Legal

Privacy Policy

Last updated: July 13, 2026

Draft notice: This policy is a working draft and must be reviewed by qualified privacy counsel before publication or use.

1. Scope and who we are

This Privacy Policy explains how Zentech Innovation Ltd, operating as ZenoraPay("we," "us," or "our"), collects, uses, discloses, and protects personal information when you visit our website, request a demo, create or use an account, integrate with our platform, receive support, or otherwise interact with our services (the "Services").

This policy applies where we act as a controller or business deciding why and how personal information is processed. When we process personal information on a merchant's instructions, that merchant is generally the controller or business and its privacy notice applies; our data processing addendum governs our role as processor or service provider.

2. Personal information we collect

Identity and contact information

Name, business name, job title, email address, telephone number, billing address, and account identifiers.

Business and verification information

Company details, ownership or representative information, industry, expected activity, tax details, and documents or screening results used for onboarding and compliance.

Account and transaction information

Plan, settings, users, order and payment references, amounts, currencies, wallet addresses, network and settlement records, refund information, and support history.

Device and usage information

IP address, browser and device type, operating system, timestamps, pages viewed, referring URLs, approximate location, cookie identifiers, logs, and interactions with our Services.

Communications and preferences

Messages, demo or sales requests, survey responses, support communications, and marketing or cookie preferences.

We may also process sensitive information required for identity, fraud, sanctions, or regulatory checks. Payment card details are intended to be collected and processed by authorized payment providers rather than stored by us, except for limited tokens, references, and transaction metadata needed to operate the Services.

3. Sources of personal information

We collect information directly from you and your organization; automatically from browsers, devices, cookies, and use of the Services; from merchants when their customers transact; and from payment, identity-verification, fraud-prevention, sanctions-screening, blockchain analytics, ecommerce, wallet, marketing, analytics, and support providers. We may also receive information from public records and business partners where permitted by law.

4. How we use information and our legal bases

We use personal information to:

  • provide, configure, maintain, support, and improve the Services;
  • create accounts, authenticate users, and manage integrations;
  • facilitate payments, conversion, settlement, refunds, and reconciliation;
  • verify businesses and identities and prevent fraud, abuse, and security incidents;
  • meet legal, tax, sanctions, anti-money-laundering, and recordkeeping duties;
  • communicate about transactions, service changes, support, and security;
  • analyze performance and develop features using aggregated or de-identified data;
  • market our Services where permitted and honor communication preferences; and
  • establish, exercise, or defend legal claims and enforce agreements.

Where the GDPR or UK GDPR applies, our legal bases may be performance of a contract, steps requested before a contract, compliance with legal obligations, our or another party's legitimate interests (including security, fraud prevention, service improvement, and business communications), and consent where required. We may process special-category data only where an additional lawful condition applies.

5. Fraud checks and automated processing

We and our providers may use automated signals to identify fraud, security, sanctions, or compliance risk and to route a transaction or account for review. These checks may affect whether a payment or account is approved. Where applicable law grants rights concerning a decision based solely on automated processing with legal or similarly significant effects, you may request human review and provide additional information.

6. How we disclose personal information

We may disclose information to your organization and its authorized users; our processing partner Mercuryo; other payment processors, conversion and settlement providers, networks, banks, wallets, and ecommerce platforms; identity, compliance, fraud, and security providers; cloud hosting, analytics, communications, customer-support, and professional advisers; regulators, courts, law enforcement, and other parties when legally required; and parties to a merger, financing, acquisition, reorganization, or sale, subject to appropriate safeguards. We may disclose information at your direction or with your consent. Providers may use information only under applicable contracts and law.

7. International data transfers

We and our providers may process information outside the country where it was collected. Where required, we use safeguards such as adequacy decisions, the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or another lawful transfer mechanism. You may contact us for information about the safeguard relevant to your data.

8. Data retention

We retain personal information only as long as reasonably needed for the purposes described here, including to provide the Services, maintain transaction and audit records, meet legal and provider requirements, resolve disputes, prevent fraud, and enforce agreements. Retention periods depend on the type of data, account status, transaction lifecycle, legal limitation periods, and regulatory duties. We delete or de-identify information when it is no longer required, unless lawful preservation is necessary.

9. Security

We use administrative, technical, and physical safeguards designed for the nature of the information and risks involved, including access controls, encryption in transit where appropriate, logging, monitoring, and provider review. No method of transmission or storage is completely secure, so we cannot guarantee absolute security. Report a suspected vulnerability or incident to security@zenorapay.com.

10. Cookies and similar technologies

We may use necessary cookies for authentication, security, preferences, and core functionality, and—with consent where required—analytics or marketing cookies to understand use and measure campaigns. You can manage non-essential cookies through our consent controls when available and through browser settings. Blocking necessary cookies may prevent parts of the Services from working. The final cookie notice will identify active vendors, purposes, and durations.

11. GDPR and UK GDPR rights

Depending on your location and our role, you may have the right to access, correct, erase, or restrict personal data; object to processing; receive portable data; withdraw consent at any time without affecting earlier processing; and obtain safeguards for international transfers. You may also object to direct marketing at any time and may have rights related to solely automated decisions.

You may lodge a complaint with the data-protection authority in your country or place of work. If we process data for a merchant, contact that merchant first; we will assist it as required. We may verify your identity and may limit a request where an exemption applies.

12. California privacy notice and CCPA rights

In the preceding 12 months, we may have collected the categories described above, corresponding to California categories of identifiers; customer records; commercial information; internet or electronic activity; approximate geolocation; professional information; inferences; and sensitive personal information used for account access, security, verification, or transaction services. We collect these categories from the sources in Section 3, use them for the purposes in Section 4, and disclose them to the recipients in Section 6.

California residents may have rights to know and access personal information, correct inaccuracies, delete information, receive a portable copy, and opt out of sale or sharing for cross-context behavioral advertising. They may also limit certain uses or disclosures of sensitive personal information and will not be discriminated against for exercising these rights.

We do not sell personal information for money. The final policy and consent controls will state whether any live advertising or analytics activity constitutes "sharing" under California law and will provide any required opt-out. You or an authorized agent may submit a request using the contact details below. We will verify requests as required and may ask an agent for proof of authority.

13. Other regional privacy rights

Residents of other US states and countries may have similar rights to access, correct, delete, or obtain personal information and to opt out of targeted advertising, sale, or certain profiling. Where available, you may appeal our response by replying to the decision. We will process requests under the law that applies to you.

14. Children's privacy

The Services are intended for businesses and are not directed to children under 18. We do not knowingly collect personal information directly from children. If you believe a child has provided information to us, contact us so we can investigate and delete it where required.

15. Third-party sites and services

Links or integrations may lead to services we do not control. Their privacy notices govern their processing. Review those notices before providing personal information to a third party.

16. Changes to this policy

We may update this policy as the Services, providers, or legal requirements change. We will post the revised policy with a new date and provide additional notice of material changes where required.

17. Contact us

To ask a privacy question or exercise a privacy right, contact compliance@zenorapay.com. We may need information to verify your identity, location, and relationship with us before completing a request.

Privacy contact: Zentech Innovation Ltd. Postal and representative details will be added after the company's registration and jurisdiction details are confirmed.