Pravno
Politika privatnosti
Ažurirano: 26. juli 2026.
Ova Politika privatnosti objašnjava kako Perper obrađuje lične podatke kada koristite SDK portal (sdk.perper.net), hosted checkout (/pay) i povezane tehnološke površine. Platne usluge se pružaju uz licencirane partnere gdje se kreće live novac — u skladu sa GDPR transparentnošću.
1. Controller and contact
- Controller for the SDK portal and related technology processing: Perper.
- Where a licensed bank, payment institution, or e-money institution processes payment data as an independent (or joint) controller, their privacy notice also applies — we will identify the active partner in product or contract materials when live settlement is enabled.
- Privacy / DPO contact: privacy@perper.net
- Complaints about payments: complaints@perper.net
2. Data we process
- Account data: username, name, email, phone, verification flags.
- Authentication data: login events, PIN verification outcomes, session and security cookies.
- Payment data: amounts, counterparties (usernames), transaction identifiers, timestamps, project identifiers, optional merchant references (customId / data), payout bank account details you submit.
- Technical data: IP address, user agent, approximate device/browser metadata needed for security and fraud prevention.
- Support data: messages you send to support or complaints channels.
3. Purposes and legal bases (GDPR Art. 6)
- Contract performance: create projects, process payments and withdrawals, operate the merchant portal.
- Legal obligation: anti-money-laundering / KYC where required, payment-service record keeping, responding to supervisory or law-enforcement requests.
- Legitimate interests: security, fraud prevention, service integrity, improving reliability (balanced against your rights).
- Consent: optional analytics cookies (if you accept them). You may withdraw consent at any time via Cookie settings.
4. PSD2 / payment-specific processing
- When you authorize a payment, we process authentication and transaction data to apply strong customer authentication principles, including linking confirmation to a specific amount and payee.
- Payment and security logs are retained only as long as needed for fraud prevention, dispute handling, and legal retention duties.
5. Recipients and processors
- Infrastructure and hosting providers that process data on our instructions.
- Licensed banking, payment-institution, or e-money partners that provide settlement, safeguarding, and payouts under their authorisation.
- Authorities when required by law.
- We do not sell personal data.
6. International transfers
- We aim to keep processing in the EEA / adequate jurisdictions. Where a transfer outside the EEA is necessary, we use appropriate safeguards (e.g. Standard Contractual Clauses).
7. Retention
- Account data: for the life of the account plus a limited period after closure for legal claims and compliance.
- Transaction records: retained for the statutory period applicable to payment services (typically several years).
- Security logs: shorter operational windows unless needed for an investigation.
8. Your rights
- You may request access, rectification, erasure, restriction, portability, and objection where applicable.
- Use the in-app Legal → Your rights page or email privacy@perper.net.
- You may lodge a complaint with your local data-protection authority.
9. Security
- We use HTTPS, HttpOnly session cookies, CSRF protections on mutations, rate limiting on authentication, and step-up checks for sensitive actions (e.g. revealing project secrets).
10. Changes
- We may update this Policy. The “Last updated” date at the top will change. Material changes will be highlighted in the portal where practicable.