Alternative Payment Solutions s.r.o. (APS)
APS always monitors legal updates and complies with all the laws governing the activities of financial institutions, anti-money laundering laws and laws against financing of terrorism, as well as European laws and directives related to data privacy. In accordance with the enactment of the General Data Protection Directive (GDPR), APS has undertaken appropriate measures as described herein.
From the 25th of May, APS adheres to a set of core privacy principles. These principles apply to all persons and organizations whose personal data we hold. We focus, in particular, on the following core principles:
Our Privacy Policy consists of the following articles:
APS is a payment system operated by Alternative Payment Solutions s.r.o., a company based in the Czech Republic (EU member state). Alternative Payment Solutions s.r.o. operates under a Electronic money issuer license issued by the Czech National Bank.
The full legal information about Alternative Payment Solutions s.r.o. is the following:
Alternative Payment Solutions s.r.o.
Company number: 05539323
Address: Ječná 2093/32A, Nové Město (Praha 2), 120 00 Praha
Email: info@oxtransfer.com
The purpose of this Privacy Policy is to give APS’s clients information on how APS collects and processes any personal data when our Clients use the website or register in the payment system APS. This includes all spheres of interaction with our clients, including our website, business relations and provision of payment services.
Under Directive 95/46/EC (General Data Protection Regulation), APS is a data controller and therefore is responsible for the use of personal data in a secure manner in compliance with the applicable law and in accordance to the agreement between APS and its Clients. Please read this Privacy Policy and the additional information related to the services offered by APS. In case of any questions, please contact us at the e-mail address indicated below.
Personal data is any information of personal nature which identifies an individual. Personal data do not include data where an individual cannot be identified from the data (anonymised). APS collects, uses, processes, stores, or transfers personal data such as:
The detailed scope of personal data required for using particular service rendered by APS can be found in the terms and conditions of APS service that are available on the website oxtransfer.cz
APS does not collect, store or process any special categories of personal data about its Clients (race, ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, information about health, genetic and biometric data).
To the extent that APS’s website includes links to third-party websites, plug-ins and applications (including cookies and widgets by third-party advertisers), by submitting the Privacy Policy, the Client should understand that by clicking on such links or enabling such connections the Client may allow third parties to collect or share his personal data. APS has no control over third-party websites and has no impact on their privacy policy.
Being an Electronic money issuer and having obligations regarding the prevention of ML and FT, APS collects data, including personal data, so as to be able to provide its services and products to the Clients. APS only collects personal data necessary to operate the payment system and provide its payment services:
Being obliged by the law and by the terms and conditions (contracts) with the Clients, APS will not be able to register, authorize and approve the Client’s registration in the payment system until we have received the data we requested.
APS collects information in different ways on its websites, namely when the Client provides his personal data directly to APS. This includes:
APS does not collect, store or process any special categories of personal data about its Clients (race, ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, information about health, genetic and biometric data).
APS collects data using various technologies when the Client accesses and browses APS’s websites. These are Usage and Technical Data. APS has its Cookies Privacy Policy, which is a part of APS’s General Privacy Policy.
Moreover, APS obtains personal data through third parties or if publicly available, namely as follows:
Being an Electronic money issuer and having obligations regarding the prevention of ML and FT, APS collects data, including personal data, so as to be able to provide its services and products to the Clients. APS only collects personal data necessary to operate the payment system and provide its payment services:
To improve products or services, APS may use automatic tools, including profiling, automated analysis of Clients’ personal data for the following purposes:
APS collects and uses personal data to provide its Payment services:
While operating with personal data of the Clients, APS shares such data with:
In any case of law enforcement, court order, National Bank inquiry, Financial Arbitrator inquiry or any other similar legal procedure, APS shall take all reasonable organizational and technical measures to ensure that every third party involved in the processing of the Client’s personal data uses protection standards in accordance with the applicable laws and in accordance with the principles set out in this Privacy Policy.
Providing numerous payment solutions and services, APS sends marketing notifications and messages. APS sends marketing notifications and messages only if the Client has subscribed for services or products from APS. The Client will also receive marketing communications from APS, if he has entered into a promotional competition, promotional offer or survey, where APS requests its Clients to provide Contact Details in order to enter or partake in the survey. In each case, APS keeps a register of marketing communications data used by APS, and each Client is entitled at any time to unsubscribe from receiving such marketing notifications by clicking on the unsubscribe link provided in such APS marketing communications. APS may also use Marketing and Communications Data in order to improve and customize the content of ads and promotions that may be of interest to the Client.
APS does not share personal data of its Clients with third parties, excluding parties which are parts of APS’s legal obligations and third parties under contractual relations when transferring of personal data is made to provide payment services. The transfer is necessary to perform and comply with the provision of our Services or to meet other operational needs of the business or in development of some of the purposes set forth in this Privacy Policy. Whenever APS transfers personal data to third parties, the Client can be assured that there is a similar level of protection of his data as by APS.
DATA RETENTION
APS may store Clients’ personal data for as long as required for the fulfilment of the purposes APS collected them for. The retention of data by APS is determined by considering compliance with legal (contractual or statutory requirements), accounting and compliance reporting requirements. APS also takes into consideration the temporary limits established in the commercial or data privacy laws in the different countries in which APS provides its services.
Any Client can claim his rights specified in the applicable law. APS guarantees the following rights related to personal data protection: es its services.
APS takes legal, technical and organizational measures that it considers necessary in order to maintain the security of Clients’ personal data, with due observance of the applicable obligations and exceptions under the legislation in force. APS follows the payments industry’s standards regarding the protection of personal data, including, among other measures, standard options of transparent encryption (Transparent Data Encryption) of databases. All data related to personal data of the Clients are encrypted by AES 256 algorithm with a cryptoperiod of 1 year. The encryption key is encrypted by the standard X.509, with a key length of 2048 bits and a 1 year-long cryptoperiod. A private key is divided between only a few employees of APS under the Shamir scheme, so that none of the employees has separate access to the data independently from other employees. The access to the informational infrastructure is safe under the PCI DSS standard.
APS reviews its policy regarding the collection, storage and processing of Clients’ personal data, including physical security measures, to prevent adulteration, loss, query, use or fraudulent or unauthorized access to Clients’ personal information. APS has installed process procedures to deal with any suspected personal data breach and will notify its Clients and any applicable regulator of a breach where APS is legally required to do so.
APS does not voluntarily or actively collect, use or disclose personal data of minors, according to the minimum age equivalent in the relevant jurisdiction, without the prior consent of the parents or guardians of the minor.
The services of APS are not intended or designed to attract minors.
If in some reason a APS employee understands or finds out that APS has collected personal information of a minor according to the jurisdiction, without first receiving any verifiable parental consent, APS will take steps to delete the information as soon as possible.
Every Client has the right to raise a complaint about APS’s processing and storing of personal data with the data protection regulator in the Client’s jurisdiction.
Every Client has the right to withdraw the consent to processing of personal data that the Client has given to APS and prevent further processing, if there is no other legitimate ground upon which APS can process the Client’s personal data.
If any complaint or claim regarding personal data or the need of their withdrawal appears, please contact us at the email address indicated below.
To raise a complaint, withdraw the consent or make any other changes to personal data, please fill in the application below and send it to the email address: aj@apsdata.net
APS uses cookies, web beacons and other access techniques (hereinafter “cookies”) on its website, mobile application and within payment system. By “cookies” are meant all IT data, text files stored on users’ terminals with the purpose of using websites. Through such files, APS recognizes the user’s terminal and displays the website in a relevant way, adapted to the user’s preferences. "Cookies" usually contain the name of the website they come from (redirect), time of being stored on the terminal and a unique number.
"Cookies" are used for the purpose of adapting the contents of websites to the user’s preferences and optimizing the use of websites. They are also used to prepare anonymous, aggregate statistics which help APS understand how the user benefits from websites, which allows for improvement of their structure and contents, excluding the user’s personal identification.
APS uses two types of "cookies" – "session" and "fixed". The "session" files are temporary files which remain on a user’s terminal until logging out from a website or closing an application (web browser). The "fixed" files remain on the user’s terminal for the time defined in cookie parameters or until they are deleted manually by the user. Personal data collected with the use of "cookies" may be collected only to perform certain functions for the user. Such data are encrypted in a way to make it impossible for unauthorised persons to access them.
In general, an application used to browse through websites allows saving cookies on the terminal by default. These settings may be changed so that automatic management of cookies is blocked in web browser settings or the user is informed each time cookies are sent to his terminal. Detailed information on the possibility and ways of dealing with cookies is available in application (web browser) settings. The limitations of using cookies may affect some features available on the website.
"Cookies" used by partners of the website operator, including, without limitation, website users, are subject to their own privacy policies.
We are currently working on our new page.