Personal Data Processing Policy

Effective Date: July 03, 2026

This Privacy and Personal Data Processing Policy (the "Policy"), adopted by ENTRAX FINTECH PAYMENT SERVICES PROVIDER L.L.C (the "Company"), defines the purposes, procedures, and conditions for processing personal data of users of the EntraX Fintech website, collected through the functionality of the EntraX Fintech website (the "Website").

This Policy has been developed in accordance with applicable data protection laws and regulations relevant to the Company, the Website, and the processing of personal data. The Policy is published for unrestricted access on the Website at: https://entrax-fintech.com.

By checking the relevant box in the personal data collection form, the user of the Website confirms that they have read and fully agree with the terms of this Policy and gives consent to the processing of their personal data under the conditions specified herein. If the user does not agree with any provision of this Policy, they must refrain from checking the box and providing their personal data.

1. Terms and Definitions

The terms and definitions used in this Policy are interpreted in accordance with applicable data protection laws and regulations.

Website User / User
an individual using the Website who is considered a data subject when their personal data is processed.
Personal Data
any information relating to an identified or identifiable natural person, either directly or indirectly.
Personal Data Subject / Data Subject
a natural person whose personal data is being processed or to whom such data relates.
Personal Data Processing / Processing
any action or set of actions performed on personal data, whether automated or manual, including collection, recording, organization, structuring, storage, updating, modification, retrieval, use, transfer, disclosure, provision of access, anonymization, restriction, deletion, and destruction of personal data.
Controller
the Company, which independently or jointly with others determines the purposes and means of personal data processing, the categories of personal data to be processed, and the actions performed with personal data.
Cookies
small fragments of data stored directly on the User's device. They are used to ensure proper functionality of the Website and to analyze traffic. Cookies do not contain an email address or other direct personal identifiers by default. However, they may allow the system to record the time of a visit, remember preferences, and understand how the User interacts with the Website.

2. Purpose of Collecting and Processing Personal Data

The Company collects and processes personal data for the following purposes:

  • Processing requests for commercial offers and consultations;
  • Processing requests related to the conclusion of service agreements with the Company and granting the User access to the Company's services, including personal accounts;
  • Processing other requests submitted via the Website;
  • Improving, maintaining, and ensuring the proper functioning of the Website.

The Company does not collect or process personal data that is not required to achieve the purposes listed above.

3. Types of Personal Data Processed

The Company processes only the personal data voluntarily provided by the User through the Website's functionality, including:

  • Name, phone number, email address, and Telegram username, including where provided by individuals or representatives of legal entities.

These data are used for handling requests for commercial offers, consultations, service agreements, and other Website-related inquiries.

4. Data Collected via Cookies

When using the Website, certain non-identifiable data may be collected automatically through cookies, including:

  • Date and time of the Website visit;
  • Number of pages viewed, their titles, and viewing duration;
  • Browser type and operating system;
  • Referring URL, meaning the website from which the User accessed the Website;
  • Other technologies used to access the Website.

Cookies that do not collect personal data may not require separate User consent, unless such consent is required by applicable law.

The Website uses a cookie banner to allow Users to accept or refuse cookies that may process personal data, such as IP address, browsing history, preferences, login-related data, or form-filling behavior.

Users may disable cookies in their browser or device settings. However, disabling certain cookies may affect Website performance and user experience.

5. Legal Grounds and Conditions for Processing Personal Data

The Company processes personal data based on the User's consent and/or other lawful grounds permitted under applicable data protection laws.

The Personal Data Subject gives consent to the processing of their personal data under the terms specified in this Policy freely, by their own will, and in their own interest. The Subject confirms that their consent is specific, informed, conscious, and unambiguous. By marking the corresponding checkbox in the forms provided on the Website, the User confirms their agreement with the conditions of personal data processing set out in this Policy, which applies solely to the Website.

If the Website contains links to other websites or services, this Policy does not apply to such resources and does not regulate their activities.

Upon receiving personal data from Website Users and starting its processing, the Company acts as the Controller of personal data. The processing of personal data is carried out in compliance with applicable principles, conditions, and rules for personal data protection.

The User of the Website is responsible for the lawful transfer and processing of any personal data contained in documents or information submitted through the Website. The Company shall not be liable for personal data provided by the User without sufficient legal basis. In case of a breach of these provisions, the User undertakes to compensate the Company for any damages caused, including, but not limited to, fines and penalties imposed by competent authorities.

Separate consent for personal data processing may not be required where another lawful basis applies under applicable law, including in the following cases:

  • Processing is necessary to realize the rights and legitimate interests of the Company or third parties, provided that the rights and freedoms of the Data Subject are not overridden;
  • Processing is required for the Company to fulfill obligations established by applicable law or by a competent authority;
  • Processing is necessary for concluding, performing, or terminating a contract with the User or with the legal entity represented by the User;
  • Processing is required where disclosure of personal data is mandatory under applicable law;
  • Processing is carried out for statistical, analytical, or other research purposes, provided that the personal data is anonymized or otherwise protected as required by applicable law.

Personal data may be processed with or without the use of automation tools, including mixed processing.

Personal data shall be stored for the period necessary to achieve the purposes of processing specified in this Policy:

  • Processing of requests for commercial offers and consultations - for the duration of the request processing and for 2 years after its completion;
  • Processing of requests related to concluding a service agreement and granting access to the Company's services, including personal accounts - for the duration of the request processing and for 2 years after its completion. If a contract is concluded, data is processed for the entire period of its validity and additionally for the period specified in the contract or required by applicable law upon its termination;
  • Processing of other requests submitted via the Website - for the duration of the request processing and for 2 years after its completion;
  • Website modernization and operation - for the entire operational period of the Website.

The processing of personal data is terminated once the purposes specified in this Policy are achieved, and the data is irreversibly deleted from the Company's information systems or otherwise destroyed within the timeframes required by applicable law, including in the following cases:

  • The purpose of personal data processing has been achieved;
  • Consent to process personal data has been withdrawn and there is no other lawful basis for processing;
  • The period of consent has expired;
  • The Company has ceased its activities;
  • The Company has discontinued the Website's operation;
  • Other cases stipulated by applicable law.

If the Company entrusts personal data processing to third parties or transfers such data to them, the Company ensures that such third parties are obliged to maintain the confidentiality of personal data, ensure its security during processing, and fulfill other obligations required by applicable personal data protection laws.

During personal data processing, personal data may be transferred across borders. In the event of such transfer, the Company undertakes to comply with all applicable requirements for cross-border transfer of personal data.

6. Rights of Data Subjects

To the extent provided by applicable law, the User, as a Personal Data Subject, has the right to:

  • Request updates, corrections, restriction, blocking, or deletion of their personal data;
  • Obtain information about their personal data being processed, its source, processing purposes, legal grounds, and retention period;
  • Request notification of all third parties who received inaccurate or incomplete data so that corrections may be applied where required by law;
  • Withdraw consent to personal data processing at any time, where processing is based on consent;
  • Exercise other rights granted under applicable data protection laws.

Users may withdraw their consent or submit questions regarding personal data processing at any time by contacting the Company at info@entrax-fintech.com.

7. Personal Data Protection

The Company implements appropriate legal, organizational, and technical measures to ensure the protection of personal data from unauthorized access, destruction, alteration, restriction, blocking, disclosure, distribution, and other unlawful actions, including:

  • Identifying and managing security threats;
  • Implementing internal policies and local regulations governing data protection;
  • Appointing responsible personnel to oversee personal data security;
  • Establishing secure storage and processing conditions;
  • Maintaining proper records of documents containing personal data;
  • Ensuring the security of information systems where personal data is processed.

8. Final Provisions

This Policy applies exclusively to the Website.

The Company reserves the right to update or amend this Policy at any time, including to comply with changes in applicable legislation.

The latest version of this Policy is always available at https://entrax-fintech.com.

For any questions regarding this Policy or the processing of personal data, Users may contact the Company via email at info@entrax-fintech.com.

Contact: info@entrax-fintech.com