1. Introduction
This Privacy Policy explains how UAB UniPayment collects, uses, stores, shares, and protects personal data in connection with this website, our onboarding process, payment-related services, and customer support activities.
UAB UniPayment is a company registered in Lithuania under company code 306661164, with its registered office at A. Goštauto g. 8-224, LT-01108 Vilnius, Lithuania.
For the purposes of applicable data protection laws, including the General Data Protection Regulation (EU) 2016/679, UAB UniPayment acts as the data controller for personal data processed in connection with the services described in this Privacy Policy.
UAB UniPayment provides payment-related services within its permitted scope as an EMI agent and does not provide crypto-asset services.
2. Personal Data We Collect
We may collect and process the following categories of personal data, depending on your relationship with us and the services requested.
Identification and Contact Information
Name, email address, telephone number, residential or business address, date of birth, nationality, identification document details, and other information required for identity verification.
Name, email address, telephone number, residential or business address, date of birth, nationality, identification document details, and other information required for identity verification.
Business and Onboarding Information
Company name, registration number, registered address, business activity, ownership and control structure, director and authorised representative information, source of funds, expected transaction activity, and other information required for customer due diligence.
Company name, registration number, registered address, business activity, ownership and control structure, director and authorised representative information, source of funds, expected transaction activity, and other information required for customer due diligence.
Payment and Transaction Information
Payment account details, Virtual IBAN information, card payment information necessary to process transactions, such as tokenised card data, partial card details, authorisation data, transaction identifiers, transaction amount, currency, payment method, settlement information, refund or chargeback information, transaction status, and related payment records.
Payment account details, Virtual IBAN information, card payment information necessary to process transactions, such as tokenised card data, partial card details, authorisation data, transaction identifiers, transaction amount, currency, payment method, settlement information, refund or chargeback information, transaction status, and related payment records.
Technical and Website Information
IP address, browser type, device information, operating system, pages visited, access times, cookies, and similar technical information collected through our website and systems.
IP address, browser type, device information, operating system, pages visited, access times, cookies, and similar technical information collected through our website and systems.
Compliance and Risk Information
Information obtained through sanctions screening, politically exposed person checks, adverse media screening, fraud prevention tools, transaction monitoring, customer due diligence reviews, and other compliance checks.
Information obtained through sanctions screening, politically exposed person checks, adverse media screening, fraud prevention tools, transaction monitoring, customer due diligence reviews, and other compliance checks.
3. How We Use Personal Data
We may process personal data for the following purposes:
- to provide, operate, and manage our payment-related services;
- to onboard customers and conduct KYC, KYB, AML/CFT, sanctions, and fraud prevention checks;
- to process transactions, settlements, refunds, chargebacks, and account-related activities;
- to communicate with customers, users, partners, and service providers;
- to provide customer support and respond to enquiries;
- to monitor, prevent, and investigate suspicious, fraudulent, unlawful, or unauthorised activity;
- to comply with legal, regulatory, reporting, audit, and record-keeping obligations; and
- to improve our website, systems, products, risk controls, and service performance.
4. Legal Bases for Processing
We process personal data only where we have a lawful basis to do so. Depending on the circumstances, this may include:
Performance of a Contract
Where processing is necessary to provide our services, manage customer relationships, process payments, or respond to service requests.
Where processing is necessary to provide our services, manage customer relationships, process payments, or respond to service requests.
Legal Obligation
Where processing is required for AML/CFT, sanctions screening, fraud prevention, regulatory reporting, tax, accounting, audit, or other legal obligations.
Where processing is required for AML/CFT, sanctions screening, fraud prevention, regulatory reporting, tax, accounting, audit, or other legal obligations.
Legitimate Interests
Where processing is necessary for business operations, risk management, fraud prevention, service improvement, network security, dispute handling, or the enforcement of our rights, provided that such interests are not overridden by your data protection rights.
Where processing is necessary for business operations, risk management, fraud prevention, service improvement, network security, dispute handling, or the enforcement of our rights, provided that such interests are not overridden by your data protection rights.
Consent
Where consent is required by law, including for certain cookies, marketing communications, or other specific processing activities.
Where consent is required by law, including for certain cookies, marketing communications, or other specific processing activities.
5. Sharing of Personal Data
We may share personal data with the following categories of recipients where necessary and lawful:
- banking, payment, card-processing, settlement, and electronic money institution partners;
- identity verification, AML/CFT, sanctions screening, fraud prevention, and compliance service providers;
- technology, hosting, infrastructure, customer support, and website service providers;
- professional advisers, auditors, insurers, and legal representatives;
- regulatory, supervisory, law-enforcement, tax, judicial, or other public authorities where required by law; and
- UniPayment group companies and authorised personnel where necessary for service delivery, compliance, risk management, or operational purposes.
We do not sell personal data.
6. International Transfers
Where personal data is transferred outside the European Economic Area, we take steps designed to ensure that appropriate safeguards are in place in accordance with applicable data protection laws.
These safeguards may include transfers to countries recognised as providing an adequate level of protection, Standard Contractual Clauses approved by the European Commission, or other lawful transfer mechanisms where applicable.
7. Data Retention
We retain personal data only for as long as necessary for the purposes for which it was collected, including the provision of services, compliance with legal and regulatory obligations, dispute resolution, maintenance of business records, and audit and compliance requirements.
Customer due diligence, transaction, and compliance records are retained for the periods required by applicable law and internal policy. Certain records may be retained for a longer period where required or permitted by law, a competent authority, or legitimate audit, legal, or dispute-resolution requirements.
When personal data is no longer required, we delete, anonymise, or securely restrict access to it in accordance with our internal retention procedures.
8. Data Security
We apply technical, organisational, and administrative measures designed to protect personal data against unauthorised access, loss, misuse, alteration, disclosure, or destruction.
These measures may include access controls, encryption, system monitoring, internal policies, staff guidance, vendor controls, and security review procedures.
No system can be guaranteed to be completely secure, but we seek to maintain controls appropriate to the nature and sensitivity of the personal data we process.
9. Your Rights
Subject to applicable law, you may have the right to:
- access your personal data;
- request correction of inaccurate or incomplete personal data;
- request deletion of personal data;
- request restriction of processing;
- object to certain processing activities;
- request data portability;
- withdraw consent where processing is based on consent; and
- lodge a complaint with a supervisory authority.
To exercise your rights, please contact us using the details below. We may need to verify your identity before responding to your request.
You also have the right to lodge a complaint with the State Data Protection Inspectorate of the Republic of Lithuania (Valstybinė duomenų apsaugos inspekcija, VDAI) or another competent data protection supervisory authority.
10. Cookies
Our website uses cookies and similar technologies to operate and secure the website and to support customer communication, security verification, and selected third-party features.
Where consent is required by applicable law, appropriate cookie controls will be provided.
More information is available in our Cookie Policy.
11. Contact
UAB UniPayment has designated a Data Protection Contact for privacy matters.
Data Protection Contact:
UAB UniPayment
A. Goštauto g. 8-224
LT-01108 Vilnius
Lithuania
Email: [email protected]
UAB UniPayment
A. Goštauto g. 8-224
LT-01108 Vilnius
Lithuania
Email: [email protected]
12. Changes to This Privacy Policy
We may update this Privacy Policy to reflect changes in our services, legal requirements, regulatory expectations, or data-processing practices.
The latest version will be published on this page.
Effective date: July 2026
Last updated: July 2026
Last updated: July 2026