Legal
Privacy Policy
This Privacy Policy explains how First Digital Pay collects, uses, shares, transfers, secures and retains personal data, and the rights available to you under the EU and UK GDPR, the UAE PDPL and DIFC Data Protection Law, and United States state privacy laws.
Last updated: September 11, 2026
1. Who We Are and Scope
First Digital Pay (for United States operations) and First Digital Payment Services (for United Arab Emirates and England & Wales operations) operate this website and the related services ("Services"). This Policy covers our websites, applications, APIs, events, marketing and business communications.
Controller and processor roles. We act as a controller for personal data we determine the purposes of, including website visitors, prospects, business contacts, applicants and compliance records. We act as a processor where we process personal data on documented instructions of a Client under a data processing agreement, for example when handling Transaction Data submitted through our platform.
For privacy inquiries, contact privacy@firstdigitalpay.com. Our Data Protection Officer, EU representative (GDPR Article 27) and UK representative can be reached at the same address, marked for their attention.
2. Personal Data We Collect
- Identity and contact data: name, company, role, email, phone, country, correspondence details.
- Onboarding and compliance data: KYC/KYB documents, identity documents, ultimate beneficial ownership, source of funds and source of wealth evidence, sanctions and PEP screening results, and adverse-media results.
- Commercial and transaction data: payment instructions, counterparties, amounts, wallet or account references, settlement destinations and verification events.
- Technical data: IP address, device and browser identifiers, operating system, referring URLs, timestamps and security logs.
- Usage data: pages viewed, features used, interaction events and preferences.
- Biometric and authentication data: only where explicitly collected for identity verification or biometric card programs under a separate agreement, and processed under GDPR Article 9(2)(a) explicit consent or another lawful condition. Biometric templates are stored as irreversible mathematical representations, not raw images, and are typically held on-device or by a licensed issuing partner.
- Communications: enquiries, support requests, call and meeting notes, and recorded communications where notified and lawful.
We do not knowingly collect special-category data other than biometric data as described above. Please do not submit health, religious, political or similar data through our forms.
3. Sources of Data
We collect data directly from you, automatically through your use of our Services, from your organization, and from third parties including identity-verification providers, sanctions and screening databases, credit and fraud-prevention agencies, public registers, blockchain analytics providers, and publicly available business sources.
4. Purposes and Legal Bases (GDPR Article 6)
- Providing and operating the Services: performance of a contract, Article 6(1)(b); or legitimate interests, Article 6(1)(f), where you act for an organization.
- Onboarding, KYC/KYB, sanctions screening and AML monitoring: legal obligation, Article 6(1)(c), and substantial public interest for criminal-offence and screening data.
- Fraud prevention, risk scoring and platform security: legitimate interests, Article 6(1)(f), in protecting the platform, our Clients and the wider payment ecosystem.
- Service communications and support: contract or legitimate interests.
- Marketing to business contacts: legitimate interests, or consent, Article 6(1)(a), where required. You may opt out at any time.
- Analytics and product improvement: consent where cookies or similar technologies are used, otherwise legitimate interests.
- Biometric identity verification: explicit consent, Article 9(2)(a), together with Article 6(1)(b) or 6(1)(c).
- Legal claims, audits and regulatory reporting: legal obligation and legitimate interests, Article 9(2)(f) where special-category data is involved.
Where we rely on legitimate interests, we have carried out a balancing assessment; you may request a summary of it. Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
5. Automated Decision-Making and Profiling
Our Payment Risk Engine applies rules and scoring to transactions to detect fraud, sanctions exposure and anomalous behaviour. This can result in a transaction being flagged, delayed or declined. Where a decision produces legal or similarly significant effects and is based solely on automated processing, we implement safeguards under GDPR Article 22, including the ability to obtain human review, express your point of view and contest the decision. Contact privacy@firstdigitalpay.com to request review. We may be legally restricted from disclosing details of AML or sanctions-related decisions.
6. How We Share Personal Data
We do not sell personal data and do not share it for cross-context behavioural advertising. We may disclose data to:
- Processors and service providers: cloud hosting, infrastructure, security, identity verification, screening, analytics, CRM and communications vendors, each bound by written contracts, confidentiality and Article 28 obligations;
- Financial and digital-asset partners: authorized counterparties, banks, licensed exchanges, card issuers and settlement providers necessary to complete a transaction;
- Professional advisers: auditors, lawyers, insurers and accountants;
- Regulators, law enforcement and authorities: where required by law, court order, regulatory request, or to establish, exercise or defend legal claims;
- Corporate transactions: an acquirer or investor in connection with a merger, financing or reorganization, subject to confidentiality;
- Group affiliates: other First Digital Pay entities for operational, compliance and support purposes.
A current list of material sub-processors is available on request.
7. International Transfers
Personal data may be transferred to and processed in the United States, the United Arab Emirates, the United Kingdom, the European Economic Area and other countries where our providers operate. Where data leaves the EEA or UK to a country without an adequacy decision, we rely on appropriate safeguards, including the European Commission Standard Contractual Clauses (2021/914), the UK International Data Transfer Agreement or UK Addendum, and DIFC-approved transfer mechanisms, supported by transfer impact assessments and supplementary technical measures such as encryption and access controls. Copies of the relevant safeguards are available on request.
8. Retention
We keep personal data only as long as necessary for the purposes described, then delete or anonymize it. Indicative periods:
- Website analytics and cookie data: up to 14 months, subject to your consent choices;
- Prospect and marketing contact data: up to 24 months after last meaningful interaction;
- Client relationship and contract records: for the term plus 6 years;
- KYC, AML and transaction records: at least 5 years after the end of the relationship, or longer where required by Applicable Law;
- Security and access logs: typically 12 months;
- Biometric templates: for the life of the enrolled credential, deleted on revocation or account closure.
9. Your Rights
Subject to your location and applicable law, you may have the right to: access your personal data; request correction; request erasure; restrict processing; object to processing based on legitimate interests or direct marketing; receive your data in a portable, machine-readable format; withdraw consent; obtain human review of automated decisions; and lodge a complaint with a supervisory authority.
United States residents (including under the CCPA/CPRA and comparable state laws) may request disclosure of categories and specific pieces of personal information collected, deletion, correction, and may opt out of sale or sharing (we do neither). We will not discriminate against you for exercising these rights. Authorized agents may submit requests with proof of authority.
To exercise rights, email privacy@firstdigitalpay.com. We will verify your identity and respond within one month (GDPR/UK GDPR), extendable by two further months for complex requests, or within 45 days under applicable US state law. Requests are free unless manifestly unfounded or excessive.
Supervisory authorities: the UK Information Commissioner's Office; the lead EU supervisory authority in your member state; the UAE Data Office; or the DIFC Commissioner of Data Protection, as applicable. We would appreciate the opportunity to address your concern first.
10. Cookies and Similar Technologies
We use strictly necessary cookies to secure your session and maintain site functionality. Non-essential analytics and marketing technologies are blocked until you give consent through our banner. You can change or withdraw consent at any time. See our Cookie Policy for details.
11. Security Measures
In line with GDPR Article 32, we implement technical and organizational measures appropriate to the risk, including:
- Encryption of data in transit (TLS 1.2+) and at rest;
- Role-based, least-privilege access control and multi-factor authentication for administrative access;
- Network segmentation, hardened infrastructure and secrets management;
- Centralized logging, monitoring and anomaly detection;
- Secure development lifecycle, code review, dependency scanning and penetration testing;
- Vendor due diligence and contractual data-protection obligations;
- Personnel background screening, confidentiality undertakings and regular security training;
- Backup, business continuity and disaster-recovery testing;
- Data minimization, pseudonymization and separation of duties.
12. Personal Data Breaches
We maintain an incident-response plan. Where a breach is likely to result in a risk to individuals, we notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware, and notify affected individuals where the risk is high. Where we act as processor, we notify the affected Client without undue delay and assist with their notification obligations.
13. Children's Privacy
The Services are directed to businesses and professional users and are not intended for individuals under 18. We do not knowingly collect personal data from children. If you believe a child has provided data, contact us and we will delete it.
14. Third-Party Sites
Our Services may link to third-party websites and platforms. We are not responsible for their privacy practices; please review their policies.
15. Changes to This Policy
We may update this Policy from time to time. The updated version will be posted here with a revised "Last updated" date. Where changes are material, we will provide additional notice where practicable.
16. Contact
Privacy and data-rights requests: privacy@firstdigitalpay.com. Security reports: security@firstdigitalpay.com. Legal notices: legal@firstdigitalpay.com.
First Digital Pay operates as a remote-first organization. Registered office details for First Digital Pay (United States), and for First Digital Payment Services (United Arab Emirates and England & Wales), are listed on our Contact page and are available on request.