This Policy was last updated on 30.07.2026 and is effective as of that date.
Exactly collects information you give us (e.g. your ID documents and financial details), information from Your device (e.g. location or IP address). Additionally, we create new information about You based on how you use our Services.
Exactly uses your Personal Data to run our Services, prevent fraud, make decisions about whether you are eligible to use certain Services, improve our Services, and send you relevant offers (where allowed).
Exactly shares your Personal Data with companies that help us provide our Services, and government authorities and agencies (if the applicable law requires it).
You have control over your Personal Data. For example, you can ask us for a copy of it, request us to delete it or ask us to stop using it (especially for marketing purposes) by contacting dpo@exactly.com. For more details about your rights please read Section 7 below.
Exactly will always keep your Personal Data safe. We will never sell your Personal Data and we will always try to give you as much control as possible over how we process your Personal Data.
Opay Holding Limited is a company registered and incorporated in England and Wales with the registration number 11921832, whose registered office is at Ground Floor, 4 Victoria Square, St Albans, Hertfordshire, United Kingdom, AL1 3TF. We are authorised by the Financial Conduct Authority (“FCA”) as an Electronic Money Institution under the Electronic Money Regulations 2011 (FRN: 901022) to issue electronic money (E‐money) and provide payment services.
In this Policy, Opay Holding Limited, trading as “Exactly” (“Exactly”, "we", "us", "our" or "ours"), shall inform you about the collection, use, retention and processing of Personal Data: i) within our business relation if you intend to be or already are our client; ii) when using our website https://exactly.com/ (hereinafter “Website”) for informative purposes; iii) when you interact with our social media pages; or iv) if you get in touch with us (jointly “Services”). Furthermore, we process Personal Data coming from publicly accessible sources (e.g. commercial registers, registers of associations, media, press, internet) whenever we have a legal ground that allows us to do so.
We will explicitly point out where any information in this Privacy Policy refers exclusively to specific Services. For information related to the usage of cookies or similar technologies on our Website please refer to https://exactly.com/documents/cookies.
This Privacy Policy is provided pursuant to the following (together, "Data Protection Law"):
the UK General Data Protection Regulation, being Regulation (EU) 2016/679 as it forms part of UK domestic law by virtue of Section 3 of the European Union (Withdrawal) Act 2018, as amended ("UK GDPR");
the Data Protection Act 2018;
the Privacy and Electronic Communications (EC Directive) Regulations 2003 (SI 2003/2426), as amended;
the Data Protection, Privacy and Electronic Communications (Amendments etc) (EU Exit) Regulations 2019 (SI 2019/419) and the Data Protection, Privacy and Electronic Communications (Amendments etc) (EU Exit) (No. 2) Regulations 2019;
the General Data Protection Regulation (EU) 2016/679 ("EU GDPR"), where applicable.
This Privacy Policy governs the way we collect, use, store, disclose, retain and protect your Personal Data in connection with the provision of our Services, and describes the rights available to you under applicable data protection law.
What the Personal Data means?
By Personal Data we mean:
That we know about you: if you are a director or an authorised representative of a merchant applying for Exactly’s Services, we may request to provide the identification documents.
Can be used to personally identify you: all and any information about personal or factual circumstances of a specific or identifiable natural person. For instance, a combination of your name, postal address and telephone number.
Data Protection Laws do not apply to information about legal entities (e.g. limited liability companies). However, they do apply to people. When we provide our Services, we process Personal Data of the individuals authorised to set up a Payment Account and give us instructions about the Payment Account, and of the individuals authorised to enter into and act under an agreement on behalf of our customers in connection with the Payment Processing Services. We also may process Personal Data about other employees, representatives and customers of the E-Merchant that receives Services from us.
This Privacy Policy explains what Personal Data we collect, how we use it, and your rights if you want to change how we use your Personal Data, this Privacy Policy only applies to Personal Data within the meaning stated in UK GDPR. It does not apply to company information.
Our Services are not intended for, and we do not knowingly offer or provide them to, individuals under the age of 18. By using our Services, you confirm and warrant that you are at least 18 years old. We are entitled to rely on that confirmation and do not independently verify the age of every user beyond our standard identity verification checks described in this Policy. If we become aware that we have inadvertently collected Personal Data from someone under 18, we will delete that data as soon as reasonably practicable, save where we are required to retain it to comply with a legal or regulatory obligation.
Please read the following policy carefully to understand how we use your Personal Data. Please note, that by using our Services, you authorize and consent to exchange of any information about you between us and third parties in connection with identity or account verification, fraud detection, or collection procedure, or as may otherwise be required by applicable law.
The responsible entity for collection, processing and use of your Personal Data is:
Opay Holding Limited
11921832
Ground Floor, 4 Victoria Square, St Albans,
Hertfordshire, United Kingdom, AL1 3TF
We are the data controller in respect of the Personal data described in this Privacy Policy, except where we process Personal Data as a data processor on behalf of merchants (as described in Section 5 below). Where we act as processor, the relevant merchant is the data controller and is responsible for its own privacy notices to its customers.
Exactly has appointed a Data Protection Officer, who is accessible via dpo@exactly.com.
Some of our Personal Data processing activities can be carried out by a third party on behalf of Exactly. Where processing of Personal Data is carried out on behalf of Exactly, we conclude a separate agreement with the processor in accordance with Article 28 of the UK GDPR.
Our list of processors includes pure data processors, meaning technical service providers, which fall under the following categories:
- IT infrastructure, security and connection providers
- Banking, financial services partners and payments networks, including Visa and Mastercard
- Back office management service providers
- Cloud infrastructure service providers
- Consultancy companies
- Identity verification and KYC service providers (e.g., Onfido Limited).
Exactly can transmit your Personal Data to other entities such as other financial institutions, regulatory and supervisory authorities, as well as public and governmental bodies and agencies, including the FCA, who will act as separate data controllers of your Personal Data, for purposes of:
- Enforcement of claims and defense within legal disputes, based on the legitimate interest of Exactly of exercising its right of defense before courts/competent authorities;
- Complying with legal obligations regarding regulatory, tax and anti-money laundering reporting requirements;
- Fraud prevention, based on the legitimate interest of Exactly not to contract or provide services to any potential customer related to fraud;
- Preventing criminal acts, based on the legitimate interest of Exactly not to contract or provide services to any potential customer related to any crimes.
Furthermore, Exactly will transmit your Personal Data to third parties, meaning other data controllers of your Personal Data, if that is triggered by you in the framework of the provision of our Services to you. Specific separate controllers will be indicated for each processing activity in more detail in the following sections of our Privacy Policy.
We process your Personal Data in accordance with Data Protection Law. To be compliant with such Data Protection Law, Exactly will only process your Personal Data if at least one of the following legal bases applies, as detailed in table below:
| UK GDPR | Legal Basis | What does it mean? |
|---|---|---|
| Article 6 (1)(b) | The processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract. | Personal data is processed to conduct financial services and banking transactions in order to fulfill our pre-contractual and contractual obligations with you. |
| Article 6 (1)(a) | The data subject has given consent to the processing of his or her personal data for one or more specific purposes. | In case you gave your consent to the processing of your Personal Data for specific purposes, the processing is permitted on the legal basis of your consent. Your consent is revocable at any time, as described in Section 7. below. |
| Article 6 (1)(f) | Processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of Personal Data. | We process your Personal Data in order to pursue our legitimate interests or the legitimate interests of a third party, where those legitimate interests override any of your rights and the data processing activities are necessary to satisfy such legitimate interests. In such cases, we have carried out a legitimate interest assessment, where those legitimate interests, impact and guarantees have been analyzed. Those cases are the following: Improving our Services level, based on the legitimate interests of Exactly of improving its internal processes and services offered to its customers and improving the customer experience. Direct marketing for Exactly products and partnership offers, based on the legitimate interest of Exactly to send customers relevant information about updates to existing products, the launch of new products as well as products which are offered together with partners and promotions, including market and opinion analysis. Enforcement of claims and defense within legal disputes, based on the legitimate interest of Exactly of exercising its right of defense before courts/competent authorities. To ensure IT security to provide our Services. Fraud and criminal acts prevention, based on the legitimate interest of Exactly not to contract or provide Services to any potential customer related to fraud and any crime, and in order to protect our customers from fraud related crimes and cyber criminality. To conduct and produce anonymised statistical research and reports. |
| Article 6 (1)(c) | Processing is necessary for compliance with a legal obligation to which the controller is subject. | Exactly is subject to several legal obligations as well as regulatory requirements which require us to process Personal Data, including for purposes of verification of your identity and age, prevention of money laundering and fraud, taking part to judicial proceedings or as part of judicial and police activities, control and reporting obligations based on provisions of the supervisory authorities, tax laws and risk assessment of Exactly. Such obligations derive from the applicable banking legislation and regulatory requirements, including from the Anti Money Laundering Laws, Laws on Countering of Terrorism Financing, Banking Laws, Tax Laws as well as other binding measures on financial matters. |
If you are a merchant, or a director, beneficial owner, or authorised representative of a merchant
When you, or the business you represent, enter into an agreement with Exactly for the provision of our Services, we collect, use and process the following categories of Personal Data:
- Full name, surname
- Date, country, place of birth
- Personal ID (passport, ID card, driving license)
- Address (billing, residence, registered)
- Residence permit
- Email address/ user ID, password
- Payments and transactions data (e.g. amount of the payment, currency of the payment, transaction request date, transaction completion date, bank account details)
- Tax number and tax residence
- Shareholding Information
Our role: Exactly acts as the data controller of this information. We decide why and how it is collected and used.
Why we are allowed to use it: We rely on the fact that this is necessary to perform our contract with you (Article 6(1)(b) of UK GDPR), and that we are legally required, as an FCA-authorised E-Money Institution, to verify our customers under anti-money laundering law (Article 6(1)(c) of UK GDPR).
If you are a cardholder or payment method user
The following Personal Data we process:
- Full name, surname
- Date, country, place of birth
- Card Details (PAN, expiry dates)
- Personal ID (passport, ID card, driving license)
- Address (billing, residence, registered)
- Residence permit
- Email address/ user ID, password
- Payments and transactions data (e.g. amount of the payment, currency of the payment, transaction request date, transaction completion date, bank account details)
- Tax number and tax residence
Our role: Here, Exactly acts as a data processor, not a controller. We process your information only on the instructions of the merchant where you are shopping; the merchant is the data controller responsible for your Personal Data.
What this means for you: If you want to exercise any of your data protection rights regarding a payment you made, you should contact the merchant directly, not Exactly. See Section 7 for more on your rights.
IDENTITY VERIFICATION AND BIOMETRIC DATA
To verify your identity and comply with our legal obligations under anti-money laundering law, we use Onfido Limited, an identity verification service provider, as one of our processors. As part of this process, you may be asked to submit a photograph of your government-issued ID document together with a live photo or short video of your face (a “selfie”), which Onfido uses to confirm that the person submitting the ID is its rightful holder.
This process involves the creation and analysis of biometric data (facial geometry data extracted from your photo or video), which is a special category of Personal Data under Article 9 of the UK GDPR.
Our role: Onfido processes this data on our instructions, acting as our processor. Exactly remains the data controller of this information.
Why we are allowed to use it: We rely on Article 9(2)(g) of the UK GDPR (processing necessary for reasons of substantial public interest), together with the applicable condition set out in Schedule 1, Part 2 of the Data Protection Act 2018 (preventing or detecting unlawful acts), given our legal obligation to verify your identity under anti-money laundering law.
Retention: Biometric data collected for identity verification is retained only for as long as necessary for verification purposes and to comply with our AML record-keeping obligations, as described in Section 8 below, after which it is securely deleted.
AML, CRIMINAL AND FRAUD PREVENTION ACTIVITIES
Separately from processing your payment, we also use Personal Data to detect and prevent fraud, monitor for suspicious activity, screen against sanctions lists, and comply with the rules of International Payment Systems such as Visa and Mastercard.
Our role: For this purpose, Exactly acts as an independent data controller — this processing is carried out for our own purposes, not on the merchant's instructions.
Why we are allowed to use it: This is required by law (Article 6(1)(c) of UK GDPR), and it is also in our legitimate interest to keep the payment system secure and prevent financial crime (Article 6(1)(f) UK GDPR).
Any decisions about your eligibility to use our Services, including as a result of these checks, are reviewed and made by our compliance team. We do not use fully automated decision-making, without human involvement, to make decisions about you that produce legal effects or similarly significantly affect you.
EMAIL COMMUNICATION
When you contact us by email, we collect and process your email address, the content of your message, and any attachments or supporting documents you choose to share with us.
Why we are allowed to use it: where your email relates to an existing contract with us, the legal basis is Article 6(1)(b) of UK GDPR. Otherwise, the legal basis is our legitimate interest in responding to your enquiry, in accordance with Article 6(1)(f) of UK GDPR. For more on legitimate interest, see Section 4 above.
SOCIAL MEDIA PLUGINS
On our Website we have share buttons linking to Facebook, Instagram, Twitter and LinkedIn. These are not third-party plugins, and do not actively send or allow third parties to fetch Personal Data or any sort of information whatsoever. The share buttons are hyperlinks that only redirect you to the respective website of the third party when clicked.
EXACTLY SOCIAL MEDIA PAGES
Exactly maintains publicly accessible social media pages on Facebook, Instagram, Twitter and Linkedin (hereinafter “Exactly Social Media Pages”; the networks jointly “Social Pages Networks”). When visiting our Social Media Pages on the Social Media Networks, the networks collect Personal Data of you as an internet user.
LinkedIn, a social media network operated by LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland (hereinafter referred to as “LinkedIn”), provides us with usage statistics related to user growth, user demography, use of the individual functionalities). LinkedIn compiles these statistics of Personal Data, which LinkedIn collects when you visit our LinkedIn page. Such data processing serves our legitimate interest in improving the user experience for our page visitors in a target group-oriented manner. The legal basis for data processing is therefore Art. 6 (1) (f) of UK GDPR. For more information on the legitimate interest as a legal basis for processing data, please see Section 4. above. We have no access to the Personal Data that LinkedIn collects to compile these statistics and cannot link these statistical data to the profiles of our fans or individual users.
In addition, LinkedIn uses cookies, which are stored on your device when you visit our page. This can apply even if you do not have a LinkedIn account or are not logged into your account while visiting our profile page. You can find details on the collection and storage of your Personal Data and on the type, scope and purpose of their use by LinkedIn in LinkedIn's privacy policy at: https://www.linkedin.com/legal/privacy-policy. We are jointly responsible with LinkedIn for the processing of your Personal Data for this purpose. We have concluded an agreement with LinkedIn in regards to the joint controllership (in terms of Article 26 of UK GDPR). You can find it here: https://legal.linkedin.com/pages-joint-controller-addendum.
Facebook, a social media network operated by Meta Platforms Ireland Ltd., 4 Grand Canal Square, Dublin 2, Ireland (hereinafter referred to as “Meta”), provides us with usage statistics related to number of site visitors, demographics of site visitors, use of the individual functionalities. Meta compiles these statistics of personal data, which Meta collects when you visit our Facebook social media page. Such data processing serves our legitimate interest in improving the user experience for our page visitors in a target group-oriented manner. The lawful basis for this data processing is our legitimate interest, in accordance with Art. 6 (1) (f) UK GDPR. For more information on the legitimate interest as a legal basis for processing data, please see Section 4. above. We have no access to Personal Data that Facebook collects to compile these statistics and cannot link these statistical data to the profiles of our followers or individual users.
In addition, Facebook uses cookies, which are stored on your device when you visit our Facebook social media page. This can apply even if you do not have a Facebook account or are not logged into your account while visiting our Facebook social media page. We have no access to personal data that Meta collects while using cookies. You can find details on the collection and storage of your personal data and on the type, scope and purpose of their use by Meta in Meta's Privacy Policy at: https://www.facebook.com/policy.php. We are joint controllers with Facebook for the processing of your personal data for this purpose. We have concluded an agreement with Facebook in regards to the joint controllership (in terms of Article 26 of UK GDPR). You can find it here: https://www.facebook.com/legal/terms/page_controller_addendum. Please find additional information here: https://www.facebook.com/legal/terms/information_about_page_insights_data.
Instagram, a social media network operated by Meta, provides us with usage statistics related to user growth, user demography, use of the individual functionalities. Meta compiles these statistics of personal data, which Meta collects when you visit our Instagram social media page. Such data processing serves our legitimate interest in improving the user experience for our page visitors in a target group-oriented manner. The lawful basis for this data processing is our legitimate interest, in accordance with Article 6 (1) (f) of UK GDPR. For more information on the legitimate interest as a legal basis for processing data, please see Section 4. above. We have no access to the Personal Data that Meta collects to compile these statistics and cannot link these statistical data to the profiles of our fans or individual users.
In addition, Instagram uses cookies, which are stored on your device while visiting our Instagram social media page. This can apply even if you do not have an Instagram account or are not logged into your account while you are visiting our Instagram social media page. We don’t have access to personal data that Instagram collects while using cookies. You can fi nd details on the collection and storage of your personal data and on the type, scope and purpose of their use by Instagram in Instagram's Privacy Policy at:
https://help.instagram.com/519522125107875. We are jointly responsible with Meta, as the operator of Instagram for the processing of your Personal Data for this purpose. We have concluded an agreement with Meta as the operator of Instagram in regards to the joint controllership (in terms of Article 26 of UK GDPR). You can find it here:
https://www.facebook.com/legal/terms/page_controller_addendum.
Please find additional information here: https://www.facebook.com/legal/terms/information_about_page_insights_data.
Data Processing by Exactly
If we use our Social Media Pages to contact us (for instance, by creating your own posts on our Social Media Pages or by tagging us, responding to one of ours posts or by sending us private messages) we collect Personal Data that you provide to us. We only use such Personal Data for the purpose of communicating with you in order to provide the requested information.
When you reach out to us regarding any contractual matters related to our Services, the lawful basis for the data processing is Article 6(1)(b) of UK GDPR. Otherwise the lawful basis for data processing is our legitimate interest, in accordance with Article 6 (1)(f) of UK GDPR. Such data processing serves our legitimate interest in allowing us to communicate with you upon your inquiry and answer your request. For more information on the legitimate interest as a legal basis for processing data, please see Section 4. above. We delete stored data when they are no longer necessary for this purpose or to comply with any applicable statutory requirements.
As Exactly provides an international service, we may transfer your Personal Data outside the United Kingdom in order for us to provide our Services.
In order to ensure an appropriate level of data protection equivalent to that granted under the Data Protection Law upon the international transfers of Personal Data, Exactly has implemented one or more of the following transfer mechanisms, in addition to safeguards in accordance with the international data transfer impact assessment on the respective data transfer, if applicable:
- Where the Secretary of State has made adequacy regulations under Article 45 of the UK GDPR confirming that the third country, territory, sector, or international organisation in question provides a standard of data protection that is not materially lower than that required under the UK GDPR, we rely on those regulations. A current list of countries, territories, sectors, and international organisations covered by UK adequacy regulations is published by the Information Commissioner's Office at https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/international-transfers/adequacy-regulations/is-the-restricted-transfer-covered-by-adequacy-regulations/
- Binding Corporate Rules (“BCRs”) approved as per Article 47 of UK GDPR, pursuant to Art. 46 (2) (b) of UK GDPR;
- Where no adequacy regulations apply, we rely on appropriate safeguards under Article 46 of the UK GDPR, in the form of the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, issued by the Information Commissioner's Office under Article 46(2)(c) of the UK GDPR. The current versions of these instruments are published by the Information Commissioner's Office at https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/international-transfers/appropriate-safeguards/what-are-standard-data-protection-clauses-the-uk-idta-and-the-addendum/;
- Your explicit consent under Article 49 (1) (a) of UK GDPR, when we transmit data to entities located outside the United Kingdom in third countries that don't provide an adequate level of protection of Personal Data in the terms of the UK GDPR and none of the other transfer mechanisms apply.
You have the following rights concerning your Personal Data:
| UK GDPR | Your right | What does it mean? |
|---|---|---|
| Article 7(3) | right to revoke your consent | If you have given us any consent we need to use your Personal Data, you can withdraw your consent at any time by sending an email to dpo@exactly.com. (Please note, it will have been lawful for us to use the Personal Data up to the point you withdraw your permission) |
| Article 15 | right of access | means you can request information on whether your Personal Data is being processed by Exactly and information on the particular processing of Personal Data, at any time, along with a copy of the information processed. In no case this right covers the access to documents or the obtention of copies of such documents. |
| Article 16 | right of rectification | means you can request the rectification of your data when they are incomplete or inaccurate. |
| Article 17 | right to erasure | means you can request the deletion of your personal data when they are no longer required by Exactly for the purposes they were initially collected for, or when you understand they have been illicitly used. Exactly can reject your request, if the data is necessary to comply with a legal obligation, for public interest reasons or for legal actions. |
| Article 18 | right to restriction of the processing | means you can request the restriction of the processing of your Personal Data when it is legally permitted and, in particular: (i) while you challenge the accuracy of your data, (ii) when you request the restriction of your data because you believe the processing is unlawful, or (iii) when the data is no longer needed for the purposes for which it was collected but Exactly needs them for legal actions. |
| Article 20 | right to data portability | means you can request Exactly to provide you Personal Data, in a structured, commonly used and machine-readable format and to transmit your data to another controller where the data processing is based on the consent, or on a contract and the processing is carried out by automated means. |
| Article 21 | right to object to the processing | If our legal basis for using your Personal Data is “Legitimate interests” and you disagree with us using it, you can object. However, if there is an overriding reason why we need to use your Personal Data, we will not accept your request. If you object to us using Personal Data which we need to provide our Services, we may need to close your Payment Account as we won’t be able to provide the Services. |
| Article 77 | right to lodge a complaint with a supervisory authority | means that you can complain before the supervisory authority if you consider that the processing of your Personal Data by Exactly infringes the UK GDPR. |
Your ability to exercise these rights will depend on several factors. Sometimes, we won’t be able to agree to your request (for instance, if we have a legitimate reason for not doing so or the right does not apply to the information, we hold about you).
Instructions for exercising Your Rights
You can send us an email at dpo@exactly.com.
Please note that for the security reasons, we can’t deal with your request if we are not sure of your identity, so we may ask you for proof of your ID. If a third party exercises one of these rights on your behalf, we may need to ask for proof that a third party has been validly authorised to act on your behalf.
Under Data Protection Law, when you exercise one of these rights, Exactly has 30 (thirty) days to give you a response or implement your changes.
Exactly will not charge you a fee when you exercise your rights. However, we are allowed by law to charge a reasonable fee or refuse to act on your request if it is manifestly unfounded or excessive.
If you are not satisfied with how we have handled your request, you can complain to the Information Commissioner’s Office https://ico.org.uk/.
We store your Personal Data for as long as it is necessary to fulfil purposes for which it was collected, including for the performance of our Services to you and other obligations resulting from the binding agreements, compliance with legal and regulatory obligations, and the establishment, exercise, or defence of any disputes and legal claims.
Where Personal Data is no longer required, it is securely deleted, destroyed, or anonymised. Where legal or regulatory requirements mandate longer retention periods than those specified above, we retain the relevant data for those extended periods. We may retain Personal Data for longer periods where required for the purposes of ongoing legal proceedings, regulatory investigations, or enforcement actions. Specifically:
- Performing regulatory and tax retention periods, which relate to the applicable laws and complementary regulation, including but not limited to the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017, applicable banking and financial services legislation, and tax legislation. The statutory retention periods and documentation obligations are between 2 (two) to 10 (ten) years depending on the specific obligation and category of Personal Data concerned. The applicable legal basis is Article 17(3)(e) of the UK GDPR together with Article 6 (1)(f) of UK GDPR.
- Keeping evidence in the context of statutory limitation periods. According to domestic laws of the United Kingdom, including the Limitation Act 1980 and in particular the primary 6 (six) year limitation period for claims founded on contract or tort under Sections 2 and 5 of the Limitation Act 1980. The applicable legal basis is Article 17(3)(e) of UK GDPR together with Article 6 (1)(f) of UK GDPR.
Furthermore, whenever your consent is the legal ground to process your Personal Data, Exactly will store that data for as long as you do not revoke your consent or until your account is closed, whatever happens the latest.
Exactly recognises the importance of protecting and managing your Personal Data. Any Personal Data we process will be treated with the utmost care and security. This Section sets out some of the security measures we have in place.
We take reasonable measures, including administrative, technical, and physical safeguards, to protect your Personal Data from loss, theft, misuse, and unauthorized access, disclosure, alteration, and destruction. We hold information about you at our own premises in accordance with the recommendations of the Payment Card Industry Security Standards Council, Customer card details are protected using Transport Layer encryption — TLS 1.2 and application layer with algorithm AES and key length 256 bit. We restrict access to personal information to our employees, contractors, and agents who need to know that information in order to transmit, store, or process it, who are subject to contractual confidentiality obligations consistent with this Policy, and who may be disciplined or terminated if they fail to meet these obligations.
When you use our public services, which includes our social network accounts, do not share any personal data that you don't want to be seen, collected or used by other customers, as this Personal Data will become publicly available.
Please note that no transmission of information via the internet is completely secure and no storage system is guaranteed to be entirely secure. If you have any reason to believe that your interaction with us is no longer secure, please contact us immediately.
We may change or update this Privacy Policy. Any changes we may make to this Privacy Policy in the future will be posted on the Website and any such changes will be effective starting from the date when we post the revised Privacy Policy. We may provide You with notifications regarding the changes in the Privacy Policy by posting them on our Website.
If you have any questions, concerns, or complaints about this Privacy Policy or about the way we process your Personal Data, or if you wish to exercise any of your data protection rights, please contact our Data Protection Officer:
Data Protection Officer: dpo@exactly.com
Postal address: Data Protection Officer, OPAY HOLDING LIMITED, Ground Floor, 4 Victoria Square,St Albans, Hertfordshire,United Kingdom, AL1 3TF
General Enquiries: support@exactly.com
Information Commissioner’s Office (“ICO”) (UK Data Protection Supervisory Authority): www.ico.org.uk | 0303 123 1113