Data Protection Policy
How Quantoz Payments B.V. collects, processes, retains and protects personal data, and the rights of the person it relates to.
Version 1.2. September 2026Introduction
Quantoz Payments B.V. (the Company) is committed to protecting and respecting the privacy of its customers. This Data Protection Policy (the Policy), together with the Company's Terms of Use, governs the collection, processing and use of customers' Personal Information.
Personal Information means information that identifies, directly or indirectly, an individual, for example a name, address, e-mail address, transaction data or banking details.
This Policy has to be read in conjunction with the Company's Governance Manual, its AML CFT Policy, its Access Control Policy, its Information Classification Policy and its management of documented information.
The effective date of this Policy is 1 July 2020.
Definitions
In this Policy the following terms and abbreviations are used.
- Company
- Quantoz Payments B.V., a private company with limited liability (besloten vennootschap met beperkte aansprakelijkheid) incorporated under the laws of the Netherlands, having its address at Europalaan 100, 3526 KS Utrecht and registered with the Dutch Chamber of Commerce (Kamer van Koophandel) under number 84071745.
- GDPR
- The General Data Protection Regulation (Regulation (EU) 2016/679).
- Responsible Person
- The Privacy Officer designated by the Company.
- Data processing register
- A register of which personal data the Company processes and how the Company shares and processes that data.
- TPP
- A third-party provider authorised as an account information service provider (AISP) or a payment initiation service provider (PISP) under PSD2.
- XS2A
- The dedicated interface for access to payment accounts referred to in Articles 66 and 67 PSD2 and the regulatory technical standards on strong customer authentication and common and secure communication (Regulation (EU) 2018/389).
- SCA
- Strong Customer Authentication as defined in the regulatory technical standards on strong customer authentication and common and secure communication (Regulation (EU) 2018/389).
Data protection principles
The Company is committed to processing personal data in accordance with its responsibilities under the GDPR. Article 5 GDPR requires that personal data shall be:
- processed lawfully, fairly and in a transparent manner in relation to individuals;
- collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes; further processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes shall not be considered to be incompatible with the initial purposes;
- adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed;
- accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay;
- kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed; personal data may be stored for longer periods insofar as they will be processed solely for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes, subject to implementation of the appropriate technical and organisational measures required by the GDPR in order to safeguard the rights and freedoms of individuals; and
- processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures.
General provisions
- This Policy applies to all personal data processed by the Company.
- The Responsible Person takes responsibility for the Company's ongoing compliance with this Policy.
- This Policy is reviewed at least annually.
Lawful, fair and transparent processing
- To ensure its processing of data is lawful, fair and transparent, the Company maintains a Data processing register.
- The Data processing register is reviewed at least annually.
- Individuals have the right to inspect, correct, delete, limit, transfer or object to the personal data that the Company processes, unless the Company cannot give effect to these rights on the basis of a legal obligation or where exceptions apply.
Lawful bases and processing purposes
All data processed by the Company must be processed on one of the following lawful bases: consent, contract, legal obligation, vital interests, public task or legitimate interests.
The Company collects and processes Personal Information on its site in order for customers to open an account, to use the platform or to perform any transactions on the platform. The types of Personal Information collected are the following, depending on tier level:
- customer name;
- customer photographic identification, including a high-quality image of a government issued identity document, passport or national identity card;
- customer address;
- customer mobile phone number;
- customer e-mail address;
- customer banking details including account numbers;
- customer date of birth;
- customer transactions;
- customer utility bill or bank statement, for confirming the customer's residential address;
- authentication data, including strong customer authentication codes and session or device-identification data, for example a device fingerprint, generated when a customer accesses the platform or a payment account;
- where the customer has granted a TPP access under Open Banking and XS2A access: the customer's consent record and the related TPP access log for that payment account.
The Company uses customers' personal data for the following purposes:
- to personalise the customer experience;
- to improve the Company's website or app;
- to analyse the use of the site or app;
- to improve customer service and respond to service requests and support needs;
- to verify the customer's identity in accordance with the AML CFT Policy and the Company's identity verification procedures;
- to process transactions;
- to send periodic e-mails relating to a customer's order or request, and occasional company news, updates, promotions and related product or service information;
- to administer a contest, promotion, survey or other site feature;
- to grant, upon the customer's explicit consent and after strong customer authentication, a TPP access to payment account information or to initiate a payment on the customer's instruction, under Articles 66 and 67 PSD2.
The Company processes personal data only for the purpose or purposes for which it has been provided, and notes the appropriate lawful basis in the Data processing register. Where consent is relied upon as a lawful basis, evidence of opt-in consent is kept with the personal data. Where communications are sent to individuals based on their consent, the option to revoke that consent is clearly available and systems are in place to ensure such revocation is reflected accurately in the Company's systems.
Data minimisation
- The Company ensures that personal data are adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed.
- Where personal data is shared with a TPP via XS2A, the Company shares only the data elements the TPP is authorised to request for the service instructed by the customer.
Accuracy
- The Company takes reasonable steps to ensure personal data is accurate.
- Where necessary for the lawful basis on which data is processed, steps are put in place to ensure that personal data is kept up to date.
Retention and removal
- The Company holds customers' Personal Information only for as long as is necessary, having regard to the purposes described in this Policy and the Company's legal and regulatory obligations. In accordance with the Company's record keeping obligations, accounts and Personal Information are retained for at least seven years after they are closed by the customer.
- Personal data generated in connection with payment services 1 and 2, including TPP consent records, TPP access logs and strong customer authentication records, is retained for the periods set out in the AML CFT Policy, the Access Control Policy, the Information Classification Policy and the applicable PSD2 and XS2A operational procedures, which govern those categories.
Security
The Company ensures that:
- personal data is stored securely using modern software that is kept up to date;
- access to personal data is limited to personnel who need access, with appropriate security in place to avoid unauthorised sharing of information;
- when personal data is deleted, this is done safely such that the data is irrecoverable;
- appropriate back-up and disaster recovery solutions are in place;
- transaction history and personal data are processed by the Company's backend platform, which is certified to ISO 27001 and with which a data processing agreement has been concluded;
- customer data is processed and stored in European data centres;
- the customer support team is trained, internally or externally, in awareness of the GDPR;
- access to the Company's dedicated XS2A interface is limited to TPPs whose eIDAS QWAC or QSealC certificate has been validated, including its revocation status, and whose PSD2 authorisation has been verified in the EBA register. The consent register is reviewed at least monthly by the Security Officer.
Personal data breaches
- In the event of a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data, the Company promptly assesses the risk to people's rights and freedoms and, if appropriate, reports the breach to the appropriate regulator, the Autoriteit Persoonsgegevens, where required within 72 hours of becoming aware of it, in accordance with Article 33 GDPR.
- The Company has a data breach (datalek) protocol.
- The Company maintains a register for data breach (datalek) incidents.
IP addresses
The Company may collect information about customers' devices, including where available the IP address, operating system and browser type, for system administration. This is statistical data about users' browsing actions and patterns and does not identify any individual.
Cookies
- The Company's site and app may use cookies. Where the Company uses cookies, this is stated in this Policy and in the app.
- The purpose of collecting such information is to evaluate the effectiveness of the site, analyse trends and administer the platform.
- Where third-party service providers are used for placing cookies, they are contractually restricted from using the information they receive from the site other than to assist the Company.
Disclosure of personal information
- Any third party that receives or has access to Personal Information is required by the Company to protect such Personal Information and to use it only to carry out the services it performs for customers or for the Company, unless otherwise required or permitted by law.
- The Company ensures that any such third party is aware of the Company's obligations under this Policy and enters into contracts with such third parties by which they are bound by terms no less protective of any Personal Information disclosed to them than the obligations the Company undertakes to its customers under this Policy, or which are imposed on the Company under applicable data protection laws.
- Access granted to a TPP under Open Banking and XS2A access is not a disclosure to a data processor or sub-processor of the Company: the TPP acts on the customer's own instruction and is independently responsible, as a controller, for its processing of the data it obtains.
Open Banking and XS2A access by third-party providers
- The Company operates a dedicated XS2A interface giving TPPs access to payment accounts, in accordance with Articles 66 and 67 PSD2.
- Before granting access, the Company validates the TPP's eIDAS QWAC or QSealC certificate, including its revocation status, verifies the TPP's PSD2 authorisation in the EBA register, verifies the customer's consent, and applies strong customer authentication in accordance with the applicable regulatory technical standards. Each request is logged.
- The consent register is reviewed at least monthly by the Security Officer. XS2A availability and incident logs are reviewed at least quarterly.
- Denial-of-access decisions are logged.
- Payment instructions, balances and transaction data handled via XS2A are processed in accordance with the Company's Information Classification Policy and the applicable encryption requirements.
- Where the dedicated interface is unavailable for a prolonged period, a fallback channel is made available for TPP access.
Cross-border data transfer
The Company uses data centres in the European Union to store Personal Information.
Contact
If you have any questions relating to this Policy, or if you wish to exercise a right described in it, please contact us at contact@quantozpay.com.
Version 1.2. September 2026. Effective date 1 July 2020.