Processing of personal data by Fin&Pay Partners OÜ
| Issued by | Fin&Pay Partners OÜ, registry code 16757225 |
|---|---|
| Registered address | Juhkentali tn 8, Kesklinna linnaosa, Tallinn, Harju maakond, 10132, Estonia |
| Trading brand | BillBlend (https://billblend.io) |
| Contact | office@billblend.com |
| Document version | 1.2 |
| Effective from | 01/01/2026 |
| Approved by | Aleksandrs Viljevs, Director |
| Review cycle | annually, or upon a material change in processing |
1.1. This Privacy Policy explains how Fin&Pay Partners OÜ, a private limited company incorporated in Estonia under registry code 16757225, with registered address at Juhkentali tn 8, Kesklinna linnaosa, Tallinn, Harju maakond, 10132, Estonia ("we", "us", "the Company"), processes personal data.
1.2. "BillBlend" is a trading brand of Fin&Pay Partners OÜ. BillBlend is not a separate legal person. All services offered under that brand are provided by Fin&Pay Partners OÜ, and Fin&Pay Partners OÜ is the entity responsible for the processing described in this policy.
1.3. This policy applies to personal data processed in connection with:
(a) the website billblend.io and any subdomain operated by us (the "Website");
(b) enquiries, demonstration requests, applications for services and pre-contractual communications;
(c) the onboarding and ongoing administration of business clients ("Merchants") and of payment and technology partners ("Partners");
(d) access to and use of our merchant dashboard, application programming interfaces and technical documentation (the "Platform");
(e) our own business administration, including accounting, security and legal compliance.
1.4. This policy does not govern:
(a) the processing of personal data of a Merchant's own customers where we act on the Merchant's documented instructions. That processing is governed by the data processing terms agreed between us and the Merchant (see clause 3.3);
(b) the processing carried out by acquiring banks, payment service providers, electronic money institutions, card schemes and other Partners in their own right and under their own privacy notices;
(c) processing by third-party websites to which the Website links.
2.1. We are not a bank, an acquirer, a payment institution or an electronic money institution. We do not issue payment instruments and we do not issue electronic money.
2.2. We do not at any time receive, hold or control funds relating to a Merchant's transactions. Funds paid by a Customer are received and held by the licensed Partner processing the transaction, and are settled by that Partner. No account and no wallet in our name is used to receive, hold or transmit those funds. We do not open accounts for Merchants and we do not maintain balances for them.
2.3. What we supply is technology: the connection between a Merchant and the payment solutions of licensed Partners, together with routing, transmission of instructions and information, reporting and support.
2.4. This has a direct consequence for data protection. Because we never hold funds, we do not process the categories of data that arise from holding them — account balances, client money records, settlement instructions given in our own name. What passes through our systems is transaction data transmitted between a Merchant and a Partner. Clause 3 sets out our role for each category.
2.5. This position is also the basis on which the services fall within the exclusion in Article 3(j) of Directive (EU) 2015/2366 for technical service providers that support the provision of payment services without at any time entering into possession of the funds to be transferred.
3.1. Data protection law distinguishes the controller, who determines the purposes and means of processing, from the processor, who processes personal data on the controller's documented instructions. Our role differs by category of data.
| Category of processing | Our role | Who the other party is |
|---|---|---|
| Website visitors, enquiries, marketing communications | Controller | — |
| Representatives, directors and beneficial owners of Merchants and Partners (onboarding, due diligence, contract administration) | Controller | — |
| Platform user accounts and access logs of Merchant and Partner personnel | Controller | — |
| Our own personnel, contractors and applicants | Controller | — |
| Payment transaction data of a Merchant's customers, transmitted, routed, formatted and stored through the Platform | Processor | The Merchant is the controller |
| Fraud prevention and risk scoring performed on our own initiative or required of us by a Partner or a card scheme | Controller (own legitimate interest and compliance purposes) | — |
| Data exchanged with a Partner where the Partner processes it for its own regulatory purposes | Each party acts as an independent controller for its own purposes | The Partner |
3.2. The allocation in the table above reflects the substance of each activity. Describing ourselves as a processor for all purposes would be inaccurate: for a substantial part of our processing, we decide the purposes and the means ourselves, and we accept controller responsibility for it.
3.3. Where we act as a processor, we do so only under a written agreement with the Merchant containing the terms required by Article 28 of the General Data Protection Regulation, including the subject matter and duration of processing, the obligation to process only on documented instructions, confidentiality, security, sub-processor conditions, assistance with data subject requests, deletion or return of data at the end of the service, and audit rights.
4.1. Depending on the relationship, we process the following categories:
| Category | Examples | Source |
|---|---|---|
| Identification data | Name, date and place of birth, nationality, identity or passport document details, personal identification number where required by a Partner | The data subject; the Merchant; official registers |
| Contact data | Business address, e-mail address, telephone number, messenger identifiers | The data subject; the Merchant |
| Corporate role data | Position held, shareholding, beneficial ownership, powers of representation | The Merchant; commercial registers; the data subject |
| Due diligence data | Results of sanctions and adverse-media screening, politically exposed person status, source of funds and source of wealth information | Screening tools; public sources; the data subject |
| Transaction data | Transaction identifier, amount, currency, timestamp, payment method, masked card number, status, descriptor, dispute and chargeback records | The Merchant; Partners |
| Technical data | IP address, device and browser characteristics, session identifiers, cookie identifiers, access and audit logs | Automatically, from the device used |
| Communications data | Correspondence with us, support tickets, call and meeting records where made | The data subject |
4.2. We do not seek to process special categories of personal data within the meaning of Article 9 of the General Data Protection Regulation. Where information revealing such categories reaches us incidentally — for example in the descriptor of a transaction or in a document supplied during due diligence — we restrict access to it and delete it as soon as the purpose for which the document was supplied has been achieved.
4.3. We do not collect full payment card numbers, card verification values or authentication credentials, and we do not store them. Card data is transmitted to the Partner processing the transaction. Verify: confirm with the technical function that no component of the Platform stores or logs full card data, and confirm the current PCI DSS scope and attestation.
5.1. We process personal data only where a legal basis under Article 6 of the General Data Protection Regulation applies:
| Purpose | Legal basis | Retention |
|---|---|---|
| Responding to enquiries and taking steps prior to entering into a contract | Article 6(1)(b) — steps at the request of the data subject prior to contract | 36 months from the last contact if no contract follows |
| Onboarding, verification and administration of a Merchant or Partner relationship | Article 6(1)(b) — performance of a contract; Article 6(1)(f) — our legitimate interest in verifying the parties we contract with | Term of the relationship |
| Business and counterparty due diligence, sanctions and adverse-media screening, monitoring for prohibited activity | Article 6(1)(f) — our legitimate interest in preventing financial crime and in meeting obligations owed to Partners and card schemes; Article 6(1)(c) where a legal obligation applies | 3 years from the end of the relationship |
| Providing, operating and supporting the Platform | Article 6(1)(b); as processor, on the Merchant's instructions | Term of the relationship |
| Fraud prevention, transaction risk management, chargeback and dispute handling | Article 6(1)(f) — legitimate interest in preventing fraud and in protecting the Platform and its users; Article 6(1)(b) where part of the service | 5 years from the transaction |
| Security, access control, audit logging and incident investigation | Article 6(1)(f) — legitimate interest in the security of our systems | 12 months |
| Accounting, tax and statutory record keeping | Article 6(1)(c) — legal obligation under Estonian law | 7 years |
| Establishing, exercising or defending legal claims | Article 6(1)(f) — legitimate interest in the defence of claims | Until the applicable limitation period expires |
| Direct marketing to business contacts | Article 6(1)(f) — legitimate interest, subject to an unconditional right to object; consent where required by applicable electronic communications rules | Until objection or 2 months of inactivity |
| Non-essential cookies and analytics | Consent — Article 6(1)(a); see the Cookie Policy | As stated in the Cookie Policy |
5.2. Where we rely on legitimate interest, we have carried out a balancing assessment and concluded that our interest is not overridden by the interests or fundamental rights of the data subject. A summary of that assessment is available on request to the contact in clause 12.
5.3. Where we rely on consent, consent may be withdrawn at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
6.1. We disclose personal data only where it is necessary for the purposes described above, and to the following categories of recipient:
(a) acquiring banks, payment service providers, electronic money institutions and providers of alternative payment methods engaged to process a transaction;
(b) card schemes and payment system operators, where required under their rules;
(c) providers of identity verification, sanctions screening, adverse-media and fraud-prevention services;
(d) providers of hosting, infrastructure, communications, customer support and analytics services;
(e) professional advisers, auditors and insurers;
(f) other companies within group, where necessary for administration and on the basis of an intra-group data transfer arrangement;
(g) competent authorities, courts and law enforcement, where disclosure is required by law or by a binding order.
6.2. We do not sell personal data and we do not disclose it for the independent marketing purposes of third parties.
6.3. A current list of sub-processors used in the provision of the Platform is available to Merchants on request. Merchants are notified of intended changes to that list in accordance with the data processing terms agreed with them.
7.1. Some recipients are established outside the European Economic Area. Transfers to those recipients take place only where one of the safeguards permitted by Chapter V of the General Data Protection Regulation is in place, namely:
(a) an adequacy decision of the European Commission covering the country or the recipient; or
(b) standard contractual clauses adopted by the European Commission, supplemented where necessary by additional technical and organizational measures identified in a transfer impact assessment; or
(c) another lawful transfer mechanism, including, in narrowly defined cases, the derogation in Article 49(1)(b) where a transfer is necessary for the performance of a contract concluded in the interest of the data subject — for example where a payment must be executed in a specific country.
8.1. We keep personal data only for as long as necessary for the purpose for which it was collected, as set out in clause 5.1, and thereafter for the period during which a legal claim may be brought.
8.2. Where personal data is processed on behalf of a Merchant, it is deleted or returned at the end of the service in accordance with the data processing terms agreed with that Merchant, unless retention is required by law.
8.3. Data that is no longer needed is deleted or irreversibly anonymized.
9.1. The Platform applies automated rules to transactions for the purposes of routing, risk scoring and fraud prevention. These rules may result in a transaction being declined, delayed or referred for manual review.
9.2. Where such processing produces a decision based solely on automated processing that has legal effects for an individual or similarly significantly affects that individual, we ensure that the individual can obtain human intervention, express a point of view and contest the decision, in accordance with Article 22(3) of the General Data Protection Regulation. Requests are addressed to the contact in clause 12 and, where the decision was taken
10.1. We apply technical and organizational measures appropriate to the risk, including access control on a need-to-know basis, encryption of data in transit and at rest, segregation of environments, logging and monitoring, secure development practices, supplier assessment, staff confidentiality undertakings and training, and a documented incident response procedure.
10.2. Personal data breaches are assessed without undue delay and, where the criteria in Articles 33 and 34 of the General Data Protection Regulation are met, are notified to the Estonian Data Protection Inspectorate and, where required, to the individuals concerned. Where we act as a processor, we notify the relevant Merchant without undue delay after becoming aware of a breach.
10.3. A description of the current measures, and the current PCI DSS scope and attestation, is available to Merchants and Partners on request.
11.1. Subject to the conditions in the General Data Protection Regulation, you have the right to:
(a) obtain confirmation as to whether we process your personal data and to obtain a copy of it (Article 15);
(b) have inaccurate data corrected and incomplete data completed (Article 16);
(c) have data erased where one of the grounds in Article 17 applies;
(d) obtain restriction of processing in the cases listed in Article 18;
(e) receive data you have provided to us in a structured, commonly used and machine-readable format and to have it transmitted to another controller, where the conditions in Article 20 are met;
(f) object at any time, on grounds relating to your particular situation, to processing based on legitimate interest (Article 21(1)), and to object at any time and without giving reasons to processing for direct marketing (Article 21(2));
(g) withdraw consent at any time where processing is based on consent;
(h) not be subject to a decision based solely on automated processing in the cases described in clause 9.
11.2. Requests are made to the contact in clause 12. We respond within one month of receipt. That period may be extended by two further months where the request is complex or where several requests have been received; we inform you of any extension and of the reasons for it within one month.
11.3. We may ask for information reasonably necessary to confirm your identity before acting on a request. We do not charge a fee, except where a request is manifestly unfounded or excessive.
11.4. Where we act as a processor, we forward the request to the Merchant that is the controller and assist that Merchant in responding. We inform you that we have done so.
11.5. You have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence or place of work or of the alleged infringement. Our lead supervisory authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), Tatari 39, 10134 Tallinn, Estonia; www.aki.ee; info@aki.ee.
12.1. Questions about this policy and requests concerning personal data are addressed to Fin&Pay Partners OÜ at office@billblend.com, or by post to Juhkentali tn 8, Kesklinna linnaosa, Tallinn, Harju maakond, 10132, Estonia.
13.1. We may amend this policy. The current version and its effective date are published at billblend.io. Where a change materially affects how we process personal data, we notify affected Merchants and Partners in advance through the usual channels of communication.
13.2. Previous versions are retained and are available on request.
We use strictly necessary cookies to make this website work. With your permission we would also like to use functional cookies for live chat and text-to-speech, and analytics cookies to understand how the website is used. You can change your choice at any time via “Cookie settings”. Cookie Policy