Carteza
    • Platform
      • Payment Gateway
      • Payment Orchestration
      • Subscriptions
      • White Label
      • Payment links
    • Payment methods
      • Card Payments
      • International Payments
      • Bank Transfer
    • Industries
      • Ecommerce
      • Gaming
      • SaaS
      • Marketplace
      • Edu
  • Pricing
  • Partners
Telegram
Telegram

Privacy Policy

Effective from: September 2026

This Privacy Policy explains in detail how Cardway Technologies OÜ (“Cardway Tech”, “we”, “our”, or “us”), operator of the website https://carteza.com (the “Site”), collects, uses, stores, discloses, and protects personal and business data in connection with your access to and use of the Site and all associated services, applications, software, integrations, and technologies (collectively, the “Services”). This Policy applies to all Users, including legal entities, business representatives, and individuals acting on behalf of organizations.

Cardway Technologies OÜ
Registration No.: 17593866 
Registered Address: Harju maakond, Tallinn, Kesklinna linnaosa, Vesivärava tn 50-201, 10152, Estonia
e-mail: [email protected] 
Supervisory Authority: Estonian Data Protection Inspectorate (AKI), Tatari 39, 10134 Tallinn, Estonia | www.aki.ee 

1. Legal Framework

Cardway Tech’s data processing activities are governed by Regulation (EU) 2016/679 (General Data Protection Regulation, “GDPR”), Directive 2002/58/EC (ePrivacy Directive), and all applicable Estonian and EU data protection laws.

Cardway Technologies OÜ acts as a data controller in respect of personal data collected directly through the Site (e.g. contact forms, account registration, and cookie analytics). Where Cardway Tech processes personal data on behalf of a business client (partner) pursuant to a written Data Processing Agreement (DPA), it acts as a data processor within the meaning of GDPR Art. 28. The applicable role is specified in the relevant DPA or service agreement.

Data generated through the use of the Services (including API interaction logs, transaction reference data, and platform usage metrics) may constitute data within the meaning of Regulation (EU) 2023/2854 (EU Data Act). Where such data is generated through the use of connected products or related services within the scope of the Data Act, users and business partners retain applicable data access and portability rights as set out in Section 1 of this Policy.

2. Categories of Data Collected

We may collect and process the following categories of personal and business data:

Identification data: full name, business name, tax identification number, national ID numbers, registration numbers.

Contact information: physical address, phone number, email address, country of residence.

Verification documents: identity cards, passports, proof of address, business registration certificates, AML/KYC forms.

Technical data: IP address, browser type, device identifiers, cookies, time zone, operating system.

Usage data: interactions with the Site, access logs, clickstream data, user agent metadata, support tickets.

Communications data: messages, inquiries, and feedback exchanged with our support or compliance teams.

Cardway Tech does not store payment card data (PAN, CVV, expiry dates) or process payment transactions on its own behalf. Technical payment-related data (e.g. transaction reference numbers, aggregated volumes, API session identifiers) may be processed solely for the purpose of providing technical integration services to our licensed payment partner(s). No card data is retained by Cardway Tech at any point.

Sources of Personal Data.
Personal data may be collected: (a) directly from the data subject via the Site (contact forms, registration, cookie consent); (b) from business clients (partners) who transmit data in connection with API integration services; (c) from publicly available sources (company registries, sanctions lists) for AML/KYC screening purposes; (d) automatically through cookies and tracking technologies as described in Section 9.

Obligation to Provide Data.
Where the collection of personal data is required to enter into or perform a contract or to comply with a legal obligation (e.g. AML/KYC), failure to provide the requested data may result in Cardway Tech being unable to provide the requested Services. Fields marked as mandatory in our forms are required for this purpose; all other fields are optional.

3. Purposes and Lawful Bases for Processing

Your data is processed strictly for legitimate and lawful purposes, including:

Providing, operating, and administering the Services (GDPR Art. 6(1)(b));

Complying with regulatory obligations, including Anti-Money Laundering (AML), Counter-Terrorist Financing (CTF), Know-Your-Customer (KYC), and taxation laws (GDPR Art. 6(1)(c));

Fraud detection, cybersecurity monitoring, auditing, and risk prevention (GDPR Art. 6(1)(f));

Improving the functionality and user experience of the Site (GDPR Art. 6(1)(f));

Direct marketing communications (including email newsletters): processed on the basis of your explicit consent (GDPR Art. 6(1)(a)) or, where you are an existing business contact, on the basis of legitimate interest (GDPR Art. 6(1)(f)), subject to your right to object at any time by contacting [email protected] or using the unsubscribe link in each communication.

Cardway Tech does not make automated individual decisions (including profiling) that produce legal or similarly significant effects, within the meaning of GDPR Art. 22. Should automated processing with such effects become necessary, Cardway Tech will notify affected data subjects and implement appropriate safeguards, including the right to human review, as required by GDPR Art. 22(2)-(4).

4. Data Retention

We retain personal data only as long as necessary for the purposes stated or as required by law, including:

AML/CTF records and KYC documentation: retained for a minimum of 5 years following the end of the business relationship or the date of an occasional transaction, as required by Directive (EU) 2015/849 (AMLD4) as amended by Directive (EU) 2018/843 (AMLD5) and transposed into Estonian law. In specific cases (e.g. ongoing investigation), retention may be extended to 10 years subject to a supervisory order.

Cookie and analytics data: retained for no longer than 13 months from the date of collection, in line with guidance from the Estonian Data Protection Inspectorate (AKI) and CNIL cookie guidelines. Targeting/advertising cookies are retained only for the duration of the consent period or until consent is withdrawn.

Contracts and support communications: for the contract duration plus any applicable statutory limitation period.

Website analytics data: typically anonymized or aggregated, or retained for no more than 2 years.

5. Data Security

We implement appropriate technical and organizational measures to protect your data, including:

Encryption of data in transit and at rest;

Role-based access controls and secure credential management;

Network firewalls, intrusion detection, and anti-DDoS infrastructure;

Internal policies for data minimization and segregation of access;

Mandatory confidentiality undertakings for all personnel and contractors.

Personal Data Breach Notification. In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of natural persons, Cardway Tech will notify the Estonian Data Protection Inspectorate (AKI) without undue delay and, where feasible, within 72 hours of becoming aware of the breach, in accordance with GDPR Art. 33. Where the breach is likely to result in a high risk to affected individuals, Cardway Tech will also notify those individuals without undue delay (GDPR Art. 34).

ICT and Operational Resilience. Cardway Tech implements ICT risk management measures consistent with applicable regulatory expectations, including those arising under Regulation (EU) 2022/2554 (DORA, in application from 17 January 2025) where relevant to its role as an ICT third-party service provider to regulated financial entities. These measures include regular security testing, incident classification procedures, and documented ICT continuity plans.

6. Sharing of Data

Personal data is shared only where strictly necessary, on a lawful basis, and with:

Regulatory authorities, courts, or law enforcement, as required by law;

Financial institutions, banking partners, and licensed payment processors, to fulfill contractual services;

Verified service providers or subcontractors, under binding data processing agreements;

Internal group companies, solely for compliance, audit, or administrative purposes.

We do not sell or rent personal data to third parties under any circumstances.

Sub-processors. Cardway Tech may engage sub-processors (e.g. cloud hosting, analytics, security monitoring) to assist in delivering the Services. All sub-processors are bound by written data processing agreements meeting the requirements of GDPR Art. 28. Data subjects and business partners will be notified of any material changes to sub-processor arrangements.

7. International Data Transfers

Where personal data is transferred outside the European Economic Area (EEA), Cardway Tech ensures adequate protection through one or more of the following safeguards: (a) an adequacy decision of the European Commission (for transfers to the United Kingdom, Cardway Tech relies on the most current applicable transfer mechanism. Users are advised to check the current status at https://ec.europa.eu/; Switzerland; and other listed countries); (b) Standard Contractual Clauses (SCCs) adopted by the European Commission under GDPR Art. 46(2)(c), including updated SCCs (Decision 2021/914/EU); or (c) other safeguards permitted under GDPR Art. 46. A list of applicable transfer mechanisms is available upon request.

Where Standard Contractual Clauses are used, Cardway Tech conducts a Transfer Impact Assessment (TIA) to evaluate whether the laws of the destination country ensure an essentially equivalent level of protection to that guaranteed in the EEA. Results of TIAs are documented and available to the supervisory authority upon request.

8. Your Rights

You have the following rights under data protection law:

Right of access: to know if we process your data and to receive a copy;

Right to rectification: to correct inaccurate or incomplete data;

Right to erasure (“right to be forgotten”): to request deletion of your data in certain circumstances;

Right to restriction: to request temporary suspension of processing in specific cases;

Right to data portability: to receive your data in a structured, commonly used, machine-readable format and transmit it to another controller;

Right to object: to processing based on legitimate interest or for direct marketing;

Right to withdraw consent: where processing is based on your consent (Art. 6(1)(a) GDPR), you have the right to withdraw that consent at any time, without affecting the lawfulness of processing carried out prior to withdrawal. Consent may be withdrawn by contacting [email protected] or, for cookies, via the cookie management tool on the Site.

Right to lodge a complaint: you have the right to lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon / AKI): Tatari 39, 10134 Tallinn, Estonia; email: [email protected] , tel.: +372 627 4135; www.aki.ee. If you are located in another EU/EEA 

Member State, you may alternatively lodge a complaint with the supervisory authority of your country of habitual residence.

How to Exercise Your Rights. To exercise any of the rights listed above, please submit a written request to [email protected] with the subject line "Data Subject Request". Cardway Tech will respond within one (1) month of receipt of your request. Where requests are complex or numerous, this period may be extended by a further two (2) months; you will be informed of any such extension within the first month. Responses are provided free of charge, except where requests are manifestly unfounded or excessive (GDPR Art. 12(5)).

9. Cookies and Tracking Technologies

The Site uses cookies and similar technologies to enhance user experience, gather analytics, and personalize services, including:

Strictly necessary cookies for session management;

Functional cookies to store preferences;

Performance cookies for usage metrics;

Targeting cookies for advertising and remarketing.

You may manage your cookie preferences via your browser settings or opt out of specific categories as required by law. Non-essential cookies (functional, performance, targeting) are only placed on your device after you have given your explicit, prior, and freely given consent via our cookie consent banner. You may withdraw or modify your consent at any time by clicking the "Cookie Settings" link in the footer of the Site. Essential cookies, necessary for the basic functioning of the Site, do not require consent and are placed automatically. Detailed information about each cookie category, including name, provider, purpose, and maximum retention period, is available in our separate Cookie Policy.

10. Policy Amendments

Cardway Tech may update this Privacy Policy from time to time. Any material changes (including, but not limited to, the introduction of new categories of personal data, new processing purposes, or new categories of recipients) will be communicated to registered users via email at least 30 days before they take effect and will be prominently displayed on the Site. The revised Privacy Policy will indicate the updated effective date. Where required by applicable law, Cardway Tech will obtain renewed consent before implementing such changes.

11. Contact Information

If you have questions, requests, or concerns regarding this Privacy Policy or your personal data, please contact:

Cardway Technologies OÜ

Email: [email protected]  

Important Notice: Cardway Technologies OÜ acts solely as a technical platform provider and does not provide regulated payment services, act as a payment institution, or hold client funds. All payment processing and related regulated activities are performed by duly licensed third-party payment service providers.

Based on its current activities, Cardway Tech has determined that the appointment of a Data Protection Officer (DPO) is not required under applicable data protection laws, including Article 37 of the GDPR. Cardway Tech does not conduct large-scale systematic monitoring of individuals as a core activity and does not process special categories of personal data on a large scale. Nevertheless, Cardway Tech maintains a dedicated data protection contact for privacy-related inquiries and requests.

Carteza

Legal Information

  • AML
  • Cookie Policy
  • Privacy Policy
  • Terms of Service
  • DORA
  • About Us
  • Blog
[email protected]
Cardway Technologies OÜ (17593866)
Payment services are provided through licensed partners. Carteza delivers the technical infrastructure and payment orchestration layer via a single API.



© 2026 Carteza. All rights reserved.

This website uses cookies

Our website uses cookies to improve functionality and user experience, and to analyze traffic. By continuing to use our site, you agree to our use of cookies.

Get Custom Pricing

Share your requirements and we'll get back to you with custom payment terms.

Business type *

Select your Business type

E-commerce

SaaS

Marketplace

Subscription business

Crypto / Web3

Mobile app

Education

Other

Interesting Geo *

Select your Geo

Aland Islands

Albania

Andorra

Antigua and Barbuda

Argentina

Armenia

Australia

Austria

Azerbaijan

Bahamas

Bahrain

Bangladesh

Barbados

Belgium

Belize

Benin

Bermuda

Bhutan

Bosnia and Herzegovina

Botswana

Brazil

Brunei Darussalam

Bulgaria

Burundi

Cambodia

Canada

Cape Verde

Chad

Chile

China

Colombia

Comoros

Costa Rica

Croatia

Cyprus

Czech Republic

Denmark

Djibouti

Dominica

Dominican Republic

Ecuador

Egypt

El Salvador

Equatorial Guinea

Estonia

Eswatini

Ethiopia

Fiji

Finland

France

French Guiana

Gabon

Gambia

Georgia

Germany

Ghana

Greece

Greenland

Grenada

Guatemala

Guyana

Honduras

Hong Kong

Hungary

Iceland

India

Indonesia

Iraq

Ireland

Israel

Italy

Jamaica

Japan

Jordan

Kazakhstan

Kiribati

Kosovo

Kuwait

Kyrgyzstan

Latvia

Lesotho

Liberia

Liechtenstein

Lithuania

Luxembourg

Madagascar

Malawi

Malaysia

Maldives

Malta

Marshall Islands

Mauritania

Mauritius

Mayotte

Mexico

Micronesia

Moldova

Mongolia

Montenegro

Morocco

Nauru

Netherlands

New Zealand

Nicaragua

North Macedonia

Norway

Oman

Pakistan

Palau

Panama

Papua New Guinea

Paraguay

Peru

Philippines

Poland

Portugal

Puerto Rico

Qatar

Reunion

Romania

Rwanda

Saint Barthelemy

Saint Kitts and Nevis

Saint Lucia

Saint Martin (French part)

Saint Vincent and the Grenadines

Samoa

San Marino

Saudi Arabia

Senegal

Serbia

Seychelles

Sierra Leone

Singapore

Slovakia

Slovenia

Solomon Islands

South Korea

Spain

Sri Lanka

Suriname

Svalbard and Jan Mayen

Sweden

Switzerland

São Tomé and Príncipe

Taiwan

Tajikistan

Thailand

Timor-Leste

Togo

Tonga

Tunisia

Turkey

Turkmenistan

Tuvalu

Uganda

Ukraine

United Arab Emirates

United Kingdom

United States

Uruguay

Uzbekistan

Vatican City

Western Sahara

Zambia

Zimbabwe

0/300

Thank you — we'll be in touch within one business day.