Privacy Statement
Last updated 11/05/2023
You can access the Privacy Statement in German here.
1. Introduction
This privacy statement (“Privacy Statement”) is intended to inform you about the processing activities carried out on your Personal Data by Mangopay, as well as your rights as data subject under applicable national legislation, including under Regulation (EU) 2016/679 of 27 April 2016 regarding the protection of data, referred to as the “General Data Protection Regulation” or “GDPR”.
“Personal Data” means any information that relates to an identified or identifiable individual. An identified or identifiable individual is one who can be identified, directly or indirectly, in particular by reference to an identifier (e.g. name, identification number or location data) or to one or more factors specific to his/her physical, physiological, mental, economic, cultural or social identity.
The entity processing your data, acting as data controller, is Mangopay S.A (referred as “Mangopay”, “we”, “our”), with its registered office located at 2 Avenue Amélie, L-1125 Luxembourg and registered in the Luxembourg Business and Companies Registry under number B173459, authorised to exercise payment and electronic money services, in the capacity of an electronic money institution. Mangopay is authorised by the Luxembourg Commission de Surveillance du Secteur Financier, 283 route d’Arlon L-1150 Luxembourg, www.cssf.lu
Mangopay has designated a Data Protection Officer (“DPO”). You may contact the latter at the following e-mail address: dpo.mangopay@mangopay.com
2. Does this Privacy Statement apply to you?
Mangopay provides payment and electronic money services through online platforms (websites or mobile applications) (“the Platforms”) operated by its partners (“the Partners”). These Partners manage Platforms through which they carry out their activities of, for example, online sales, marketplace, intermediation in participative funding (donation, crowdfunding) and have decided to integrate the Mangopay payment solution to process the payments on their Platforms.
When you register with these Partners, you may also be asked to register with the services provided by Mangopay, that will allow you to transfer funds or receive payments for transactions made on the Platforms. To provide these payment or e-money services, Mangopay is required to process your Personal Data.
By “you”, we refer to:
- natural persons who registered for Mangopay's services and/or concluded a contract with Mangopay for the provision of services - these include (i) Partners who are natural persons (i.e. sole traders who conclude a contract with Mangopay); and (ii) Partner’s Platform users, to whom we provide services - these include for example users for whom we create Mangopay accounts and/or enable receipt of funds;
- natural persons who act as legal representatives, shareholders, beneficial owners and/or contact persons employed by the Partner who is a legal person, for the purpose of concluding a contract for provision of Mangopay's services and managing relationship between Mangopay and the Partner (these can include names and surnames of legal representatives, beneficial owners, contact persons etc.);
- natural persons who made payment(s) on a Partner’s Platform without creating a Mangopay account and/or registering for our services.
3. What Personal Data is processed by Mangopay? How is it collected?
Depending on how you interact with Mangopay and which of our services you use, one of the following instances of Personal Data processing will apply to you.
If you are a newsletter subscriber or user of Mangopay's website available at mangopay.com or our blog, your Personal Data can be collected through contact forms and through the use of cookies and similar technologies. For more information on how we process your Personal Data, please refer to our Privacy and Cookies Policy available here.
For other instances of Personal Data processing, please refer to one of the sections below:
- INFORMATION FOR PERSONS WHO REGISTERED FOR MANGOPAY’S SERVICES THROUGH A PARTNER’S PLATFORM
- INFORMATION FOR PERSONS WHO MADE PAYMENT(S) ON A PARTNER’S PLATFORM WITHOUT REGISTERING FOR MANGOPAY’S SERVICES
- INFORMATION FOR PERSONS ACTING AS PARTNER’S LEGAL REPRESENTATIVES, AGENTS, BUSINESS CONTACTS OR BENEFICIAL OWNERS
- INFORMATION FOR PARTNERS WHO ARE SOLE TRADERS (NATURAL PERSONS)
3.1. INFORMATION FOR PERSONS WHO REGISTERED FOR MANGOPAY’S SERVICES THROUGH A PARTNER’S PLATFORM
3.1.1. REGISTRATION DATA
Categories of data. When you register for Mangopay's services through a Partner’s Platform (e.g. when you subscribed to a Partner’s Platform and you wish to accept payments for the goods or services you offer via the Platform), you will be required to provide us with certain Personal Data. The categories of Personal Data processed mainly pertain to identification data, for example, your first and last name, date of birth, nationality, country of residence, email address. You might also be requested to provide, where necessary, a copy of an official identity document or any additional document we consider necessary to comply with our Anti-Money Laundering and Counter Financing of Terrorism (“AML/CFT”) legal obligations. In addition, if you are a US taxpayer or have registered a US bank account, you will be required to provide your TIN number in order for Mangopay to comply with US tax laws and regulation.
Purpose of processing. Your Personal Data is processed for the purpose of creating your Mangopay account, enabling provision of our services to you and ensuring compliance with our AML/CFT obligations as a regulated entity. We also collect and process your Personal Data for the purpose of ensuring security and fraud prevention.
Legal basis. We process your Personal Data because:
- The processing is necessary to fulfill contractual obligations we have towards you
The processing of your Personal Data is necessary for the execution of contractual obligations we have towards you and to take steps, at your request, prior to entering into a contract. This means that the processing is necessary for us to start the provision of Mangopay services to you, as well as registering for Mangopay services which require verification of your identity etc.
- Mangopay has a legal obligation to process your Personal Data
As a regulated entity, Mangopay is subject to strict legal obligations which require it to process certain categories of Personal Data (including copies of your identification document(s)) for the purpose of fulfilling AML/CFT obligations. These obligations are imposed on Mangopay as a licensed e-money institution and are necessary to verify your identity.
- Mangopay has a legitimate interest in processing your Personal Data
In connection with providing services to you, Mangopay processes your Personal Data based on our legitimate interest in preventing fraud and ensuring security of our services.
Your Personal Data is collected directly from the Partner’s Platform through Mangopay's API (technical infrastructure processing the payments). Provision of your Personal Data is mandatory in order to register for Mangopay's services. The required Personal Data is visibly indicated on the collection forms displayed on the Partner’s Platform. Refusal to provide the required Personal Data may result in refusal or suspension of Mangopay's services.
3.1.2. PERSONAL DATA COLLECTED IN CONNECTION WITH PROVISION OF SERVICES TO YOU
Categories of data. Throughout the contractual relationship between you and Mangopay, we will process your Personal Data which is generated through your use of Mangopay's services. This Personal Data includes, but is not limited to, transactional data (amounts transferred, transaction titles, recipients) and bank account data (when payments to your external bank account are executed by Mangopay). We also collect certain technical data related to your device, electronic identifiers, IP address and information on your interaction with the Partner’s Platform for security and fraud prevention purposes.
Purpose of processing. Your Personal Data is processed for the purpose of providing high quality services to you, tailoring services to your needs and ensuring security, as well as fraud prevention. Your Personal Data might also be processed for statistical purposes to enhance the quality of Mangopay's services.
Legal basis. We process your Personal Data because:
- The processing is necessary to fulfill contractual obligations we have towards you
The processing of your Personal Data is necessary for the execution of contractual obligations we have towards you. This means that the processing is necessary for us to provide Mangopay services to you, in particular the execution of payments.
- Mangopay has a legal obligation to process your Personal Data
As a regulated entity, Mangopay is required to process your Personal Data for a prescribed period of time, in order to comply with our AML/CFT obligations
- Mangopay has a legitimate interest in processing your Personal Data
In connection with providing services to you, Mangopay processes your Personal Data based on our legitimate interest in:- preventing fraud and ensuring security of our services
- improving the quality of services based on statistical analysis of your Personal Data
- defending against legal claims and processing Personal Data with relation to legal disputes, if applicable.
Your Personal Data is collected directly from you, through your use of Mangopay's services. Provision of your Personal Data is mandatory in order to enable provision of services. Refusal to provide the required Personal Data may result in refusal or suspension of Mangopay's services.
3.1.3. CUSTOMER SUPPORT DATA
Categories of data. Whenever you contact Mangopay's support team for assistance, your Personal Data will be processed to handle your requests. The Personal Data processed is generally limited to identification data such as your first and last name, email address, phone number, but may also include Personal Data relating to the use of Mangopay's services, depending on the subject of your request and on the actions to be taken by Mangopay's support team. We also process the content of your messages and other communication sent to Mangopay's customer and support teams. Please note that Mangopay's support team may record your telephone conversations for the purpose of ensuring and improving the quality of the services. These recordings are subject to a strict retention period of six months.
Purpose of processing. Your Personal Data is processed for the purpose of responding to your customer support requests and other queries related to provision of Mangopay's services to you. Your Personal Data is processed to ensure you can use our services in an uninterrupted way and that the level of services is of high standard.
Legal basis. We process your Personal Data because:
- The processing is necessary to fulfill contractual obligations we have towards you
The processing of your Personal Data is necessary for the execution of contractual obligations we have towards you, in particular ensuring that you receive high level services.
- Mangopay has a legitimate interest in processing your Personal Data
In connection with providing services to you, Mangopay processes your Personal Data based on our legitimate interest in:- addressing your customer support requests and other queries you may have;
- enhancing the quality of Mangopay's services and of our customer service experience;
- defending against legal claims and processing Personal Data with relation to legal disputes, if applicable.
Your Personal Data is collected directly from you, when you contact us with customer support and other queries, or through the Partner. Provision of your Personal Data is mandatory in order to enable responding to your queries and contacting you. Refusal to provide the required Personal Data may result in Mangopay's inability to respond to your queries and help with troubleshooting.
3.2. INFORMATION FOR PERSONS WHO MADE PAYMENT(S) ON A PARTNER’S PLATFORM WITHOUT REGISTERING FOR MANGOPAY’S SERVICES
Categories of data. When you make a payment by card or using other means of payment (“MOP”) on a Partner’s Platform, it is necessary that you provide certain Personal Data, such as your first and last name, card number, card verification code and expiration date. The types of Personal Data processed may vary depending on the MOP available on the Platform and selected by you. We also collect your Personal Data, such as transactional data, through the execution of the payment order. We also collect certain technical data related to your device, electronic identifiers, IP address and information on your interaction with the Partner’s Platform for security and fraud prevention purposes.
Purpose of processing. Your Personal Data is processed for the purpose of executing your payment.
Legal basis. We process your Personal Data because:
- Mangopay has a legal obligation to process your Personal Data
As a regulated entity, Mangopay is required to process your Personal Data for a prescribed period of time, in order to comply with our AML/CFT obligations.
- Mangopay has a legitimate interest in processing your Personal Data
In connection with providing services to you, Mangopay processes your Personal Data based on our legitimate interest in:- executing your payment order and making your payment possible;
- resolving issues with your payments;
- enhancing the quality of Mangopay's services;
- preventing fraud and ensuring security of our services;
- defending against legal claims and processing data with relation to legal disputes, if applicable.
Personal Data is obtained directly from you. Provision of Personal Data is necessary - if you fail to provide the required information, we will not be able to ensure execution of your payment.
3.3. INFORMATION FOR PERSONS ACTING AS PARTNER’S LEGAL REPRESENTATIVES, BUSINESS CONTACTS OR BENEFICIAL OWNERS
3.3.1. PERSONAL DATA COLLECTED FOR CONCLUSION OF CONTRACT WITH MANGOPAY
Categories of data. In order for our Partners who act in their capacity as legal persons to conclude a contract with Mangopay, we will require provision of certain identification data of the Partner’s legal representatives and beneficial owners. These will include, among others, names and surnames, tax identification numbers, information on place of residence, copies of identification documents and contact details. The list of required documents and/or Personal Data requested may vary depending on circumstances.
Purpose of processing. Your Personal Data is processed for the purpose of concluding the contract for provision of Mangopay's services with the Partner, verification of the representative’s, or beneficiary’s identity, as well as fulfillment of our AML/CFT obligations as a licensed e-money institution.
Legal basis. We process your Personal Data because:
- Mangopay has a legal obligation to process your Personal Data
As a regulated entity, Mangopay is required to process your Personal Data to verify your identity, in accordance with our Know-Your-Business (“KYB”) process, and to retain it for a prescribed period of time, in order to comply with our AML/CFT obligations.
- Mangopay has a legitimate interest in processing your Personal Data
In connection with providing services to you, Mangopay processes your Personal Data based on our legitimate interest in:- enabling conclusion of contract between Mangopay and the Partner for provision of our services;
- preventing fraud and ensuring security of our services;
- defending against legal claims and processing Personal Data with relation to legal disputes, if applicable.
Provision of Personal Data is mandatory in order to enable provision of services. Refusal to provide the required Personal Data may result in our inability to conclude a contract with you and, subsequently, to provide Mangopay's services.
3.3.2. MANGOPAY’s HUB AND DASHBOARD INTERFACE
Categories of data. In order to provide oversight over the payment operations carried out through their Platforms, Mangopay's Partners are provided access to our HUB and Dashboard interfaces. These designed infrastructures provide Partners with a certain degree of supervision and control over the payment flux on their Platforms. In order to provide you access to our HUB and Dashboard, processing of your Personal Data is necessary. The required Personal Data is limited to identification data (such as your first and last name and email address). Personal Data is also generated from the use you make of Mangopay's interfaces (e.g. logs, pages consulted, etc.).
Purpose of processing. Personal Data is processed in order to ensure access to Partner’s employees and other persons authorized by the Partner to the Hub and Dashboard, in order to monitor payments made on the Platform. Data is also processed to provide the Partner with a smooth experience through the display of contextual information, as well as to ensure security.
Legal basis. We process your Personal Data because:
- Mangopay has a legitimate interest in processing your Personal Data
In connection with providing services to you, Mangopay processes your Personal Data based on our legitimate interest in:- enabling provision of high quality services by Mangopay to the Partner and monitoring transactions made on the Platform;
- preventing fraud and ensuring security of our services;
- defending against legal claims and processing Personal Data with relation to legal disputes, if applicable.
Provision of Personal Data is mandatory in order to enable provision of services. Refusal to provide the required Personal Data may result in refusal to provide Mangopay's services.
3.3.3. CUSTOMER SUPPORT DATA
Categories of data. Whenever you contact Mangopay's support team for assistance, your Personal Data will be processed to handle your requests. You can make your requests directly through the HUB. The Personal Data processed is generally limited to identification data such as your first and last name, email address, phone number, but may also include Personal Data relating to the use of Mangopay's services, depending on the subject of your request and on the actions to be taken by Mangopay's support team. We also process the content of your messages and other communication sent to Mangopay's customer and support teams. Please note that Mangopay's support team may record your telephone conversations for the purpose of ensuring and improving the quality of the services through quality control and training. These recordings are subject to a strict retention period of six months.
Purpose of processing. Your Personal Data is processed for the purpose of responding to your customer support requests and other queries related to provision of Mangopay's services to you. Your Personal Data is processed to ensure you can use our services in an uninterrupted way and that the level of services is of high standard.
Legal basis. We process your Personal Data because:
- Mangopay has a legitimate interest in processing your Personal Data
In connection with providing services to the Partner, Mangopay processes your Personal Data based on our legitimate interest in:- addressing your customer support requests and other queries you may have;
- enhancing the quality of Mangopay's services and of our customer service experience;
- defending against legal claims and processing data with relation to legal disputes, if applicable.
Your Personal Data is collected directly from you, when you contact us with customer support and other queries. Provision of your Personal Data is mandatory in order to enable responding to your queries and contacting you. Refusal to provide the required Personal Data may result in Mangopay's inability to respond to your queries and help with troubleshooting.
3.3.4. MARKETING DATA
Categories of data. From time to time, we may reach out to business contacts who represent the Partner in relationship with Mangopay, in order to inform them about the new services we offer and to inform the Partner about possibilities to improve our services. For that purpose we can process, among others, your contact details, such as name, surname, role, e-mail address and/or phone number.
Purpose of processing. Provide you with information about our services and improve the quality of services provided to the Partner.
Legal basis. We process your Personal Data because:
- Mangopay has a legitimate interest in processing your Personal Data
In connection with providing services to the Partner, Mangopay processes your Personal Data based on our legitimate interest in:- direct marketing of our services and those of our group companies, if relevant to the Partner’s scope of business;
- enhancing the quality of Mangopay's services and of our customer service experience.
Your Personal Data is collected directly from you, on a voluntary basis. In case you refuse to provide the required Personal Data, we will not contact you for marketing purposes.
3.4. INFORMATION FOR PARTNERS WHO ARE SOLE TRADERS (NATURAL PERSONS)
3.4.1. PERSONAL DATA COLLECTED FOR CONCLUSION OF CONTRACT WITH MANGOPAY
Categories of data. In order for our Partners who act in their capacity as natural persons to conclude a contract with Mangopay, we will require provision of certain identification data of the Partner. These will include, among others, names and surnames, tax identification numbers, information on place of residence, copies of identification documents and contact details. The list of required documents and/or Personal Data requested may vary depending on circumstances.
Purpose of processing. Your Personal Data is processed for the purpose of concluding the contract for provision of Mangopay's services with you, verification of your identity, as well as fulfillment of our AML/CFT obligations as a licensed e-money institution.
Legal basis. We process your Personal Data because:
- Mangopay has a legal obligation to process your Personal Data
As a regulated entity, Mangopay is required to process your Personal Data to verify your identity, in accordance with our Know-Your-Customer (“KYC”) process, and retain it for a prescribed period of time, in order to comply with our AML/CFT obligations.
- The processing is necessary to fulfill contractual obligations we have towards you
The processing of your Personal Data is necessary for the execution of contractual obligations we have towards you and to take steps, at your request, prior to entering into a contract. This means that the processing is necessary for us to start the provision of Mangopay's services to you, as well as registering for Mangopay's services which requires verification of your identity etc.
- Mangopay has a legitimate interest in processing your Personal Data
In connection with providing services to you, Mangopay processes your Personal Data based on our legitimate interest in:- preventing fraud and ensuring security of our services;
- defending against legal claims and processing Personal Data with relation to legal disputes, if applicable.
Provision of Personal Data is mandatory in order to enable provision of services. Refusal to provide the required Personal Data may result in our inability to conclude a contract with you and, subsequently, to provide Mangopay’s services.
3.4.2. MANGOPAY’s HUB AND DASHBOARD INTERFACE
Categories of data. In order to provide oversight over the payment operations carried out through their Platforms, Mangopay's Partners are provided access to the HUB and Dashboard interfaces. These designed infrastructures provide Partners with a certain degree of supervision and control over the payment flux on their Platforms. In order to provide you access to our HUB and Dashboard interfaces, processing of your Personal Data - or Personal Data of your employees and/or representatives, is necessary. The required Personal Data is limited to identification data (such as your first and last names and email address). Personal Data is also generated from the use you make of Mangopay's interfaces (e.g. logs, pages consulted, etc.).
Purpose of processing. Personal Data is processed in order to ensure access to Partner or Partner’s employees and/or other persons authorized by the Partner to the Hub and Dashboard, in order to monitor payments made on the Platform. Data is also processed to provide the Partner with a smooth experience through the display of contextual information, as well as to ensure security.
Legal basis. We process your Personal Data because:
- The processing is necessary to fulfill contractual obligations we have towards you
The processing of your Personal Data is necessary for the execution of contractual obligations we have towards you. This means that the processing is necessary for us to provide Mangopay services to you within the scope defined in the contract concluded between you and Mangopay.
- Mangopay has a legitimate interest in processing your Personal Data
In connection with providing services to you, Mangopay processes your Personal Data based on our legitimate interest in:- enabling provision of high quality services by Mangopay to the Partner;
- preventing fraud and ensuring security of our services;
- defending against legal claims and processing Personal Data with relation to legal disputes, if applicable.
Provision of Personal Data is mandatory in order to enable provision of services. Refusal to provide the required Personal Data may result in refusal to provide Mangopay's services.
3.4.3. CUSTOMER SUPPORT DATA
Categories of data. Whenever you (or one of your employees/representatives) contact Mangopay's support team for assistance, your Personal Data (or that of your employee/representative) will be processed to handle the requests. The requests can be made directly through the HUB. The Personal Data processed is generally limited to identification data such as first and last name, email address, phone number, but may also include Personal Data relating to the use of Mangopay's services, depending on the subject of the request and on the actions to be taken by Mangopay's support team. We also process the content of messages and other communication sent to Mangopay's customer and support teams. Please note that Mangopay's support team may record your telephone conversations for the purpose of ensuring and improving the quality of the services through quality control and training. These recordings are subject to a strict retention period of six months.
Purpose of processing. Personal Data is processed for the purpose of responding to customer support requests and other queries related to provision of Mangopay's services to you. Personal Data is processed to ensure you can use our services in an uninterrupted way and that the level of services is of high standard.
Legal basis. We process your Personal Data because:
- The processing is necessary to fulfill contractual obligations we have towards you
The processing of your Personal Data is necessary for the execution of contractual obligations we have towards you. This means that the processing is necessary for us to provide Mangopay services to you within the scope defined in the contract concluded between you and Mangopay.
- Mangopay has a legitimate interest in processing your Personal Data
In connection with providing services to you, Mangopay processes your Personal Data based on our legitimate interest in:- enabling provision of high quality services by Mangopay to the Partner;
- preventing fraud and ensuring security of our services;
- defending against legal claims and processing Personal Data with relation to legal disputes, if applicable.
Your Personal Data is collected directly from you, when you contact us with customer support and other queries. Provision of your Personal Data is mandatory in order to enable responding to your queries and contacting you. Refusal to provide the required Personal Data may result in Mangopay's inability to respond to your queries and help with troubleshooting.
3.4.4. MARKETING DATA
Categories of data. From time to time we may reach out to you (or your employees/representatives), in order to inform you about the new services we offer and to let you know about possibilities to improve our services. For that purpose we can process, among others, your contact details or contact details of your employee/representative, such as name, surname, e-mail address and/or phone number.
Purpose of processing. Provide you with information about our services and improve the quality of services provided to the Partner.
Legal basis. We process your Personal Data because:
- Mangopay has a legitimate interest in processing your Personal Data
In connection with providing services to the Partner, Mangopay processes your Personal Data based on our legitimate interest in:- direct marketing of our services and those of our group companies, if relevant to Partner’s scope of business;
- enhancing the quality of Mangopay's services and of our customer service experience.
Your Personal Data is collected directly from you, on a voluntary basis. In case you refuse to provide the required Personal Data, we will not contact you for marketing purposes.
4. Profiling and automated decision-making
For the purpose of fraud, money laundering and terrorist financing prevention, Mangopay relies on profiling, i.e. automated processing of your personal data to evaluate certain personal aspects related to you – in this case we rely on certain technical information, among others, about the device you use, system preferences and information on you interaction with our services.
The processing of your personal data by Mangopay may in some cases lead to automated decision making based on the aforementioned data – for example a temporary block on payment, payout or limitation of access to user account, in the event that based on profiling Mangopay suspects suspicious activity.
The automated decisions are of temporary nature and, in principle, do not result in automated decision-making that could significantly affect your legal rights, produce legal effects or otherwise similarly affect you in a significant way.
However, even if based on particular circumstances an automated decision was considered to produce legal effects or significantly affect you, the decision is necessary for Mangopay for the purpose of entering into and performance of a contract with you (art. 22(2)(a) GDPR). Automated processing of your data is necessary in order to comply with Mangopay’s legal obligations, ensure security of transactions and to prevent fraud, money laundering and terrorist financing. The processing is essential to the services we provide and is necessary to ensure secure payments.
The legal bases of profiling are: 1) performance and execution of the agreement with you; 2) Mangopay’s legitimate interest in ensuring security and fraud prevention.
If you are unhappy with the automated decision based on profiling and would like to contest the decision or receive more information, please contact us at: dpo.mangopay@mangopay.com to exercise your right to human intervention in the automated process.
5. How long is your Personal Data kept?
Mangopay will retain your Personal Data for no longer than is necessary to achieve the defined purpose of the processing activity. Retention periods are defined, among others, based on regulatory requirements to process your Personal Data in order to meet our obligations as an e-money licensed institution. In particular, the following retention periods specifically apply:
- Data which has been provided for the purpose of AML/CFT compliance will be retained for up to ten (10) years, starting from the end of the contractual relationship. This includes any copies of your identification documents, declarative data, as well as transactional data.
- Data necessary for handling potential contestations or disputes and communications with Mangopay's support team will be kept for five (5) years. Audio recordings for quality control purposes will only be kept for a period of six (6) months.
- Data processed for marketing purposes based on our legitimate interest in marketing of our services is processed throughout the contractual relationship with the Partner and/or for three (3) years as of the last contact with the Partner or Partner’s representative. Data subjects have the right to object to processing of their Personal Data for marketing purposes, in which case, upon request, Mangopay will cease processing the aforementioned data immediately.
- Data stored in logs is retained for a period of six (6) months;
- Data necessary for accounting purposes shall be retained for a period of ten (10) years, starting from the closing of the relevant accounting period.
6. Where is your Personal Data stored?
Mangopay relies on a cloud-based infrastructure for the storage of your Personal Data. As part of this infrastructure, the servers used to store your Personal Data are located in Ireland (Dublin) and Germany (Frankfurt).
We might transfer your Personal Data to some processors whose services are necessary for carrying out our services and who are located outside the EU/EEA. In this case, we ensure that appropriate safeguards, such as an European Commission adequacy decision or valid Standard Contractual Clauses (SCCs), are in place.
7. Who are the recipients of your Personal Data? Is it transferred to third parties?
As part of our services and our responsibilities as a regulated entity, your Personal Data may be transferred to the following recipients:
7.1. Affiliates
We share your Personal Data with Mangopay's Affiliate companies. The sharing of your Personal Data with our Affiliates is necessary for the purposes identified under the present Privacy Statement.
7.2 Competent authorities
In order to respond to legitimate requests from competent authorities (e.g. judicial authorities, AML/CFT-related organisations or banking supervisory authorities), Mangopay may be required to disclose your Personal Data. Prior to any disclosure of Personal Data, each request is carefully assessed and documented by our legal department to establish its legitimacy.
7.3 Processors
To ensure a high service level, Mangopay makes use of selected service providers. The latter may be required to process your Personal Data, on our behalf, to deliver the services. We ensure that these processors process your Personal Data only under Mangopay's detailed instructions and exclusively for the purpose of providing the services to Mangopay. Mangopay's third party service providers are carefully selected and are subject to strict contractual obligations, including obligations to ensure an appropriate level of security, confidentiality obligations and obligations to implement appropriate technical and organizational measures, etc.
7.4 Payment partners
Mangopay cooperates with a number of payment partners (including banks and acquirers) in order to protect funds or carry out payment operations as part of providing Mangopay's services. These entities act as separate data controllers and receive your Personal Data for the purpose of processing your transactions. Depending on our relationship with you, the legal basis for the transfer of your data to our payment partners is either the performance of our contract with you (when there is an agreement between Mangopay and you) or our legitimate interest in ensuring that payments are properly executed. The scope of transferred data is strictly limited to transactional data necessary to process payments.
8. What are your rights concerning your Personal Data?
8.1 Right of access
You have the right to access your Personal Data. If you exercise this right, we will send you a description of the processing of your Personal Data (the purposes of data processing, the categories of Personal Data in question, etc.). This information will be provided to you in a currently used electronic format. However, you have the possibility of requesting that this information be provided to you in another format, provided that Mangopay is technically capable of providing you the information in the format requested based on available means and/or on the particularities of the request at hand.
In case you request additional copies, you are informed that we may require the payment of fees based on the administrative costs incurred.
8.2 Right of rectification
If your Personal Data is inaccurate or incomplete, you have the right to request this Personal Data to be rectified or updated.
8.3 Right to erasure (“Right to be forgotten”)
You may request erasure of your Personal Data if one of the following conditions applies:
- Your Personal Data is no longer necessary for the purposes for which it has been collected or processed;
- Your Personal Data has been subject to illegal processing;
- Your Personal Data has been collected solely on the basis of your consent and you would like to withdraw it;
- Based on your particular situation, you object to the processing of your Personal Data that is based on Mangopay's legitimate interests, including profiling, and there are no overriding legitimate grounds for the processing;
- You object to the processing of your Personal Data for direct marketing purposes;
- Your Personal Data must be erased to comply with a legal obligation under applicable law.
Please do note that your request for deletion of your Personal Data will be refused when processing is necessary to exercise the right of the freedom of expression and information, for the exercise or defense of legal claims, or for complying with a legal obligation to which Mangopay is subject, in particular to regulatory Personal Data retention obligations.
8.4 Right to restrict data processing
You have the right to request the processing of your Personal Data to be restricted in one of the following cases:
- If you contest the accuracy of your Personal Data. If processing of your Personal Data is restricted under this ground, it shall only be processed with your consent;
- If the processing is unlawful and you wish that this processing of your Personal Data be restricted rather than erased;
- If your Personal Data is no longer needed for the initial purpose of the processing but it is still necessary for you to establish or exercise defense of legal claims;
- If you have objected to the processing of your Personal Data that is based on Mangopay's legitimate interests in light of your particular situation, processing of your Personal Data will be restricted until verification of whether Mangopay's legitimate grounds override yours.
In case your request for the restriction of the processing of your Personal Data has been granted, we will inform you before the restriction is lifted.
8.5 Right to object to data processing
You have the right to object to the processing of your Personal Data that is based on Mangopay's legitimate interests. Unless Mangopay demonstrates compelling legitimate grounds for the processing which override your rights, freedoms, and interests or if the processing is necessary for the establishment, exercise or defense of legal claims, your Personal Data will no longer be processed.
You also have the right to object to the processing of your Personal Data for direct marketing purposes without demonstrating grounds for objecting.
If your Personal Data is processed by Mangopay for statistical purposes, you have the right to object to the processing on grounds relating to your particular situation. Should you object on this ground, your Personal Data will no longer be processed for this purpose unless processing is necessary for the performance of a task carried out for reasons of public interest.
8.6 Right to data portability
You have a right to receive the Personal Data that you have transmitted to Mangopay if the processing of your Personal Data is based on your consent or a contract between you and Mangopay and is carried out by automated means. Your Personal Data will be transferred in a structured format, currently used and readable by machine. You also have the right to request that your Personal Data be transmitted directly to another data controller, when this is technically possible. In case the processing of your Personal Data is necessary for the performance of a task carried out in the public interest, your request will be rejected.
9. How to exercise your rights?
You may exercise your rights by either contacting Mangopay's Partner or Mangopay at the following e-mail address: dpo.mangopay@mangopay.com. You may also send your request via post to the following address: Mangopay S.A., 2 Avenue Amélie, L-1125 Luxembourg.
For any exercise of rights requests demonstrating a reasonable doubt on your identity, we may request that you verify your identity before addressing your request.
Responses to your requests will be communicated to you electronically, unless you request they be otherwise communicated. In this case, you must specify the preferred format in your request.
Mangopay undertakes to respond to all requests within the legal maximum time limit of one (1) month, starting from the receipt of your request. In case your request is particularly complex or if the number of requests to be handled is particularly important, this time frame may be extended by two (2) additional months. In such a case, we will keep you informed of such an extension and the reasons thereof within the initial one month legal deadline, starting from the receipt of your request.
10. How is your Personal Data secured?
Mangopay implements appropriate technical and organizational measures in order to ensure the confidentiality and integrity of your Personal Data, and specifically, to prevent its destruction, loss, alteration, unauthorized disclosure, or unauthorized access. These security measures include encryption, pseudonymisation, as well as implementing measures that ensure the availability and constant resiliency of our infrastructure.
11. What is the relationship between Mangopay and its Partners for managing your Personal Data?
If you have registered for Mangopay's services or make a payment on a Partner’s Platform, Mangopay is acting as a separate data controller, who processes your personal data independently from the Partner, for the purpose of providing e-money or payment services to you and/or executing your payment. In such cases, the Partners are independently responsible for processing your personal data and ensuring the legality of its processing in connection with operation of their Platform. For more information please refer to Partner Platform’s privacy policy.
However, in some circumstances, Mangopay and Partner may be acting as joint controllers in the processing of your Personal Data, depending on the workflow agreed between Mangopay and the Partner. In such cases, it is the Partner’s and Mangopay's responsibility to carry out the processing of your Personal Data for the following activities in compliance with applicable regulation:
- Registering for and using the services (payment services or electronic money services);
- Managing client relations (for example, providing statements of operations);
- Handling your questions and your potential claims;
- Complying with the legal and regulatory obligations in relation to AML/CFT.
This joint responsibility is contractually established between each Partner and Mangopay through a joint controllership agreement. Should you want to exercise any of your rights as a data subject, you may first directly address the Partner with whom you are in a relationship by following the procedure on the Partner’s platform. Mangopay cooperates with each Partner in order to ensure the protection of your Personal Data. Furthermore, Mangopay cooperates with each Partner in order to ensure the highest level of security of your Personal Data and to respond as efficiently as possible to any of your requests.
12. Contacting Mangopay's supervisory authority
If you consider that your rights have been infringed as a result of the processing of your Personal Data, you have the right to lodge a complaint with or directly contact the Commission Nationale pour la Protection des Données at any time by filing the complaint form available here.
13. Modification of the Privacy Statement
Please note that this Privacy Statement may be updated or modified at any time for important reasons, in particular to reflect any evolutions of our processing activities, changes to our business model or in response to regulatory or legislative changes. The last version will be the one available on Mangopay's website. You will find an indication of the last update on the first page.