Dataretentie bij PAY. (en)
PAY. manages data from your company, your customers and data that becomes available during the payment process. This data is necessary to provide our services and to comply with legal and contractual obligations.
Why does PAY. retain data?
PAY. retains data for, among other things:
- Correctly processing payments.
- Complying with obligations arising from our licence and the Dutch Financial Supervision Act (Wft).
- Providing services to and communicating with end users, merchants and employees of merchants.
- Combating fraud, chargebacks and other risks to which an end user may expose a merchant.
- Providing insight into generated revenue and generating management reports for merchants.
- Troubleshooting and logging.
What data does PAY. retain?
- Order data
- Statistical data
- Transaction data
- Clearings
- Invoices
- Company & employees
- Payment method communication
- Exchange communication
Service level agreement
Depending on the package you have purchased, PAY. offers you the option to view financial insights and reports. In addition to the commercial agreements that we refer to as the Service Level Agreement (SLA), PAY. also has a legal obligation (arising from our licence) or contractual obligations (with payment method providers) to retain payment data.
It is therefore possible to upgrade your package during your relationship with PAY., as a result of which previously archived information may become visible again.
Important: Once the agreement with PAY. has been terminated, you have another 35 days to export your data. After this period, this data will no longer be available. Please take this into account when deciding when to terminate your agreement.
1. Order data
Order data is a group of data that PAY. receives from the merchant's systems and that contains information relating to the purchase.
- Invoice data (invoice number, invoice date and delivery date)
- Address data (billing address, delivery address)
- Customer data (name, company name, date of birth, email address)
- Product data, descriptions and prices.
This data is sometimes forwarded to payment methods in order to create an invoice (for deferred or instalment payments). This data may be used to determine fraud risks (for example, delivery data, email data and invoice data). This data may be used to block certain purchases (for example, an age restriction for alcohol or gaming). Via Quicksearch in the dashboard, you can search this data for a period of 13 months. This data is retained for a maximum of 13 months (this is the period during which your customer can submit an MOI notification or chargeback). There is no legal obligation to retain this data for longer. This data is not archived after this period.
Both the payer and the merchant can request that we delete this data on the basis of the GDPR. If there are no legal obligations at that time requiring us to retain this data, we will comply with the request.
2. Statistical data
Stats data is data that the merchant can provide and that is stored in PAY.'s reporting tools. Based on this data, an employee can perform searches and group certain transactions into a clear management report.
- Extra1
- Extra2
- Extra3
- Tool
- Info
- Object
- PromotorID
It is not permitted to store personal data in these fields. If you include personal data in these fields, we will completely delete the contents of these fields. This data remains stored online for 5 years. Depending on the agreement, it can be retrieved by the merchant for up to a maximum of 5 years.
Statistical data is visible according to the SLA:
- Pioneer: 12 months
- Professional: 24 months
- Business: 36 months
- Corporate: 60 months
- Submerchants of Alliances: 12 months
3. Transaction data
Transaction data contains data relating to the payment(s) involved in the merchant's order.
Payer data
- Account holder
- Bank account number, credit card number, telephone number, PayPal email address, account ID (for Alipay and WeChat Pay) or gift card number
- BIC / Swift data.
Recipient data
- Company name
- Trade name
- Clearing account (payout)
Reason for payment
- Merchant transaction ID
- Merchant transaction description
- Name of the sales location
- Category
- Description of the sales location (what the payment is being made for)
Transaction data is visible according to the SLA:
- Pioneer: 12 months
- Professional: 24 months
- Business: 36 months
- Corporate: 60 months
Financial institutions are required to retain this data for 7 years (this is done offline).
4. Clearing
Once a revenue period has ended, PAY. creates a clearing through which the received funds are transferred to your account. The associated transaction data that is bundled together into a clearing is visible and retrievable depending on your SLA.
Clearing instructions to your IBAN account:
- Pioneer: 9 months
- Professional: 21 months
- Business: 40 months
- Corporate: 46 months
Clearing insight per transaction:
- Pioneer: not available
- Professional: 6 months
- Business: 9 months
- Corporate: 12 months
5. Invoices
Depending on the invoicing frequency, invoices are generated weekly or monthly.
Invoices are visible:
- Pioneer: 9 months
- Professional: 12 months
- Business: 15 months
- Corporate: 18 months
- Submerchants of Alliances: not applicable
6. Company & employees
If you use PAY., we also collect user data. Depending on your role within the company, you are required to identify yourself. In certain cases, we will request additional information. It is also possible that we consult external sources.
Company data
As a financial institution, PAY. is legally required to retain company data for a period of 7 years.
Personal data of your employees
Your employees can request that we delete their personal data. In this case, we will delete all personal data. It will then no longer be possible for you to see, based on their name, who performed an action and on what date. This information will be replaced by the AL code. You can find these codes in your administration panel under the relevant user.
Personal data of UBOs, authorised signatories or representatives
If you fulfil a special role within the company, we are required to retain your personal data for a period of 7 years.
7. Payment method communication
Processing payments involves a great deal of communication with payment methods. This data is logged by PAY. in order to monitor the quality and availability of the services provided by these parties. Examples of such logs include:
- Credit card authorisation and capture request
- PIN transaction request to a terminal
- Login, balance enquiry and charging of a gift card
- Credit check and initiation of a deferred payment instruction
- Communication between a bank and PAY. during an iDEAL payment
The above information is available for a period of 1 month after the payment. You can therefore make an enquiry up to a maximum of 1 month after the payment has been processed. This enquiry can only be handled by a second-line support employee (from the Business package onwards).
8. Exchange communication
PAY. communicates payment statuses to external systems. This may be your webshop, your cash register or your accounting software. We call this an exchange.
This information is retained for 1 month for troubleshooting purposes.
Overview of retention periods per data type
| Data type | Package | Availability / retention period | Explanation |
|---|---|---|---|
| Data after termination of the agreement | All packages | Available for export for 35 days | After termination of the agreement, the merchant has another 35 days to export data. After that, the data is no longer available. |
| Order data | All packages | Maximum 13 months | After this period, the data is deleted and not archived. This corresponds to the period during which a customer can still submit an MOI notification or chargeback. |
| Statistical data | Pioneer | Visible for 12 months | The statistical data itself remains stored online for a maximum of 5 years. |
| Statistical data | Professional | Visible for 24 months | The statistical data itself remains stored online for a maximum of 5 years. |
| Statistical data | Business | Visible for 36 months | The statistical data itself remains stored online for a maximum of 5 years. |
| Statistical data | Corporate | Visible for 60 months / 5 years | This is also the maximum online retention period. |
| Statistical data | Submerchants of Alliances | Visible for 12 months | The statistical data itself remains stored online for a maximum of 5 years. |
| Statistical data | All packages | Maximum 5 years of online storage | Depending on the SLA, this data can be retrieved by the merchant for a shorter or equal period. |
| Transaction data | Pioneer | Visible for 12 months | Transaction data is legally retained for 7 years; after the online period, this is done offline. |
| Transaction data | Professional | Visible for 24 months | Transaction data is legally retained for 7 years; after the online period, this is done offline. |
| Transaction data | Business | Visible for 36 months | Transaction data is legally retained for 7 years; after the online period, this is done offline. |
| Transaction data | Corporate | Visible for 60 months / 5 years | Transaction data is legally retained for 7 years; after the online period, this is done offline. |
| Transaction data | All packages | 7-year statutory retention period | Financial institutions must retain this data for 7 years. The data is stored offline for this purpose. |
| Clearing instructions to IBAN | Pioneer | Visible for 9 months | Concerns clearing instructions through which received funds are transferred to the merchant's account. |
| Clearing instructions to IBAN | Professional | Visible for 21 months | Depending on the SLA. |
| Clearing instructions to IBAN | Business | Visible for 40 months | Depending on the SLA. |
| Clearing instructions to IBAN | Corporate | Visible for 46 months | Depending on the SLA. |
| Clearing per transaction | Pioneer | Not available | No insight per transaction. |
| Clearing per transaction | Professional | Visible for 6 months | Insight into which transactions are part of a clearing. |
| Clearing per transaction | Business | Visible for 9 months | Insight into which transactions are part of a clearing. |
| Clearing per transaction | Corporate | Visible for 12 months | Insight into which transactions are part of a clearing. |
| Invoices | Pioneer | Visible for 9 months | Invoices are generated weekly or monthly, depending on the invoicing frequency. |
| Invoices | Professional | Visible for 12 months | Depending on the SLA. |
| Invoices | Business | Visible for 15 months | Depending on the SLA. |
| Invoices | Corporate | Visible for 18 months | Depending on the SLA. |
| Invoices | Submerchants of Alliances | Not applicable | No invoice availability period applies to this group. |
| Company data | All packages | 7 years | As a financial institution, PAY. is legally required to retain this data for 7 years. |
| Personal data of employees | All packages | Until deletion request / as long as necessary | Employees can request the deletion of their personal data. If possible, the personal data will be deleted and their name for performed actions will be replaced by the relevant AL code. |
| Personal data of UBOs, authorised signatories and representatives | All packages | 7 years | A statutory retention period of 7 years applies to persons with these specific roles. |
| Communication with payment methods / payment method logs | Business and higher for enquiries | Available for 1 month after payment | Enquiries can be made up to 1 month after the payment has been processed and can only be handled by second-line support. |
| Exchange communication | All packages | 1 month | Communication through which PAY. sends payment statuses to external systems is retained for 1 month for troubleshooting purposes. |