Privacy Policy - Structure and Key Provisions

Introduction

  • Service Designation: The topsend.live website and application.
  • Joint Data Controllers: Clear demarcation of responsibilities.
    • Certech Borrow s.r.o. (Czech Republic) acts as the platform operator for users within the EU/EEA.
    • Palmex Group Inc. (Canada, MSB License M23548908) acts as the financial services and payment processing provider.
  • Applicable Law: Commitment to compliance with the General Data Protection Regulation (GDPR) and the Personal Information Protection and Electronic Documents Act (PIPEDA).

1. Data We Collect

  • Identity Data: First name, last name, and date of birth.
  • Contact Data: Phone number, email address, and residential address.
  • Financial Data: Sender and recipient card numbers, IBANs, and transaction history.
  • KYC / Verification Data: Copies of identity documents and proof of address. All identity verification is strictly processed through our actively integrated technical service provider (TSP) using secure, encrypted data transmission.
  • Technical Data: IP addresses, geolocation, and device specifications (essential for anti-fraud systems).

2. Purpose of Processing

  • Providing payment services and routing cross-border transfers.
  • Supporting the underlying Banking-as-a-Service (BaaS) infrastructure.
  • Complying with statutory legal obligations, primarily Anti-Money Laundering (AML) and Counter-Terrorism Financing (CTF) regulations.
  • Fraud prevention and risk management.

3. Data Sharing & Third Parties

  • Partner Banks and Payment Gateways: For the execution of transactions and IBAN issuance.
  • KYC / AML Service Providers: For identity verification strictly within the secure environment of our designated verification partner.
  • Regulatory Authorities: Exclusively upon official legal requests from regulatory bodies (e.g., FINTRAC in Canada, Financial Analytical Office in the Czech Republic).

4. International Data Transfers

Given the operational infrastructure spanning the EU and Canada, data protection mechanisms must be outlined. Canada holds an "Adequacy Decision" from the European Commission, streamlining secure data exchange between Certech Borrow s.r.o. and Palmex Group Inc. For data transfers to other jurisdictions, Standard Contractual Clauses (SCCs) apply.

5. Data Retention

Specification of exact retention periods. In accordance with MSB and AML regulatory frameworks, financial and KYC data must typically be retained for a mandatory minimum of 5 to 7 years following account closure or the execution of the final transaction. Marketing data is deleted upon user request.

6. Your Privacy Rights

  • Right to Access: Requesting copies of personal data.
  • Right to Rectification: Correcting inaccurate or incomplete information.
  • Right to Erasure ("Right to be Forgotten"): Requesting the deletion of data (with the explicit caveat that this right is superseded by mandatory AML data retention laws).
  • Right to Data Portability: Requesting the transfer of data to another organization.

7. Updates to this Policy

The protocol for notifying users regarding material changes to data collection or processing procedures.

8. Contact Us

Download Privacy Policy PDF version