Privacy Policy
1. Who we are
P26M is a payment orchestration platform incorporated in the European Union. We act as data controller for the personal data of merchants and their authorised users, and as data processor for transaction data submitted through our payment APIs.
All infrastructure is hosted in AWS eu-central-1 (Frankfurt, Germany). No data is processed or stored outside the EEA.
2. What data we collect
Account & contact data
Name, email address, phone number, company name, and role — collected when you create a merchant account or contact us directly.
Transaction data
Payment amounts, currency, masked card numbers (last 4 digits only), transaction status, PSP response codes, and timestamps. Full PANs are tokenized immediately on receipt via HashiCorp Vault Transit and are never stored in plaintext.
Technical data
IP addresses, API request logs (without cardholder data), browser type, and session identifiers — used for security monitoring and abuse prevention.
3. Legal basis for processing
- Contract performance (GDPR Art. 6(1)(b)) — processing necessary to provide the payment orchestration service.
- Legitimate interest (GDPR Art. 6(1)(f)) — security monitoring, fraud prevention, and service improvement.
- Legal obligation (GDPR Art. 6(1)(c)) — AML, PSD2, and PCI DSS retention requirements.
- Consent (GDPR Art. 6(1)(a)) — analytics cookies and marketing communications (opt-in only).
4. How we use your data
- Routing and processing your payment transactions across PSP partners.
- Providing merchant dashboard access, reporting, and analytics.
- Sending transactional emails (payment confirmations, alerts, invoices).
- Security incident detection and response.
- Compliance with regulatory obligations and audit requirements.
5. Sharing & sub-processors
We share data only as necessary to deliver the service:
- PSP partners — transaction data required to process payments (UPC, OschadBank, PayLink, LiqPay, Hutko). Each PSP is contractually bound to our data handling standards.
- AWS — cloud infrastructure, EU region (eu-central-1) only.
- HashiCorp Vault — self-hosted within our infrastructure. No card data leaves our network to a third-party Vault service.
We do not sell personal data. We do not use data for third-party advertising.
6. Retention
- Transaction records: 13 months (PCI DSS requirement for chargeback defence).
- Financial records: 7 years (EU accounting directive).
- Account data: duration of contract, then deleted within 30 days of termination.
- Security logs: 12 months (AWS CloudTrail, GuardDuty findings).
7. Your rights
Under GDPR you have the right to:
- Access — receive a copy of the personal data we hold about you.
- Rectification — correct inaccurate or incomplete data.
- Erasure — request deletion where no overriding legal obligation applies.
- Portability — receive your data in a structured, machine-readable format.
- Objection — object to processing based on legitimate interest.
- Lodge a complaint with your national data protection authority.
To exercise any right, email our DPO at privacy@p26m.com.
8. International transfers
We do not transfer personal data outside the European Economic Area. All data is processed and stored in AWS eu-central-1 (Frankfurt). Where PSP partners process data outside the EEA, Standard Contractual Clauses are in place.
9. Data Protection Officer
Contact our DPO at privacy@p26m.com for any privacy-related question or rights request.
10. Changes to this policy
We will notify active merchants of material changes at least 30 days in advance via the email address on their account. Continued use of the platform after the effective date constitutes acceptance of the revised policy.