_Notices

General Data Protection Regulation

Our Commitment to Data Protection

We process financial data, including transactional data and risk management profiles. Privacy, security, and trust are foundational to our operational viability and the economic stability of the data subjects. We are fully committed to complying with the General Data Protection Regulation (GDPR) for all individuals within the European Economic Area (EEA).

Lawful Basis for Processing Data

As a data processor and infrastructure provider, Bancstac relies on specific legal bases for processing personal data. Data is processed under the basis of contractual necessity to deliver payment processing services, and legal obligations to meet Anti-Money Laundering (AML) and Counter-Terrorism Financial (CTF) regulatory requirements.

Data Minimization and Privacy by Design

Bancstac enforces the principle of data minimization by ensuring that our systems only collect and process personal data that is strictly necessary for the specified financial transaction. We maintain a data inventory and map data flows to track where data moves across our infrastructure. Our systems are architected with zero-trust, least-privilege access controls.

Security and Confidentiality

Bancstac is audited, certified, and fully compliant with PCI DSS Level 1 and PCI 3DS standards. We implement technical and organizational measures to protect personal data from unauthorized access, utilizing Advaned Encryption Standards (AES) for data at rest and Transport Layer Security (TLS) for data in transit across networks.

International Data Transfers and Third-Parties

Bancstac ensures that any personal data transferred outside the EEA is protected by equivalent security and compliance safeguards.

Data Subject Rights

Bancstac is a data processor for banks, payment networks and merchants, we povide the technical tools necessary for the data controllers to facilitate the rights requests of the data subject, including the right to access, rectification, erasure, and data portability, subject to regulatory obligations concerning data retention.