Privacy Policy
Last updated: 2026. This is a template — have it reviewed by legal counsel before going live.
1. Data controller
Cardencer acts as processor or controller depending on the context: controller for merchant account data, and processor for transaction data processed on behalf of merchants and partner payment institutions.
2. What we collect
- Account data — name, email, password hash, business details provided during onboarding.
- Transaction data — payment amounts, card scheme, truncated card numbers, customer email.
- Technical data — IP addresses, device information, and logs used for fraud prevention and security.
3. Why we process it
- To provide the gateway services and your dashboard (performance of contract).
- To prevent fraud and secure the platform (legitimate interest / legal obligation).
- To support onboarding checks performed by licensed partner institutions (legal obligation).
4. Where data lives
Data is stored and processed in the EU. Transfers outside the EEA, if any, use approved safeguards such as SCCs.
5. Retention
Transaction records are retained as required by applicable financial regulations; account data is retained for the life of the account plus statutory periods.
6. Your rights
Under the GDPR you may request access, rectification, erasure, restriction, portability, or object to processing. Contact privacy@cardencer.eu. You may also lodge a complaint with your supervisory authority.