Privacy Policy
Version: 0.9 (draft) · Dernière mise à jour: 2026-09-11
Ce document est tenu en anglais ; le texte anglais fait foi.
1. Who is responsible
AtaForge Inc. (operating as Baynoy) is the controller for personal data processed to provide the Services, unless the Data Processing Addendum makes us a processor for a platform customer. Contact: privacy@baynoy.com.
2. What we collect
We collect only what running a regulated payment product requires:
- Account data — name, business role, email, phone, language.
- Verification data — company registry information, documents, directors and owners, identity checks and their results.
- Transaction data — payments, payouts, balances, cards, crypto movements, and the counterparty details they contain.
- Device and usage data — IP address, device identifiers, security signals, and product usage events.
- Support data — messages you send us and records of how we resolved them.
3. Why we process it
Each purpose has a legal basis:
- Providing the Services and executing your instructions (contract).
- Verification, sanctions screening, fraud and financial-crime prevention (legal obligation and legitimate interest).
- Security of accounts and infrastructure (legitimate interest).
- Accounting, tax and record-keeping (legal obligation).
- Product communications about your account (contract); optional news only with consent.
5. International transfers
Where data leaves the region it was collected in, we use recognised safeguards such as adequacy decisions or standard contractual clauses.
6. How long we keep it
Verification and transaction records are kept as long as financial-services law requires (typically five to ten years after the relationship ends, depending on country). Everything else is kept only while needed for its purpose, then deleted or anonymised.
Where an address resolves to is worked out on our own servers using a local copy of the DB-IP City Lite database (© db-ip.com, CC BY 4.0) — no address is ever sent to a third-party lookup service. IP addresses, the city they resolve to, and the raw browser identification string attached to an administrative or sign-in event are deleted 90 days after the event. The record of the event itself — who acted, on what, when, from which country, on what class of device, and whether it was allowed — is kept, because it is the audit evidence financial-services law requires and it does not identify a person on its own.
7. Your rights
Depending on your jurisdiction you can request access, correction, deletion, restriction, portability, and object to certain processing; where processing rests on consent you can withdraw it. Some records cannot be deleted while retention law applies — we tell you when that is the case. Write to privacy@baynoy.com; you may also complain to your data-protection authority.
8. Security
Data is encrypted in transit and at rest, access is role-based and logged, card numbers never touch our servers in the clear, and administrative actions land in an immutable audit log. The Security page describes our practices; the Responsible Disclosure policy explains how to report a vulnerability.
10. Changes
We will post changes here with a new date and, for material changes, notify account holders.