1. Introduction
The societe anonyme under the name COSMOTE Payments - ELECTRONIC MONEY SERVICES SINGLE MEMBER S.A., seated in Marousi, Attica (99 Kifissias ave.), (hereinafter COSMOTE Payments or COMPANY) considers it particularly important to protect your personal data and respects the principle of transparency concerning their processing. If you wish to be generally informed on the processing of your personal data by COSMOTE Payments, you are kindly requested to read the text of the General Notice concerning the Personal Data Protection Policy, which you may find here.
COSMOTE Payments has created and manages the payzy pro application (hereinafter “payzy pro”) for the provision of electronic money and payment services to “Businesses” (Micro-Enterprises and Business Users). The definitions in Section 1 “Definitions” of the Framework Service Agreement-Terms of Use of the COSMOTE Payments E-Wallet - hereinafter “Framework Agreement” - for the avoidance of repetitions, also apply for these terms, unless otherwise specified therein. Through payzy pro, various services are provided (hereinafter the “Services”), which are described in detail in the text τof the Terms and Conditions of use of payzy pro. A prerequisite for the use of payzy pro and the provision of electronic money and payment services to the Business, is the authentication-verification of the Business and the legal representatives thereof. The management of payzy pro is made by you, since you have been appointed manager of the business Payment Account upon its authentication-verification process (hereinafter “Business Manager(s)”).
We hereby wish to inform you on the processing of your personal data while using payzy pro and the Services.
These Terms are part of the Terms and Conditions of Use of the payzy pro application and shall always be interpreted in combination with them as a single set.
If the use of a Service, provided through payzy pro, is regulated by separate terms concerning the personal data processing, the latter are considered to be a single set with these terms, but they prevail over them if they regulate the same matter differently.
2. What are the identity and the communication details of the data controller?
The data controller is COSMOTE Payments, which you can contact by e-mail at customerprivacy@cosmotepayments.gr or by post by sending a letter to “COSMOTE Payments - ELECTRONIC MONEY SERVICES SINGLE MEMBER S.A.”, Marousi, Attica (99 Kifissias ave.).
3. Which personal data categories do we collect and process during the use of payzy pro and the Services and for which purpose?
3.1 For the use of the Services provided through payzy pro, we process aiming at the execution of the agreement between us (GDPR article 6 par. b), personal data of yours, and in particular:
3.1.1 For the execution of transactions through the “Wallet” Service (e.g. payment account loading / unloading), the execution of card transactions, the display of the payment account balance and the display of the transaction history, payzy pro processes the below data:
a) Data such as the Business payment account number at COSMOTE Payments, bank account number (IBAN) at COSMOTE Payments or/and a third bank, time, beneficiary, amount of transaction, payment method.
b) Payment cards data for loading / unloading the payment account.
c) Payment cards data to be used as a way of payment on payzy pro.
3.1.2 For the creation of a profile of a Store that belongs to the Business, all the necessary information: store name, address, Website, contact tel. number, working hours, profile photo. The Store profile is visible to all Authenticated Users through the payzy by COSMOTE application, as well as to the the COSMOTE APP if the Business participates in the COSMOTE DEALS FOR YOU program.
3.1.3 For the execution of transactions through the Service of acceptance of payments with a QR code - created by the Business Manager - by Authenticated Users of the payzy by COSMOTE application (hereinafter “Payers”): Data such as the business name, professional payment account number at COSMOTE Payments, bank account number (IBAN) at COSMOTE Payments or/and a third bank, time, beneficiary, transaction amount.
3.1.4 For your participation in the cashback Loyalty Program:
Number of your personal debit card issued to you by COSMOTE Payments, payment history you have made using your personal debit card issued to you by COSMOTE Payments, total reward amount you have collected, cashback history you have collected , IBAN number and balance of the Payment Account to COSMOTE Payments.
3.1.5 For the use of the Service of Issuance and Use of Cards, and in particular for the application of issuance and dispatch of a payzy debit card for the Business, in plastic/physical form:
- ID card details, postal address, Payment Account number (IBAN) at COSMOTE Payments, Business name, Business Manager’s full name.
3.1.6 For the use of the Service of Account Payment with a Single RF Payment Code: Payment Account number (IBAN) at COSMOTE Payments, data of the Single RF Payment Code registered.
3.1.7 For the Amount Reimbursement Service (hereinafter “Cashback”) to the Payers, as a reward for the payment through payzy pro, we process either for the payment of the Cashback or for the creation of a detailed report of the Cashbacks paid: Business Name, Payment Account number (IBAN) at COSMOTE Payments, transaction date and time, Cashback amount.
3.1.8 For the Review of the payment procedure we process: the Payers’ reviews and the total average collected by the Business store.
3.1.9 For the Service of supplementary terminals for the acceptance of payments through QR we process: Data such as Business store name, Business Store profile photo, professional Payment Account number at COSMOTE Payments, bank account number (IBAN) at COSMOTE Payments or/and a third bank, time, beneficiary, amount of transaction, Cashback.
3.1.10 The data we process during the Authentication-Verification process of the Business through the Authentication-Verification Application are mentioned in detail in the Notice on the Processing of your Personal Data through the COSMOTE Payments Business Authentication-Verification Application on the Business Authentication-Verification Application of COSMOTE Payments.
Moreover, in order to serve you better and resolve any problems that you may face while using the Services and payzy pro we process: data arising from the registration, activation and use of the Services and the Application, the identity details, the type, model and specifications of your device, connection details, details from your communication with us (e.g. contact telephone number and availability for your communication with an agent, registration of your conversation with our agent, detailed recording of the problem, etc.), transactions data and other data that you will communicate to us to investigate questions, complaints, charging disputes, etc.
3.2 With your consent (GDPR article 6 par. 1a) we process personal data for the provision of specific features of payzy pro. In particular:
- For the creation of an individual profile: data arising from the registration, activation and use of the Services and payzy pro for the creation of your individual profile as Business Manager based on your preferences. The creation of an individual profile is a form of automated processing of your above data, through which we can assess some of your preferences, for example suggest products that may be of your interest and send you relevant notifications/advertisements corresponding to your interests. You can deactivate this processing from the payzy pro settings and more specifically settings → terms of use and personal data → individual profile and personalization → individual profile.
- payzy pro enables the storage of your payment card (debit / credit / prepaid), so that no new entry of the card is not required for each transaction. For the protection of payment cards data and for the security of transactions, a tokenization process of payment card numbers is applied. Payment card data are stored in a secure environment of COSMOTE Payments.
3.3 Based on our legitimate interest (GDPR article 6 par. 1f) we process your personal data with the purpose of:
The receipt of news and notifications: For direct marketing of our products and services, COSMOTE Payments may process a limited range of your data and mainly those data included in your agreement, aggregated details of use or/and requests that you have submitted to us. Such processing is limited and aims exclusively at submitting proposals, offers, news and notifications on related products or/and services. You have the right to object to this communication from the payzy pro settings and specifically settings → terms of use and personal data → individual profile and personalization → news, notifications and promotional messages.
4. Trackers / Cookies
Cookies are small files stored on the Manager’s computer or mobile device and are placed by the websites they visit or/and on the mobile applications they use, in order to recognize them. In addition to cookies, there are other trackers as well, such as pixels (e.g. Facebook Pixel), local storage, third-party SDKs included in mobile applications, etc. The trackers store information or gain access to information stored in the user’s terminal equipment (computer, mobile phone, tablet etc.).
5. Permissions of payzy pro
The operation of payzy pro and the provision of the Services through it presupposes the installation and use of the payzy pro application, which, depending on the operating system in which it is installed, may require or request optional access to the following data of your terminal device:
- Location data (GPS): aiming to show your location on the map and display your store on it.
- Camera: Use of the camera to set the Business profile photo within the use of the Application.
- Storage space: Access is required for the storage of the PDFs of the quarterly statements on the transactions and payment acts of your Payment Account, including those through the analyses Cards, proofs of payment, for the alternative way of setting your Business photo profile you create within using the Application.
- Internet: The application requires access to the internet to communicate with the COSMOTE Payments systems and show the information concerning you (e.g., connection details, account details, etc.).
6. Display of push notifications
The payzy pro application sends notifications to your device to:
- inform you or/and complete the transactions (e.g. for the execution of payment services),
- notify you on messages you receive through the Chat Service,
- receive promotional messages and news, provided that you have not requested to be exempted from them either upon registration or through the settings in section “Communication Settings”,
- receive personalized suggestions and offers based on your personal profile, provided that you have given your consent (section “Communication Settings”).
If you wish to opt out of receiving any notifications, you can change your selections in the device settings.
7. For how long do we retain your personal data?
If you delete your account from payzy pro, your data (e.g. chat discussions with Payers) will be deleted in a way not rendering technically feasible their retrieval or will be anonymized, within 90 days.
8. Will COSMOTE Payments process your personal data for other purposes as well?
COSMOTE Payments will not process your personal data for other purposes except for those mentioned above. In case COSMOTE Payments wishes to use your personal data for other purposes, it will do so only after notifying you to this regard and after receiving your express consent.
9. Who are the recipients and why are personal data transmitted to them?
Recipients of your personal data may be:
A. Third companies with which we are cooperating for the provision and support of payzy pro, as well as of the Services, provided through it. In particular:
- Cognity S.A., which supports the operation of payzy pro and is seated in Greece.
- NEXI GREECE PROCESSING SERVICES SINGLE MEMBER SOCIETE ANONYME, which provides payment processing and card issuance services and is seated in Greece.
- NETCOMPANY-INTRASOFT S.A., which provides and supports the operation of the COSMOTE Payments banking systems and is seated in Greece.
- HELLENIC TELECOMMUNICATIONS ORGANIZATION S.A. (Independent Processor) with whom we cooperate for your participation in the COSMOTE DEALS FOR YOU program and the notification to the COSMOTE APP of the information of the Businesses and physical stores participating in payzy pro for the redemption of COSMOTE DEALS FOR YOU codes.
In these cases, these third companies are processors on behalf of COSMOTE Payments, that is partners of COSMOTE Payments, that undertake the execution of a specific project following our instructions and applying the strict procedures of OTE Group concerning the processing of your personal data. In these cases, COSMOTE Payments continues to be responsible for the processing of your personal data.
The processing of your personal data for the above purposes by our partners is conducted mainly within Greece and the European Union (EU). In case we cooperate with companies outside the EU, these will process your data, only following our order and if there is an adequacy decision of the European Commission or if appropriate clauses ensuring high-level security concerning the processing of your personal data are agreed.
Apart from the aforementioned companies, COSMOTE Payments does not process or publish your personal data to third parties except for the cases where their disclosure / transmission is imposed by the applicable legislation or is required for the verification of your data.
10. Which are your rights as Business Manager with regard to the processing of your personal data?
The rights you may exercise include:
- Right of access: You have the right to be informed on your personal data we process (e.g., the purposes of processing, the types of data, the recipients to whom they are disclosed, the period for which they are retained) and receive from us copies thereof.
- Right to rectification: You have the right to request the rectification of your data (e.g., correction of address, contact details).
- Right of erasure: You have the right to request the erasure of your personal data in case these are not necessary any more in relation to the purposes for which they were processed or in case you have withdrawn your consent based on which we collected and processed them.
- Right of restriction of processing: You have the right to request the restriction of processing for a specific reason (e.g., I do not want to receive notifications to my email for marketing purposes).
- Right to data portability: You have the right to receive your personal data you have provided to the company, in a structured, commonly used format, which is also in a readable form.
- Right to object to the processing of your personal data in the cases you do not wish the processing of your personal data.
To exercise your rights, you may:
a. send an e-mail to customerprivacy@cosmotepayments.gr , or
b. a fax to 0030 2102511888 or
c. a letter to the address COSMOTE Payments Customer Service, 99 Kifissias ave., 15124, Marousi with subject “Exercise of personal data rights”
stating your full name and your mobile or fixed-line phone number.
If you believe that we did not sufficiently satisfy your request and the protection of your personal data is affected in any way, you may file a complaint through a special web portal to the Hellenic Data Protection Authority (Athens, 1-3 Kifissias ave., P.C. 115 23, tel.: +30 210 6475600). Detailed instructions for filing a complaint are provided on the Authority’s website.
COSMOTE Payments will reply free of charge to your requests without delay, within one month from the receipt of the request. In exceptional cases, this deadline may be extended for two (2) months if the complexity of your request requires so. In any case, we will inform you on the said extension and on the reason thereof.
If we deem your request manifestly unfounded or exaggerated, we retain the right to request the payment of a reasonable fee for its satisfaction, considering the administrative expenses for its execution or even refuse to follow up on your request.
If you wish to address a question on the processing of your personal data to COSMOTE Payments or exercise one of your rights, you are kindly requested to be informed to this regard by the Data Protection Policy of COSMOTE Payments, which is available here.
11. What kind of measures apply for the protection of your personal data?
At COSMOTE Payments we provide in our corporate processes for the appropriate technical and organizational measures and apply them to the information systems and platforms used for collecting, processing or using data.
These include:
- measures preventing the access of unauthorized persons to the data processing systems (login authorization control).
- measures ensuring that the data processing systems cannot be used by unauthorized persons (access denial control).
- measures ensuring that the persons authorized to use the data processing systems have access solely to the data for which they have been authorized, and that the personal data cannot, during processing or use or after registration thereof, be transmitted, copied, modified or deleted by unauthorized persons (data access control).
- measures ensuring that during electronic transmission, or during transfer or registration, the personal data cannot be transmitted, copied, changed or removed by unauthorized persons, and that the processors, to whom personal data have been transmitted through data transmission equipment, may be controlled and verified (data transmission control).
- measures ensuring that it is possible to retrospectively examine and verify whether and by whom personal data were entered, modified or deleted in the data processing systems (data entry control).
- measures ensuring that the personal data processed by third parties/contractors are processed only pursuant to our instructions (contractor control)
- measures ensuring that the data collected for different purposes may be processed separately (separation rule).