Third Party Index

Snapshot 24239

Document
Privacy policy
URL
https://www.yapily.com/legal/privacy-policy
Fetched
HTTP status
200
Content type
text/html
Fetch mode
static
Size
100837 bytes
SHA-256 (raw)
e652938531b0bc27b6cbdd64d00186e27ef59424a046a854b8bb51f453921b95
SHA-256 (normalized text)
33462474b3ff18274ad3674d2a869facc80f5a0a3606ad99edef4d4043fbe0b3

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Yapily’s Privacy Policy
Last updated: 01/10/2026
This Privacy Policy outlines how we process your information in compliance with the relevant data protection laws, including but not limited to the General Data Protection Regulation (EU 2016/679) (“GDPR”), the Data Protection Act 2018 (“DPA”) and the GDPR, as incorporated under UK law within the Data Protection Act 2018 and amended from time to time ("UK GDPR") (collectively, the “Data Protection Laws”).
If you provide personal information to us on behalf of someone else, you acknowledge that this notice will apply to that data and that you are responsible for informing those third parties that this notice will apply to their personal data and for collecting and recording their consent where necessary.
Please read this Privacy Notice carefully as it sets out the basis on which we collect, use, store, process and protect any personal data from or about you. We may change this Privacy Notice from time to time and encourage you to regularly check the current version which will be available at www.yapily.com (our “Website”).
Who we are
The Yapily Group includes:
Yapily Ltd (company number 10842280) with registered office at 86-90 Paul Street, London, England, EC2A 4NE, United Kingdom (“Yapily Ltd”);
Yapily Connect Ltd (“YC UK”) (company number 11598433), with registered office at 86-90 Paul Street, London, England, EC2A 4NE, United Kingdom; and
Yapily Connect UAB (“YC UAB”) (company number 305602679) with registered office at Palangos g. 4-101, LT-01402 Vilnius, Lithuania (each referred to as “we” or “us” or “our” or collectively (“Yapily”).
Yapily’s Privacy Principles
Data processing at Yapily is based on the following principles:
We are committed to safeguarding the privacy and security of your personal data and processing it in a fair, lawful and transparent manner;
We only collect and use your personal data where we believe we have a valid legal basis to do so;
The personal information we request from you is adequate, relevant and limited to what is necessary for the purposes for which it is processed;
Your personal information is kept no longer than is necessary for the purposes for which the personal information is processed;
We ensure personal information stored within our records is kept accurate and up to date;
Your personal information will be processed in accordance with your data subject rights;
We will ensure that your personal data is securely disposed of at the end of the appropriate retention period;
Our staff are appropriately trained on their privacy obligations and AI literacy; and
We will ensure there are appropriate measures in place to protect your personal data regardless of where it is held and ensure that safeguards are in place before transferring your information to countries outside of the Territories.
What Yapily does
Yapily Ltd provides open banking connectivity via application programming interface (“API”) technology and related services to companies who are Yapily’s customers (our “Clients”) or to their clients (our “Subclients”) in the United Kingdom and Europe (the “Territories”).
YC UK and YC UAB provide Account Information Services (“AIS”) and Payment Initiation Services (“PIS”).
Separately, Yapily offers data products, such as our Data Plus product (collectively, the “Yapily Data Products”).
Our services allow our Clients and Subclients to do business with their customers (who might be individual consumers or corporate “end-users” of AIS / PIS) and to create innovative products to connect to online payment providers like banks and credit card issuers (“Financial Institutions”).
How Yapily uses your personal information
Yapily is the controller of your personal data where we collect this data for our own requirements, such as for our own internal products development, or where you contact us directly via email or as a recruitment candidate.
Where Yapily collects personal data from one of our Clients, Subclients or from a Financial Institution we process that data according to their instructions, meaning Yapily is typically not a controller for the purpose of that processing. However, under certain circumstances, Yapily may need to carry out its own checks on the data subjects this personal data information belongs to so that we can meet our legal obligations to Financial Institutions (e.g. where we are required to carry out KYC checks). Where we process your data for this purpose, Yapily will be the data controller.
Artificial Intelligence (“AI”) I is an umbrella term for a range of technologies that replace manual processes and solve complex tasks by carrying out functions that previously required human action. Tasks that we have traditionally done by thinking and reasoning are increasingly being done by, or with the help of, AI. For example, we are using AI to enhance our customer support and for data enrichment.
Where Yapily is the provider of an AI system, we ensure any personal data used to train the AI is anonymised (except where the models are being used to deliver a service you have explicitly requested). The anonymisation process is carried out within a controlled Yapily environment to keep this data secure. Once anonymisation is complete, the resulting anonymised data is no longer personal data, and its subsequent use falls outside the scope of this Privacy Notice.
Data Plus is our AI enabled transaction categorisation product. Where you request this as part of the service you receive from us, we use the transaction data accessed through the AIS you have requested in order to provide that categorisation to you. We train, maintain and improve the artificial intelligence model behind Data Plus (the categorisation engine) using your transaction data, including in anonymised form, for the purpose of providing a categorisation service you have requested. Our lawful basis for carrying out the anonymisation is described in the section below.
Legal grounds we rely on for the use of your personal information
We will only process your personal information where we have a legally valid reason to do so. Under the GDPR, this is called a legal basis, and more than one legal basis may apply depending on the processing activity. This section is organised by category of data subject. To find the processing information relevant to you, please identify which of the following categories you fall into and refer to the corresponding table:
Customers: individuals whose personal data we process in connection with our commercial relationships, including individuals at Client, Subclient, professional adviser, supplier and Financial Institution organisations, and individuals we contact through social media in connection with our business.
Payment Service Users (“PSUs”): individual end-users of our AIS and PIS services, and individuals whose personal data flows through our platform in connection with those services (in each case where Yapily is acting as controller of that personal data).
Prospective Customers: individuals who have expressed an interest in Yapily's products or services but who are not yet Customers.
Employees and Prospective Employees: our current employees, workers and contractors, and individuals who apply for a role at Yapily.
Where a processing activity applies to more than one category, it is set out in each applicable table below.
Customers
The following table sets out how we process the personal data of Customers.
How we use your information
Personal information we may process:
Legal grounds for Processing
For our own information management purposes, including managing our accounting records, analysis of financial results, internal audit requirements and receiving professional advice.
Contact data: full name, organisation, email address and phone number.
Your financial details.
Consent: You or someone on your behalf has confirmed your consent;
Legal obligation: We may need to process your information to comply with certain legal obligations with regard to the security and operation of our systems and maintenance of accounting records; or
Performance of a contract: Properly managing your information is necessary in order to provide AIS, PIS and other services to you.
Communicating marketing information to you via post, phone, email, text message or social media and developing and tailoring our marketing activities.
Contact data: full name, organisation (if you are a representative of a legal person), email address and phone number.
Your marketing preferences.
Your behaviour and usage data.
Consent: You or someone on your behalf has confirmed your consent; or
Legitimate interest: We have a legitimate business need to tailor advertising to and market to customers and prospective customers who show an interest in us.
Contacting customers via social media
Your name.
Your social media profile.
Legitimate interest: We have a legitimate business need to tailor advertising to and market to customers and prospective customers who actively show an interest in us.
To prevent, detect and investigate fraud, such as by using third party databases to verify your identity.
Your contact and identifying details.
Your location.
Your financial details.
Legal obligation: We have a legal obligation to prevent, detect and investigate fraud.
Complying with our legal or regulatory obligations.
Your contact and identifying details.
Your location.
Your financial details.
Legal obligation: We may need to process your information to comply with certain legal obligations to Financial Institutions.
For research and analytical purposes, to enhance our service quality, training and information security.
Your financial details.
Information shared during your interactions with us, e.g. information via our website.
Consent: You or someone on your behalf has confirmed your consent; or
Legitimate interest: We have a legitimate business need to use your personal information to enhance our service, training and information security.
To communicate with you to resolve any data subject rights requests or complaints you may have.
Contact data: full name, email address and phone number.
Legitimate interest: We have a legitimate interest in receiving, investigating and responding to complaints about our services and in maintaining records of such complaints and their resolution; or
Legal obligation: We may need to process personal data to comply with our statutory obligations relating to your complaint.
Anonymising personal data for the purpose of AI model training and related analytics (e.g. enriching transaction data and deriving point in time insights)
Contact data: full name, email address and phone number.
Records of your interactions with our services and, where applicable, with customer support (e.g. emails, chat logs, transcripts).
Legitimate interest: We have a legitimate business need to anonymise personal data in order to develop and train AI models and generate related analytics, on the basis that the resulting AI models and analytics use only anonymised (non-personal) data.
Payment Service Users (“PSUs”)
The following table sets out how we process the personal data of PSUs.
How we use your information
Personal information we may process:
Legal grounds for Processing
To provide you with our services, such as PIS or AIS.
Identification and contact data: name, email, address. personal code (only if you reside in Lithuania).
Account data: sort code/account number, IBAN, SWIFT, account name, nickname, type, balance, currency.
Transaction data: transaction ID, amount, currency, reference, payee, other transaction details.
We may request additional data (e.g. date of birth) either from you, your Financial Institution or public registers.
Any data required by your Financial Institution for verification purposes, which might include your online user credentials.
Electronic device details: internet protocol (“IP”) address, technical information including hardware model, operating system, browser data, timezone setting, location, device ID, network activity such as which features that you access within our service.
Performance of a contract: The processing of this personal information is necessary to provide our payment services to you, or is necessary as a pre-contractual step in order to provide these services; or
Legal obligation: We may need to process your information to comply with certain legal obligations with regard to KYC and AML.
To provide you with access to PIS or AIS for software development purposes.
Identification and contact data: name, email, address. personal code (only if you reside in Lithuania).
Performance of a contract: The processing of this personal information is necessary to provide our payment services to you, or is necessary as a pre-contractual step in order to provide these services; or
Legal obligation: We may need to process your information to comply with certain legal obligations with regard to KYC and AML.
Complying with our legal or regulatory obligations.
Your contact and identifying details.
Your location.
Your financial details.
Legal obligation: We may need to process your information to comply with certain legal obligations to Financial Institutions.
To prevent, detect and investigate fraud, such as by using third party databases to verify your identity.
Your contact and identifying details.
Your location.
Your financial details.
Legal obligation: We have a legal obligation to prevent, detect and investigate fraud.
To communicate with you to resolve any data subject rights requests or complaints you may have.
Contact data: full name, email address and phone number.
Legitimate interest: We have a legitimate interest in receiving, investigating and responding to complaints about our services and in maintaining records of such complaints and their resolution; or
Legal obligation: We may need to process personal data to comply with our statutory obligations relating to your complaint.
Performing continuous monitoring of transaction data to allow financial health warnings and significant change detection.
Your account identifiers.
Your financial details.
Consent: you or someone on your behalf has confirmed your consent.
Identifying and profiling payment risk behaviour across the Yapily merchant network to reduce payment failure rates and fraud for our merchants.
Your account identifiers.
Your financial details.
Consent: You or someone on your behalf has confirmed your consent; or
Legal obligation: This processing is necessary for Yapily to meet its legal obligations such as detecting and preventing fraud and sanctions checks on its merchant network.
Creating consumer risk profiles of Yapily payment service users to enable informed payment acceptance, credit and risk decisions made by merchants.
Your account identifiers.
Your financial details.
Legal obligation: This processing is necessary for Yapily to meet its legal obligations such as detecting and preventing fraud and sanctions checks on its merchant network; or
Consent: You or someone on your behalf has confirmed your consent.
Providing you with the Data Plus categorisation service
Your account identifiers
Your financial details.
Transaction data
Performance of a contract: processing your transaction data is necessary to provide the categorisation service you have requested; and/or
Consent: you or someone on your behalf has confirmed your consent.
Anonymising personal data for the purpose of AI model training and related analytics.
Contact data: full name, email address and phone number.
Records of your interactions with our services and, where applicable, with customer support (e.g. emails, chat logs, transcripts).
Account identifiers and transaction data
Legitimate interest: We have a legitimate business need to anonymise personal data in order to develop and train AI models, and generate related analytics, on the basis that the resulting AI models and analytics use only anonymised (non-personal) data.
Enriching your transaction data and deriving point-in-time insights, and sharing certain insights with merchants
Account identifiers and transaction data accessed through the AIS you have requested.
Legitimate interest: We have a legitimate business need to enrich and share certain AIS transaction data with merchants. This will enable Yapily to hold more accurate data. It also reduces administrative costs by avoiding the need for repeated AIS calls.
Prospective Customers
The following table sets out how we process the personal data of Prospective Customers.
How we use your information
Personal information we may process:
Legal grounds for Processing
To provide prospective customers who have expressed an interest in our services with additional information.
Your contact and identifying details.
Your marketing preferences.
Your behaviour and usage data.
Consent: You or someone on your behalf has confirmed your consent; or
Legitimate interest: We have a legitimate interest in providing you with additional information where you have actively expressed an interest in our services our products.
Communicating marketing information to you via post, phone, email, text message or social media and developing and tailoring our marketing activities.
Contact data: full name, organisation (if you are a representative of a legal person), email address and phone number.
Your marketing preferences.
Your behaviour and usage data.
Consent: You or someone on your behalf has confirmed your consent; or
Legitimate interest: We have a legitimate business need to tailor advertising to and market to customers and prospective customers who show an interest in us.
To communicate with you to resolve any data subject rights requests or complaints you may have.
Contact data: full name, email address and phone number.
Legitimate interest: We have a legitimate interest in receiving, investigating and responding to complaints about our services and in maintaining records of such complaints and their resolution; or
Legal obligation: We may need to process personal data to comply with our statutory obligations relating to your complaint.
Contacting prospective customers via social media
Your name.
Your social media profile.
Legitimate interest: We have a legitimate business need to tailor advertising to and market to customers and prospective customers who actively show an interest in us.
Employees and Prospective Employees
The following table sets out how we process the personal data of our current employees, workers and contractors, and of individuals who apply for a role at Yapily.
How we use your information
Personal information we may process:
Legal grounds for Processing
To process your application where you have applied for a role at Yapily and, where you are engaged, to carry out pre-employment checks.
Identification and contact data: full name, date of birth, email address, phone number and other identification and/or contact data you provide to us.
Employment & qualifications data: CV, previous employers, roles, academic institutions, etc.
For positions at YC UAB: when required by law we may process data relating to criminal convictions and offences.
Immigration status and documentation: passport, visa, biometric residence permit.
Consent: You or someone on your behalf has confirmed your consent; or
Legal obligation: We are required by law to verify that our employees and workers have the right to work in the jurisdiction in which they are engaged and, where required by the role, to carry out other pre-employment checks.
To administer the employment relationship, including payroll, benefits, pensions, expenses, tax reporting, holiday and absence records, performance management, training and development, and managing the end of your employment.
Identification and contact data.
Employment data: job title, start date, salary, working hours, performance and training records.
Financial data: bank account details for payroll.
Tax and social security identifiers.
Records of leave and absence.
Performance of a contract: The processing of this personal information is necessary to perform our contract of employment with you;
Legal obligation: We may need to process your information to comply with certain legal obligations under employment, tax and social security law; or
Legitimate interest: We have a legitimate interest in properly administering the employment relationship.
To manage employee health, including sickness absence, occupational health and workplace health and safety.
Records of sickness absence.
Occupational health assessments.
Data relating to disability and reasonable adjustments.
Records of accidents and incidents.
Legal obligation: We may need to process your information to comply with certain legal obligations under employment, health and safety and equality legislation; or
Performance of a contract: The processing is necessary to perform our contract of employment with you.
To protect the security and integrity of our IT systems and to monitor use of Yapily systems.
Access logs, device identifiers, IP addresses, application usage data and security event data.
Legitimate interest: We have a legitimate business need to protect the security and integrity of our IT systems and confidential information.
To communicate with you to resolve any data subject rights requests or complaints you may have.
Contact data: full name, email address and phone number.
Any other employee data relevant to the substance of your request or complaint.
Legitimate interest: We have a legitimate interest in receiving, investigating and responding to complaints about our services and in maintaining records of such complaints and their resolution; or
Legal obligation: We may need to process personal data to comply with our statutory obligations relating to your complaint.
Who we share personal information with
We will not share your personal data other than as outlined in this Privacy Notice. We may share your personal data with our staff, our Clients, your Financial Institution and within Yapily as is necessary to carry out the purposes set out in the table above.
Personal data may also be shared with third-parties such as service providers, data processors and their affiliates, sub-contractors or delegates who assist with the running of our Website and provision of our services, e.g., IT services providers, accountants, marketing partners, email hosting services. Some examples of where we may disclose personal information to third parties includes:
to our professional advisers including lawyers, auditors and insurers;
if we sell or buy any business or assets, in which case we may need to disclose certain personal data to the prospective seller or buyer of such business or assets;
if all or substantially all of Yapily’s assets are acquired by a third party, in which case personal data held about our customers will be one of the transferred assets;
if we are under a duty to disclose or share your personal data to comply with any legal or regulatory obligation or for the prevention of crime;
if necessary, to protect the vital interests of a person; and
to enforce or apply our terms and conditions or to establish, exercise or defend the rights of any member of the Yapily group, our staff, clients or others.
Our third-party service providers and data processors are subject to security and confidentiality obligations and are only permitted to process your personal information for specified purposes and in accordance with our instructions.
International Data Transfers
To deliver Yapily’s services to you, it may be necessary for us to transfer your personal data to service providers and business partners located outside of the Territories, including the following service providers and you may find information about how they process personal data at the following web addresses:
Google LLC (“Google”) https://policies.google.com/privacy?hl=en-US
Whenever we transfer your personal data out of the Territories, we ensure a similar degree of protection is afforded to it by ensuring at least one of the following safeguards is implemented:
We will only transfer your personal data to countries that have been deemed to provide an adequate level of protection for personal data by the UK Information Commissioner’s Office or the European Commission;
Where we use service providers based outside the Territories we may use the International Data Transfer Agreement or Addendum approved by the UK Information Commissioner’s Office or the standard contract clauses approved by the European Commission which give personal data the same protection it has in the Territories; and
Other valid transfer mechanisms in accordance with applicable laws.
If you want further information on the specific mechanism used by us when transferring your personal information out of the Territories, please contact our Data Protection Officer using the details set out at section 13 below.
How long we retain your personal data for
We will not retain your personal data for longer than we think is necessary, considering the following:
our contractual obligations and rights in relation to the personal data involved;
legal obligation under applicable law to retain data for a certain period of time;
whether you have since withdrawn your consent for us to hold that data;
statute of limitations under applicable law;
our legitimate interests where we have carried out balancing tests;
fraud and risk management;
potential or actual disputes; and
guidelines issued by relevant data protection authorities.
Your rights as a data subject
Depending upon where you reside, you have various rights regarding your personal data. For example, you may have the right to ask us for a copy of your personal information, ask us to correct mistakes, change the way we use your information, or even ask us to delete it. We’ll either do what you’ve asked or explain why we can’t – usually because of a legal or regulatory issue.
To contact us about any of your data subject rights, please use the details of the Data Protection Officer provided below. Please note that in some cases we may not be able to comply with your request for reasons such as our own obligations to comply with other legal or regulatory requirements. We will always respond to any request you make and if we can't comply with your request we will tell you why.
The following rights may be available to you under the GDPR:
The right to access your personal information
You are entitled to a copy of the personal information we hold about you and certain details of how we use it, including any profiling or automated decision-making taking place. There will not usually be a charge for dealing with these requests. Your personal information will usually be provided to you in a secure electronic format, unless otherwise requested.
The right to rectification
We take reasonable steps to ensure that the personal information we hold about you is accurate and complete. However, if you believe that any of the personal information we hold is incorrect, please let us know so that we can update or amend it. This includes any personal information input into profiles we have created about you.
The right to erasure
In certain circumstances, you have the right to ask us to erase your personal information, for example where the personal information we collected is no longer necessary for the original purpose or if you withdraw your consent (where applicable). However, this will need to be balanced against other factors, for example there may be legal and regulatory obligations which mean we cannot comply with your request. Please note that if we erase your personal data, this may restrict our ability to provide our services to you.
Right to restriction of processing
You are entitled to ask us to stop using your personal information. If you request that we restrict processing of your personal data, this may also restrict our ability to provide our services to you.
Right to data portability
You have the right to ask that we transfer any personal information that you have provided to us in connection with our services to another third party of your choice. Once transferred, the other party will be responsible for looking after your personal information.
Right to object
You have the right to object to the processing of your personal data. An objection may be made in relation to all of the personal data we hold about you or only to certain information. You may also object only to a particular purpose we are processing the data for, such as objecting to marketing or profiling using your data.
Right not to be subject to automated decision-making
You have the right not to be subject to decisions that are made automatically by inputting your personal information into a system or computer. To exercise this right, you simply need to contact us via the details of the Data Protection Officer provided below.
The right to withdraw consent
For certain uses of your personal information, we may ask for your consent. Where we rely on this lawful basis, you have the right to withdraw your consent to further use of your personal information. You can do this by contacting us via the details provided below. Please note in some cases we may not be able to provide our services to you if you withdraw your consent.
The right to lodge a complaint
Under the GDPR, you have the right to complain to the relevant Data Protection government body in the country you reside in at any time if you object to the way in which we use your personal information.
Please note that in some cases we may not be able to comply with your request for reasons such as our own obligations to comply with other legal or regulatory requirements. We will always respond to any request you make and if we can't comply with your request we will tell you why.
Timing and charges
Yapily will respond to you or exercise your rights within thirty (30) days. If the request is very complex or the number of requests received is very high, this term may be extended for sixty (60) days. In this case, we will notify you about this extension and reasons for it within thirty (30) days from your request. Save as described in this Privacy Notice or provided under any applicable data protection laws, there is no charge for the exercise of your legal rights. However, if your requests are manifestly unfounded or excessive, in particular because of their repetitive character, we may either: (a) charge a reasonable fee taking into account the administrative costs of providing the information or taking the action requested; or (b) refuse to act on the request.
Security
We are committed to ensuring that your information is secure. As part of this commitment, Yapily has implemented appropriate technical and organisational security measures to prevent the loss of, damage to or unauthorised destruction of personal data and the unlawful access to or processing of such data.
As part of this commitment, we have systems in place to control your data in a way that minimises its exposure. For example, to prevent unauthorised access or disclosure we have put in place suitable physical, electronic and managerial procedures to safeguard and secure the information we collect.
Where we process personal data for the purpose of anonymisation prior to AI model training, we do so within a segregated Google Cloud environment subject to access controls, and identifiable personal data is not transferred out of that environment. Only the resulting anonymised data is transferred to the separate environment in which our AI models are trained.
External Links
Our Website makes use of certain third-party applications and websites which are subject to their own privacy policies and website terms and conditions. Where you choose to access one of these applications or links, Yapily will not be the data controller and therefore does not control how your data may be processed within those applications and websites.
Children
Our services and our Website are not intended for or directed at children under the age of 16 years and we do not knowingly collect data relating to children.
Contact details of the Data Protection Officer
If you have any questions or want to exercise any of your rights described in this Privacy Notice you can contact: the Data Protection Officer at [email protected] or via post to the address listed below:
Roland Selmer, Data Protection Officer
Yapily Ltd
86-90 Paul Street London EC2A 4NE United Kingdom
If you have any questions or complaints regarding our Privacy Notice or practices, please contact our Data Protection Officer. You also have the right to make a complaint at any time with a supervisory authority in the Territory where you work, normally live or where any alleged infringement of data protection laws occurred.
The supervisory authority in the UK is Information Commissioner’s Office who can be contacted at https://ico.org.uk or telephone on 0303 123 1113.
The supervisory authority in Lithuania is the State Data Protection Inspectorate who can be contacted via email [email protected] or phone (8 5) 271 28 04, (8 5) 279 1445.