Privacy policy

Elaris Payments L.L.C-FZ

1. Who we are and what this is

Elaris is a payment service: we help companies accept payments on a website, in an app, in a messenger and through a payment link, and make payouts. The website and the service are operated by Elaris Payments L.L.C-FZ.

This document explains what data we receive from website visitors, from companies that submit an application for onboarding, and from active merchant clients. It also covers why we need that data, who we share it with, how long we keep it and how you can influence this.

The policy applies to the Elaris website and to the services we provide under contract. It does not apply to merchant websites or to third-party services that may be linked from our website: they have their own data practices.

Elaris Payments L.L.C-FZ

Legal form: Limited Liability Company

Licence 2654048.01, registration number 2654048, issued by Meydan Free Zone, Dubai, U.A.E.

Licensed activities: Payment Services Provider, Digital content services

Address: Meydan Grandstand, 6th floor, Meydan Road, Nad Al Sheba, Dubai, U.A.E.

2. What data we collect

We collect only what is needed to reply to an enquiry, to onboard a client and to keep the service running. We do not collect data about race, health, religious or political views, and we do not ask you to send it.

What dataWhy
Application data: name, phone number, company name, website address, the comment you leave in the form, email address if you provide one To contact you, understand the task, suggest suitable payment methods and terms, answer your question
Technical data: IP address, device type, operating system, browser, language, pages viewed, date and time of the visit, referring source To serve the website correctly, measure traffic, find errors, protect forms from automated attacks and spam
Merchant onboarding data: company details, registration and tax numbers, licences and permits, description of the business and its products, contacts of responsible staff, bank details for payouts, documents we request during the check To conclude and perform the contract, verify the business before onboarding, meet the requirements of acquiring banks, payment systems and anti-money-laundering legislation
Transaction data: amount, currency, date and time, payment method, status, order reference and technical payment identifier, masked card number in the first and last digits format To process payments and payouts, display transactions in the merchant dashboard, handle disputes, refunds and chargebacks, keep accounting records
Correspondence: support messages, email enquiries, records of onboarding arrangements To handle the request, keep the history of the case, confirm the terms agreed

Part of the technical data is collected through cookies and similar technologies. Which cookies we set and how to refuse the optional ones is described in the Cookie policy.

3. Why we collect it and on what basis

We process data only for specific purposes and only while a legal basis for the processing exists. The bases are:

  • Conclusion and performance of a contract. Handling the application, verifying the company before onboarding, configuring the service, processing payments and payouts, support, invoicing and reporting to the client.
  • Legal requirements and payment industry rules. Client identification, checks on the source of transactions, retention of documents and transaction records, responses to lawful requests from competent authorities, compliance with the requirements of acquiring banks and international payment systems.
  • Our legitimate interest. Protecting the service from fraud and automated attacks, quality control in support, basic traffic analytics, defending our rights in disputes. We make sure such processing does not override your rights and we keep its scope limited.
  • Consent. Optional cookies, newsletters and product updates. Consent can be withdrawn at any time, which does not affect the lawfulness of processing carried out before the withdrawal.

We do not sell personal data and do not pass it to third parties for their own advertising.

4. Cardholder payment data

This section covers the most sensitive part. When a customer pays on a merchant website through Elaris, the full card details are entered on a secure payment form or in a banking app, not on the merchant side.

  • Elaris does not store the full card number, the expiry date or the card verification code.
  • Elaris does not pass full card details to the merchant. The merchant only sees the transaction status, amount, currency, order reference and the masked card number in the first and last digits format.
  • Card data is handled inside a secure processing environment that follows the PCI DSS industry security standard, with encryption in transit and restricted access.
  • Transactions are confirmed using 3-D Secure, that is an additional check of the payer on the issuing bank side.

When a customer pays on a merchant website, the merchant decides what order data it collects and how it uses it. In that part the merchant is responsible for its own data and publishes its own policy. Elaris processes such data only to the extent needed to execute the payment.

5. Who we share data with

Access is granted only to those who need it to run the service, and only to the extent required. We share data with the following categories of recipients:

  • Acquiring banks and partner payment institutions. To execute transactions, settlements and payouts, and to run the mandatory client checks before onboarding.
  • Payment systems. To the extent required for transaction authorisation, settlement, refunds and chargeback handling.
  • Infrastructure providers. Data centres and hosting, email and messaging services, ticketing systems, web analytics and attack protection tools. Such vendors act on our instructions and are bound by confidentiality obligations.
  • Professional advisers. Lawyers, auditors and accountants, where this is needed to support the company operations.
  • Competent authorities. Where disclosure is required by law, made in response to a lawful request, or necessary to protect the rights of Elaris, its clients and third parties.
  • Successors. In a reorganisation or a sale of the business or part of it, data may pass to the successor with the terms of this policy preserved.

6. Cross-border transfer and storage

Elaris Payments L.L.C-FZ is registered in Meydan Free Zone, Dubai, U.A.E. The main systems and servers holding client data and service records are located in the U.A.E.

The service operates across several countries, so data may be transferred outside the country where you are located: for example to acquiring banks, payment systems and infrastructure providers in other jurisdictions. In such cases we:

  • transfer only the volume of data the recipient needs for its role;
  • sign agreements with recipients that include confidentiality and data protection obligations;
  • use encrypted transmission channels and access control;
  • comply with the applicable legislation on cross-border data transfer.

Where a specific transfer requires your consent, we request it separately.

7. Retention periods

We keep data exactly as long as the purpose it was collected for requires, and then delete or anonymise it.

  • Application data where onboarding did not follow. Up to 12 months from the last contact, so that we can pick up the conversation if you write again. Sooner if you ask us to delete it.
  • Merchant data and verification documents. For the term of the contract and then for the period prescribed by legislation and payment industry rules for keeping such documents.
  • Transaction and accounting records. For the period set by financial reporting and primary document retention requirements.
  • Support correspondence. Up to 3 years, to keep the history of the case and confirm what was agreed.
  • Technical logs and web analytics data. As a rule up to 12 months; security logs may be kept longer where this is needed to investigate an incident.

If data is needed to defend our rights in a pending dispute or to comply with an order of a competent authority, the retention period is extended until that procedure is completed.

8. Your rights

In relation to your data you can:

  • find out whether we process your data and obtain a copy of it;
  • ask us to correct inaccurate or incomplete data;
  • ask us to delete data where we no longer have a basis to keep it;
  • restrict processing or object to processing based on our legitimate interest;
  • withdraw consent where the processing was based on it, including unsubscribing from mailings;
  • receive your data in a machine-readable format where this applies to your case;
  • lodge a complaint with a competent data protection authority.

To exercise a right, write to the address in section 10 and describe your request. We reply within a reasonable time, as a rule within 30 days. To avoid disclosing data to the wrong person, we may ask you to confirm your identity or your connection to a client company.

In some cases we may refuse in full or in part: for example, where the law requires us to keep the data or where the request affects the rights of other people. We will explain the reason for any refusal.

If you are a customer and your question concerns an order with a particular merchant, contact that merchant first: it is the merchant that decides what order data is collected and how it is used.

9. Security

We protect data with organisational and technical measures, including:

  • encryption of data transmitted over public networks;
  • role-based access control and the principle of least privilege;
  • logging of access to sensitive data and regular review of those logs;
  • separation of development and production environments, change control;
  • card data handled in an environment that follows the PCI DSS industry standard;
  • anti-fraud transaction monitoring and protection of forms and APIs from automated attacks;
  • backups and tested recovery procedures;
  • confidentiality obligations for employees and contractors.

No service can guarantee absolute security. If an incident occurs that may create a risk to your rights, we will notify the affected clients and the competent authorities in the manner required by applicable law. On your side, keep dashboard credentials and API keys secret and tell us if you believe they have been compromised.

10. Changes and contacts

We may update this policy: for example when our processes, our vendors or legal requirements change. The current version is always available on this page, and the version date is shown in the document header. If the changes are material, we will notify you separately by email or through the dashboard.

For any question about data processing, and to exercise the rights listed in section 8, write to us:

info@elarispayments.com

Postal address: Elaris Payments L.L.C-FZ, Meydan Grandstand, 6th floor, Meydan Road, Nad Al Sheba, Dubai, U.A.E.

See also the Terms of use, the Public offer and the Cookie policy.