GDPR Compliance Policy

Last Updated:

1. Purpose

This General Data Protection Regulation (“GDPR”) Compliance Policy sets out how VistaPay Limited (“VistaPay”, “we”, “us”, or “our”) ensures compliance with the UK GDPR, the Data Protection Act 2018, and, where applicable, the EU GDPR.

VistaPay is committed to protecting the rights and freedoms of individuals whose personal data we process and to ensuring that personal information is handled lawfully, fairly, and transparently.

2. Scope

This Policy applies to:

  • All personal data processed by VistaPay, whether relating to customers, merchants, suppliers, or employees.

  • All employees, contractors, and third parties acting on behalf of VistaPay.

  • All processing activities carried out in the UK and, where applicable, in the EU.

3. Data Protection Principles

VistaPay adheres to the following GDPR principles. Personal data must be:

  1. Lawfulness, fairness and transparency – processed lawfully, fairly, and in a transparent manner.

  2. Purpose limitation – collected for specified, explicit, and legitimate purposes and not processed in a manner incompatible with those purposes.

  3. Data minimisation – adequate, relevant, and limited to what is necessary.

  4. Accuracy – accurate and, where necessary, kept up to date.

  5. Storage limitation – kept for no longer than is necessary for the purposes for which it is processed.

  6. Integrity and confidentiality – processed securely to protect against unauthorised or unlawful processing, accidental loss, destruction, or damage.

  7. Accountability – VistaPay is responsible for demonstrating compliance with these principles.

4. Lawful Bases for Processing

VistaPay relies on the following lawful bases under Article 6 UK GDPR:

  • Contract – processing necessary to provide our Services.

  • Legal obligation – processing to comply with AML, KYC, tax, and regulatory requirements.

  • Legitimate interests – processing to improve Services, ensure security, prevent fraud, and request feedback.

  • Consent – for marketing communications and optional cookies where required.

Special category data will only be processed under Article 9 conditions (e.g., where required for legal compliance or with explicit consent).

5. Data Subject Rights

VistaPay upholds the rights of individuals, including:

  • Right to be informed.

  • Right of access.

  • Right to rectification.

  • Right to erasure.

  • Right to restrict processing.

  • Right to data portability.

  • Right to object.

  • Rights relating to automated decision-making and profiling.

Requests may be made by contacting privacy@vistapay.co.uk. VistaPay will respond within one month, in line with GDPR requirements.

6. Data Protection Officer (DPO)

VistaPay has appointed a Data Protection Officer (DPO) to oversee compliance with GDPR obligations and act as a point of contact for data subjects and regulators.

Contact: privacy@vistapay.co.uk

7. Data Security

VistaPay applies appropriate technical and organisational measures to ensure personal data is secure, including:

  • Encryption of sensitive data in transit and at rest.

  • Access controls and role-based permissions.

  • Secure development practices for software.

  • Regular penetration testing and security monitoring.

  • Incident response and breach notification procedures.

8. International Data Transfers

Where personal data is transferred outside the UK or EEA, VistaPay ensures that appropriate safeguards are in place, such as:

  • Adequacy regulations issued by the UK or EU.

  • Standard Contractual Clauses (SCCs) approved by the ICO/EU Commission.

  • Supplementary technical and organisational measures where required.

9. Data Retention

VistaPay retains personal data only for as long as necessary to meet legal, regulatory, and contractual obligations:

  • AML/KYC data: minimum 5 years after the end of the business relationship.

  • Transaction data: minimum 5 years after processing.

  • Marketing data: until consent is withdrawn or you opt out.

10. Data Breach Management

VistaPay will:

  • Maintain an incident response plan.

  • Notify the ICO of a notifiable breach within 72 hours of becoming aware of it.

  • Inform affected individuals without undue delay if their rights and freedoms are at high risk.

  • Keep records of all personal data breaches, whether reportable or not.

11. Training and Awareness

All VistaPay employees and contractors receive GDPR and data protection training, with refresher training provided annually.

12. Accountability and Governance

VistaPay maintains internal policies, records of processing activities (RoPA), and regular audits to demonstrate GDPR compliance.

13. Review

This Policy will be reviewed annually, or sooner if there are significant changes in legislation, regulation, or VistaPay’s business model.

14. Approval

This Policy has been approved by the Board of Directors of VistaPay Limited.

Signed:
Syed Ahmad
Director, VistaPay Limited

Date: 9 September 2025