Certain of our subsidiaries may have different privacy policies depending on the services we provide or the countries in which we provide them and the websites relating thereto, in which case additional privacy notices will be provided at or before onboarding and are available on the corresponding website. For a list of such additional country specific privacy policies, please refer to the Region Specific Information section at the end of this policy.
Personal Information We Collect
EVO provides payment acceptance services and value-added merchant services, including transaction processing, point-of-sale terminal management, payment gateway services and integrated solutions (the “Services”). When you submit a request for EVO to contact you via our Websites, you will provide certain personal information which we will use to contact you. We will also collect additional personal data in order to process your application for Services and during the course of your contract for Services with us.
Personal information collected when you submit a ‘contact us’ request or submit an application for our Services online or via our sales teams, or have a contract with us for Services may include:
- Personal and Online Identifiers:Your full name, and, for Know Your Customer (KYC)/Anti-Money Laundering (AML) purposes, we may collect your date of birth, place of birth, nationality, ID document
- Contact Information: Telephone number, email address and postal address
- Internet or Other Electronic Network Activity Information: Authentication data, click-stream data, cookies, pixel tags and other similar technologies that uniquely identify your browser, where you give consent to such technologies where your consent is required
- Your marketing communication preferences
- Geolocation Information: Your IP address, country code, post code, work address, personal address
- Professional or Employment-Related Information
- Financial Information and Commercial Information: Business ownership percentage, tax number (VAT ID or National Insurance Number as applicable), proof of address such as a bank statement, housing contract or a utility bill, bank account information (e.g. bank name, account holder name, address, bank account number and sort code, SWIFT/BIC, IBAN), source of wealth, annual income.
- Account data: Username, password and associated connection details.
- Transaction data: Information about the transactions made via our Services, such as the details of transactions, the details of payment, the amount and timestamp.
- Inferences drawn from the above information about your predicted characteristics and preferences.
We collect the Following Categories of Information from Third Parties:
We may receive referrals from banks, independent software vendors or independent sales organizations with which you have a relationship. This will include your full name, company, email address, telephone number and job title.
How and Why We Use Your Personal Information and What Is Our Lawful Basis for Processing
We process personal information for the following purposes:
- To fulfil a contract, or take steps linked to a contract, i.e. in order to process your application and provide the Services: this is relevant where, in the course of your business or the business of your employer:
- You request or purchase a service from EVO;
- We process your account registration and identify you as a user, including setting up and administering any log-facility available on our Websites;
- We process payments made by your customers;
- We provide customer services, technical support and provide products or services such as on website installations;
- As required by EVO to conduct our business and pursue our legitimate interests, in particular:
- Providing Services to you or your employer, responding to your questions and requests, providing customer service, installing terminals on site, technical support, sending you informational notices, or to contact you if we need to obtain or provide additional information;
- Provision and use of the Websites – information required to provide you with access to Websites and ensure its stability and security
- Facilitating, managing, personalizing, and improving our Services for you.
- Providing you with relevant marketing and assessing the effectiveness of our marketing;
- Preventing and addressing fraud, money laundering or breach of policies or terms. This includes, among other matters, analysing and improving the safety and security of the Services together with implementing and enhancing security measures and protections to combat fraud and identity theft;
- Ensuring the security and integrity of the personal information we process;
- Complying with applicable legal requirements;
- To protect or defend us, our subsidiaries, affiliates, or parent company and any of their officers, directors, employees, agents, contractors and partners, in connection with any legal action, claim or dispute;
- Where you give us consent:
- where consent is required by applicable law, we will send you direct marketing in relation to our relevant products and services, or other products and services provided by us, our affiliates and carefully selected partners.
- where consent is required by applicable law, we place cookies and use similar technologies (see How we use tracking technologies below)
- on other occasions where we ask you for consent, we will use the data for the purpose which we explain at that time.
- For purposes which are required by law:
- In response to requests by government or law enforcement authorities conducting an investigation;
- To comply with legal, regulatory or administrative requirements of governmental authorities, including reporting obligations relating to fraud and anti-money laundering;
How We Use Tracking Technologies
Different types of cookies (or similar tracking technologies) may be used for specific purposes, for example:
These cookies are required to enable core functionality and must be accepted for some Services to work. They can be used for authentication, security or localisation purposes. These cookies are compulsory for the website to be able to function.
Up to 6 months
Functional and performance cookies
These cookies help us improve or optimise the experience we provide. They allow us to measure Website usage and improve performance. These cookies help us understand how visitors interact with EVO’s Services and we use this information to improve user experience and performance.
Up to 6 months
These cookies collect information about your browsing habits in order to make advertising more relevant to you and your interests. They are also used to limit the number of times you see an advertisement as well as help measure the effectiveness of an advertising campaign.
Up to one year
For more information on our use of tracking technologies and cookies, contact us at email@example.com.
Transfer of Personal Information to Third Parties
We are a multinational business headquartered in the United States, with subsidiaries in various countries around the world.
If you are receiving service from one of our subsidiaries in the United Kingdom or the European Union, please refer to the region-specific privacy policies referenced below to find out where your information is being transferred to and the safeguarding mechanism being relied upon for such transfers where necessary.
Generally, your personal information may be disclosed to recipients located outside of your country, including our global subsidiaries, as well as other types of third parties engaged to help us run our business, subject to your consent if required by law.
These types of third parties include distributors of our products and services, service providers retained to perform functions on our behalf or to provide services to us such as accounting, audit, consulting, legal, and other professional service providers, and providers of other services related to our business. Portions of our services may be provided by organizations with which we have a contractual relationship, including subcontractors, and, accordingly, your personal information may be disclosed to them.
If, in the course of our data processing, data is forwarded to service providers or subcontractors, we will be responsible for ensuring that your personal information continues to be protected with the same level of protection as if we were dealing with it directly.
We may also disclose your personal information to third parties:
- in the event we sell or buy any business or assets, in which case we may disclose your personal information to the prospective seller or buyer of such business or assets;
- if EVO or substantially all of its assets are sold, merged with, or acquired by a third party, including at bankruptcy, in which case personal information held by us about our customers will be one of the transferred assets;
- to protect the rights, property or safety of EVO, our customers or others (and this includes exchanging information with other companies and organizations for the purposes of fraud prevention and credit risk reduction).
- With your consent or as otherwise disclosed at the time of collection.
- We may also share aggregate or de-identified information with third parties in our discretion.
We do not sell your personal information to third parties.
Your personal data is stored until the purpose for which it was entrusted to us has been fulfilled or for as long as the law requires us if there is a legal requirement to retain your personal information.
If you are receiving service from one of our subsidiaries in the United Kingdom or the European Union, please refer to our region-specific policies set out below to find out the specific retention periods applicable to you.
Subject to your consent if required by applicable law, we may use your personal information to provide you with direct marketing information about our products and services as well as those of our affiliates and we may permit those affiliates to send their own direct marketing to you. Our direct marketing may be by e-mail, telephone, post or SMS or such other method(s) as may become relevant. In addition, we may provide direct marketing information as allowed by our customers’ respective contracts. If we need your consent for direct marketing communications under applicable law, and if you provide your consent, you will be able to change your mind at any time. To do this you can follow the instructions contained in the communication. For example, in e-mails, we may provide you with an “unsubscribe” link.
Other Websites and Information Security
Other websites that may be linked to or by our website(s) are subject to their own policies which may differ from ours. You should carefully read the privacy policies of these websites before submitting any personal information. We are not responsible for any losses or damages in connection with the information, security, privacy practices, availability, content or accuracy of materials of such third-party websites.
If you are in the US you have the following rights in relation to your personal information:
California Privacy Rights. California residents have certain rights with respect to the personal information collected by businesses. If you are a California resident, you may exercise the following rights regarding your personal information, subject to certain exceptions and limitations:
- The right to know the categories and specific pieces of personal information we collect, use, disclose, and sell about you; the categories of sources from which we collected personal information about you; our purposes for collecting or selling personal information about you; the categories of personal information about you that we have either sold or disclosed for a business purpose; and the categories of third parties with which we have shared personal information.
- The right to request that we delete the personal information we have collected from you.
- The right not to receive discriminatory treatment for the exercise of the privacy rights conferred by the California Consumer Privacy Act (“CCPA”).
Nevada Privacy Rights. Although we do not currently conduct sales of personal information, Nevada residents may submit a request directing us to not sell personal information we maintain about them if our practices change in the future.
To exercise any of the above rights, please contact us using the following information and submit the required verifying information, as further described below:
- By phone at 844-275-5092
- By email: firstname.lastname@example.org.
If you are in the United Kingdom or the European Union subject to certain conditions you have the right to ask us to:
- Provide you with information about our processing of your personal information and give you access to your personal information.
- Update or correct inaccuracies in your personal information.
- Delete your personal information.
- Transfer a machine-readable copy of your personal information to you or a third party of your choice.
- Restrict the processing of your personal information.
- Object to our processing of your personal information for direct marketing purposes.
- Object to our legitimate interests as the basis for processing of your personal information.
- Where consent is the lawful basis, withdraw your consent at any time. The withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.
These rights may be limited, for example if fulfilling your request would reveal personal information about another person, where they would infringe the rights of a third party (including our rights) or if you ask us to delete information which we are required by law to keep or have compelling legitimate interests in keeping. Relevant exemptions are included in the GDPR, UK GDPR, its local implementing legislation and the UK Data Protection Act 2018. We will inform you of relevant exemptions we rely upon when responding to any request you make.
For more detailed information regarding rights that apply to you, please refer to the country specific privacy policies.
To make a query, raise a concern, or exercise your data protection rights, please contact us at email@example.com
ADDITIONAL INFORMATION FOR CALIFORNIA RESIDENTS
This section contains disclosures required by the CCPA and applies only to “personal information” that is subject to the CCPA.
Personal Information We Collect. Please see the section above titled “Personal information We Collect” for a list of the categories of personal information about California consumers we collected in the preceding 12 months. All categories of personal information listed have been disclosed to the categories of third parties designated as “Recipients of California Personal Information” below.
- Our business purposes as identified in the CCPA, which include:
- Auditing related to our interactions with you;
- Legal compliance;
- Detecting and protecting against security incidents, fraud, and illegal activity;
- Performing services (for us or our service provider) such as account servicing, processing orders and payments, and analytics;
- Internal research for technological improvement;
- Internal operations;
- Activities to maintain and improve our services; and
- Other one-time uses.
Recipients of California Personal Information. We do not sell personal information to third parties.
We disclose the categories of personal information designated above to the categories of third parties listed in the section above titled “Transfer of personal information to third parties”.
Verification Process and Required Information. Note that we may need to request additional information from you to verify your identity or understand the scope of your Data Subject request, although you will not be required to create an account with us to submit a request or have it fulfilled. For example, we may ask you for information associated with your account, including your contact information or other identifying information.
Authorized Agent. You may designate an authorized agent to make a CCPA request on your behalf. If you designate an authorized agent to make a rights request on your behalf, we may require proper proof of that authorization as well as direct verification of your identity from you.
Minors’ Right to Opt In. We do not sell the personal information of minors under 16 years of age.
Region Specific Information
Certain of our subsidiaries have privacy policies applicable to the services they are providing in a particular country. Those subsidiaries, countries, and the associated policies are set out below.
EVO Payments International GmbH
EVO Payments International GmbH, Irish branch (trading as BOI Payment Acceptance)
EVO Payments International GmbH, UK Branch (also trading as BOI Payment Acceptance or CardPay from the AA)
Anderson Zaks Limited
Centrum Elektronicznych Ustug Pfatnlczych eServlce Sp. z.o.o.
Universalpay, Entidad De Pago, S.L
EVO Payments International s.r.o.
EVO Czech Republic s.r.o
EMS Payments Mexico S de RL de CV;
EVO Payments Mexico S de RL de CV