https://arayo.io/ ("Arayo") is the data controller for personal data described in this policy. Contact: privacy@arayo.io Data protection officer: dpo@arayo.io
Business clients and their directors, owners and authorised users; payment recipients; website visitors; partner and supplier contacts; job applicants. Arayo serves businesses, but running a payments platform means processing personal data about the people behind those businesses and payments.
Identity and contact data (names, dates of birth, addresses, ID documents for KYB/KYC); business and ownership information; transaction data (payment details, recipients, amounts, wallet addresses on the settlement leg); device and usage data from the platform and website; communications with our team. We collect this from you, from your business, and from third-party sources used in onboarding and screening.
To provide the services under our contract with your business. To meet legal obligations: anti-money laundering, counter-terrorist financing, sanctions screening, fraud prevention and reporting to regulators. For legitimate interests: securing the platform, improving the product, business communications. With consent where required, for example certain marketing and non-essential cookies. We do not sell personal data.
Payments are international by nature. Where personal data leaves the UK we use safeguards recognised under UK GDPR: adequacy regulations, the UK International Data Transfer Agreement or Addendum, and partner due diligence.
Onboarding and transaction records are kept for at least five years after the relationship ends, as required by anti-money laundering law. Other data is kept only as long as needed for the purpose collected.
Under UK GDPR you can request access, correction, deletion, restriction, portability and object to certain processing. Some rights are limited where we must retain data by law (for example AML records). To exercise a right, contact privacy@arayo.io .
Data is encrypted in transit and at rest, access is role-based and logged, and we run continuous monitoring. No system is perfectly secure; we notify affected parties and regulators of reportable breaches as the law requires.
We update this policy as the product and law change, with the date above and notice for material changes.