1. Introduction

This Privacy Policy explains how CONFIG MONEY LIMITED (trading as GiroTap, we, us, or our) collects, uses, and protects personal data when you use the GiroTap payment platform, whether as a paying customer on a merchant checkout or as a merchant using our services.

GiroTap is a SEPA Direct Debit payment platform for European merchants. Payments are authorised with biometric and passkey cryptographic consent, and funds move directly from the customers bank account to the merchant no card networks, no intermediaries.

We are the data controller for the personal data described in this policy. This policy is written to comply with the EU General Data Protection Regulation (GDPR), the UK GDPR, and the UK Data Protection Act 2018.

2. Data We Collect

We only collect data we need to run the payment platform, prove consent, and defend against fraud and chargebacks. We break the data we process into four categories.

Account data

  • Merchant account data business name, company registration details, beneficial owner information, bank account details for settlement, contact names and email addresses. Collected during onboarding for KYB (Know Your Business) checks.
  • Customer account data email address for pre-debit notifications and receipts, full name as it appears on the bank mandate, and a stable user identifier.

Biometric and authentication data

  • Biometric data stays on your device. Face ID, Touch ID, fingerprint, or equivalent biometric checks are performed entirely by your operating system. GiroTap never receives, processes, or stores raw biometric templates.
  • Passkey public keys when you authorise a payment, your device signs a cryptographic challenge using a passkey. We store the associated public key and signed attestation, but never the private key, which never leaves your devices secure enclave.
  • Mandate signatures the signed consent artefact authorising GiroTap to debit your account via SEPA Direct Debit, together with the timestamp and a hash of the mandate text you saw.

Transaction and mandate data

  • Bank account details (IBAN, BIC, account holder name) obtained through PSD2 open banking via our licensed providers, or provided directly when creating a mandate.
  • Account intelligence where permitted by open banking access, limited account metadata (account age, primary/secondary status, recent activity indicators) used to assess debit risk before we initiate a charge.
  • Payment history amount, currency, merchant, timestamp, status (authorised, settled, failed, returned, refunded), mandate reference, and end-to-end transaction identifiers.

Device and technical data

  • Device fingerprints browser user agent, device type, operating system, screen dimensions, time zone, and a non-reversible device hash used for fraud detection.
  • IP address and approximate geolocation derived from the IP address, used for fraud scoring, sanctions screening, and determining which regulatory regime applies.
  • Log data request logs, error traces, and diagnostic information generated when you interact with GiroTap.

3. How We Use Your Data

We use the data described above for the following purposes:

  • Processing payments. Creating mandates, initiating SEPA Direct Debit instructions, sending pre-debit notifications, and reporting settlement status to the merchant.
  • Proving consent. Assembling the cryptographic evidence bundle (signed passkey assertion, mandate text hash, timestamp, device attestation) that the merchant can present if a customer disputes a debit.
  • Fraud prevention and risk scoring. Combining device, IP, and account-intelligence signals to decide whether a debit should proceed, be challenged, or be declined.
  • Compliance. Meeting our obligations under payment services regulation, anti-money-laundering rules, sanctions screening, and tax record-keeping requirements.
  • Customer support. Responding to questions from customers and merchants about specific payments, mandates, or refunds.
  • Service operation and improvement. Monitoring availability, investigating incidents, and improving reliability and security. Where we use data for product improvement, we aggregate and anonymise wherever feasible.
  • Communications. Sending transactional messages (receipts, pre-debit notices, mandate confirmations, failed-debit alerts). We do not use your data for marketing unless you have given separate consent.

We do not sell your personal data. We do not share it with advertising networks or data brokers. We do not profile you for purposes unrelated to running the payment service.

4. Legal Bases (Article 6 GDPR)

We rely on the following legal bases under Article 6 of the GDPR for each processing purpose:

  • Performance of a contract (Art. 6(1)(b)). Processing mandates, initiating SEPA Direct Debits, settling funds, providing receipts, and delivering customer support all of these are necessary to perform the payment you have asked us to process.
  • Compliance with a legal obligation (Art. 6(1)(c)). Retaining mandate and transaction records, running sanctions checks, and producing regulatory reports where we are required to do so by EU payment services law, anti-money-laundering rules, and tax legislation.
  • Legitimate interests (Art. 6(1)(f)). Fraud prevention, risk scoring, securing our systems, analysing service reliability, and defending against chargebacks. We have assessed that these interests are not overridden by your rights and freedoms, and we minimise the data used for each of these purposes.
  • Consent (Art. 6(1)(a)). Where we ask you to link a bank account via open banking, the bank authorisation you give is the legal basis for us to access your account information. You can withdraw this consent at any time, after which we will no longer fetch new data, though we will retain records we are required to keep under other legal bases.

We do not process special category personal data under Article 9 GDPR. Biometric authentication happens on your device and never reaches our systems.

5. Who We Share Data With

We work with a small number of carefully selected providers to deliver the payment service. Each of them is contractually bound to process your data only as instructed, and only for the purposes listed below.

  • Paynovate our licensed payment institution partner for SEPA Direct Debit initiation and settlement. We share the mandate details, IBAN, payment amount, and reference information necessary to process each payment.
  • Lunchflow and GoCardless licensed Account Information Service Providers (AISPs) that we use for PSD2 open banking bank-account linking and account intelligence. They receive the minimum information needed to initiate and complete the bank link flow you have authorised.
  • TrulyYou our biometric and passkey infrastructure provider. TrulyYou handles the WebAuthn challenge flow and passkey attestation verification. Biometric templates never leave your device; TrulyYou only ever sees public keys and signed attestations.

We may also disclose data to professional advisors (lawyers, auditors, accountants) bound by confidentiality, and to regulators, law-enforcement authorities, and courts where we are legally compelled to do so.

Beyond the providers listed above, we do not share your data with any other third parties.

6. Data Retention

We keep personal data only for as long as we need it, or as long as the law requires:

  • Mandate data retained for up to 10 years after the mandate is cancelled, in line with financial record-keeping obligations and the SEPA Direct Debit scheme rules that allow authorised claims to be brought within that period.
  • Transaction data retained for up to 8 years, in line with EU tax and accounting record-keeping obligations.
  • Biometric data never stored centrally. Biometric templates remain on your device and are controlled entirely by your operating system.
  • Cryptographic evidence bundles retained for the same period as the underlying transaction, so they remain available for chargeback defence.
  • Logs and diagnostic data retained for up to 90 days for operational logs, and up to 12 months for security and fraud-relevant logs.
  • Merchant account data retained for the duration of the merchant relationship, and for up to 5 years after the account is closed for anti-money-laundering record-keeping.

After these periods expire, we delete or irreversibly anonymise the data.

7. Your Rights

Under the GDPR and the UK GDPR you have the following rights in relation to your personal data:

  • Access obtain a copy of the personal data we hold about you, together with information about how we use it.
  • Rectification ask us to correct personal data that is inaccurate or incomplete.
  • Erasure ask us to delete personal data when we no longer need it for the purpose it was collected, subject to our legal retention obligations.
  • Portability receive a copy of the personal data you have provided to us in a structured, commonly used, machine-readable format, or ask us to send it directly to another provider.
  • Objection object to processing that we base on legitimate interests, including our fraud-prevention processing. Where you object, we will stop processing unless we can show compelling legitimate grounds that override your rights, or the processing is needed for a legal claim.
  • Restriction ask us to limit how we use your data while a dispute or correction request is being resolved.
  • Withdraw consent where processing is based on your consent, you can withdraw it at any time, without affecting the lawfulness of any processing we carried out before the withdrawal.
  • Lodge a complaint complain to your local data protection supervisory authority. In the UK this is the Information Commissioners Office (ico.org.uk). In other EU/EEA countries, you can contact your national data protection authority.

To exercise any of these rights, email us at sales@girotap.com. We will respond within one month as required by the GDPR. We may ask you to verify your identity before releasing personal data.

8. International Transfers

GiroTap is built to keep personal data inside the European Economic Area (EEA). Our production infrastructure, databases, and operational teams for payment processing are located in the EEA, and our sub-processors for SEPA settlement and open banking are EU or EEA licensed institutions.

Where any limited transfer outside the EEA is unavoidable for example, where a support tool is accessed from the United Kingdom following Brexit, or where a technical sub-processor operates globally we rely on appropriate safeguards recognised under Article 46 GDPR, such as the European Commissions Standard Contractual Clauses (SCCs), together with supplementary technical measures (encryption and pseudonymisation) where the transfer impact assessment indicates they are needed.

9. Security

We take the security of your data seriously. Our technical and organisational measures include:

  • Encryption in transit. All connections to GiroTap APIs and dashboards use TLS 1.2 or higher.
  • Encryption at rest. Personal data in our databases and backups is encrypted with AES-256.
  • Cryptographic evidence signing. Every mandate and payment authorisation produces a cryptographically signed bundle that cannot be altered after the fact without detection.
  • On-device biometrics. Biometric authentication is performed by your devices secure enclave. We never receive or store raw biometric templates.
  • Passkeys, not passwords. Authentication is based on WebAuthn passkeys with private keys that never leave the users device.
  • Access controls. Access to production systems is limited to authorised personnel, protected by multi-factor authentication, and logged for audit.
  • Monitoring. We operate security monitoring and incident response procedures, and we conduct regular security reviews of our infrastructure and code.

10. Cookies

GiroTap uses a small number of strictly necessary cookies to keep you signed in, remember your preferences, and prevent fraudulent sessions. We do not use third-party advertising or tracking cookies, and we do not participate in cross-site behavioural advertising. For more detail on the specific cookies we set and how to manage them, see our Cookie Policy.

11. Children

GiroTap is a payment service for adults. It is not directed at children, and we do not knowingly process personal data of anyone under 16. If you believe a child has provided personal data to GiroTap, please contact us and we will delete it.

12. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in the service, in the providers we work with, or in the law. When we make a material change, we will update the Last updated date at the top of this page and, where appropriate, notify you by email or through the merchant dashboard before the changes take effect. We encourage you to review this page periodically.

13. Contact Us

If you have questions about this Privacy Policy, want to exercise any of your rights, or would like to raise a concern about how we handle your personal data, please contact us:

CONFIG MONEY LIMITEDCompany No. 16474180
124-128 City Road, London, EC1V 2NX, United Kingdom
Email: sales@girotap.com