Institutional Privacy Policy
How PayFlow governs, encrypts, and retains corporate and transactional telemetry across our global multi-rail clearing infrastructure.
Questions regarding regulatory jurisdiction, audit reports, or DPO coordination?
Data Collection & Ingestion Boundaries
Scope of information processed during institutional onboarding and transaction settlement.
PayFlow collects and processes data strictly necessary to provision institutional payment infrastructure, execute multi-rail clearing, and fulfill global Anti-Money Laundering (AML) and Know Your Customer (KYC) statutory obligations.
When merchants apply for sandbox or production credentials, we ingest entity verification records including registered company details, corporate identification, beneficial ownership structures, authorized director credentials, and institutional contact channels.
During API execution, our edge gateway automatically records technical telemetry: static outbound IP addresses, TLS cryptographic cipher metadata, cryptographic HMAC signature timestamps, and API call volumes for threat prevention and anomaly detection.
PayFlow never logs or stores raw merchant secret keys or unhashed passwords. Both API Key and Secret Key are confidential server-side credentials stored in isolated cryptographic enclaves.
Lawful Basis & Processing Operations
How and why merchant and transaction data is utilized across our financial engine.
We process merchant and transaction data exclusively under legitimate business interests, contractual necessity, and statutory regulatory compliance.
Core operational uses include: executing real-time deposit and payout clearing via partner banking nodes, calculating zero-spread USDT peg conversions, dispatching cryptographically signed webhooks, and performing continuous double-entry ledger balance reconciliations.
We do not engage in profiling, automated credit discrimination, or behavioral surveillance advertising. Transaction telemetry is utilized strictly for system stability, network security, and forensic audit trails.
Cryptographic Enclaves & Infrastructure Security
Technical countermeasures deployed to safeguard confidential institutional data.
All edge network communication is enforced through TLS 1.3 with forward secrecy. REST API endpoints require reciprocal timestamped HMAC-SHA256 signatures to eliminate tampering and replay vectors.
Merchant credentials and operational databases are encrypted at rest using AES-256-GCM. Cryptographic keys are rotated on an automated schedule through hardware-backed Key Management Systems (KMS).
Production infrastructure access requires multi-party authorization, hardware FIDO2 WebAuthn keys, and isolated VPN bastions with comprehensive immutable audit trails.
Data Retention & Ledger Archival
Statutory holding periods and cryptographic archival schedules.
In accordance with international financial regulations and banking partner requirements, core transaction ledgers, settlement receipts, and KYC verification records are retained for seven (7) years following account termination.
Transient edge telemetry, temporary sandbox simulation logs, and non-transactional system metrics are purged automatically after ninety (90) days.
Upon expiration of mandatory statutory retention windows, merchant records are irreversibly scrubbed or mathematically anonymized in accordance with NIST SP 800-88 standards.
Merchant Rights & Global Privacy Standards
Rights available under GDPR, CCPA, and international data protection laws.
Subject to statutory ledger archival obligations, institutional clients and their authorized representatives maintain the right to inspect personal information held on file, request immediate corrections of inaccurate corporate records, and obtain structured exports of historic transaction ledgers.
Where processing relies on consent, such consent may be withdrawn at any time, provided that withdrawal does not invalidate prior lawful processing necessary to execute active financial settlements.
Regulatory Inquiries & Compliance Desk
Direct escalation contact for Data Protection Officers and legal inquiries.
For all privacy inquiries, data subject access requests, or regulatory audits, contact our Data Protection Officer (DPO) directly through our dedicated compliance channels.
Standard institutional inquiries receive a response within twenty-four (24) business hours.
Have specific legal or institutional questions?
Our regulatory compliance counsel is available for bilateral NDA execution and formal data governance audits.