AxiomePayments
Privacy Policy
Last updated: 01.03.2026
Undercover Payments sp. z o.o. operates AxiomePayments. Registration Number: 0001069394. Registered Address: ul. Bartycka 22B/21A, 00-716 Warszawa, Mazowieckie, Poland.
This Privacy Policy describes how Undercover Payments sp. z o.o. ("AxiomePayments," "we," "us," or "our") collects, uses, stores, and protects personal data in connection with our website and payment platform. We process personal data in accordance with the EU General Data Protection Regulation (GDPR) and applicable Polish data protection law.
1. Who We Are
Undercover Payments sp. z o.o. is the data controller for personal data processed through the AxiomePayments platform — meaning we determine the purposes and means of that processing. Our contact details are at the bottom of this page. AxiomePayments is a trading name of Undercover Payments sp. z o.o.
2. Personal Data We Collect
We collect the following categories of data to operate the platform:
- Account data: name, email address, phone number, and password (stored as a salted hash, never in plain text) when you register as a merchant or agent.
- Verification data: business registration documents, beneficial-owner identity information, and related KYB documentation, where required to activate certain account features.
- Buyer checkout data: when a buyer completes a checkout, we collect the information they provide (name, email, phone, date of birth, country) to process that specific payment and pass required fields to our payment providers.
- Transaction data: payment amounts, currencies, timestamps, wallet addresses, and blockchain transaction hashes associated with settlements.
- Technical data: IP address and basic request metadata collected automatically as part of normal web server operation.
On this public website, we also collect:
- Enquiry data: the business details you submit on merchant or partner intake forms (for example name, company, business email, website, country, and operational brief), so we can review fit and reply. These forms are not a channel for identity documents, bank statements, or cardholder data.
- Registration-access verification: a challenge token when you request Merchant Registration or Agent Registration from this website, so we can distinguish a person from automated abuse before you continue to the registration application.
- Technical data for this website: IP address and basic request metadata used for security, rate limiting, and operation of the site.
3. Legal Basis and Purpose of Processing
We process personal data under the following legal bases recognized by the GDPR:
- Contract performance: to create and manage your account, process payments, review an enquiry you submit on this website, and provide the services you or your business signed up for.
- Legal obligation: to meet know-your-business (KYB), anti-money-laundering, and financial record-keeping requirements that apply to a payment platform.
- Legitimate interests: to maintain platform and website security, detect and prevent fraud and automated abuse, and improve reliability — balanced against your right to privacy.
- Consent: for anything not covered above, such as optional marketing communications, which you can withdraw at any time. This website does not run advertising or analytics tracking.
5. International Transfers
Where personal data is transferred outside the European Economic Area — for example, to a service provider located elsewhere — we rely on appropriate safeguards recognized under GDPR Chapter V, such as the European Commission's Standard Contractual Clauses, to ensure an equivalent level of protection.
6. Data Retention
We retain personal data only for as long as necessary for the purposes described above. Transaction and KYB-related records are generally retained for the periods required under applicable anti-money-laundering and accounting regulations. Account data is retained for the life of the account and a reasonable period afterward for legal and dispute-resolution purposes, after which it is deleted or anonymized. Enquiry correspondence submitted on this website is retained only as long as needed for those same purposes, then deleted or anonymized.
7. Security
We apply technical and organizational measures appropriate to the sensitivity of the data we hold, including encrypted connections, restricted database access, and hashed password storage. This marketing website transmits form submissions over encrypted connections and does not store a marketing database of submissions on the website itself. No system is completely secure, and we encourage you to use a strong, unique password for your account.
8. Your Rights
Under the GDPR, you have the right to:
- Be informed about how your data is used (this policy is part of that);
- Access the personal data we hold about you;
- Request correction of inaccurate or incomplete data;
- Request erasure of your data, subject to our legal retention obligations (e.g. AML records);
- Object to processing based on legitimate interests or direct marketing;
- Request a portable copy of data you provided to us;
- Lodge a complaint with the Polish data protection authority (Urząd Ochrony Danych Osobowych, UODO) or your own country's supervisory authority.
To exercise any of these rights, contact us using the details below. We may ask you to verify your identity before acting on a request.
9. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will update the "Last updated" date when we do. Continued use of the platform after a change takes effect means you accept the revised policy.
10. Contact Us
Questions or requests regarding this Privacy Policy or your personal data can be sent to support@axiomepayments.com, or by post to:
Undercover Payments sp. z o.o., ul. Bartycka 22B/21A, 00-716 Warszawa, Mazowieckie, Poland. Registration Number: 0001069394. Website: https://axiomepayments.com.
