Legal
Privacy Policy
Last updated: June 13, 2026
1. Who We Are
Paymos is a stablecoin payment infrastructure for businesses, operated from the Republic of Seychelles (the "Service", "we", "us", "our"). This Privacy Policy explains what data we process when you use the Service — as a merchant with an account, or as a visitor paying through a Paymos checkout — and the rights you have over that data.
This Policy is written to align with the principles of the EU General Data Protection Regulation (GDPR) and the UK GDPR. Where you are located in a jurisdiction with its own data-protection law, that law may grant you additional rights.
By using the Service, you accept the practices described here. If you do not agree, discontinue use of the Service.
2. Scope
This Policy applies to:
- —Merchants — businesses that register an account to accept payments.
- —Checkout visitors — buyers who pay an invoice through a Paymos-hosted or embedded checkout, without a Paymos account.
It does not cover data processed offline or on third-party platforms we do not control.
3. Data We Collect
- —Account data — email address, business name, and country provided at sign-up or in onboarding.
- —Technical data — IP address, device and browser information (User-Agent), log files, and usage and performance data — collected while you use the Service.
- —Blockchain data — wallet addresses, withdrawal-whitelist addresses, transaction history, and balances. This data is read from, or written to, public blockchains.
- —Verification data — government-issued identity documents, proof of address, and related records, collected only if identity verification is triggered under our AML/KYC Policy.
- —Support content — messages, attachments, and metadata you send through in-product or checkout support chat.
We never ask for, and never store, your wallet private keys or seed phrase. Never trust anyone who asks you to enter them.
4. Legal Basis for Processing
We process personal data on the following bases:
- —Performance of a contract — to provide the Service you sign up for.
- —Legitimate interests — to secure the Service, prevent fraud and abuse, and improve the product through aggregate analysis.
- —Legal obligation — to meet anti-money-laundering, record-keeping, and lawful-disclosure requirements.
- —Consent — for non-essential analytics cookies (see Cookie Policy). You can withdraw consent at any time.
5. How We Use Your Data
- —Provide, operate, and maintain the Service.
- —Secure accounts and detect fraudulent or abusive activity.
- —Process account and transaction records when required for manual review, lawful disclosure, or enforcement of account limits (see our AML/KYC Policy).
- —Respond to support requests and communicate with you.
- —Improve Service quality and reliability.
6. Blockchain Transparency
Payments and withdrawals settle on public blockchains. Transaction data on these networks — including sending and receiving addresses, amounts, and timing — is public, permanent, and outside our control. It can be read by anyone and, when combined with other information, may reveal identity.
We are not responsible for how personal data is processed within decentralized, permissionless blockchain networks. Paymos uses public blockchain data to reconcile payments, withdrawals, and balances; this operational use is not a sanctions-screening service for merchants.
7. Third Parties and Sub-Processors
We do not sell your personal data. We share it with service providers strictly as needed to operate the Service:
- —Blockchain infrastructure & cross-chain settlement providers — routing and settling a portion of payments across networks.
- —Email & hosting infrastructure — transactional email, hosting, and storage.
- —Web analytics — aggregate usage measurement (consent-based).
A portion of payments is routed through third-party blockchain infrastructure and cross-chain settlement providers we do not own or control. Their processing is governed by their own terms.
8. Disclosure
We may disclose personal data:
- —To comply with a legal request, court order, subpoena, or official investigation.
- —To law-enforcement or regulatory authorities where we have a good-faith belief it is required.
- —In connection with a merger, acquisition, or restructuring.
- —To affiliates and processors where necessary for operational purposes.
9. Retention
We keep personal data only as long as needed for the purposes above. Verification and transaction records are retained for at least five years from the end of the business relationship, in line with anti-money-laundering record-keeping requirements. Aggregated data that cannot identify you is kept as long as it is useful for reporting and analysis.
10. Your Rights
Subject to applicable law, you have the right to:
- —Access the personal data we hold about you.
- —Rectify inaccurate or incomplete data.
- —Erase your data, where no legal obligation requires us to keep it.
- —Restrict or object to certain processing.
- —Portability — receive your data in a structured, machine-readable format.
To exercise any right, contact [email protected]. We respond within the timeframe required by applicable law.
11. International Transfers
We may process data in jurisdictions other than your own. Where we transfer personal data across borders, we apply safeguards appropriate to the data and the jurisdiction involved.
12. Security
We protect data with encryption in transit and at rest, access controls, and audit logging. Withdrawal signing uses multi-party computation (MPC) threshold signing — no single key exists on the network. No system is perfectly secure, and you are responsible for safeguarding your account credentials.
13. Children
The Service is not intended for anyone under 18. We do not knowingly collect data from children. If you believe a minor has used the Service, contact us.
14. Changes
We may update this Policy. The current version is always on this page. We will notify merchants of material changes by email. Continued use after an update constitutes acceptance.
Questions: [email protected]