Last updated 30 July 2026

Privacy Policy

This policy explains how Norcapay collects, uses, shares and protects personal data. It is written to meet the requirements of the EU General Data Protection Regulation (GDPR) and the UK GDPR.

1. Who we are

Norcapay is the controller of the personal data described in this policy. Our registered office is 36 St Thomas Street, London, SE1 9QU, United Kingdom. You can reach us at info@norcapay.com for any privacy question or to exercise your rights.

Where we process payment data on behalf of a merchant, that merchant is the controller and Norcapay acts as a processor under a data processing agreement.

2. Personal data we process

  • Contact and business data: name, surname, email address, phone number, Telegram ID, company details and the requirements you submit through our forms.
  • Onboarding and compliance data: identification documents, ownership structure, licences and other KYC/KYB material required by law.
  • Transaction data: cardholder reference data, amounts, currencies, timestamps, settlement and chargeback records.
  • Technical data: IP address, device and browser information, and logs generated when you use our website or platform.

3. Why we process it and our legal bases

  • Contract (Art. 6(1)(b) GDPR): to respond to enquiries, onboard merchants and provide payment services.
  • Legal obligation (Art. 6(1)(c) GDPR): anti-money-laundering, counter-terrorist-financing, sanctions screening, accounting and regulatory reporting.
  • Legitimate interests (Art. 6(1)(f) GDPR): fraud prevention, risk management, network and information security, and improving our services.
  • Consent (Art. 6(1)(a) GDPR): non-essential cookies and optional marketing communications, which you may withdraw at any time.

4. Sharing your data

We share personal data only where necessary with acquiring banks and card schemes, licensed payment institutions, KYC/AML and fraud-prevention providers, IT and hosting providers acting as our processors, professional advisers, and competent authorities where the law requires it. We do not sell personal data.

5. International transfers

Because we operate globally, personal data may be transferred outside the EEA or the UK. Such transfers are protected by an adequacy decision or by the European Commission's Standard Contractual Clauses (with the UK Addendum where relevant), together with supplementary technical and organisational measures.

6. Retention

Enquiry data is retained for up to 24 months from our last contact. Merchant onboarding, compliance and transaction records are retained for the statutory period applicable to payment and anti-money-laundering records, generally at least five years after the end of the business relationship. After that we delete or anonymise the data.

7. Your rights

  • Access a copy of your personal data.
  • Rectify inaccurate or incomplete data.
  • Erase data where there is no overriding legal obligation to keep it.
  • Restrict or object to processing based on legitimate interests.
  • Receive your data in a portable, machine-readable format.
  • Withdraw consent at any time, without affecting prior lawful processing.
  • Lodge a complaint with your supervisory authority, for example the UK Information Commissioner's Office or your national EU data protection authority.

To exercise any of these rights, email info@norcapay.com. We respond within one month.

8. Security

We apply encryption in transit and at rest, strict access controls, network segregation, logging and regular reviews. Card data is handled within PCI DSS-compliant environments of our acquiring and processing partners.

9. Changes to this policy

We may update this policy from time to time. The date at the top of this page shows when it was last revised; material changes will be communicated to merchants directly.