Legal
Privacy Policy
What the platform stores, why, for how long, and who processes it.
Last updated: 30 July 2026
1. Who is responsible
The Moneva platform is operated by MNVA Pay EDPK, a company incorporated in Bulgaria ("Moneva", "we"). Moneva is the entity responsible under this notice and the contact point for anything in it: ops@moneva.io. This notice covers the Moneva website, the dashboard, and the platform API.
2. The roles we act in
- Controller. For website visitors, dashboard users (your team's accounts), and business contacts (prospects, sales and support correspondence), Moneva decides how and why data is processed and is the controller.
- Processor. For end-customer data that you, the merchant, submit through the platform, you are the controller. Moneva processes that data only on your documented instructions, as processor, under the Data Processing Addendum signed at production onboarding.
3. What we process
By audience:
- Site visitors. Technical data (IP address, browser data) handled transiently at the network edge for security and delivery. No advertising trackers. If you open the support chat, what you write there and the technical data your browser sends are processed by our live-chat provider so we can answer you. Nothing reaches that provider unless you open the chat yourself.
- Dashboard users. Name, work email, role and permissions, sign-in and security events.
- Business contacts. Contact details and correspondence.
- Merchants' end customers (processor role): identity data, beneficiary bank details, and transfer records, as itemized below.
| Data | Purpose | Retention |
|---|---|---|
| Organization and developer contact details | Account administration, security notices | Life of the account |
| End-customer identity data (name, email, residency, date of birth) | KYC and sanctions screening, performed by licensed partners | Until erasure, or account close plus 90 days, for the platform-held copy |
| Beneficiary bank details | Executing payouts you instruct | While the beneficiary is active, then with the financial record |
| Transfer and account records | Processing, support, regulatory reporting | 5 years after the customer relationship ends |
| Webhook events | Delivery and replay | 90 days |
| API request logs (path, status, timing, request id; never bodies or keys) | Debugging and abuse prevention | 30 days |
| Staff console audit log | Security accountability | 2 years |
4. Purposes and legal bases
Where Moneva is the controller, each purpose rests on a legal basis under Article 6 GDPR. Where Moneva is your processor, your legal bases apply and choosing them is your responsibility as controller.
| Purpose | Typical data | Legal basis |
|---|---|---|
| Operating your account and the dashboard | Organization and developer contact details, roles, sign-in events | Contract, Art. 6(1)(b) |
| Business verification (KYB) and sanctions screening of merchants | Company details, ownership, representatives | Legal obligation, Art. 6(1)(c), where it applies; otherwise legitimate interests, Art. 6(1)(f): keeping illegal activity off the platform and meeting duties owed to licensed partners |
| Security, debugging, and abuse prevention | API request logs, audit logs, security events | Legitimate interests, Art. 6(1)(f) |
| Service, security, and legal notices | Account contact details | Contract, Art. 6(1)(b) |
| Keeping financial records | Transfer and account records | Legal obligation, Art. 6(1)(c), where it applies; otherwise legitimate interests, Art. 6(1)(f) |
| Answering inquiries and managing business relationships | Business contact details, correspondence, support-chat conversations | Legitimate interests, Art. 6(1)(f) |
| Operating and protecting the website | Technical data at the network edge | Legitimate interests, Art. 6(1)(f) |
5. How it is handled
- No selling of data. Data is processed to provide the service, meet legal obligations, and nothing else.
- Keys are never stored in plaintext. API keys are stored and matched only in irreversibly hashed form.
- Encryption. TLS in transit everywhere; encryption at rest for stored records.
- Access is controlled. Staff access to personal data is role-gated and recorded in an audit trail.
- EU hosting. Platform records are stored and processed in the EU. Where a recipient is outside the EU or EEA, transfers are protected by contractual safeguards.
6. Recipients
The table lists every category of party in the platform's data chain, with the role each one plays. The parties marked Subprocessor are engaged by Moneva and bound to data-protection obligations no weaker than the Data Processing Addendum. Licensed payout and banking partners act as independent controllers under their own regulatory obligations, and the identity verification provider is their processor, engaged by them and not by Moneva. Contracted merchants are notified directly, at the account contact, before a new subprocessor processes personal data. The named register is provided to contracted merchants under the Data Processing Addendum and on written request to ops@moneva.io, subject to confidentiality.
| Party | Role | Purpose | Location |
|---|---|---|---|
| Licensed payout & banking partners | Independent controller | Payout rails: banking, FX and payout execution | EU |
| Identity verification provider | Processor of the payout partner | KYC and sanctions screening | EU / UK |
| Cloud database provider | Subprocessor | Primary data store, encrypted at rest | EU |
| Cloud compute provider | Subprocessor | Compute and hosting | EU |
| Cloudflare | Subprocessor | Network edge: TLS termination, DDoS protection | Global edge network |
| Transactional email provider | Subprocessor | Status and sign-in email delivery | EU |
| Error-monitoring provider | Subprocessor | Error monitoring; personal data scrubbed before send | US |
| Support-chat provider | Subprocessor | Website support chat, loaded only after a visitor opens the chat | EU |
7. International transfers
Platform records are stored and processed in the EU. The network edge that fronts the platform operates globally. Where a recipient is outside the EU or EEA, transfers rely on an adequacy decision or on Standard Contractual Clauses, with supplementary measures where needed. Payouts can involve downstream banking partners under contractual safeguards. Details for a given corridor are available to contracted merchants on written request to ops@moneva.io.
8. Retention
The table in Section 3 states the retention period next to each record type: 5 years for transfer and account records after the customer relationship ends, erasure or account close plus 90 days for the platform-held copy of end-customer personal data, 90 days for webhook events, 30 days for API request logs, and 2 years for the staff console audit log.
The 5 year period for transfer and fee records mirrors the EU anti-money-laundering record-keeping standard. That record-keeping duty takes precedence over erasure for the financial record. Everything else is kept no longer than its purpose requires, then deleted or anonymized.
9. Your rights
Where Moneva is the controller of your data, you can ask for access and a copy, rectification, erasure, restriction of processing, and portability, and you can object to processing based on legitimate interests. Where a purpose rests on consent, you can withdraw it at any time without affecting earlier processing.
To exercise a right, write to ops@moneva.io. We verify identity, answer within one month, and may extend by up to two further months for complex requests, telling you if so. Requests are free unless manifestly unfounded or excessive.
10. Your users' rights, via the API
When one of your users exercises a GDPR or UK GDPR right, you relay it with one API call. You stay the controller; the platform executes as processor. The endpoints are plain authenticated REST and work the same from any backend.
POST /v1/customers/{id}/eraseanonymizes the stored personal data in place for the right to erasure (Article 17): name and KYC profile removed, email replaced with a non-routable alias, a business's contact person removed. The customer moves to closed; creating new transfers, accounts or beneficiaries afterwards answers409 customer_erased.GET /v1/customers/{id}/exportreturns everything stored about the customer as one JSON download, for data portability (Article 20) or access (Article 15): the customer record including the KYC profile, accounts, beneficiaries, and the transfer history.
- The financial record stays. Financial-crime rules require the transaction record to survive erasure after the relationship ends and override erasure for it, so transfers, accounts and fee records remain queryable after an erase. Wallet addresses stay with them: on-chain pseudonymous data inseparable from that record.
- The erase covers the platform copy, not the provider's. Identity documents and verification results held by the licensed KYC provider sit outside the endpoint's reach and are retained under that provider's own AML obligations, on that provider's schedule. Where a data subject wants those addressed too, raise it with us at ops@moneva.io and we relay the request to the provider; the provider decides what its legal duty lets it delete.
- Erase is idempotent. Calling it again returns the same response with the original erasure timestamp.
- Export still works after erasure and returns exactly what remains, so you can evidence what was removed.
11. Complaints
You can lodge a complaint with the Bulgarian Commission for Personal Data Protection (CPDP), Sofia, cpdp.bg, or with the supervisory authority where you live or work. We would appreciate the chance to resolve the issue first: ops@moneva.io.
12. Cookies and analytics
The website and dashboard use only what is strictly necessary to operate: sign-in session state and the security controls of the network edge. No advertising trackers, no cross-site tracking, and no advertising analytics.
The support chat is the one third-party component on the website, and it requests nothing from its provider until you click the chat button. From that click onward, the provider stores a session identifier in your browser so your conversation survives moving between pages, which is strictly necessary for the chat you asked for. A visitor who never opens the chat has nothing stored by it and is not disclosed to that provider.
13. Automated decision-making
Moneva itself makes no automated decisions that produce legal or similarly significant effects. Identity verification and screening decisions for end customers sit with the licensed partners performing those regulated services, under their own notices and obligations. Questions about such a decision can be raised through us at ops@moneva.io and we relay them.
14. Children
The platform is built for businesses and is not directed at children. We do not knowingly process children's data as controller.
15. Changes to this policy
Material changes are announced on this page, under the Last updated date above, and notified to account contacts before they take effect.
16. Contact
Questions or data requests: ops@moneva.io.