Privacy Policy

About us

Exxa Limited is a registered company in the United Kingdom, with company number 11593450, with its registered office at South Quay Building, 189 Marsh Wall, Canary Wharf, London, E14 9SH, United Kingdom.

ExxaPay was developed by Exxa Limited.

Questions about the ExxaPay Service, GDPR and your data privacy rights can be resolved by contacting our Data Protection Officer via:

the website at www.exxapay.com
E‐mail to info@exxapay.com

Purpose of the policy
This Data Privacy Policy describes how we protect your privacy and how we use information about you when providing the ExxaPay Service to you.

Our belief is that your data belongs to you and only to you. We do not share your data with third parties, we do not allow anyone else to use or access your data outside the purposes for delivering the ExxaPay Service to you.

Any data we are in possession of about you is protected and handled in accordance with:

The Data Protection Act 1998 (UK)
EU General Data Protection Regulation

Exxa Limited are committed to protecting and respecting your privacy. This Data Privacy Policy sets out how we both use and protect the personal information that you provide to us when you use the ExxaPay Services.

What information we collect
To provide the ExxaPay Services we will need to collect information from you for the purposes of registration, enrolment and continued use of the services. This data collection is required in order for the services to be provided to you under the terms of this Contract. The mandatory data collected is:

First name
Last name
Mobile number
E-mail address
Password
Payment card number (only the last four numbers are kept)
Payment card expiry date
Records of purchases made through ExxaPay
Image of your face

What we do with the information we collect
We collect information from you to provide the ExxaPay Service you have requested, and in particular:

To provide a requested service or carry out a contract with you
To register you as a user of the ExxaPay services
To verify your identity to authorise payment by the Payment Service Provider
To provide you with service messages, including messages notifying you about changes to ExxaPay services or changes to our terms, conditions and policies
To confirm your identity with your face image ID and facilitate you making a payment

If we have your consent.

To register you as a user of the ExxaPay services
To verify your identity to authorise payment by the Payment Service Provider
To provide you with service messages, including messages notifying you about changes to ExxaPay services or changes to our terms, conditions and policies
To confirm your identity with your face image ID and facilitate you making a payment
If we have your consent.

To contact you (including by email or SMS) with marketing messages according to your marketing preferences

Where we have a legitimate interest to improve customer experience and the quality of the ExxaPay services.

To help us respond to your Technical or Service queries
To aggregate anonymised data to produce market trend information
To enable us to contact you by means such as SMS, email

Where we have a legal obligation.

To comply with our legal and regulatory obligations (including fraud prevention, anti-money laundering and sanction screening). This may include checking the information you provide to us against information from other sources.

How long we retain your personal information

We only retain your information for as long as is necessary for us to use your information to provide you with the ExxaPay Services as described above or to comply with our legal obligations.

You may delete your ExxaPay account at any time by using the “delete” button in your ExxaPay account. If you cease to be a ExxaPay user we will generally delete personal information we hold on you within 120 days from the date of termination. However, please be advised that we may retain some of your information after you cease to be a ExxaPay user or use the ExxaPay Services, for instance if this is necessary to meet our legal obligations such as retaining the information for regulatory purposes.

Your information will be encrypted and stored in accordance with legal requirements for a period of 7 years for audit purposes. After 7 years the data is permanently removed from our systems.

When determining the relevant retention periods, we will take into account factors including:

Our contractual obligations and rights in relation to the information involved
Legal obligation(s) under applicable law to retain data for a certain period of time
Statute of limitations under applicable law(s)
(Potential) disputes
Guidelines issued by relevant data protection authorities
Otherwise, we securely erase your information once this is no longer needed.

Who we share information with

The data you provide to us will not be disclosed to organisations other than to the suppliers that we work with to deliver the service to you.

We may disclose your personal data where we have your permission or where we are under a duty to share your personal information in order to comply with any legal obligations.

How you can access or amend the information we hold about you

You may request details of personal information we hold about you in accordance with the Data Protection Act (1998) and EU General Data Protection Regulation. To do so, or if you think the information we hold about you is incomplete or incorrect or you wish to have your account deleted, please contact our Data Protection Officer at:

Exxa Limited, South Quay Building, 189 Marsh Wall, Canary Wharf, London, E14 9SH, United Kingdom.
E-mail: info@exxapay.com
Web: www.exxapay.com

If the information we hold about you is inaccurate, you can also access and update it at any time by logging on to your ExxaPay account and updating your details.

Furthermore, under the EU General Data Protection Regulation, you have the following rights;

The right to be informed
The right of access
The right to rectification
The right to erasure
The right to restrict processing
The right to data portability
The right to object
Rights in relation to automated decision making and profiling*
The right to lodge a complaint with a supervisory authority (The UK ICO is an example)

  • We only collect information necessary to supply ExxaPay services. We do not use your data for profiling.

How we protect your data

We operate under an extensive security policy framework to ensure that all reasonable efforts are made to ensure that all data (including personal information) collected by the service is made available to you, remains confidential, and is protected from disclosure or unauthorised amendment.

Where we send data to third parties to help us provide the service to you, we will provide those third parties with only the information they need to deliver the service. Those third parties are prohibited from using this information for any other purpose than stated in this Data Privacy Policy and are contractually obligated to maintain and manage data in accordance with our Terms and Conditions.

How we use cookies

We use cookies to help us deliver an effective online service. Cookies are files that store information on your hard drive or your browser. These cookies mean that the Website can recognise that you have previously visited the Website. This allows you to maintain your preferences on the Website and for us to measure the usability of the Website.

You can, if you wish, disable the cookies from your browser and delete all the cookies currently stored on your computer. However, by deleting the cookies you may find you are prevented from using all the features of the Website.

You can find out how to delete cookies for your browser by clicking ‘help’ on your browser’s menu. For further information on how to do this, visit www.aboutcookies.org or www.allaboutcookies.org.

We use only session cookies to help identify your computer so we can improve the website’s usability, analyse the use of the website, prevent fraud and improve the security of the website.

We use Google Analytics with anonymous IP to analyse and create reports about the use of our website, this processing does not identify you as an individual. We do not profile our users. We don’t use third party cookies for any commercial purposes.

How to contact us

If you have any questions regarding this Data Privacy Policy or would like any further information regarding how your information is used or shared please contact our Data Protection Officer at:

Exxa Limited, South Quay Building, 189 Marsh Wall, Canary Wharf, London, E14 9SH, United Kingdom.
E-mail: info@exxapay.com
Web: www.exxapay.com

Changes to this data privacy policy

Our Data Privacy Policy may require updates from time to time. Any changes we may make to our Data Privacy Policy in the future will be published on our website www.exxapay.com. In addition, registered users will receive an email to inform them of changes.

In the event that you are not in agreement with any modified or revised ExxaPay Data Privacy Policy updates, then you are able to withdraw from using the service via your ExxaPay account. In your account you have the possibility to delete your account.