1. Introduction
This Privacy Policy explains how Transaqo collects, uses, stores, shares and otherwise processes personal information in connection with:
- the website available at transaqo.com and its subdomains;
- the Transaqo platform, accounts, dashboards, APIs, SDKs, checkout components, connectors, integrations, documentation and software;
- support, communications and commercial relationships; and
- other technology and related services made available under the Transaqo name,
collectively, the “Services”.
“Transaqo”, “we”, “us” and “our” refer to Transaqo, the provider and operator of the Website, platform, software, technology infrastructure and related services made available under the Transaqo name.
This Policy is intended to apply globally and to reflect generally recognised privacy and data-protection principles. Rights and obligations may differ according to location, the nature of the relationship and the law applicable to particular processing.
Local mandatory requirements apply to the extent they cannot lawfully be excluded or modified.
2. Transaqo’s privacy roles
For the purposes of applicable data protection and privacy laws, Transaqo is the controller, business, organisation or other responsible party in relation to personal information processed for its own purposes.
These purposes include:
- managing accounts and customer relationships;
- providing and securing the Services;
- billing and administration;
- communicating with users;
- operating the Website;
- conducting analytics;
- improving products;
- preventing fraud and misuse;
- meeting legal obligations; and
- protecting legal rights.
Where Transaqo processes personal information solely on behalf of a customer and under that customer’s instructions, Transaqo ordinarily acts as a:
- processor;
- service provider;
- contractor; or
- equivalent recipient under applicable law.
In those circumstances:
- the customer determines the purposes and essential means of processing;
- the customer’s privacy notice ordinarily governs its relationship with the relevant individual;
- processing is subject to the customer’s instructions and applicable contractual terms;
- a data processing addendum may apply; and
- privacy requests relating to customer-controlled data should ordinarily be directed to the relevant customer.
Transaqo may assist customers with such requests where contractually and legally required.
3. Scope
This Policy applies when you:
- visit or use the Website;
- create or administer an account;
- use the Platform;
- use an API, SDK, connector, checkout component or integration;
- communicate with Transaqo;
- request or receive support;
- enter into or discuss a commercial relationship;
- receive business communications;
- attend a meeting or event involving Transaqo;
- interact with Transaqo through a professional network or third-party platform; or
- otherwise use the Services.
This Policy does not govern an independent third party’s processing merely because its service connects to or is referenced by Transaqo.
4. Definitions
“Personal information” means information that identifies, relates to, describes or is reasonably capable of being associated or linked with an identified or identifiable individual.
Depending on applicable law, it may also be called:
- personal data;
- personally identifiable information;
- protected personal information; or
- personal information about an identifiable individual.
“Processing” includes collecting, recording, organising, structuring, storing, adapting, retrieving, consulting, using, transmitting, disclosing, combining, restricting, deleting or otherwise handling personal information.
“Customer Data” means information submitted to or processed through the Services by or for a customer.
Information that has been irreversibly anonymised so that no individual can reasonably be identified is not personal information under this Policy.
5. Personal information we may collect
The information collected depends on how you interact with the Services, which products are used, the selected configuration and the role of Transaqo in the relevant processing.
5.1 Identity and business-contact information
We may collect:
- name;
- business email address;
- telephone number;
- job title;
- department;
- employer or organisation;
- business address;
- country or region;
- time zone;
- professional profile information;
- signature;
- preferred language; and
- professional relationship information.
5.2 Account and authentication information
We may collect:
- account identifier;
- username;
- hashed password;
- multi-factor authentication information;
- authentication tokens;
- account role;
- user permissions;
- login history;
- account status;
- security settings; and
- credential-management records.
Passwords should be stored in protected form. Transaqo does not need access to your readable password.
5.3 Customer, contractual and administrative information
We may collect:
- organisation details;
- customer or prospect status;
- products and integrations used;
- Order Forms and agreements;
- authorised-user lists;
- billing contact information;
- invoices and payment status;
- subscription details;
- service preferences;
- implementation information;
- support entitlement;
- procurement information;
- tax-related business information; and
- records of approvals and instructions.
Where payment for Transaqo Services is made through a third-party billing provider, that provider may process payment-card or bank details under its own terms. Transaqo may receive limited billing confirmation, transaction references and payment status rather than full payment credentials.
5.4 Platform configuration and integration information
We may collect:
- provider and integration selections;
- routing and cascading rules;
- webhook settings;
- endpoint information;
- feature configurations;
- deployment preferences;
- access permissions;
- merchant or project identifiers;
- technical environment information;
- API usage;
- integration events;
- error records; and
- configuration history.
5.5 Transaction-related technical information
Depending on the Services and configuration, the Platform may process or transmit:
- merchant transaction references;
- order identifiers;
- amounts and currencies;
- transaction status;
- payment-method type;
- provider and acquirer identifiers;
- tokens;
- masked payment details;
- issuer or country indicators;
- authentication results;
- routing decisions;
- retry and cascading events;
- fraud and risk indicators;
- chargeback or refund status;
- provider responses;
- timestamps;
- device and network indicators; and
- other technical metadata connected with a transaction.
Transaqo provides technology infrastructure and does not receive, hold or control the underlying funds merely because payment-related information passes through the Platform.
The categories of transaction-related information processed depend on customer configuration, integration design and the relevant third-party provider.
5.6 End-user and payer information
Where customers configure the Services to process information relating to their own users, buyers, payers, merchants or other individuals, Customer Data may include:
- name;
- email address;
- telephone number;
- billing or delivery information;
- customer or merchant reference;
- IP address;
- device details;
- transaction-related information;
- fraud-prevention information;
- authentication information; and
- communications connected with the transaction.
In such circumstances, Transaqo ordinarily processes the information on behalf of the relevant customer.
Customers must not submit information that is unnecessary for the configured Services.
5.7 Communications and support information
We may collect:
- email correspondence;
- support requests;
- contact-form submissions;
- meeting records;
- call notes;
- feedback;
- issue descriptions;
- attachments;
- troubleshooting information;
- communications preferences; and
- records of consents or objections.
Calls or meetings may be recorded only where legally permitted and after appropriate notice.
5.8 Website and usage information
When you interact with the Services, we may collect:
- Internet Protocol address;
- browser type and version;
- operating system;
- device type;
- device and browser settings;
- language;
- approximate geographic region;
- referring page;
- visited pages;
- links or buttons selected;
- session duration;
- access times;
- navigation path;
- application events;
- feature usage;
- response times;
- errors;
- crash data; and
- performance information.
5.9 Security and diagnostic information
We may collect:
- authentication events;
- access logs;
- API request logs;
- security alerts;
- suspected fraud indicators;
- rate-limit events;
- credential changes;
- administrative actions;
- vulnerability information;
- malware indicators;
- abuse reports;
- incident records; and
- information required to investigate unauthorised activity.
5.10 Cookie and preference information
We may collect information through cookies and similar technologies, including:
- consent choices;
- language and interface settings;
- session identifiers;
- analytics identifiers;
- Website interaction information; and
- device or browser identifiers.
Further information is provided in the Cookie Policy and Cookie Settings interface.
5.11 Marketing and professional information
Where permitted, we may collect:
- professional role;
- company and industry;
- publicly available business contact information;
- business interests;
- engagement with communications;
- event attendance;
- referral source;
- campaign information; and
- marketing preferences.
5.12 Derived, aggregated and anonymised information
We may derive information from existing records, such as:
- account health indicators;
- likely support needs;
- product-usage trends;
- security risk indicators;
- service-performance metrics; and
- aggregated statistical information.
Where information is anonymised so that it can no longer reasonably identify an individual, it may be used for any lawful purpose.
6. Information we do not ordinarily request
Unless expressly required through an appropriately secured and authorised process, you should not submit:
- full payment-card security codes;
- online-banking passwords;
- private encryption keys;
- passwords used for another service;
- unrestricted copies of identity documents;
- biometric templates;
- medical information;
- genetic information;
- information concerning sexual life or orientation;
- political or religious beliefs;
- trade-union membership;
- detailed criminal-history information; or
- another person’s sensitive information.
If unnecessary sensitive information is submitted, Transaqo may delete, restrict or minimise it.
7. Sources of personal information
We may obtain personal information:
7.1 Directly from you
For example, when you create an account, communicate with us, configure the Services or submit information.
7.2 From your organisation
An employer, customer, administrator or colleague may create an account for you, assign permissions or provide business-contact details.
7.3 From Transaqo customers
Customers may submit or cause the Platform to process information about their users, payers, merchants, employees, contractors or other individuals.
7.4 From integrations and service providers
Information may be received from:
- payment providers;
- acquirers;
- banks;
- payment methods;
- identity and authentication providers;
- fraud-prevention services;
- hosting providers;
- analytics providers;
- communication services;
- technical partners; and
- other integrations selected by a customer.
7.5 From public and professional sources
Where lawful, limited business information may be obtained from:
- company websites;
- professional networks;
- industry directories;
- conferences;
- corporate registers;
- publications;
- referrals; and
- other publicly available business sources.
7.6 Automatically
Technical, security, usage and cookie information may be generated automatically when you use the Services.
8. Purposes of processing
We may process personal information to:
- provide, operate and administer the Services;
- create and manage accounts;
- authenticate users and maintain access controls;
- configure and maintain integrations;
- transmit customer instructions to selected third parties;
- route and manage transaction-related technical information;
- provide dashboards, reporting and analytics;
- monitor service operation and performance;
- provide support and troubleshoot issues;
- communicate about accounts, updates and security;
- process fees and maintain billing records;
- manage contracts and business relationships;
- prevent fraud, abuse and unauthorised activity;
- protect the security and integrity of the Services;
- detect and respond to incidents;
- enforce agreements and acceptable-use requirements;
- improve, develop and test products and features;
- conduct internal research and statistical analysis;
- understand product usage and customer needs;
- maintain business and audit records;
- comply with law, legal process and official requests;
- establish, exercise or defend legal claims;
- conduct permitted business-to-business marketing;
- manage communication preferences and opt-outs;
- evaluate or complete a business transaction or restructuring;
- protect the rights, property and safety of users and others; and
- perform other compatible purposes disclosed at collection.
Personal information will not be used for a materially incompatible new purpose without appropriate notice and, where required, consent.
9. Legal grounds
Where applicable law requires a legal ground, processing may rely on one or more of the following.
9.1 Performance of a contract
Processing may be necessary to:
- provide requested Services;
- administer an account;
- fulfil an Order Form;
- provide support;
- manage billing;
- enforce contractual rights; or
- take requested steps before entering into a contract.
9.2 Legitimate interests
Where permitted, processing may be necessary for legitimate interests, including:
- operating a secure technology business;
- providing and improving the Services;
- managing customer relationships;
- preventing fraud and misuse;
- maintaining network and information security;
- understanding service performance;
- conducting proportionate business-to-business marketing;
- protecting legal rights;
- maintaining records; and
- supporting business continuity.
We consider the nature of the information, reasonable expectations, safeguards and possible effect on individuals before relying on legitimate interests.
9.3 Consent
We may rely on consent for:
- optional cookies and analytics;
- certain electronic marketing;
- recording calls or meetings where required;
- optional information;
- particular uses disclosed when consent is requested; and
- processing for which applicable law specifically requires consent.
Consent may be withdrawn at any time. Withdrawal does not affect processing lawfully carried out before withdrawal.
9.4 Legal obligation
Processing may be necessary to comply with:
- applicable law;
- court orders;
- binding official requests;
- tax or accounting rules;
- security and breach-notification requirements;
- sanctions and export-control requirements; or
- other legal obligations.
9.5 Protection of rights and interests
Where recognised by applicable law, processing may be necessary to protect vital interests, public interests, network security or the rights and safety of Transaqo, customers, users and other persons.
10. Customer instructions and processor activities
Where Transaqo acts as a processor or service provider, it will process personal information:
- for the business purposes specified in the agreement;
- on documented customer instructions;
- subject to confidentiality obligations;
- using appropriate security measures;
- through authorised subprocessors where permitted;
- for the agreed duration; and
- as otherwise permitted or required by law.
Transaqo will not retain, use or disclose such personal information outside the relationship with the customer except:
- to provide the Services;
- on the customer’s instructions;
- for permitted security and operational purposes;
- as allowed by applicable law; or
- as otherwise agreed.
A customer must not instruct Transaqo to process personal information unlawfully.
11. How personal information may be disclosed
We may disclose information to the following categories of recipients.
11.1 Customers and authorised users
Account, Platform and Customer Data may be made available to the customer that controls the account and to its authorised users according to configured permissions.
11.2 Selected integrations and payment providers
Where a customer activates an integration, relevant information may be transmitted to the selected:
- bank;
- acquirer;
- payment provider;
- payment method;
- fraud service;
- identity service;
- authentication provider;
- technology platform; or
- other third-party integration.
The receiving party may act as an independent controller or provider under its own terms and privacy policy.
11.3 Infrastructure and service providers
Information may be disclosed to providers supporting:
- cloud hosting;
- content delivery;
- data storage;
- network services;
- cybersecurity;
- authentication;
- communications;
- customer support;
- billing;
- analytics;
- monitoring;
- software development;
- document management;
- professional collaboration; and
- business administration.
Providers are authorised to process information only for specified purposes and subject to appropriate safeguards.
11.4 Professional advisers and insurers
Information may be disclosed to legal advisers, auditors, accountants, compliance advisers, security specialists, consultants and insurers where reasonably necessary.
11.5 Authorities and legal recipients
Information may be disclosed where reasonably believed necessary to:
- comply with law or legal process;
- respond to a binding request;
- investigate fraud or security incidents;
- prevent harm;
- enforce agreements;
- protect rights or property; or
- establish, exercise or defend legal claims.
Where legally permitted, Transaqo may assess the validity, jurisdiction and proportionality of a request.
11.6 Corporate and business transactions
Information may be disclosed in connection with an actual or proposed:
- merger;
- acquisition;
- financing;
- investment;
- restructuring;
- reorganisation;
- sale of assets;
- transfer of Services; or
- insolvency process.
Recipients will be expected to protect personal information and use it consistently with applicable law.
11.7 At your direction
Information may be disclosed to another person where you direct or authorise the disclosure.
12. Sale, sharing and targeted advertising
Transaqo does not sell personal information merely by engaging service providers to process information on its behalf.
Transaqo does not sell personal information for monetary consideration unless a specific notice expressly states otherwise and applicable rights are provided.
Transaqo will not share personal information for cross-context behavioural advertising or use targeted-advertising technologies where applicable law requires prior consent or an opt-out, unless:
- the practice is disclosed;
- the required mechanism is provided; and
- the user’s applicable choice is respected.
Where legally required, a recognised Global Privacy Control signal will be treated as an opt-out request for the browser or device transmitting the signal.
13. Business communications and marketing
Transaqo may send product, service, industry and business communications where:
- you requested them;
- you provided consent;
- an existing business relationship makes the communication reasonably expected;
- business-contact information was lawfully obtained;
- the communication is permitted under applicable business-marketing rules; or
- another lawful ground applies.
Marketing messages will provide a reasonable unsubscribe method.
You may opt out by:
- using an unsubscribe link;
- replying with an opt-out request; or
- contacting privacy@transaqo.com.
Opting out of marketing does not prevent:
- service communications;
- security notices;
- billing messages;
- responses to requests;
- legal notices; or
- other non-promotional communications.
A limited suppression record may be retained to ensure that the opt-out continues to be respected.
14. Cookies and similar technologies
The Services may use cookies, local storage, pixels, tags, scripts and similar technologies.
Strictly necessary technologies may be used to operate, secure and administer the Services.
Optional analytics, functional or advertising technologies will be managed in accordance with applicable law and the Cookie Policy.
Where consent is required:
- optional technologies will not be activated before consent;
- consent may be refused;
- categories may be selected separately where appropriate; and
- consent may be withdrawn.
15. International processing and transfers
Transaqo provides Services internationally and may use service providers and technical infrastructure located in multiple countries.
Personal information may therefore be processed outside the country in which it was collected.
The laws and government-access rules of another country may differ from those of your location.
Where required, Transaqo will use an appropriate transfer mechanism, which may include:
- an adequacy decision;
- standard contractual clauses;
- contractual data-protection commitments;
- transfer assessments;
- customer instructions;
- consent where legally valid;
- localisation measures; or
- another legally recognised safeguard.
Additional safeguards may include encryption, access restrictions, data minimisation and security reviews.
Information about a transfer mechanism applicable to a particular relationship may be requested from privacy@transaqo.com, subject to confidentiality and legal restrictions.
16. Retention
Personal information is retained only for as long as reasonably necessary for the purposes described in this Policy, taking account of:
- the duration of the relationship;
- customer instructions;
- contractual requirements;
- legal limitation periods;
- security needs;
- audit requirements;
- tax and accounting rules;
- dispute and enforcement needs; and
- applicable law.
Indicative retention periods include:
16.1 Account information
Account information is generally retained while the account remains active and for a reasonable period afterwards to administer closure, prevent fraud, resolve disputes and comply with law.
16.2 Customer and contractual records
Contracts, billing records and material business correspondence may generally be retained for the relationship and for up to seven years afterwards, or longer where required by applicable law or an active dispute.
16.3 Customer-controlled data
Customer Data processed on behalf of a customer is retained according to:
- customer instructions;
- contractual settings;
- the applicable data processing addendum;
- backup cycles; and
- legal requirements.
16.4 Transaction-related technical data
Retention depends on the configuration, operational requirements, security needs and customer instructions. Such information may be retained for reporting, reconciliation, troubleshooting, fraud prevention, dispute handling and legal compliance.
16.5 Security and diagnostic logs
Security, authentication and system logs are generally retained for a period proportionate to their purpose, commonly between 90 days and 24 months, unless a longer period is required for an incident, investigation or legal obligation.
16.6 Support and communications
Support records and business communications may generally be retained for up to three years after the last meaningful interaction, or longer if connected with an active customer relationship or legal matter.
16.7 Marketing information
Marketing contact information is retained while communications remain relevant and lawful, until an objection or opt-out is received, or until the information is no longer reasonably needed.
16.8 Consent and suppression records
Consent records may be retained for as long as reasonably necessary to demonstrate and manage consent. Suppression records may be retained for as long as necessary to honour an opt-out.
16.9 Cookie and analytics information
Cookie duration is described in the Cookie Policy and Cookie Settings interface.
16.10 Legal preservation
Information may be retained for longer where subject to:
- a legal hold;
- an investigation;
- litigation;
- an official request;
- an unresolved complaint;
- fraud prevention; or
- another legal necessity.
When information is no longer required, it may be deleted, anonymised or securely isolated until deletion is technically completed.
17. Security
Transaqo uses reasonable administrative, organisational and technical safeguards designed to protect personal information against:
- accidental loss;
- unlawful destruction;
- unauthorised access;
- misuse;
- alteration;
- disclosure; and
- compromise.
Measures may include:
- access controls;
- authentication;
- encryption in transit;
- encryption at rest where appropriate;
- network security;
- logging and monitoring;
- least-privilege access;
- vulnerability management;
- secure development practices;
- backups;
- incident response;
- vendor review;
- staff confidentiality obligations; and
- business-continuity measures.
Security controls are reviewed and adjusted according to the nature of the Services, information and identified risks.
No electronic transmission or storage system can be guaranteed completely secure.
Users are responsible for protecting their devices, accounts, credentials and integrations.
18. Security incidents
Transaqo maintains processes to identify, assess, contain and respond to suspected personal-information incidents.
Where required by applicable law or contract, Transaqo will notify:
- affected customers;
- affected individuals;
- competent authorities; or
- other required recipients.
Notifications will be made within the period and in the form required by applicable law, taking account of the nature of the incident and available information.
Where Transaqo acts as a processor, incident notification will ordinarily be provided to the relevant customer so that the customer can meet its own obligations.
19. Automated processing
Transaqo may use automated tools to:
- route technical instructions;
- apply customer-configured rules;
- detect security threats;
- identify suspected fraud or misuse;
- prioritise support;
- monitor system performance; and
- produce operational analytics.
Transaqo does not ordinarily make decisions producing legal or similarly significant effects about individuals solely through automated processing for its own purposes.
A customer may configure or use the Services in a way that involves automated decisions. In that case, the customer is responsible for:
- identifying the applicable legal requirements;
- providing required notices;
- establishing a lawful basis;
- enabling required human review; and
- responding to individual rights.
Where applicable law grants a right concerning automated decisions, you may contact privacy@transaqo.com or the relevant customer.
20. Privacy rights
Depending on applicable law and Transaqo’s role, you may have the right to:
- know whether personal information is processed;
- receive information about processing;
- access personal information;
- receive a copy of personal information;
- correct inaccurate or incomplete information;
- request deletion;
- request restriction or limitation;
- object to processing;
- withdraw consent;
- receive certain information in a portable format;
- opt out of direct marketing;
- opt out of sale, sharing or targeted advertising;
- limit certain uses of sensitive personal information;
- object to or request review of qualifying automated decisions;
- appeal a refusal of a request;
- appoint an authorised agent;
- complain to a privacy or data-protection authority; and
- receive equal service and pricing when exercising rights, subject to lawful exceptions.
Rights are subject to applicable:
- definitions;
- verification requirements;
- exemptions;
- legal limitations;
- retention duties; and
- Transaqo’s role in the processing.
As a general privacy-management practice, Transaqo will consider reasonable requests for access, correction, deletion and marketing opt-out even where a specific statutory right does not apply.
21. Exercising privacy rights
Requests may be submitted to privacy@transaqo.com.
A request should describe:
- the right being exercised;
- the relevant account, communication or interaction;
- the email address or identifier used;
- the information concerned; and
- any relevant date or context.
Transaqo may request information reasonably necessary to:
- verify identity;
- confirm authority;
- prevent fraudulent requests;
- locate records; and
- protect another person’s rights.
Verification information will be used only for the request and related security purposes.
Transaqo may decline or limit a request where permitted by law, including where:
- identity cannot reasonably be verified;
- the request concerns another person;
- an exemption applies;
- retention is legally required;
- disclosure would affect security, trade secrets or third-party rights;
- the request is manifestly unfounded or excessive; or
- Transaqo acts only as a processor and the request must be handled by the customer.
Where legally required, Transaqo will explain a refusal and provide information about appeal or complaint options.
Transaqo will not unlawfully discriminate against an individual for exercising a privacy right.
22. Authorised agents
Where applicable law permits an authorised agent to act for you, Transaqo may require:
- signed authorisation;
- direct confirmation from you;
- verification of your identity;
- verification of the agent’s identity; or
- a legally valid power of attorney.
These requirements are intended to prevent unauthorised access or deletion.
23. Requests concerning customer-controlled data
Where a request concerns information controlled by a Transaqo customer, you should ordinarily contact that customer directly.
If Transaqo receives such a request, it may:
- identify the relevant customer;
- refer the request to the customer;
- notify the customer;
- assist the customer as required by contract or law; or
- respond directly where legally required.
Transaqo will not independently alter or delete customer-controlled data where doing so would conflict with lawful customer instructions, unless required by law.
24. Regional disclosures
24.1 European Economic Area, United Kingdom and Switzerland
Where applicable European-style data-protection law applies:
- the relevant legal grounds are described in Section 9;
- international-transfer safeguards are described in Section 15;
- individuals may have rights of access, rectification, erasure, restriction, objection and portability;
- consent may be withdrawn;
- objections may be made to processing based on legitimate interests;
- direct-marketing objections will be honoured; and
- a complaint may be made to a competent supervisory authority.
Where processing is based on legitimate interests, information about the balancing assessment may be requested, subject to legal and confidentiality restrictions.
Where a representative or data protection officer is formally appointed and disclosure is required, applicable contact information may be obtained through privacy@transaqo.com.
24.2 United States state privacy notice
Depending on the interaction, Transaqo may process the following categories of personal information recognised under United States state privacy laws:
- identifiers;
- customer-record information;
- commercial information;
- Internet or electronic-network activity;
- approximate geolocation;
- professional or employment-related information;
- account credentials;
- communications;
- transaction-related technical information;
- inferences relating to likely business or security needs; and
- limited sensitive personal information, such as account login credentials.
These categories may be used for the purposes described in Section 8 and disclosed to the categories of recipients described in Section 11.
Transaqo does not use sensitive personal information to infer characteristics about individuals for unrelated advertising purposes.
Where applicable, residents may have rights to:
- know;
- access;
- correct;
- delete;
- obtain portability;
- opt out of sale;
- opt out of targeted advertising or sharing;
- opt out of qualifying profiling;
- limit certain sensitive-information uses;
- appeal a refusal; and
- use an authorised agent.
Requests may be submitted to privacy@transaqo.com.
A recognised Global Privacy Control signal will be honoured where applicable law requires it.
24.3 Canada
Where Canadian private-sector privacy law applies, Transaqo will follow applicable principles concerning:
- accountability;
- identified purposes;
- meaningful consent;
- limited collection;
- limited use, disclosure and retention;
- accuracy;
- safeguards;
- openness;
- individual access; and
- complaint handling.
Individuals may request access or correction and may raise a complaint with Transaqo or an applicable privacy authority.
24.4 Brazil
Where Brazil’s Lei Geral de Proteção de Dados applies, a data subject may have rights to:
- confirmation of processing;
- access;
- correction;
- anonymisation, blocking or deletion of unnecessary or unlawfully processed data;
- portability where applicable;
- information about sharing;
- deletion of consent-based data, subject to exceptions;
- information about the consequences of refusing consent;
- withdrawal of consent;
- objection; and
- review of qualifying automated decisions.
Requests may be submitted to privacy@transaqo.com.
24.5 Australia and New Zealand
Where applicable law applies, individuals may have rights to:
- receive notice of collection;
- access personal information;
- correct information;
- complain about handling;
- receive information concerning overseas disclosure; and
- object to certain marketing.
Transaqo will take reasonable steps to manage personal information openly and securely and to address applicable complaints.
24.6 Singapore and other Asia-Pacific jurisdictions
Where applicable, Transaqo will follow requirements concerning:
- consent or other lawful grounds;
- purpose limitation;
- notification;
- access and correction;
- accuracy;
- protection;
- retention limitation;
- transfer limitation;
- breach response; and
- accountability.
Privacy enquiries may be directed to privacy@transaqo.com.
24.7 Other jurisdictions
Individuals in other jurisdictions may have additional rights.
Transaqo will apply mandatory local requirements to the extent they govern the relevant processing.
25. Children
The Services are intended for business and professional users and are not directed to children.
Transaqo does not knowingly collect personal information directly from children under 16 through general Website or account registration.
Where local law establishes a higher age for independent consent, the applicable age will be respected.
If you believe that a child has submitted personal information without appropriate authorisation, contact privacy@transaqo.com.
This section does not prevent a customer from processing information relating to minors through the Services where the customer has an appropriate lawful basis and the processing is permitted under applicable law. In such circumstances, the customer is responsible for the relevant notices, safeguards and permissions.
26. Third-party services
Third-party integrations, websites and services may collect and process information under their own privacy policies.
Transaqo is not responsible for independent third-party privacy practices.
You should review the relevant third-party terms and privacy documentation before enabling or using an integration.
27. Changes to this Policy
Transaqo may update this Policy to reflect changes in:
- the Services;
- information practices;
- legal requirements;
- security measures;
- third-party relationships; or
- organisational arrangements.
Material changes may also be communicated through the Website, Platform, account or email.
Where required, additional notice or consent will be obtained before a material change applies.
28. Complaints
A privacy concern may be submitted to privacy@transaqo.com.
Transaqo will review the concern and respond within a reasonable period or the period required by applicable law.
You may also have the right to complain to a privacy, consumer-protection or data-protection authority in:
- the country where you live;
- the country where you work;
- the place where the relevant processing occurred; or
- another jurisdiction having competent authority.
Contacting Transaqo first does not remove the right to approach an authority directly.
29. Contact
Privacy questions, requests and complaints may be submitted to:
Privacy: privacy@transaqo.com
Legal: legal@transaqo.com
Security: security@transaqo.com
Website: transaqo.com