Welcome to EnterPay. We, EnterPay, may process your Personal Data (as defined below), for example, when you visit our Website or when we provide Services (as defined below) to you. This Privacy Statement discloses how we collect, use, share, retain, and protect your Personal Data (as defined below), and the legal basis on which we do so.
1.1 In this Privacy Statement, the following terms, always written with a capital letter and used in both singular and plural, have the following meaning:
1.1.1 Agreement: the agreement between the Parties for the access to and/or use of the Service;
1.1.2 Customer: the natural person or legal entity to whom EnterPay performs Services and/or who has an Agreement with EnterPay;
1.1.3 Controller: the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of Personal Data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law, as described in article 4(7) GDPR;
1.1.4 Documentation: the documentation as accessible at the Website;
1.1.5 EEA: European Economic Area;
1.1.6 EnterPay: the company EnterPayment OÜ, established under the laws of the Republic of Estonia, registered with the Estonian Chamber of Commerce under registration number 17391111;
1.1.7 Features: the Services' current features, which can be updated by EnterPay at any time, as described in the Documentation and/or on the Website;
1.1.8 GDPR: Regulation (EU) 2016/679 ('General Data Protection Regulation');
1.1.9 Personal Data: any information relating to an identified or identifiable natural person ('data subject'); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, as described in article 4(1) GDPR. In short, it refers to all information that identifies you or can be reasonably linked to you as a person;
1.1.10 Platform: the application which EnterPay makes available to the User indirectly through the Website, and through the Terminal, as described on the Website and in the Documentation, and which forms part of the Service;
1.1.11 Privacy Statement: this formal, legally binding public declaration by EnterPay (as Controller) that discloses how it collects, uses, shares, retains, and protects Personal Data. It serves to satisfy statutory transparency obligations under privacy laws, such as the GDPR, by informing data subjects of their rights and the legal basis for processing their information;
1.1.12 Processor: a natural or legal person, public authority, agency or other body which processes personal data on behalf of the Controller, as described in article 4(8) GDPR;
1.1.13 Service: the provision of the Website and (Features of) the Platform and/or Terminal, as described on the Website and in the Documentation;
1.1.14 Terminal: the hardware or software interface provided to the User for accepting crypto asset payments, and which forms part of the Service;
1.1.15 User: the Party that concluded the Agreement with EnterPay for the use of the Service and/or uses (parts of) the Service without concluding the Agreement;
1.1.16 Website: the website accessible at https://enterpay.com, including all associated subdomains, web pages, and all content, data, files, and resources made available through them (such as text, images, scripts, and other materials), which together form part of the Service.
2.1 This Privacy Statement only applies to the processing of Personal Data by EnterPay as a Controller. Where an organisation processes Personal Data through our products or Services, that organisation acts as the Controller and we act as the Processor. Consequently, this Privacy Statement does not govern such processing. For information on how your Personal Data is handled in these instances, please refer to the privacy statement of the respective Controller.
3.1 We value your privacy and are committed to handling your Personal Data responsibly. We process Personal Data strictly for legitimate purposes, in accordance with this Privacy Statement and applicable data protection laws. To ensure compliance, we:
3.1.1 Clearly define our purposes before processing any Personal Data;
3.1.2 Store only the minimum amount of Personal Data necessary for those specific purposes;
3.1.3 Only process Personal Data when a valid legal basis exists;
3.1.4 Implement appropriate technical and organisational security measures to protect your data, and we contractually impose these same obligations on our data Processors;
3.1.5 Fully respect your legal rights, including your rights to access, rectify, port, or delete your Personal Data.
3.2 We do not knowingly collect Personal Data from anyone under 16. If we discover that we have inadvertently collected such data, we will delete it immediately.
3.3 EnterPay uses cookies for various purposes, which are outlined in this Privacy Statement.
3.4 If you have any questions or require further information about our data handling practices, please contact us using the details provided at the end of this Privacy Statement.
4.1 We aim to inform you in a clear and transparent manner about how and why we process Personal Data. This includes the purposes of processing, the legal basis for that processing, how long we retain Personal Data, and which categories of parties may be involved. Below is a non-exhaustive overview of the main categories of processing activities, organised by context:
4.1.1 When you visit our Website;
4.1.2 When we provide Services to you, as our Client;
4.1.3 When you contact us for support;
4.1.4 When you apply for a job;
4.1.5 When you supply goods or services to us.
| Processing activity & purpose | Personal Data | Legal basis | Retention period | Categories of processors |
|---|---|---|---|---|
| CookiesTo enable the proper functioning of the Website (essential cookies) and, where you give consent, to support analytics and marketing features. | Necessary/essential cookies: Pseudonymous identifiers, usage data, and language settings. | Legitimate interest (strictly necessary for Website operation) (article 6(1)(f) GDPR). Consent for analytics and marketing cookies (article 6(1)(a) GDPR). | Session cookies: deleted when the browser is closed. Persistent cookies: retained until the browser cleans cookies. | Consent management platforms. |
| Cookies consent managementTo collect, record, and manage your choices regarding the use of cookies and similar tracking technologies, ensuring compliance with GDPR requirements. | Pseudonymous identifiers (consent ID), consent records (choices, timestamps), and technical context (browser type, truncated IP address, coarse geo-location). | Legal obligation (article 6(1)(c) GDPR). | We retain consent records as long as needed for legal compliance, up to five (5) years. Every twelve (12) months, we will ask you again whether or not you give your consent. | Consent management platforms. |
| Web analyticsTo measure visits, page views, traffic sources, and user flows on the website in order to evaluate performance, and to improve user experience. | Analytical cookies: Pseudonymous identifiers, technical data, Website usage and interaction data (e.g., pages visited), truncated IP address and coarse geo-location. | Consent (article 6(1)(a) GDPR). | Up to fourteen (14) months. Deleted upon withdrawal of consent or request, subject to technical feasibility. After expiry, data could be anonymised and aggregated. | Web analytics & conversion tracking providers. |
| Logging & security monitoringTo ensure proper functioning of the Website, maintain security, detect and resolve errors, and prevent misuse, or automated abuse. | Connection metadata, such as IP address, timestamps, URLs, user-agent (browser/device info), and related diagnostic/error information. | Legitimate interest (article 6(1)(f) GDPR). | Up to 30 days. We may retain the data for longer if required by law or necessary to investigate or address a security incident. | Security information & event management providers. Log management platforms. |
| Processing activity & purpose | Personal Data | Legal basis | Retention period | Processors |
|---|---|---|---|---|
| Client managementTo provide Clients with information regarding our Services. | Identification data (name, email), contact data, and Client preferences. | Performance of a contract (article 6(1)(b) GDPR). Consent for the use of the Platform (article 6(1)(a) of GDPR). | We retain this data for as long as you are our Client, or as long as needed for legal compliance and statutory financial record-keeping obligations, up to ten (10) years. | CRM & Client management systems. |
| Orders & paymentsTo process orders, payment processing, and invoicing. | Identification data, order details, address data (billing address), contact data, payment metadata (method, transaction ID, no full card data), wallet addresses, and bank account details. | Performance of a contract (article 6(1)(b) GDPR). Legal obligation (statutory financial obligations) (article 6(1)(c) GDPR). | We retain this data for as long as you are our Client, or as long as needed for legal compliance and statutory financial record-keeping obligations, up to ten (10) years. | Financial & accounting software. Payment service providers (PSPs) & payment gateways. |
| Service communicationTo send Service related messages. | Identification data (name), contact data (email, phone number if used), Service details, and communication metadata. | Legitimate interest (article 6(1)(f) GDPR). Performance of a contract (article 6(1)(b) GDPR). Consent for the use of the Platform (article 6(1)(a) of GDPR). | We retain this data for as long as you are our Client, or as long as needed for legal compliance and statutory financial record-keeping obligations, up to ten (10) years. | Office & productivity software. |
| Marketing communicationTo send newsletters, promotional offers, and Service updates to Clients who have consented or to existing Clients under applicable legal exceptions for direct marketing. | Contact details (name, email) and optional metadata (interest category, referral source, region). | Consent for marketing communication (article 6(1)(a) of GDPR). Consent for the use of the Platform (article 6(1)(a) of GDPR). | As long as you are registered for marketing communication, or until you withdraw your consent. | Marketing automation & email delivery platforms. |
| Accounting & taxTo comply with statutory obligations for bookkeeping, accounting, financial reporting, and tax compliance. | Identification data, Service details, contact data, address data, payment metadata, and copies of the issued invoices. | Legitimate interest (article 6(1)(f) GDPR). Legitimate interest (article 6(1)(f) GDPR). Legal obligation (statutory financial obligations) (article 6(1)(c) GDPR). | We retain this data for as long as you are our Client, or as long as needed for legal compliance and statutory financial record-keeping and tax obligations, up to ten (10) years. | Financial & accounting software. |
| Know-Your-Customer (KYC) and Know-Your-Business (KYB)To comply with legal obligations, such as Anti-Money Laundering (AML), Know-Your-Customer (KYC), and Know-Your-Business (KYB) obligations. | Primary contact name, job title, phone number, email address, preferred settlement currency, bank account holder name, IBAN/bank account number, SWIFT/BIC, bank name & address, full name, position/role. | Performance of a contract (article 6(1)(b) GDPR). Legal obligation (article 6(1)(c) GDPR). | We retain this data for as long as you are our Client, or as long as needed for legal compliance and statutory financial record-keeping obligations, up to ten (10) years. | Identity verification & compliance platforms (KYC / KYB / AML). |
| Processing activity & purpose | Personal Data | Legal basis | Retention period | Processors |
|---|---|---|---|---|
| Client supportTo respond to Client inquiries, provide technical assistance, and resolve issues. | Identification data (name, email address, if provided), communication content, and technical context. | Legitimate interest (article 6(1)(f) GDPR). Performance of a contract (article 6(1)(b) GDPR). | Until the issue is addressed and for up to six (6) months thereafter, and/or as long as needed for the performance of a contract. | Office & productivity software. |
| Processing activity & purpose | Personal Data | Legal basis | Retention period | Processor |
|---|---|---|---|---|
| Candidate sourcing, application management, and recruitment evaluationTo assess your suitability, qualifications, and skills for the specific role you applied for (and potentially future open roles), to communicate with you throughout the hiring process, and to conduct reference or background checks if a provisional offer is extended. | Identification data (name, email address, physical address, if provided), communication content, and technical context. Professional history: your resume/CV, cover letter, work experience, education history, certifications, and portfolios. Interview notes: feedback and ratings from recruiters and hiring managers during interviews. Public professional profiles: information from professional platforms you link to (like LinkedIn). | Legitimate interest (article 6(1)(f) GDPR). Consent (article 6(1)(a) GDPR). | Up to four (4) weeks after the position is filled. If you give us the permission to keep your CV for future roles, we will hold your data up to 12 months, calculated from the moment that the position was filled, before asking you to renew your consent or delete your data automatically. | Office & productivity software. |
| Processing activity & purpose | Personal Data | Legal basis | Retention period | Processors |
|---|---|---|---|---|
| Vendor onboarding, supplier relationship management, and contract administrationTo manage our business relationship, communicate regarding orders, facilitate the delivery of goods or services, process invoices and payments, evaluate vendor performance, and handle any contractual disputes. | Business contact details: name, business email address, phone number, job title, and physical business address of your contact persons. Financial & transactional data: bank account details, VAT/tax identification numbers, signature on contracts, and payment history. Communication: emails, meeting notes, and correspondence related to the execution of the services or goods supplied. | Legitimate interest (article 6(1)(f) GDPR). Performance of a contract (article 6(1)(b) GDPR). Legal obligation (statutory financial obligations) (article 6(1)(c) GDPR). | We retain this data for as long as you are our supplier, or as long as needed for legal compliance and statutory financial record-keeping obligations, up to ten (10) years. | CRM & Client management systems. Office & productivity software. Identity verification & compliance platforms (KYC / KYB / AML). Financial & accounting software. |
10.1 We protect your Personal Data by taking technical and organisational measures against unauthorised, unlawful, or accidental access, loss, destruction, or damage to Personal Data. We ensure that only our necessary persons have access to your Personal Data, that access to Personal Data is secure, and that our security measures are regularly checked and evaluated. We continuously take steps to improve data security.
10.2 To ensure that third parties also adhere to our high standards, we only store Personal Data with carefully selected third parties who help us to protect your Personal Data. We do not sell your data to third parties. However, we may engage third parties to process certain Personal Data on our behalf and under our responsibility, as specified above. Some of these third parties are located in the EEA, while others are located outside the EEA, such as in the United States. When Personal Data is processed or stored outside the EEA, we ensure that appropriate safeguards, such as the European Commission's Standard Contractual Clauses (SCC) and the EU-U.S. Data Privacy Framework (DPF), are in place to enable such transfers.
10.3 For transfers to third parties in the United States certified under the DPF, we rely on the adequacy decision of the European Commission. You can verify the certification status of our US partners on the official DPF website: dataprivacyframework.gov/list.
10.4 For transfers to third parties outside the EEA that are not covered by an adequacy decision (or do not hold DPF certification), we enter into Standard Contractual Clauses as approved by the European Commission. Where necessary, we enforce supplementary technical and organisational security measures.
10.5 In order to protect your Personal Data and comply with our legal obligations, we will only engage third parties for processing if those third parties offer sufficient guarantees for the protection of your Personal Data. We also have the right to disclose Personal Data to competent authorities, regulators, or law enforcement officials when required to comply with legal or regulatory obligations.
10.6 We reserve the right to update or expand the main categories of third-party service providers as our Services evolve.
11.1 If you have a complaint about the way we process your Personal Data, please contact us. You also have the right to file a complaint with the supervisory authority. In the Republic of Estonia, this is the Estonian Andmekaitse Inspektsioon (AKI).
11.2 As a data subject, you have various rights under the GDPR:
11.2.1 Right of access, rectification, and erasure ('right to be forgotten')
11.2.2 Right to restriction of processing
11.2.3 Right to object (in particular to legitimate interest)
11.2.4 Right to data portability
11.2.5 The right to withdraw consent at any time
11.3 You can exercise your rights by contacting us. We may ask you to provide further information so that we can assist you as effectively as possible.
12.1 The way in which we process Personal Data, and the composition of the data we process, may change from time to time. We therefore reserve the right to change this Privacy Statement at any time. For this reason, we encourage you to check the Privacy Statement regularly to stay informed of any changes. Are you a Client? If so, we will keep you informed by email.
13.1 If you have any questions or comments about this Privacy Statement and/or the processing of your Personal Data by EnterPay, please contact us using the contact details below:
EnterPayment OÜ
Registered address: Harju maakond, Tallinn, Kristiine linnaosa, Rahumäe tee 6b-67, 13415, Republic of Estonia
Registration number: 17391111
privacy@enterpay.com