (por ejemplo, el saldo del Usuario, los inicios de sesión anteriores y las transacciones anteriores).
- A través de fuentes disponibles públicamente. Por ejemplo, recopilamos cierta información sobre ti a través de la información disponible públicamente de tu(s) Cuenta(s) SN, listas negras de tarjetas de crédito disponibles públicamente y listas oficiales de cuentas bancarias limitadas, así como otra información pública en línea.
- De servicios de terceros. Por ejemplo, podemos recoger algunos datos cuando utilizamos servicios de terceros para prestar nuestro Servicio y evitar el fraude.
- Información que nos proporcionas. Por ejemplo, recopilamos los Datos Personales necesarios para utilizar el Servicio que nos proporcionas al rellenar el formulario de registro, el proceso de incorporación (si te registras como Cliente) y/o al ponerte en contacto con nosotros directamente.
- Cuando tus Datos Personales, con tu consentimiento, nos son facilitados por otras personas, incluidas empresas que utilizan nuestros Servicios. Por ejemplo, cuando dichas empresas indican tus contactos, se refieren a ti como persona autorizada, etc.
La persona que nos proporcione Datos Personales es responsable de que dichos Datos Personales sean correctos, completos y pertinentes, así como del consentimiento de la persona cuyos datos se facilitan para enviarnos sus Datos Personales. Podemos pedirle que confirme que la persona tiene derecho a proporcionarnos Datos Personales (por ejemplo, rellenando formularios de pedido de servicios o de registro). Si es necesario (por ejemplo, si una persona nos pregunta sobre la recepción de sus Datos Personales), indicaremos el proveedor de dichos Datos Personales.
- ¿Qué datos personales tratamos?
Tratamos tus Datos Personales para los siguientes fines y en las siguientes condiciones:
Finalidad del tratamiento de los Datos Personales
Datos personales tratados
Período de tratamiento de los Datos Personales
Legal basis for the processing of Personal Data
Registration, use of account, user identification, provision of Service (individuals)
Name, surname, username, e-mail, password, phone number, , personal identity code, date of birth, country of birth, address, address for correspondence, nationality, citizenship, gender, passport/ID card copy and its details (e. g. type, number, issuance place and date, expiry date, MRZ code, signature), selfies, IP address, device geographical location, KYC questionnaire, details of user’s bank accounts and payments, Service and account usage history, monetary operations, information on sources of income, tax data, Wallet ID, information about the Services ordered and used and changes therein, data on PEP’s, other information required by law.
Personal data collected for the implementation of the obligations under the Law on Money Laundering and Terrorist Financing Prevention shall be stored in accordance with the Law on Prevention of Money Laundering and Terrorist Financing of the Republic of Lithuania up to 8 (eight) years as of the transaction/termination of the Company's relationship with the user. The retention period may be extended for a period not exceeding 2 (two) years, provided there is a reasoned request from a competent authority.
–
Data processing is necessary for the conclusion and performance of the contract (Article 6(1)(b) GDPR)
Consent of the data subject to the processing of such data (Article 6(1)(a) GDPR)
Legitimate interests of the data controller or a third party (Article 6(1)(f) GDPR)
Registration, use of account, user identification, provision of Service (corporate)
Name, former name (if changed), trading name or doing business as, name and surname of representative of the customer (if any), names and surnames of all directors of the customer, including board members, supervisory council, names and surnames of ultimate beneficial owners of the customer (if any), names and surnames of persons with access right to the customer’s account at the Company, titles of general and limited partners (in case of partnerships), names, surnames, titles of main partners, citizenship, date of birth, declaration on connection with politically exposed persons of all above mentioned persons, gender of all natural persons, business registration address, business operational address, registration number, incorporation date, extract of registration and its date of issue, company’s status, proof of address for each UBO and customer’s representative (who acts under PoA), ID/Passport of UBO and representative persons and authorized persons to account, records of remote identification and verification of legal entity’s representative, records of remote identification and verification of legal entity’s persons who have access to its account, power of attorney (if applicable), representatives personal code (if applicable); e-mail; phone number and residence address.
Information obtained via KYC questionnaire: number of employees, main business activities, business activities countries, authorized capital, last year turnover, planned turnover for next year, purpose of intended business relationship, source of incoming funds, anticipated monthly turnover, anticipated monthly count of transactions, any other document/ information on ad hoc basis.
Personal data collected for the implementation of the obligations under the Law on Money Laundering and Terrorist Financing Prevention shall be stored in accordance with the Law on Prevention of Money Laundering and Terrorist Financing of the Republic of Lithuania up to 8 (eight) years as of the transaction/termination of the Company's relationship with the user. The retention period may be extended for a period not exceeding 2 (two) years, provided there is a reasoned request from a competent authority.
Data processing is necessary for the conclusion and performance of the contract (Article 6(1)(b) GDPR)
Consent of the data subject to the processing of such data (Article 6(1)(a) GDPR)
Legitimate interests of the data controller or a third party (Article 6(1)(f) GDPR)
Other payments activity, Buy/Sell Crypto
Payments in fiat information: amounts and currency, external IBANs, purpose of transactions.
Payments in crypto information: amounts and currency, wallet address.
name and Surname;
Selfies, ID or passport, billing address, phone number, email address, IP address, device geographical location, credit/debit cards info: first 6 and last 4 digits, BIN country, BIN bank.
From 3 to 8 years from the date of execution of the payment transaction.
Data processing is necessary for the conclusion and performance of the contract (Article 6(1)(b) GDPR).
Legitimate interests of the data controller or a third party (risk assessment) (Article 6(1)(f) GDPR).
Branded Cards
First 4 and last 4 card digits, phone number for One Time Password, name and surname, payment history: amounts, currencies, fees, merchant name and address, linked internal account number.
8 years as of the transaction/termination of the Company's relationship with the customer.
Data processing is necessary for the conclusion and performance of the contract (Article 6(1)(b) GDPR).
Legitimate interests of the data controller or a third party (Article 6(1)(f) GDPR).
Chargeback
Name and surname, POID document, billing address, email, phone number, account number, IP address, device geographical location, wallet address, payment amount and currency, Zendesk tickets, device ID, chargeback request and other related information and proof.
The entire period of the dispute/claim and 5 years after the end of the out-of-court dispute /claim.
Data processing is necessary for the conclusion and performance of the contract (Article 6(1)(b) GDPR).
Consent of the data subject to the processing of such data (Article 6(1)(a) GDPR).
Execution of financial operations, accounting, debt management.
Name, surname, e-mail, phone number, position, place of work, address, relationship with the represented legal entity, account number, credit institution, payment information, debt information, data transferred by the company collecting the contributions and confirmations of payments.
According to the regulatory legal acts, as well as in accordance with the Index of General Document Storage Periods Approved by order No. V-100 of the Chief Archivist of the Republic of Lithuania of 9 March 2011.
When the data does not fall within the above-mentioned storage area – the period of validity of the contract/cooperation between the parties and 10 years after the end of the contract/relationship (last contact).
Data processing is necessary for the conclusion and performance of the contract (Article 6(1)(b) GDPR)
Data processing is necessary for to fulfil a legal obligation imposed on the data controller (Article 6(1)(c) GDPR)
Legitimate interests of the data controller or a third party (Article 6(1)(f) GDPR)
Evaluation and selection of candidates for the offered job.
Name, surname, e-mail, phone number, address, education and activity data, content of the CV, other information required for the selection/evaluation of the candidate or provided by the candidate.
The selection period and 3 months after the selection if the candidate's consent to the retention of data after the selection has been obtained.
When data are received not for a specific selection, they shall be stored for 3 months after the date of their receipt.
Consent of the data subject to the processing of such data (Article 6(1)(a) GDPR)
Legitimate interests of the data controller or a third party (Article 6(1)(f) GDPR)
Management of electronic information channels (Platform, Site, Social Accounts), conducting analysis of Platform to provide more relevant content, ensure functionality and security and improve quality of the Service.
IP address, data collected with the help of cookies and settings, browser used, date and time of login, mobile device model and manufacturer, mobile device operating system (iOS, Android), password, account, and Service usage information.
Data collected through the integration of Social Accounts.
Site, Platform data are stored as described in this Privacy Policy.
Site and Platform data that is not included in the cookie information is stored for a maximum of 1 year from the date of collection, unless the person revokes his/her consent (when the data are processed based on consent).
Information in Social Accounts is stored according to the conditions set by the owner of this network
Consent of the data subject to the processing of such data (Article 6(1)(a) GDPR)
Legitimate interests of the data controller or a third party (Article 6(1)(f) GDPR)
Sending news, conducting surveys, direct marketing, advertising.
Name, e-mail address, phone number, the data requested in the survey announcement/ questionnaire.
Data is processed for 1 year from the receipt of consent, unless you revoke your consent earlier.
Consent of the data subject to the processing of such data (Article 6(1)(a) GDPR).
Settlement of disputes and claims.
Name, surname, workplace address, workplace position, contact with the represented legal entity, phone number, e-mail, the content of the claim or other similar document, information/documents related to the dispute/claim.
The entire period of the dispute/claim and 5 years after the end of the out-of-court dispute /claim resolution and 10 years after the end of judicial proceedings.
Data processing is necessary for to fulfil a legal obligation imposed on the data controller (Article 6(1)(c) GDPR)
Legitimate interests of the data controller or a third party (Article 6(1)(f) GDPR)
In Social Accounts we can share information about ourselves, our content, events, news, surveys, as well as information about the employees we are looking for. Social accounts users are also subject to the privacy policies of the social networks owners. When you contact us on Social Accounts, depending on the privacy settings you choose, we may see certain user account information such as profile first name, surname, image, sex, e-mail address, location, etc. (the list is not exhaustive). If a user posts information by communicating with us on our Social Accounts (e. g. posts a comment in the comments section of our Social Account or posts a message on our Social Account profile), depending on the privacy settings chosen, the posted information may be made public (for example, visible on our Social Account to other users).
In some cases, we may send messages related to the ordering or provision of our Service through the contact data provided by you, for example, to inform you about the confirmation of the order for Services, the expiration date of the ordered Service, temporary or permanent changes to the Service, including, but not limited to, planned outages, new features offered, version updates, point releases, major releases, abuse warnings, and changes to our TOU, Privacy Policy and other documents and agreements. Such communications are necessary for the proper provision of our contractual obligations and Service and are not considered to be direct marketing communications.
When providing our Services, we may, in certain cases, apply automated data decision-making, for example to prevent fraud, to ensure compliance with AML/CTF policies, etc. Automated decision-making refers to the processing of Personal Data using, for example, a software code or algorithm that does not require human intervention. We regularly review the criteria and models used in automated decision-making to ensure their integrity, efficiency, and impartiality. You may always ask for a revision of such automated decisions as it is indicated in the section 11 of this Privacy Policy.
We may, in certain cases, process Personal Data longer than indicated in this Privacy Policy, e. g. when we are required to do so by law, when we are engaged in litigation, arbitration, pre-trial investigation, etc. Company assures that in such cases your Personal Data will be deleted immediately as soon as it becomes unnecessary for such purposes.
- Do we share your Personal Data?
Also, we might share your personal data with parent company (Nuvei group). However, we undertake to do so only according to this Privacy Policy. Such transfers may only take place if we will sign EU standard contractual clauses approved by the European Commission, have other legal basis for such transfer or anonymize your personal data.
Our business partners, suppliers, sub-contractors, or agents who perform services for it, or consultants such as auditors, lawyers, tax advisors, analytics and search engine providers that assist us in the improvement and optimization of the Platform, etc., as well as the Personal Data Processors we use, such as ancillary service providers, IT companies, advertising and marketing companies, accounting companies, etc. We require data processors to store, process and treat Personal Data as responsibly as we do and only in accordance with our instructions. We have such partners and data processors:
Marketing, Advertising Partners – TrustPilot (Denmark);
Payment partners – PAYBIS (UK), PAYBIS US (ZEROHASH), ELASTUM (LT, EE), H FINANCE (LT) (data is securely transmitted when the service provider signs EU standard contractual clauses approved by the European Commission for the transfer of data outside the European Economic Area)
Accounting, financial services – Hashavim, PWC Israel, Billbeez, Altshuler Shaham Benefits, Howden, Priority, Jonathan Lubik consultants \ Econpartners, IBI trustee, Financial immunities, Michpal, Made Finance, Liram, OvdimNet Ayalon, Kna'an, Hi Bob (USA), RMR Consultants, Sima Kedem Ltd, Yoram Zilberman insurance agency, Baker Tilly Baltics (LT), UAB Scandinavian Accounting and Consulting (LT), SIA Ernst & Young Baltic (LV), MK TAX, Cogency Global, Mazars (data is securely transmitted when the service provider signs EU standard contractual clauses approved by the European Commission for the transfer of data outside the European Economic Area);
IT solutions, IT security maintenance and technical services – 7CI (Israel), Ingenie (UK) Kyte Consultants Ltd (Malta) (data is securely transmitted when the service provider signs EU standard contractual clauses approved by the European Commission for the transfer of data outside the European Economic Area).
Cloud and hosting providers - Amazon Web Services, Inc. (USA) Google, Inc. (USA) (data is securely transmitted when the service provider signs EU standard contractual clauses approved by the European Commission for the transfer of data outside the European Economic Area).
To publish your content to Social Accounts, we provide data to these social media platform operators:
LinkedIn Ireland Unlimited Company (Ireland), LinkedIn Corporation (Ireland), Facebook Ireland Ltd. (Ireland), Facebook, Inc. (USA), YouTube, Inc. (USA), Twitter, Inc. (USA), Twitter International Company (Ireland), A Medium Corporation (USA) (data is securely transmitted when the service provider signs EU standard contractual clauses approved by the European Commission for the transfer of data outside the European Economic Area).
State or local government institutions and authorities, law enforcement and pre-trial investigation institutions, courts and other dispute resolution institutions, other persons performing functions assigned by law, in accordance with the procedure provided for by legislation of the Republic of Lithuania. We provide these entities with mandatory information required by law or specified by the entities themselves.
Other third parties, such as payment institutions, etc. If necessary, to companies that intend to buy or would buy the Company's business or would conduct joint activities with us or would cooperate in another form. To affiliates with whom, we are under common corporate control. In case such affiliate is established outside the EEA we will conduct such Personal Data transfer only following conditions of this Privacy Policy (e. g. will sign EU Standard Contractual Clauses Approved by the European Commission for the transfer of data outside the EEA with such Affiliate).
We normally process Personal Data within the EEA, but in some cases your Personal Data may be transferred outside the EEA. The Company will always take steps to ensure any transfer of such information to entities based outside the EEA is carefully managed to protect your rights and interests by implementing Appropriate safeguards to protect Personal Data.
Your Personal Data will only be transferred outside the EEA under the following conditions:
- Data are transferred only to our reliable partners who ensure the provision of our services to you;
- EU Standard Contractual Clauses Approved by the European Commission, which ensure the security of transfers of your Personal Data, have been signed with such partners;
- The Commission of the European Union has decided on the eligibility of the country in which our partner is established, i.e., an adequate level of security is ensured;
- You have given your consent to the transfer of your Personal Data outside the EEA; or
- A special permit of the State Data Protection Inspectorate of the Republic of Lithuania was obtained to carry out such transfer.
Please note that for the purposes of identity verification and required regulatory screenings, Nuvei utilizes certain third-party identity verification and authentication services, provided by Onfido. Onfido’s collection and use of the information, which includes a copy of a government-issued ID and a photo selfie for biometric comparison, is described in Onfido’s privacy policy https://onfido.com/privacy/ .
For the purposes of complaints handling, Nuvei uses customer support platform - Zendesk Inc., to answer queries via chat, email or online ticket form. You might have to identify yourself by giving your name, surname, email address. Zendesk Inc. collection and use of the information is described in Zendesk Inc. privacy policy https://www.zendesk.com/company/agreements-and-terms/privacy-notice/.
- Minors
To use the Service, you must be over the age of eighteen (18). Company does not knowingly process Personal Data from children under the age of eighteen (18) and does not wish to do so. We reserve the right to request proof of age at any stage so that we can verify that minors under the age of eighteen (18) are not using the Service. If it comes to our knowledge that a person under the age of eighteen (18) is using the Service, we will prohibit and block such User from accessing the Service and will take appropriate measures to prevent that User from making use of our Service.
- Tracking technologies
When you access or use the Service, Site or Platform, we may use (and authorize third parties to use) industry-wide technologies such as cookies or similar technologies, including web beacons, pixel tags, scripts, tags and other technologies that store certain information on your computer (“Local Storage”) and which will allow us to enable automatic activation of certain features, and make your Service experience much more convenient and effortless (collectively “Tracking Technologies”). These Tracking Technologies allow us and third parties to automatically collect information about you (such as your IP address, device unique identifiers and your online behavior), to enhance your navigation on our Site, improve our Site’s performance and customize your experience on our Site, as well as for advertising and fraud prevention purposes. We also use this information to collect statistics about the usage of our Site, perform analytics, deliver content which is tailored to your interests.
To learn more please visit our Cookie Policy, available here:
nuvei.com/nuvei-accounts/cookies-policy.
Direct marketing
With your consent (only), we may use your Personal Data for direct marketing purposes to provide you with newsletters, offers and information about our Service, as well as to inquire about the quality of our performance.
The above content can be sent by e-mail, messages to the phone number specified by you, as well as messages in your account in the Platform or Site. Your contacts may be transferred to our partners who provide us with news sending or quality assessment services.
After sending such content, we can collect information about the people who received it, for example, which message people opened, what links they clicked on, etc. Such information is collected to offer you relevant and more tailored news and content.
Even if you have given your consent to the processing of Personal Data for direct marketing purposes, you can easily withdraw this consent for all or part of the Personal Data processing activities at any time. To do this, you can:
- notify us of your withdrawal in the manner specified in the provided message (e. g. by clicking on the “unsubscribe” link in the newsletter, etc.); or
- send us a notification in a manner specified in this Privacy Policy. If you so request withdrawal of consent, we may ask you to verify your identity.
If you withdraw your consent, we will try to stop sending such content to you immediately.
Withdrawal of consent does not automatically oblige us to destroy your Personal Data or provide you with information about the Personal Data processed by us, therefore, for these actions you should submit a separate request.
- Your rights
As a data subject, you have the following rights regarding your Personal Data:
- To know (to be informed) about the processing of your Personal Data (right to know);
- To access your Personal Data and the way they are processed (right of access);
- To request the correction or, depending on the purposes of the processing of Personal Data, supplementation of incomplete Personal Data (right to rectification);
- To request the erasure of your Personal Data or the suspension of your Personal Data processing activities (excluding storage) (right to erase and right to “be forgotten”);
- To request us to restrict the processing of Personal Data for one of the legitimate reasons (right to restrict);
- The right to transfer data (right to transfer). This right may be exercised only if there are grounds for its exercise and appropriate technical measures to ensure that the transfer of the requested Personal Data does not pose a risk of security breach to the data of other Data Subjects;
- The right to object the processing of your Personal Data when we process Personal Data based on a legitimate interest of the Company or a third party, including profiling. If you object, we will only be able to further process your Personal Data for compelling legitimate reasons that take precedence over your interests, rights, and freedoms, or to make, enforce or defend legal claims;
- Revoke your consent to the processing of your Personal Data when this data is processed or intended to be processed for direct marketing purposes, including profiling as far as such direct marketing is concerned (based on the Personal Data you provide, profiling may be carried out for direct marketing purposes to offer you individually tailored solutions and proposals. You can revoke your consent to the processing of Personal Data by automated processing, including profiling, or object to it at any time).
We may refuse to exercise your rights listed above, except for refusal to process your Personal Data for direct marketing purposes, competitions or in other cases when Personal Data is processed with your consent, when your request is allowed to us not to comply with the provision of the GDPR, or when, in cases provided for by law, it is necessary to ensure the prevention, investigation and detection of crimes, violations of official or professional ethics, as well as the protection of the rights and freedoms of the Data Subject, us and other persons, or when the Company has a legitimate interest.
You can exercise part of your rights as a Data Subject by changing the user account settings in the Platform or Site and the information contained therein. You may submit any request or instruction related to the processing of Personal Data to us in writing via Company’s internal system for handling Data Subject’s request. Please go to the UAB Nuvei Privacy Center and choose Data subject’s request options here: accounts.nuvei.com/privacy-policy.
When submitting such a request, we may ask you to fill in the necessary forms, as well as provide an identification document or other information that will help us to verify your identity, to better understand the content of your request. You may also send Data Subject’s request together with authorized personal document (ID or passport) copy to our office - Lvivo g. 37, Vilnius, LT-09306, Lithuania, however, we encourage you to submit you requests via our internal system since that channel is dedicated specifically to handle Data Subject’s requests.
Upon receipt of your request or instruction regarding the processing of Personal Data, no later than within 1 month from the date of the request, we will provide a response and perform the actions specified in the request or inform you why we refuse to perform them. If necessary, the specified period may be extended by a further 2 months, considering the complexity and number of requests. In such a case, within 1 month from the date of receipt of the request, we will inform you of such extension.
If Personal Data is deleted upon your request, we will only store copies of information that are necessary to protect our legitimate interests and those of others, to comply with the obligations of law, to resolve disputes, to recognize interference or to comply with any agreements you have entered with us. Please note that these rights are not absolute, and requests are subject to any applicable legal requirements, including legal and ethical reporting or document retention obligations (such as AML/CTF regulations).
- How do we secure your Personal Data?
We take great care in implementing and maintaining the security of the Service and safeguarding any Personal Data we process. Personal Data, trusted to us, is hosted on Amazon Web Services and Google Cloud Services, which provides advanced security features. Company employs industry standard procedures and policies to ensure the safety of the Personal Data processed and to prevent unauthorized use of any such information. In addition, to safeguard the privacy expectation of the data subjects, Nuvei is Payment Card Industry Data Security Standards (“PCI DSS”) certified. Please note that while we take reasonable measures to safeguard your Personal Data, we cannot fully guarantee its absolute security.
- Changes to this Privacy Policy
Company reserves the right to change this Privacy Policy at any time, so please re-visit this page frequently. We will provide notice of substantial changes to this Privacy Policy on the Service and/or we will send you an email regarding such changes to the e-mail address that you volunteered. Such substantial changes will take effect seven (7) days after such notice was provided on any of the above-mentioned methods. Otherwise, all other changes to this Privacy Policy are effective as of the stated “Last Revised” date, and your continued use of the Service after the Last Revised date will constitute acceptance of, and agreement to be bound by, those changes.
- Our contacts:
If you have any questions (or comments) concerning this Privacy Policy, you are welcome to contact us through the following Accounts Privacy Center, available here:
https://nuvei.com/accounts-privacy-center/.
Or
Data Protection Officer: dpo@nuvei.com.
We will try to reply within a reasonable timeframe. Please feel free to reach out to us at any time. If you are unsatisfied with our response or decision, you can reach out to the applicable data protection authority:
The State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija in Lithuanian, website available at https://vdai.lrv.lt/).
On this page
Ready to grow everywhere?
Get started with Nuvei – the growth infrastructure for every payment, everywhere. One intelligent system, built to scale.