Privacy Policy
for DIMOCO Business Partners
DIMOCO Payments GmbH takes data protection seriously. We process personal data received from or in connection with Our Business Partners, including data relating to their officers, employees, legal representatives and beneficial owners, as well as personal data that We are required to process under applicable legal or regulatory requirements. We process this information with due care and confidentiality in accordance with this Privacy Policy for DIMOCO Business Partners (the “Policy”) and applicable law. This Policy explains the essential aspects of how DIMOCO processes personal data in connection with its Business Partners.
1. General Information
DIMOCO Payments GmbH is a company incorporated under FN 199901y of the Company Register of the Regional Court of Wiener Neustadt, Austria, having its registered offices at Campus 21, Europaring F15/302, A-2345 Brunn am Gebirge, Austria, and doing business as a payment institution licensed with the Austrian Financial Markets Authority (FMA) providing payment services to our customers (“Merchants”). DIMOCO is acting as controller of the personal data relating to its Business Partners and the individuals engaged by them when doing business with Us, as described in this Policy.
For the purposes of this Policy:
- any reference to “DIMOCO” , “We” , “Us” or “Our” shall mean DIMOCO Payments GmbH.
- any reference to “Business Partners” shall mean the third parties DIMOCO is doing business with, such as Our customers (“Merchants”), suppliers or vendors, as well as any parties interested in the purchase of services from or the provision of services to Us.
- any reference to “You” or “Your” shall mean (i) a Business Partner, where the Business Partner is a natural person, or (ii) an officer, employee, legal representative, beneficial owner or other individual acting for, representing or otherwise associated with a Business Partner.
2. What Data Will Be Processed?
During initial business contacts, negotiations, the establishment of potential business relationships and the subsequent management of those relationships, We collect and process certain professional and identification information relating to Business Partners and the individuals associated with them, including the following categories:
- General data on Business Partners and/or their officers and employees: Data relating to individuals in the Business Partner’s company used in Our business relations including, but not limited to, first name, surname, academic degree, date of birth, address, phone and fax number and email address, nationality, job title, signing rights, etc.
- KYC data on legal representatives and ultimate beneficiaries of Business Partners that (intend to) make use of Our payment services (Merchants): Details of individuals who directly or indirectly own or control more than 25% (twenty-five percent) of the shares or voting rights in or who otherwise exercise control over the management of the Merchant (e.g. first name, surname, academic degree, date of birth, address, phone and fax number and e-mail address, nationality, passport data, video identification date, etc.).
We generally obtain Your personal data directly from You or from the relevant Business Partner. We may also obtain personal data from publicly accessible registers, competent authorities, credit-reference agencies, service providers involved in Business Partner due diligence, or other lawful sources where this is necessary for the purposes described in this Policy.
3. What is the Purpose and Legal Basis of the Data Processing (the “Purpose”)
We process such data relating to Our Business Partners to properly select our Business Partners (including legal due diligence operations), negotiate, prepare, enter into, maintain and perform business relations and contracts with Our Business Partners, maintain a customer relations database, ensure orderly communication with our Business Partners and fulfil statutory reporting obligations.
We further process personal data relating to the legal representatives and beneficial owners of Merchants for risk-management purposes and to comply with applicable customer due diligence, identity-verification, anti-money laundering and counter-terrorist financing obligations, including when assessing whether to enter into or continue a business relationship.
Depending on the relevant processing activity and Your relationship with DIMOCO, We rely on the following legal bases:
- performance of a contract or steps taken at Your request before entering into a contract, where You are personally a party to that contract;
- compliance with legal obligations to which DIMOCO is subject, including applicable customer due diligence, anti-money laundering and reporting obligations; and
- Our legitimate interests or those of a third party, including establishing and managing business relationships, communicating with Business Partners, assessing business and financial risks, preventing fraud, and establishing, exercising or defending legal claims, provided that such interests are not overridden by Your interests or fundamental rights and freedoms.
Where the provision of personal data is required by law, necessary to enter into or perform a contract, or otherwise necessary for the relevant business relationship, failure to provide the required data may prevent DIMOCO from entering into or maintaining the business relationship or providing the relevant services. Where the provision of data is optional, We will indicate this at the time of collection.
4. How the Data Will Be Processed?
We process personal data in accordance with applicable law, in particular the General Data Protection Regulation of the European Union (“GDPR”) and relevant Austrian data protection law. We implement appropriate technical and organisational measures designed to protect personal data against unauthorised or unlawful processing and against accidental loss, destruction or damage.
5. Who Has Access to Your Data
Access to the personal data will only be granted to authorized personnel of DIMOCO subject to secrecy, particularly the competent department of DIMOCO responsible for engaging in and doing business with You.
We disclose personal data only where this is necessary for the purposes described in this Policy and where a valid legal basis permits the disclosure. Recipients may include processors acting on Our instructions, independent controllers, public authorities and other third parties where disclosure is necessary to comply with legal obligations, perform contractual obligations, pursue legitimate interests, or establish, exercise or defend legal claims.
- Service providers providing outsourced services, such as IT-services, software-providers and data storage, banks, telecommunication providers, KYC-service providers or payment processing services, each subject to secrecy and obligatory data processing agreements.
- The register of commercial loans of the Kreditschutzverband von 1870 or other institutions for the protection of creditors for credit information.
- Lawyers or collection agencies for carrying out a credit check and/or collecting invoice amounts.
- Such service providers used by DIMOCO to carry out the Business Partner due diligence.
Where personal data is transferred to a recipient outside the European Economic Area, We ensure that the transfer is based on an applicable adequacy decision or appropriate safeguards recognised under the GDPR. Further information on the applicable transfer mechanism and a copy of the relevant safeguards may be requested using the contact details set out below.
6. Retention Periods and Your Permission and Rights
We will save and retain such personal data provided in relation to You or Our Business Partners only for as long as the relevant data is required for the fulfilment of the (pre-)contractual relationship with the respective Business Partner, or to comply with Our legal/regulatory (in particular commercial and fiscal or AML) or contractual (e.g. with Operators or Payment Infrastructure Providers) obligations applicable to DIMOCO and its business, whichever is the longer. Depending on the purpose for which the relevant personal data was provided, the relevant data retention periods will vary. For example,
- in accordance with Section 132(1) of the Austrian Federal Fiscal Code (“Bundesabgabenordnung”), books, records and related supporting documents relevant for tax purposes are generally retained for seven years, calculated from the end of the calendar year to which the relevant records or documents relate, and for longer where they remain relevant to pending tax proceedings.
- in accordance with Article 21 of the Austrian Financial Markets Anti-Money Laundering Act [“Finanzmarkt Geldwäschegesetz”], the data set provided for the onboarding of the Merchant (Merchant Due Diligence) will be retained for a period of 10 (ten) years following the termination of the contractual relationship with DIMOCO.
- data may also be retained for the duration of applicable limitation periods and for as long as reasonably necessary to establish, exercise or defend claims arising from the business relationship.
After expiry of the applicable retention period, We will securely erase or anonymise the relevant personal data unless continued storage is required or permitted by applicable law, including where the data is necessary for the establishment, exercise or defence of legal claims. Where immediate deletion from backup systems is not technically feasible, the data will be isolated from active use and deleted in accordance with the applicable backup-deletion cycle.
Where the applicable legal requirements are met, You have the following rights in relation to Your personal data:
- Right of access (Art. 15 GDPR)
- Right to rectification (Art. 16 GDPR)
- Right to erasure (Art. 17 GDPR)
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to object (Art. 21 GDPR)
- Right to withdraw the consent You gave Us to process Your data (if consent is the legal basis). Please note that withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal and will lead to suspension of any business processes subject to it.
- Right to lodge a complaint with the Austrian Data Protection Authority (Datenschutzbehörde) according to Art. 77 GDPR.
If You have any questions about this Policy, the processing of Your personal data or the exercise of Your rights, please contact Us using the details below:
DIMOCO Payments GmbH
Campus 21, Europaring F15/302
2345 Brunn am Gebirge
Austria
E-mail: [email protected]
Telephone: +43 1 33 66 888 – 0