Privacy and Data Protection Policy
1. Our commitments
We provide a payment routing and orchestration platform under the brand name “OKARDS” that helps businesses ("Client") connect to multiple acquiring banks and payment providers through a single integration, and route each transaction to the bank best placed to process it.
Running that kind of platform means handling data that sits close to critical payment operations and we take that responsibility seriously. We see ourselves as stewards of the information entrusted to us, and we treat privacy and security not as a compliance checkbox, but as a condition of the trust our Clients, their customers, and our partners place in us. That commitment shapes our technology, our choice of partners, and how we run day-to-day operations.
This Policy explains what personal data we collect, why, how we protect it, and the rights available to the people whose data we process: from the businesses we work with, their customers, to visitors of this website.
2. Definitions
GDPR - the EU General Data Protection Regulation (Regulation (EU) 2016/679), which governs the processing of personal data of individuals in the European Union.
UK GDPR - the UK's version of the GDPR, retained under the UK's Data Protection Act 2018 following its withdrawal from the EU, applicable to the personal data of individuals in the United Kingdom.
California Privacy Law (CCPA/CPRA) - the California Consumer Privacy Act, as amended by the California Privacy Rights Act, which governs the collection and use of personal information of California residents.
Personal Data - any information relating to an identified or identifiable individual. In this Policy, personal data in scope includes the data described in Section 4
Controller - the party that decides why and how personal data is processed.
Processor - the party that processes personal data on a Controller's behalf and instructions.
Sub-processor - a third party engaged by us to assist in processing personal data on the Client's behalf (see Appendix B).
Data Processing Agreement (DPA) - the separate agreement between us and a Client that sets out the contractual terms of processing, including instructions, security obligations, and liability.
Data Transfer - the transmission of personal data across a national or regional border, which under GDPR, UK GDPR, and similar laws must rely on an approved transfer mechanism (e.g., Standard Contractual Clauses) where the destination does not offer an equivalent level of protection.
Security Measures / TOMs - the Technical and Organizational Measures we apply to protect personal data, set out in Appendix A.
Cookies - small files or similar tracking technologies placed on a website visitor's device to enable website functionality, measure usage, or support marketing, as described in Section 7.
Client - the business that integrates our platform to route and process its transactions.
End User of the Client - an individual completing a transaction that is routed through our platform on the Client's behalf.
Website Visitor - an individual browsing the website.
3. Scope and Applicability
This Policy forms an integral part of the Terms of Use between us and the Client and shall be read in conjunction with it. The specific contractual terms of processing (including instructions, liability, and audit rights) between the Company and a Client are set out in a separate Data Processing Agreement ("DPA"), executed between the Company and each Client. In the event of any conflict between this Policy and the Terms of Use or the DPA on matters they respectively govern, the Terms of Use and the DPA shall prevail over this Policy.
This Policy describes:
- the categories of data the Company processes in connection with service,
- the purposes of such processing,
- the respective roles and responsibilities of the Company and its Clients under data protection frameworks,
- the technical and organizational measures applied to protect data, and
- the third parties involved in the provision of the service.
This Policy applies to personal data relating to:
- authorized users of the Client who access the Company's admin panel ("Client's Authorized Users");
- individuals who complete transactions routed through the Company's platform ("End Users of the Client");
- visitors to the Company's website, including individuals who submit a contact, demo-request, or newsletter subscription form ("Website Visitors").
Section 6 sets out the specific categories of data processed in relation to each group and the purposes of such processing.
4. Description of Services
4.1 Payment Routing & Orchestration
At the core of the platform is a routing engine: for every transaction, OKARDS decides which of the Client's connected acquiring banks is best placed to process it, based on factors such as the card's brand, type, and issuing bank. This is designed to improve approval rates and give its clients the flexibility of working with several payment providers through a single integration, without having to manage that complexity themselves.
4.2 Risk & Fraud Analytics
Alongside routing, OKARDS analyzes signals to help assess the risk profile of a transaction. This analysis feeds directly into the routing decision and also surfaces as alerts and reporting inside the Client's admin panel, giving Clients visibility into fraud patterns and transaction risk over time.
5. Roles and Responsibilities
Processing a card payment involves several parties, each playing a different role in the transaction. The table below lays out who does what in a transaction that runs through the platform, and how each party is classified from a data protection standpoint.
The allocation of Controller and Processor responsibilities, including the scope of the Company's processing on the Client's behalf, is defined in detail in the DPA executed between the Company and the Client.
6. Data and Purposes of Processing
Different people interact with our Services and website in different ways: representative of a Client managing the platform, users completing a payment that is routed through Services, or simply as a visitor of our website. The table below explains, for each of these groups, what we actually collect and why.
7. Cookies and Similar Technologies
The Company's website uses cookies and similar technologies as follows:
Where required by applicable law, non-essential cookies are only set with the visitor's consent, obtained through the cookie banner presented on the website. Visitors may withdraw consent at any time via their browser settings or the cookie preference tool on the website.
7.1. Contact Forms, Demo Requests and Newsletter Subscriptions
Where a Website Visitor submits a contact form, requests a product demo, or subscribes to the Company's newsletter, the Company processes the information provided (e.g., name, email address, company name, message content) to respond to the inquiry, provide the requested information, or send the requested communications. Newsletter and marketing communications are sent only where the visitor has opted in, and the visitor may unsubscribe at any time.
8. Legal Basis for Processing
9. Security and Compliance Statement
Protecting data is one of our highest responsibilities. We treat the information entrusted to us not just as an asset to safeguard, but as a marker of the trust that makes our business possible. That trust shapes how we build our systems, choose our partners, and hold ourselves accountable.
We maintain a security programme combining technical safeguards, organisational controls, and ongoing risk management, designed to protect data against unauthorised access, disclosure, alteration, or loss. The specific measures we apply are set out in Appendix A: Technical and Organizational Measures (TOMs).
We will notify affected Clients of a confirmed security incident involving their data without undue delay, and in any event within the timeframe specified in the DPA.
10. Third-Party Vendors and Sub-processors
The Company may engage third parties in personal data processing (i.e. sub-processors). A complete, current list of the Company's sub-processors - covering core Services providing, infrastructure, hosting, and monitoring providers involved in all processing activities with data is maintained in Appendix B.
11. Data Retention
The Company retains the categories of data described in Section 6 only for as long as necessary to fulfil the purposes described in this Policy, or as required by applicable law. Specific retention periods are set out in the DPA and/or Appendix A.
12. International Data Transfers
Where we transfer personal data across borders in connection with the Services described in this Policy, such transfers are made subject to an appropriate safeguard recognized under applicable law.
- Data processed on a Client's behalf (e.g., End Users' transaction and risk data) - the applicable transfer mechanism (e.g., Standard Contractual Clauses) is set out in the DPA between us and the Client.
- Website Visitor data (e.g., cookies and analytics identifiers as well as data submitted through website’s forms) - where such data is transferred outside the visitor's jurisdiction, we rely on Standard Contractual Clauses, adequacy decisions, or another transfer mechanism recognized under applicable law, including, for UK residents, the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses.
13. Data Subject Rights
This section sets out the rights available to individuals under applicable data protection laws.
13.1 Rights Available
Subject to conditions and exceptions under applicable law, individuals may request to:
- Access — obtain confirmation of, and a copy of, the personal data we hold about them.
- Rectification — correct inaccurate or incomplete personal data.
- Erasure — request deletion of their personal data, where applicable.
- Restriction — limit how their personal data is used, in certain circumstances.
- Portability — receive their personal data in a structured, machine-readable format, or have it transferred to another party.
- Object — object to processing based on legitimate interest, including for direct marketing.
- Not be subject to solely automated decisions that produce legal or similarly significant effects, as described in Section 13.3.
13.2. Exercising Rights
Who to contact depends on which role we play in relation to that data:
Requests are verified before being actioned and are responded to within the timeframe required by applicable law
13.3 Automated Decision-Making
Risk-based routing may inform whether a transaction is approved or declined. If an individual believes such a decision has significantly affected them, they (or the Client on their behalf) may request a review, express their point of view, or contest the decision by contacting the Client, who controls the underlying transaction and customer relationship.
13.4 Limitations
These rights are not absolute and may be limited by applicable law, including retention obligations. Additional rights specific to California and UK residents are set out in Sections 14 and 15.
14. Notice for California Residents (CCPA/CPRA)
This section applies to California residents whose personal information is processed by the Company, in addition to the rights set out in Section 13, to the extent required by the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA").
Categories of personal information. The categories of personal information the Company collects about California residents correspond to the categories described in Section 6 of this Policy (e.g., identifiers, internet or network activity, geolocation data, and commercial/transaction information). The Company does not collect Social Security numbers, financial account credentials, or other categories.
Sale and sharing. The Company does not sell personal information. To the extent the analytics or marketing cookies described in Section 7 constitute "sharing" of personal information for cross-context behavioral advertising under the CPRA, California residents may opt out via the cookie preference tool on the website or by submitting a request using the contact details in Section 16.
Rights. Subject to applicable exceptions, California residents may exercise the right to:
- know and access the specific pieces and categories of personal information collected;
- delete personal information;
- correct inaccurate personal information;
- opt out of the sale or sharing of personal information;
- limit the use of sensitive personal information; and
- not be discriminated against for exercising any of these rights.
How to exercise these rights. Requests may be submitted using the contact details in Section 1, or by an authorized agent acting on the resident's behalf. The Company will verify the request in accordance with applicable law and respond within the timeframe required by the CCPA.
Role of the Company. Where personal information relating to a California resident is processed as part of the End Users of the Client category, the Company acts as a "service provider" to the Client, who is the "business" under the CCPA. Requests relating to that data should be directed to the relevant Client.
15. Additional Rights for UK Residents
This section applies to residents of the United Kingdom, whose personal data is processed by the Company subject to the UK GDPR and the Data Protection Act 2018.
The rights available to UK residents are the same as those described in Section 13 of this Policy (access, rectification, erasure, restriction of processing, objection to processing, and data portability), and are exercised in the same manner: Client's Authorized Users and Website Visitors should contact the Company using the details in Section 1; End Users of the Client should contact the relevant Client.
International transfers. Where personal data of a UK resident is transferred outside the United Kingdom, the Company relies on an appropriate transfer mechanism recognized under UK data protection law (e.g., the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses), as further described in the DPA.
Right to complain. UK residents have the right to lodge a complaint with the UK supervisory authority, the Information Commissioner's Office (ICO), at ico.org.uk, if they consider that the Company's processing of their personal data infringes applicable data protection law.
16. Changes to This Policy
This Policy is reviewed periodically and may be updated to reflect changes in the Company's services, processing activities, or applicable law. The "Last reviewed" date at the top of this Policy indicates the most recent update. Material changes affecting the Company's PCI DSS scope will be communicated to Clients and acquiring banks in advance.
Appendix A: Technical and Organizational Measures (TOMs)
Appendix B: List of Sub-processors
This list identifies the Company's key sub-processors involved in the processing activities under Policy and Terms of Use. It is not necessarily exhaustive of every vendor engaged by the Company, and may be updated as the Company's vendor arrangements change. The Company will update this list on the website.