Arayo

Privacy policy

https://arayo.io/ ("Arayo") is the data controller for personal data described in this policy. Contact: privacy@arayo.io Data protection officer: dpo@arayo.io

1. Who this policy covers

Business clients and their directors, owners and authorised users; payment recipients; website visitors; partner and supplier contacts; job applicants. Arayo serves businesses, but running a payments platform means processing personal data about the people behind those businesses and payments.

2. What we collect

Identity and contact data (names, dates of birth, addresses, ID documents for KYB/KYC); business and ownership information; transaction data (payment details, recipients, amounts, wallet addresses on the settlement leg); device and usage data from the platform and website; communications with our team. We collect this from you, from your business, and from third-party sources used in onboarding and screening.

3. Why we process it (lawful bases)

To provide the services under our contract with your business. To meet legal obligations: anti-money laundering, counter-terrorist financing, sanctions screening, fraud prevention and reporting to regulators. For legitimate interests: securing the platform, improving the product, business communications. With consent where required, for example certain marketing and non-essential cookies. We do not sell personal data.

4. Who we share it with

Licensed payout and on/off ramp partners, only as needed to execute payments in their market. Banking, safeguarding and stablecoin infrastructure providers. Verification, screening and fraud prevention services. Regulators and law enforcement where legally required. Professional advisers and, in a corporate transaction, prospective buyers under confidentiality.

5. International transfers

Payments are international by nature. Where personal data leaves the UK we use safeguards recognised under UK GDPR: adequacy regulations, the UK International Data Transfer Agreement or Addendum, and partner due diligence.

6. How long we keep it

Onboarding and transaction records are kept for at least five years after the relationship ends, as required by anti-money laundering law. Other data is kept only as long as needed for the purpose collected.

7. Your rights

Under UK GDPR you can request access, correction, deletion, restriction, portability and object to certain processing. Some rights are limited where we must retain data by law (for example AML records). To exercise a right, contact privacy@arayo.io .

8. Security

Data is encrypted in transit and at rest, access is role-based and logged, and we run continuous monitoring. No system is perfectly secure; we notify affected parties and regulators of reportable breaches as the law requires.

9. Cookies

The website uses essential cookies for operation and, with consent, analytics cookies. Manage preferences via the cookie banner.

10. Changes

We update this policy as the product and law change, with the date above and notice for material changes.