Privacy Policy
Last updated: June 22, 2026
This document is a template pending legal review.
This Privacy Policy explains how Praevidense (operated by VOTAN TEC LTD, a company registered in Cyprus (registration number HE 451931), “Praevidense”, “we”, “us”) processes data in connection with our business-to-business platform for real-time anti-money-laundering (AML) monitoring and chargeback prediction (the “Service”).
Praevidense is a processor and, in limited respects, a controller acting on behalf of regulated acquirers, payment service providers, and merchants (our “Customers”). It is deliberately designed to be PII-minimal: we do not need or store cardholder names, identity documents, or postal addresses to deliver the Service.
1. Data we collect
We process the minimum data required to score transactions and produce audit-grade decisions:
- Transaction identifiers and tokens — pseudonymous transaction IDs, payment tokens, amounts, currencies, timestamps, merchant category codes, and risk signals.
- Limited contact data — a cardholder email and an operator email where supplied for case handling and notifications.
- Operator account data — Customer staff credentials, API keys, role assignments, and console activity logs.
- Technical data — IP address, coarse geolocation, and device/user-agent metadata used for sanctions screening, fraud defence, and security.
We do not collect cardholder names, government identity documents, or residential addresses. That data remains with the acquirer and never enters the Praevidense platform.
2. Why we process data
- To provide AML monitoring, sanctions screening, and case workflows.
- To generate and serve chargeback predictions and risk scores.
- To operate the Public API and authenticate API requests.
- To maintain an immutable audit trail for regulatory evidence.
- To secure the Service, prevent abuse, and meet legal obligations.
3. Legal bases (GDPR)
- Performance of a contract — to deliver the Service to our Customers.
- Legal obligation — to meet AML, sanctions, and record-keeping requirements.
- Legitimate interests — to secure the platform, prevent fraud, and improve risk models, balanced against data-subject rights.
4. Sub-processors
We engage a limited set of vetted sub-processors under data-processing agreements. By category these include:
- Transactional email delivery (e.g. Resend).
- Cloud hosting and infrastructure providers.
- IP-geolocation providers.
- Sanctions and watchlist data providers.
A current list of sub-processors is available on request from [email protected].
5. Data retention
- Operational data — retained for 30 to 90 days to support active monitoring, case handling, and dispute windows.
- Audit archive — written to an immutable WORM (write-once, read-many) store and retained for 7 years to satisfy regulatory and evidentiary obligations.
6. International transfers
Where data is transferred outside its country of origin, we rely on appropriate safeguards such as Standard Contractual Clauses and equivalent mechanisms. Transfer details are available on request.
7. Your rights
Subject to applicable law, individuals have the right to access, rectify, erase, restrict, or object to processing, and to data portability. Because Praevidense processes most data on behalf of our Customers, requests are typically routed through the relevant Customer; we will assist them in responding. To exercise a right, contact [email protected].
8. Security
We are building a control environment aligned with SOC 2 Type II and SOX expectations (independent audit in progress), including encryption in transit and at rest, least-privilege access, immutable audit logging, and continuous monitoring. No system is perfectly secure, but we work to keep risk proportionate to the sensitivity of the data we hold.
9. Contact
Data protection enquiries: [email protected].
Controller: VOTAN TEC LTD, a company registered in Cyprus (registration number HE 451931), registered office Asklipiou, 1, Sunorama Central, Flat/Office 103, 6021, Larnaca, Cyprus. Data protection contact: [email protected].