This Privacy Policy describes how aiwrallex Ltd. ("aiwrallex", "we", "us", or "our") collects, uses, and protects personal data when you use our global payments infrastructure, APIs, dashboard, documentation, and related services (collectively, the "Services"). Please read this policy carefully.
We collect information you provide directly: name, email address, company name, billing information, and API credentials when you register or use aiwrallex services.
We automatically collect technical data including IP addresses, browser type, operating system, pages visited, request logs, and device identifiers.
We may collect payment-related data (transaction amounts, currency, timestamps) processed through our infrastructure to deliver and improve our services.
To provision, operate, and improve aiwrallex payment infrastructure; authenticate users; and process transactions on your behalf.
To send transactional communications (invoices, security alerts, API status updates) and, where you have opted in, product announcements.
To comply with legal obligations, detect fraud, prevent abuse, and enforce our Terms of Service.
We share data with sub-processors (cloud infrastructure, fraud detection, identity verification) only to the extent necessary to deliver our services. All sub-processors are bound by data processing agreements.
We do not sell, rent, or trade your personal data to third parties for marketing purposes.
We may disclose data to law enforcement or regulatory authorities when required by applicable law.
Under GDPR, you have the right to access, rectify, erase, restrict, or port your personal data, and to object to certain processing. EEA/UK users may lodge complaints with their local supervisory authority.
Under CCPA, California residents may request disclosure of personal information collected, request deletion, and opt out of the sale of personal information (we do not sell personal information).
To exercise any right, contact us at [email protected]. We respond within 30 days.
We retain account data for the duration of your contract plus 7 years to comply with financial regulations (e.g., AML/KYC obligations).
Technical logs are retained for up to 12 months. Anonymised aggregate analytics may be retained indefinitely.
We apply AES-256 encryption at rest, TLS 1.3 in transit, role-based access controls, and regular third-party penetration testing.
We maintain SOC 2 Type II certification. In the event of a breach affecting your data, we will notify you within 72 hours as required by GDPR.
aiwrallex services are intended solely for business users aged 18 and over. We do not knowingly collect personal data from minors.
If we become aware that a minor has provided us with personal data, we will delete it promptly.
We may update this Privacy Policy periodically. Material changes will be communicated via email or a prominent notice in your dashboard at least 14 days before taking effect.
Continued use of aiwrallex services after the effective date constitutes acceptance of the revised policy.
Data Controller: aiwrallex Ltd., 1 Canada Square, Canary Wharf, London, E14 5AB, United Kingdom.
For privacy enquiries or to reach our Data Protection Officer: [email protected]
For EU/EEA residents: our EU Representative can be reached at [email protected].
Questions about your privacy?
Contact our Data Protection Officer at [email protected] — we aim to respond within 30 days.
aiwrallex © 2026 | [email protected] | +1 (800) 294-5510 | 340 Pine Street, Suite 800, San Francisco, CA 94104, USA