Privacy Policy

Bitolo respects the right to personal privacy and makes all reasonable efforts to ensure the security and confidentiality of the personal data and other information processed on this website. By visiting this website and/or using the information and/or services contained therein, the Client accepts and agrees that they understand and agree to this Privacy Policy. Bitolo reserves the right to change the provisions of this Privacy Policy at its own discretion; therefore, when visiting this website, the Client has the responsibility to make sure that they are familiar with the newest version of the Privacy Policy which will be available each time the Client visits the website.

Personal Data Management

Some of the data contained on this website, which Bitolo receives directly from the Client and/or public information files, can be considered personal data and therefore will be processed by Bitolo in accordance with the law. The Client may visit this website without providing any information about him/herself, but should the Client wish to start using services offered by Bitolo on the website, Bitolo asks the Client to provide his/her email address and/or phone number, also name and surname or company name, and other information (in accordance with the services the Client aims to use). Bitolo manages the following personal data: name and surname; email address; phone number; company address; IP address; and any other information provided by the Client to Bitolo. Data, which the Client submits, is processed with the following aims: as contact information, to form relevant offer/proposal to the Client, analytics etc. Personal data, or personal information, means any information about an individual from which that person can be identified. It does not include data from which the identity of the individual cannot be discerned (anonymous data).

We use different methods to collect data from and about you. Data is collected through the following:

When you use our website, we may collect, use, store and transfer the following data:

Information you give us while using our website. We may ask you to provide us with personally identifiable information while you use our website. This includes your full name, e-mail address, phone number and your website. Automated technologies or interactions. We may use cookies, server logs and other technologies, such as web beacons, to collect information that your browser sends us when you are using our website. This includes your computer’s internet protocol, browser type, browser version, the country from which you visited our website, how you arrived at our website, length of your visit and which pages you viewed.


Personal data collected from our merchants. We will ask you to provide us with personal data when you apply to become our merchant. We may require you to provide us with additional personal data as you use our Services. If you are a merchant applying to use our Services, we will collect, store and process personal data relating to you and other individuals associated with you, such as full name, email address, date of birth, home address, proof of address, photocopy of a personal identification card or passport and other information as required to on-board you and meet applicable legal requirements. Information provided by third parties. We may collect personal data about you from third parties, as set out below: - Personal data collected while processing your payment. If you are a card-holder making a payment to a merchant using our Services to process your payment, we may, directly or through a merchant using our payment processing service, collect, store and process financial and transaction related personal data about you and your transaction. This may include your billing address, delivery address, date of birth, purchase amount, date of purchase, payment method, credit or debit card number, bank account information and additional necessary information required to process your transaction. Merchants are responsible for providing appropriate privacy information to you about our processing of your data. - When required for compliance with applicable laws (including specifically anti-money laundering and counter-terrorism financing laws and regulations), we may verify your information and collect information from publicly available sources, credit reference or fraud prevention agencies or check data against government sanction lists, either directly, or using identity verification providers or due diligence and screening information providers. - When securing our website and Services, we may collect details about your device, your transaction, your computer’s internet protocol and other technical information, through our data security and firewall providers. - When marketing our Services, we may collect identity and contact data from publicly available sources.

Personal Data

We may process your personal data in the following circumstances: Where we need to perform the contract we are about to enter into, or have entered into with you as our merchant. Where it is necessary for our legitimate interests (or those of a third party) and your interests and fundamental rights do not override those interests, such as mitigating financial loss or other harm to our merchants, you and us. Where we need to comply with legal or regulatory obligations, such as detecting and preventing fraud. Where we need to improve and analyse our products, website, systems and tools.

Examples of how we may process your personal data include:

To manage risk and protect the website, the Services and you from fraud, abuse and other illegitimate activities, by monitoring, detecting and preventing such activities. To comply with our obligations and to enforce the terms of our website and Services, including to comply with all applicable laws and regulations. Process a payment, communicate with third-parties regarding a payment, and provide related customer service. Monitor illegitimate activities and prevent information security risks related to our website and Services. Evaluate your application to use our Services and verify your identity for compliance purposes. Respond to enquiries, send service notices and provide customer support. For audits, regulatory purposes, and compliance with industry standards. Notify you about changes to the nature or terms of our Service. To administer our website, including troubleshooting, data analysis, testing, research, statistical and survey purposes. To improve our website to ensure that content is presented in the most effective manner. Authenticate your access to your account. To improve or modify our Services. To develop new products. To send marketing communications. To conduct aggregate analysis and develop business intelligence that enable us to operate, protect, make informed decisions, and report on the performance of our business. For our legitimate interests, including to: - enforce the terms of our website and Services; - manage our everyday business needs, such as monitoring and analysing; and - anonymise personal data in order to provide aggregated statistical data to third parties, for example to our clients.

Your Data Security

Protecting your information and your privacy is of the utmost importance to us. Being entrusted with some of your most valuable data, we have set high standards for data security. We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed, altered or disclosed in an unauthorised manner. We are PCI DSS (Payment Card Industry Data Security Standard) Level 1 compliant, which is the highest standard set by the payment card industry to ensure that credit card data is processed, stored or transmitted in a secure environment. In addition, we limit access to your personal information to those employees and third parties who have a need-to-know. They will only process your personal information on our instructions and they are subject to a duty of confidentiality. We also have procedures in place to deal with any suspected data security breach and will notify you and any applicable regulator of a suspected breach where we are legally required to do so.

Disclosing Your Personal Data

We share your personal data with trusted third parties for the purpose of providing our Services and promoting our business, as follows:

Affiliates. Your information may be shared with our affiliates at Bitolo, to provide you with our Services.

Business partners, payment industry suppliers and participants to your transactions. We may share your personal data with our merchants and their service providers, card schemes, payment method providers and third party acquirers, as necessary to process payments or provide our Services. The information shared includes: Personal data necessary to facilitate the transaction and activities related to your transaction; Personal data to help our partners resolve disputes and detect and prevent fraud; and Personal data and performance analytics to help our merchants better understand the uses of their platform and to help our merchants enhance their customers’ experiences. Third-party service providers. We may also use third-party service providers acting on our behalf. These service providers help us with data and cloud services, website hosting, data analysis, application services, advertising networks, information technology and related infrastructure, customer service, communications and auditing.