Legal

Data Protection Notice

This Data Protection Notice provides specific information required under the Data Protection (Jersey) Law 2018, the UK General Data Protection Regulation and, where applicable, the EU General Data Protection Regulation. It supplements our Privacy Policy.

1. Controller

VAULT LIMITED (company number OE025824, registered office: 44 Esplanade, St Helier, Jersey, JE4 9WG), trading as VaultPay is the data controller for personal data collected through vaultpay.org.uk and through our onboarding and compliance processes. Contact: support@vaultpay.org.uk.

2. Categories of data subjects

(a) directors, officers and ultimate beneficial owners of applicant merchants; (b) authorised signatories and operational contacts; (c) employees and contractors of merchants involved in onboarding; (d) representatives of partner institutions; (e) visitors to vaultpay.org.uk; (f) individuals submitting enquiries or complaints.

3. Categories of personal data

Identification, contact, business, financial, technical, communications, risk-screening and audio-recording data as described in our Privacy Policy. Special-category data is not routinely collected; where unavoidable (for example, biometric features in an ID document), it is processed only to satisfy AML obligations.

4. Lawful bases

Performance of a contract (or pre-contract steps), legal obligation (AML/CFT, sanctions, record-keeping), legitimate interests (operating a compliant business, securing our platform, preventing fraud), and consent (marketing communications, certain cookies).

5. Recipients

Acquiring banks, processors and card schemes; KYB/KYC, sanctions and credit-bureau vendors; cloud, email, CRM and identity-verification providers; professional advisers; regulators and law-enforcement authorities upon lawful request; and any successor entity.

6. International transfers

Transfers outside Jersey, the UK and the EEA are protected by adequacy decisions, the UK IDTA, the EU SCCs or equivalent safeguards. A copy of the relevant transfer mechanism is available on request.

7. Retention

Onboarding and AML records: at least five (5) years after the end of the business relationship. Marketing data: until consent is withdrawn. Website analytics: up to twenty-six (26) months. Longer retention may apply where required by law.

8. Data-subject rights

Access, rectification, erasure, restriction, objection, portability and the right to withdraw consent. To exercise any right, email support@vaultpay.org.uk with sufficient information to verify your identity. We will respond within one (1) month, extendable by a further two (2) months for complex requests.

9. Supervisory authorities

Jersey: Office of the Information Commissioner (oicjersey.org). United Kingdom: Information Commissioner's Office (ico.org.uk). EEA residents may also contact their local supervisory authority.

10. Security and breach notification

We apply administrative, technical and physical safeguards as described in our Privacy Policy. In the event of a personal-data breach likely to result in a high risk to data subjects, we will notify the relevant supervisory authority within 72 hours and affected individuals without undue delay, in line with applicable law.

11. Automated decision-making

We do not carry out solely automated decision-making producing legal or similarly significant effects.

12. Contact

Send all data-protection enquiries to support@vaultpay.org.uk with the subject line "Data Protection".

Last updated: May 2026. Questions? Contact support@vaultpay.org.uk.