We use cookies to improve your experience on the Markesto Digital website and analyse how it is used.
By continuing to browse you agree to our Privacy Policy.

Privacy and Data Protection Policy

Last updated on 24/08/2026

1. Our commitments

We provide a payment routing and orchestration platform under the brand name “OKARDS” that helps businesses ("Client") connect to multiple acquiring banks and payment providers through a single integration, and route each transaction to the bank best placed to process it.

Running that kind of platform means handling data that sits close to critical payment operations and we take that responsibility seriously. We see ourselves as stewards of the information entrusted to us, and we treat privacy and security not as a compliance checkbox, but as a condition of the trust our Clients, their customers, and our partners place in us. That commitment shapes our technology, our choice of partners, and how we run day-to-day operations.

This Policy explains what personal data we collect, why, how we protect it, and the rights available to the people whose data we process: from the businesses we work with, their customers, to visitors of this website.

2. Definitions

GDPR - the EU General Data Protection Regulation (Regulation (EU) 2016/679), which governs the processing of personal data of individuals in the European Union.

UK GDPR - the UK's version of the GDPR, retained under the UK's Data Protection Act 2018 following its withdrawal from the EU, applicable to the personal data of individuals in the United Kingdom.

California Privacy Law (CCPA/CPRA) - the California Consumer Privacy Act, as amended by the California Privacy Rights Act, which governs the collection and use of personal information of California residents.

Personal Data - any information relating to an identified or identifiable individual. In this Policy, personal data in scope includes the data described in Section 4 

Controller - the party that decides why and how personal data is processed.

Processor - the party that processes personal data on a Controller's behalf and instructions.

Sub-processor - a third party engaged by us to assist in processing personal data on the Client's behalf (see Appendix B).

Data Processing Agreement (DPA) - the separate agreement between us and a Client that sets out the contractual terms of processing, including instructions, security obligations, and liability.

Data Transfer - the transmission of personal data across a national or regional border, which under GDPR, UK GDPR, and similar laws must rely on an approved transfer mechanism (e.g., Standard Contractual Clauses) where the destination does not offer an equivalent level of protection.

Security Measures / TOMs - the Technical and Organizational Measures we apply to protect personal data, set out in Appendix A.

Cookies - small files or similar tracking technologies placed on a website visitor's device to enable website functionality, measure usage, or support marketing, as described in Section 7.

Client - the business that integrates our platform to route and process its transactions.

End User of the Client - an individual completing a transaction that is routed through our platform on the Client's behalf.

Website Visitor - an individual browsing the website.

3. Scope and Applicability 

This Policy forms an integral part of the Terms of Use between us and the Client and shall be read in conjunction with it. The specific contractual terms of processing (including instructions, liability, and audit rights) between the Company and a Client are set out in a separate Data Processing Agreement ("DPA"), executed between the Company and each Client. In the event of any conflict between this Policy and the Terms of Use or the DPA on matters they respectively govern, the Terms of Use and the DPA shall prevail over this Policy. 

This Policy describes:

  • the categories of data the Company processes in connection with service,
  • the purposes of such processing,
  • the respective roles and responsibilities of the Company and its Clients under data protection frameworks,
  • the technical and organizational measures applied to protect data, and
  • the third parties involved in the provision of the service.

This Policy applies to personal data relating to:

  • authorized users of the Client who access the Company's admin panel ("Client's Authorized Users");
  • individuals who complete transactions routed through the Company's platform ("End Users of the Client");
  • visitors to the Company's website, including individuals who submit a contact, demo-request, or newsletter subscription form ("Website Visitors").

Section 6 sets out the specific categories of data processed in relation to each group and the purposes of such processing.

4. Description of Services 

4.1 Payment Routing & Orchestration

At the core of the platform is a routing engine: for every transaction, OKARDS decides which of the Client's connected acquiring banks is best placed to process it, based on factors such as the card's brand, type, and issuing bank. This is designed to improve approval rates and give its clients the flexibility of working with several payment providers through a single integration, without having to manage that complexity themselves.

4.2 Risk & Fraud Analytics

Alongside routing, OKARDS analyzes signals to help assess the risk profile of a transaction. This analysis feeds directly into the routing decision and also surfaces as alerts and reporting inside the Client's admin panel, giving Clients visibility into fraud patterns and transaction risk over time.

5. Roles and Responsibilities

Processing a card payment involves several parties, each playing a different role in the transaction. The table below lays out who does what in a transaction that runs through the platform, and how each party is classified from a data protection standpoint.

Party What they do Data protection role
The Company Decides which acquiring bank should handle each transaction and routes it there. Processor for data handled on the Client's behalf; controller for its own admin panel accounts and platform's components
Client The business using our Services; owns the relationship with its own customers. Controller for its end customers' data
Acquiring Bank Submits the transaction to the card network for authorization Independent party, processing data per Client's instructions
Card Networks / Issuing Bank Authorize or decline the transaction Not addressed by this Policy

The allocation of Controller and Processor responsibilities, including the scope of the Company's processing on the Client's behalf, is defined in detail in the DPA executed between the Company and the Client.

6. Data and Purposes of Processing

Different people interact with our Services and website in different ways: representative of a Client managing the platform, users completing a payment that is routed through Services, or simply as a visitor of our website. The table below explains, for each of these groups, what we actually collect and why.

Who Data we collect Purposes of processing Our role
Client and admin panel users Contact data: email, name, role.

Activity data: user ID, session ID, request ID, IP address, browser user agent, routing outcome
to provide core Services; to ensure security and account administration Controller
End Users of the Client (i.e. payers) Device & risk data: device fingerprint, device ID, location, ZIP code where applicable.

Metadata: card brand, type, issuing bank, issuing country.

Transaction data: token ID, timestamp, amount, currency, package name.

Contact data: email, customer ID, IP address
to assess risk, route the transaction, and report on transaction activity Processor, per Client's instructions
Website Visitors Cookies (Section 7); IP and browser/device info; contact data

To run the website, ensure website’s security and accurate data transmission; respond to inquiries, and send communications Controller

7. Cookies and Similar Technologies

The Company's website uses cookies and similar technologies as follows:

Cookie category Purpose Examples Legal basis
Strictly necessary Enable core website functionality (e.g., security, load balancing, session management) Session and security cookies Legitimate interest
Analytics Understand website usage in order to maintain and improve the website Usage and analytics identifiers Consent, where required by applicable law
Marketing (if used) Measure and deliver marketing communications Marketing/tracking identifiers Consent

Where required by applicable law, non-essential cookies are only set with the visitor's consent, obtained through the cookie banner presented on the website. Visitors may withdraw consent at any time via their browser settings or the cookie preference tool on the website.

7.1. Contact Forms, Demo Requests and Newsletter Subscriptions

Where a Website Visitor submits a contact form, requests a product demo, or subscribes to the Company's newsletter, the Company processes the information provided (e.g., name, email address, company name, message content) to respond to the inquiry, provide the requested information, or send the requested communications. Newsletter and marketing communications are sent only where the visitor has opted in, and the visitor may unsubscribe at any time.

8. Legal Basis for Processing 

Processing activity Data subject group Legal basis
Payment routing and orchestration; risks and fraud analysis processed on the Client's instructions Client; End Users of the Client Performance of Terms of Use with Client; our legitimate interests, provided that they do not override Client's rights and freedoms
Administration of admin panel accounts Client's Authorized Users Performance of Terms of Use with Client; legitimate interests (i.e. platform security and administration); legal obligations to ensure security and confidentiality of data
Essential website functionality Website Visitors Legitimate interest
Analytics cookies Website Visitors Consent, where required by applicable law
Newsletter and marketing communications Website Visitors Consent
Responding to contact form or demo request submissions Website Visitors Legitimate interest; intention to execute Terms of Use

9. Security and Compliance Statement

Protecting data is one of our highest responsibilities. We treat the information entrusted to us not just as an asset to safeguard, but as a marker of the trust that makes our business possible. That trust shapes how we build our systems, choose our partners, and hold ourselves accountable.

We maintain a security programme combining technical safeguards, organisational controls, and ongoing risk management, designed to protect data against unauthorised access, disclosure, alteration, or loss. The specific measures we apply are set out in Appendix A: Technical and Organizational Measures (TOMs).

We will notify affected Clients of a confirmed security incident involving their data without undue delay, and in any event within the timeframe specified in the DPA.

10. Third-Party Vendors and Sub-processors

The Company may engage third parties in personal data processing (i.e. sub-processors). A complete, current list of the Company's sub-processors - covering core Services providing, infrastructure, hosting, and monitoring providers involved in all processing activities with data is maintained in Appendix B.

11. Data Retention

The Company retains the categories of data described in Section 6 only for as long as necessary to fulfil the purposes described in this Policy, or as required by applicable law. Specific retention periods are set out in the DPA and/or Appendix A.

12. International Data Transfers

Where we transfer personal data across borders in connection with the Services described in this Policy, such transfers are made subject to an appropriate safeguard recognized under applicable law.

  • Data processed on a Client's behalf (e.g., End Users' transaction and risk data) - the applicable transfer mechanism (e.g., Standard Contractual Clauses) is set out in the DPA between us and the Client.
  • Website Visitor data (e.g., cookies and analytics identifiers as well as data submitted through website’s forms) - where such data is transferred outside the visitor's jurisdiction, we rely on Standard Contractual Clauses, adequacy decisions, or another transfer mechanism recognized under applicable law, including, for UK residents, the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses.

13. Data Subject Rights

This section sets out the rights available to individuals under applicable data protection laws. 

13.1 Rights Available

Subject to conditions and exceptions under applicable law, individuals may request to:

  • Access — obtain confirmation of, and a copy of, the personal data we hold about them.
  • Rectification — correct inaccurate or incomplete personal data.
  • Erasure — request deletion of their personal data, where applicable.
  • Restriction — limit how their personal data is used, in certain circumstances.
  • Portability — receive their personal data in a structured, machine-readable format, or have it transferred to another party.
  • Object — object to processing based on legitimate interest, including for direct marketing.
  • Not be subject to solely automated decisions that produce legal or similarly significant effects, as described in Section 13.3.

13.2. Exercising Rights

Who to contact depends on which role we play in relation to that data:

Data subject group Whom to contact Our role
Client and admin panel users Us directly We are the Controller; Where the Client is the Controller of admin panel users, the Client shall remain responsible for their rights and we assist the Client in responding, as set out in the DPA
Website Visitors Us directly We are the Controller
End Users of the Client The relevant Client The Client is the Controller; we assist the Client in responding, as set out in the DPA

Requests are verified before being actioned and are responded to within the timeframe required by applicable law 

13.3 Automated Decision-Making

Risk-based routing may inform whether a transaction is approved or declined. If an individual believes such a decision has significantly affected them, they (or the Client on their behalf) may request a review, express their point of view, or contest the decision by contacting the Client, who controls the underlying transaction and customer relationship.

13.4 Limitations

These rights are not absolute and may be limited by applicable law, including retention obligations. Additional rights specific to California and UK residents are set out in Sections 14 and 15.

14. Notice for California Residents (CCPA/CPRA)

This section applies to California residents whose personal information is processed by the Company, in addition to the rights set out in Section 13, to the extent required by the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA").

Categories of personal information. The categories of personal information the Company collects about California residents correspond to the categories described in Section 6 of this Policy (e.g., identifiers, internet or network activity, geolocation data, and commercial/transaction information). The Company does not collect Social Security numbers, financial account credentials, or other categories.

Sale and sharing. The Company does not sell personal information. To the extent the analytics or marketing cookies described in Section 7 constitute "sharing" of personal information for cross-context behavioral advertising under the CPRA, California residents may opt out via the cookie preference tool on the website or by submitting a request using the contact details in Section 16.

Rights. Subject to applicable exceptions, California residents may exercise the right to:

  • know and access the specific pieces and categories of personal information collected;
  • delete personal information;
  • correct inaccurate personal information;
  • opt out of the sale or sharing of personal information;
  • limit the use of sensitive personal information; and
  • not be discriminated against for exercising any of these rights.

How to exercise these rights. Requests may be submitted using the contact details in Section 1, or by an authorized agent acting on the resident's behalf. The Company will verify the request in accordance with applicable law and respond within the timeframe required by the CCPA.

Role of the Company. Where personal information relating to a California resident is processed as part of the End Users of the Client category, the Company acts as a "service provider" to the Client, who is the "business" under the CCPA. Requests relating to that data should be directed to the relevant Client.

15. Additional Rights for UK Residents

This section applies to residents of the United Kingdom, whose personal data is processed by the Company subject to the UK GDPR and the Data Protection Act 2018.

The rights available to UK residents are the same as those described in Section 13 of this Policy (access, rectification, erasure, restriction of processing, objection to processing, and data portability), and are exercised in the same manner: Client's Authorized Users and Website Visitors should contact the Company using the details in Section 1; End Users of the Client should contact the relevant Client.

International transfers. Where personal data of a UK resident is transferred outside the United Kingdom, the Company relies on an appropriate transfer mechanism recognized under UK data protection law (e.g., the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses), as further described in the DPA.

Right to complain. UK residents have the right to lodge a complaint with the UK supervisory authority, the Information Commissioner's Office (ICO), at ico.org.uk, if they consider that the Company's processing of their personal data infringes applicable data protection law.

16. Changes to This Policy

This Policy is reviewed periodically and may be updated to reflect changes in the Company's services, processing activities, or applicable law. The "Last reviewed" date at the top of this Policy indicates the most recent update. Material changes affecting the Company's PCI DSS scope will be communicated to Clients and acquiring banks in advance.

Appendix A: Technical and Organizational Measures (TOMs)

Category Description of measures
Access Control Access to system components and data is restricted based on the need-to-know and least-privilege principles, with each user assigned only the privileges required for their job function. All users are assigned a unique account; sharing of credentials and use of shared, group, or generic accounts are strictly prohibited. Access for terminated users is revoked immediately. Accounts inactive for more than 90 days are disabled. Access rights and privileges are reviewed every 6 months. Authentication uses a strong password and also MFA is required.
Encryption All HTTPS transmissions use TLS 1.2 or above. Only valid, trusted, non-expired, and non-revoked certificates are accepted. All connections to database instances require SSL/TLS.

All data stored in our infrastructure is automatically encrypted at rest. VM instance disks are additionally encrypted with encryption keys.
Network Security The network infrastructure is divided into isolated segments, with security controls enforced at all boundaries between trusted and untrusted networks. All inbound and outbound traffic is restricted to explicitly approved services, protocols, and ports, each with a documented business justification. Intrusion detection mechanisms are in place. Automated alerts are configured to detect changes to network configurations, firewall rules, and routing.
Logging & Monitoring Audit logging is enabled across all in-scope system components. Logs from all systems are collected, aggregated, and analysed centrally.

Audit logs are protected against modification through configuration policy and are backed up to a secure central location. Read access to log files is limited to personnel with a job-related need.
Vulnerability Management New security vulnerabilities are continuously monitored using industry-recognised sources. All identified vulnerabilities are assessed and ranked as Critical, High, Medium, or Low based on potential impact. External vulnerability scans are performed at least once every three months by a PCI SSC Approved Scanning Vendor (ASV), and after any significant change to the environment.
Penetration Testing Internal penetration testing is conducted by qualified personnel with assigned responsibility.
Incident Response A formal Incident Response Plan is in place and ready to be activated upon a suspected or confirmed security incident. The plan defines roles and responsibilities, communication and escalation procedures, containment and recovery steps, and reporting obligations to internal stakeholders, legal authorities, etc.
Business Continuity / Disaster Recovery All critical business services are deployed across a minimum of two availability zones to ensure high availability and minimize the impact of regional infrastructure failures. Continuous 24/7 automated monitoring is in place for all critical operations, with incident response procedures ensuring timely detection, escalation, and recovery.

All critical business services are regularly backed up.
Employee Security Access to system components and data is restricted based on the need-to-know and least-privilege principles, with each user assigned only the privileges required for their job function. All access control systems are set to "deny all" by default. An inventory of all personnel with access to the in-scope environment is formally documented and reviewed at least annually.

Endpoint security tools are deployed on all devices to protect against compromise, including malware detection and response.
Data Retention & Deletion Audit logs are retained for a minimum of 12 months, with the most recent three months immediately available for analysis. Log storage is protected against tampering and premature deletion through immutable storage policies.

Appendix B: List of Sub-processors

This list identifies the Company's key sub-processors involved in the processing activities under Policy and Terms of Use. It is not necessarily exhaustive of every vendor engaged by the Company, and may be updated as the Company's vendor arrangements change. The Company will update this list on the website.

Sub-processor Service provided Link to sub-processors' information and data protection commitments
Paysafe Payment processing / acquiring services Privacy Policy
Unlimint Payment processing services Privacy Notice
NMI Payment gateway services Global Privacy Policy
Emerchantpay Payment processing / acquiring services Legal Space
MaxMind GeoIP and fraud-risk data services Privacy Policy
Google Cloud Cloud infrastructure hosting Privacy & Terms
GitLab Source code repository Trust Center