This document clarifies the data protection roles and responsibilities when using the Payaz platform. It is designed to help your charity understand how donor data is handled and what you need to communicate to your supporters.
Q: In GDPR terms, what is the relationship between our charity and Payaz?
A: Your charity is the Data Controller. You decide why and how donor data is collected and used. Payaz acts as the Data Processor. We provide the technology and platform to collect that data on your behalf and according to your instructions.
Q: Where do Stripe, SumUp and Go Cardless fit in?
A: Stripe, SumUp, Go Cardless are also Data Processors (or in some specific payment contexts, independent Controllers). They handle the actual movement of money and financial security. When a donor taps their card, Payaz handles the “front-end” donor info (like Gift Aid), while Stripe, SumUp & Go Cardless handles the “back-end” payment processing.
Q: Why does the Payaz “Transaction Complete” screen look the way it does?
A: Under GDPR, consent must be “granular.” This means you cannot bundle different types of data collection together. We have designed the interface so that a donor must make a distinct choice for:
Adding Gift Aid: (Optional choice; Legal/Tax requirement if selected)
Opting into Marketing: (Consent-based)
Requesting a Digital Receipt: (Contractual/Service-based)
Q: Do we need a “Legal Basis” for each of these?
A: Yes. Typically:
Gift Aid: While the donor has the choice to opt-in or out, if they choose to add Gift Aid, you collect their data based on a Legal Obligation to HMRC.
Marketing: This strictly requires Explicit Consent (an opt-in).
Receipts: This is processed on a Contractual basis. When a donor requests a receipt, you are fulfilling a service/transactional obligation to provide proof of their donation.
Q: How do we show our Privacy Policy to donors on the kiosk?
A: It is essential that you add your organization’s Privacy Policy URL within your Payaz Dashboard Settings.
Navigate to the GDPR & Privacy section in the Setting Page of the Payaz Dashboard.
Paste the link to your policy in the Privacy Policy URL field.
Click Save. This ensures that the “Privacy Policy” links on the donation screen correctly point to your specific terms, fulfilling your duty of transparency.
Q: What should we include in our policy regarding Payaz?
A: We recommend including language similar to the following:
“We use Payaz as a third-party platform to facilitate our digital donations. When you donate via our kiosks or mobile links, your personal data is processed by Payaz on our behalf. Financial transactions are securely handled by our payment partners, Stripe/SumUp/Go Cardless. We only share the information necessary to process your donation, claim Gift Aid (where applicable), provide receipts, and record your marketing preferences”
Q: Is the data secure while being processed?
A: Absolutely. Payaz uses industry-standard encryption (SSL/TLS) for all data in transit. Furthermore, Payaz does not store full credit card numbers; these are “tokenized” by Stripe, SumUp & Go Cardless meaning the sensitive financial data never actually touches our servers in a readable format.
Q: What happens if a donor asks to be “Forgotten”?
A: As the Data Controller, if a donor contacts you requesting the deletion of their data, you must instruct us to remove their record from the Payaz portal. We will then purge that data from our systems in accordance with your request.
Ownership: You own the donor data; Payaz simply manages it for you.
Action Needed: You must save your Privacy Policy URL in the dashboard settings to remain compliant.
Audit Trail: Payaz provides the reports you need to prove consent was given, which is a key requirement if the ICO ever asks for an audit.
Disclaimer: This document is for informational purposes and does not constitute legal advice. We recommend consulting with a legal professional to ensure your charity is fully compliant with UK GDPR.