Skip to main content

    Privacy Policy

    Effective Date: 6 February 2026 · Last Updated: 24 September 2026 · Version: 2.3

    1. Introduction

    BeamPay Ltd ("BeamPay", "we", "us", or "our") is committed to protecting your privacy and processing your personal data in a transparent, lawful and fair manner.

    This Privacy Policy explains how we collect, use, store, disclose and otherwise process Personal Data when you:

    • visit or interact with our website at beampay.tech (also accessible via beampay.co.uk) (the "Website");
    • communicate with us as a business contact, prospect, partner or adviser;
    • access or use our platform, dashboards, APIs, software and related services (the "Service") as a business customer; or
    • otherwise engage with BeamPay in a business capacity.

    This Policy is intended to support compliance with the UK General Data Protection Regulation ("UK GDPR"), the Data Protection Act 2018, and, where applicable, the EU General Data Protection Regulation (EU) 2016/679 ("EU GDPR") and the Privacy and Electronic Communications Regulations 2003 ("PECR").

    In this Privacy Policy, "Data Protection Laws" means the UK General Data Protection Regulation, the Data Protection Act 2018, the EU General Data Protection Regulation (where applicable), and other applicable data protection and privacy legislation.

    This Privacy Policy applies where BeamPay acts as a data controller. Where BeamPay processes Personal Data on behalf of customers, such processing is governed by the applicable Data Processing Agreement.

    2. Data Controller

    The data controller responsible for your Personal Data is:

    • BeamPay LTD — Company number: 16903978
    • Registered in England and Wales
    • Registered office: 128 City Road, London EC1V 2NX, United Kingdom
    • Privacy and legal enquiries: privacy@beampay.tech

    3. Important: Our Role (Controller vs Processor)

    3.1 When We Act as a Controller

    BeamPay acts as an independent data controller for Personal Data processed in the context of our own business operations, including:

    • Website and communications: data of visitors to our Website, recipients of our communications, and individuals who engage with our marketing content or events.
    • B2B relationship management: data of employees and representatives of customers, prospects, partners, vendors and professional advisers.
    • Account administration and security: data relating to customer administrators and authorised users, for identity and access management, billing, security monitoring and support.
    • Corporate operations: recruitment, corporate governance, finance, tax, compliance screening and legal enforcement.

    3.2 When We Act as a Processor (Customer Data)

    When providing the Service to a bank, PSP/EMI, platform or software business (each a "Customer"), BeamPay typically processes Personal Data on the Customer's behalf as a processor (or, where applicable, a sub-processor). In this scenario:

    • The Customer is the controller for Personal Data processed within or via the Service;
    • BeamPay processes such data only on the Customer's documented instructions, as set out in our Data Processing Agreement ("DPA");
    • Responsibility for providing privacy notices to end users and establishing lawful bases lies with the Customer; and
    • BeamPay supports the Customer in meeting its obligations under Data Protection Laws.

    3.3 B2B / No Consumer Service

    The Service is intended for business use only. BeamPay does not offer the Service directly to consumers. If you are an end user of a Customer's service, your primary privacy relationship is with that Customer, and you should review the Customer's privacy notice for details on how your Personal Data is used.

    3.4 Data Subject Requests — Who to Contact

    • If you are an end user / merchant of one of our Customers: please direct requests to the relevant Customer. BeamPay will assist the Customer as required by our DPA.
    • If you are a business contact, website visitor or authorised user: contact us directly at privacy@beampay.tech.

    4. Personal Data We Collect

    4.1 Data You Provide to Us

    Data CategoryExamplesPurpose
    Business contact detailsName, email, phone number, job title, company nameResponding to enquiries, managing business relationships
    Account and identity dataUser IDs, usernames, role assignments, account preferencesAccount administration, access management
    Authentication dataLogin credentials, SSO identifiers, MFA statusAccess control and security
    Communication dataContent of messages, support tickets, attachmentsHandling requests, providing support

    4.2 Data We Collect Automatically

    Data CategoryExamplesPurpose
    Technical dataIP address, browser type/version, OS, device identifiersWebsite and Service functionality, security
    Usage and performance dataPages visited, feature usage, timestamps, API calls, latency metricsUnderstanding usage patterns, improving the Service
    Security and audit dataAccess logs, audit trails, error logs, security eventsDetecting and preventing fraud, misuse, and unauthorised access
    Cookie dataSession identifiers, preference cookies, analytics cookiesWebsite functionality and analytics (see Cookie Policy)

    4.3 Customer Data (Processed on Behalf of Customers)

    Depending on a Customer's configuration, the Service may process Customer Data containing Personal Data relating to the Customer's merchants, employees, contractors and/or end users. The precise categories are determined by the Customer, and in these cases BeamPay acts as a processor/sub-processor under the applicable DPA.

    4.4 Support, Onboarding and Communications

    When you contact us or interact with our support and onboarding teams, we may process support requests, correspondence, attachments, screenshots or files you share, and records of troubleshooting and resolutions provided.

    5. Legal Basis for Processing

    5.1 Controller Processing

    Where BeamPay acts as controller, we process Personal Data based on the following lawful bases under Article 6(1) of the UK GDPR / EU GDPR:

    Legal BasisProcessing Activities
    Performance of a contract (Art. 6(1)(b))Providing the Service, administering accounts, delivering contracted functionality, support, billing
    Legitimate interests (Art. 6(1)(f))Security and fraud prevention; B2B communications; service analytics and improvement; quality assurance; establishing, exercising or defending legal claims
    Legal obligation (Art. 6(1)(c))Complying with corporate, tax/accounting and other legal requirements; responding to lawful requests from courts, regulators or authorities
    Consent (Art. 6(1)(a))Non-essential cookies and similar technologies; certain electronic marketing where required by PECR

    5.2 Processor Processing (Customer Data)

    Where BeamPay processes Customer Data as a processor, the Customer determines the lawful basis and transparency obligations. BeamPay processes Customer Data only on documented instructions and in accordance with the DPA.

    6. How We Use Personal Data

    We process Personal Data only where necessary for the purposes described below:

    PurposeDescription
    A. Provide and operate the ServiceProvision accounts, onboard users, authenticate, operate dashboards/APIs, deliver functionality, updates and patches
    B. Security, integrity and fraud preventionPrevent, detect and investigate fraud, misuse and unauthorised access; maintain audit logs; implement vulnerability management and incident response
    C. Support and customer successRespond to support requests, diagnose and resolve issues, provide onboarding and training assistance
    D. Billing and relationship managementAdminister contracts, invoice, process payments, manage vendor relationships
    E. Improve and develop the ServiceAnalyse performance and usage trends, improve features, develop new functionality (preferably using aggregated/de-identified data)
    F. Legal, compliance and enforcementComply with applicable laws, enforce our Terms, investigate violations, maintain records for compliance and dispute resolution
    G. B2B marketing and business developmentSend product updates, event invitations and newsletters; manage sales pipeline (with opt-out options)

    BeamPay processes Personal Data only where necessary for the purposes described in this Privacy Policy and in accordance with applicable Data Protection Laws. We apply data minimisation principles and, where possible, use aggregated, anonymised or pseudonymised data for analytics, service improvement and product development.

    7. Data Sharing and Third Parties

    We do not sell your Personal Data. We do not disclose Personal Data to third parties for their independent marketing purposes.

    7.1 Service Providers (Processors / Sub-processors)

    CategoryPurpose
    Cloud infrastructure providersHosting, compute, storage, networking
    Monitoring and security providersSecurity monitoring, logging, alerting, threat detection
    Support and ticketing platformsCustomer support case management
    Email delivery providersSystem notifications and service communications
    Analytics providersUsage analytics, performance insights (aggregated/de-identified where feasible)
    Professional advisersLegal, audit, accounting, corporate administration

    All service providers are bound by appropriate confidentiality, security and data processing obligations. Where a provider processes Customer Data, they are appointed as a sub-processor under our DPA.

    We count Website visits with Cloudflare Web Analytics, which does not use cookies or store data on your device, based on our legitimate interest in understanding and improving the Website. With your consent, we also use Google Analytics 4. Google Analytics processes pseudonymous browser and session identifiers, visits, selected campaign codes and categorical enquiry events. We do not send the contents of enquiry fields to analytics, and we do not enable advertising personalisation. You can withdraw Google Analytics consent through Cookie Settings. This website analytics is separate from processing customer payment data through our products.

    7.2 Customers (Deployment Context)

    We may share certain information with the Customer that controls a given deployment for account administration and service delivery (e.g. user roles, audit logs, usage metrics, support communications).

    7.3 Legal, Regulatory and Enforcement

    We may disclose Personal Data where necessary to comply with legal obligations, court orders, or lawful requests by authorities; enforce our Terms; or protect rights, property or safety.

    7.4 Corporate Events

    In the event of a merger, acquisition, financing or restructuring, we may disclose Personal Data to relevant third parties subject to appropriate confidentiality and security protections.

    8. International Transfers

    BeamPay may process Personal Data in countries outside the UK and/or EEA. Where such processing involves a restricted transfer under Data Protection Laws, we ensure appropriate safeguards are in place, including:

    • UK transfers: UK International Data Transfer Agreement ("UK IDTA") and/or UK Addendum to the EU Standard Contractual Clauses
    • EEA transfers: EU Standard Contractual Clauses ("EU SCCs")
    • Adequacy decisions: where the UK Government or European Commission has recognised a destination country as providing adequate protection

    9. Transparency and Accountability

    BeamPay is committed to responsible and accountable data protection practices. We maintain internal policies and procedures designed to ensure that Personal Data is processed in accordance with applicable Data Protection Laws, including internal data protection governance, staff awareness and training, and documented procedures for handling personal data securely.

    10. Security of Personal Data

    BeamPay implements appropriate technical and organisational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. These measures include:

    • Encryption of data in transit using industry-standard protocols
    • Encryption of data at rest where appropriate
    • Role-based access controls and least-privilege access principles
    • Monitoring, logging and anomaly detection systems
    • Vulnerability management and security review processes
    • Internal incident response procedures

    11. Data Retention

    We retain Personal Data only for as long as reasonably necessary. Typical retention periods are as follows:

    Data TypeRetention Period
    Account and business contact dataDuration of relationship + 12–24 months
    Support recordsUp to 24 months after ticket closure
    Billing, finance and contractual recordsAs required by law (typically 6 years in the UK)
    Technical logs and audit trails30–180 days for standard logs; up to 12–24 months for security audit trails
    Website analytics (cookies)See Cookie Policy
    Marketing preferencesUntil withdrawal of consent or end of legitimate relationship

    Customer Data retention is governed by the Customer's instructions and the applicable DPA. After the retention period expires, we securely delete or irreversibly anonymise your Personal Data.

    12. Privacy by Design and by Default

    BeamPay incorporates privacy and data protection considerations into the design and development of its services. We apply the principles of privacy by design and privacy by default when developing new products, features and services. This includes implementing appropriate technical and organisational safeguards, minimising the collection of personal data, and ensuring that default settings support the protection of personal data.

    13. Your Rights

    Under the UK GDPR and EU GDPR, you have the following rights (where applicable):

    RightDescription
    AccessRequest a copy of the Personal Data we hold about you
    RectificationRequest correction of inaccurate or incomplete data
    ErasureRequest deletion of your Personal Data ("right to be forgotten")
    Restrict processingRequest that we limit how we use your data
    Data portabilityReceive your data in a structured, machine-readable format
    ObjectObject to processing based on legitimate interests or for direct marketing
    Withdraw consentWhere processing is based on consent, withdraw it at any time

    To exercise any of these rights, please contact us at privacy@beampay.tech. We will respond within one month of receiving your request. In complex cases, we may extend this by a further two months, with notice. We may need to verify your identity before processing your request.

    14. Complaints

    You can raise a data protection complaint with BeamPay by emailing privacy@beampay.tech with the subject "Data protection complaint". Explain your concern and how we can contact you; please do not include payment card details or passwords. We will acknowledge your complaint within 30 days, investigate it and communicate the outcome. This complaint process is separate from the data rights requests described above.

    You also have the right to lodge a complaint with a supervisory authority:

    • UK residents: Information Commissioner's Office (ICO) — ico.org.uk — Telephone: 0303 123 1113
    • EU residents: your local data protection supervisory authority.

    15. Children's Privacy

    Our Website and Service are not intended for children under the age of 16. We do not knowingly collect Personal Data from children. If you believe we have collected data from a child, please contact us immediately at privacy@beampay.tech.

    16. Cookies and Similar Technologies

    We use cookies and similar technologies on our Website to operate the site, ensure security, analyse usage and improve functionality. Please see our separate Cookie Policy for full details.

    17. Changes to This Policy

    We may update this Privacy Policy from time to time. Material changes will be notified via the Website or by email where appropriate. Any changes will be posted on this page with an updated "Last Updated" date and version number.

    18. Contact Us

    If you have any questions about this Privacy Policy or our data practices:

    • BeamPay LTD, 128 City Road, London EC1V 2NX, United Kingdom
    • Privacy and legal enquiries: privacy@beampay.tech

    BeamPay has not appointed a formal Data Protection Officer (DPO). Privacy and data protection matters are handled by our internal compliance and legal team.