es

Privacy Policy

TRANZA L.L.C-FZ | tranza.io
Last updated: 5 October 2026

1. Company and Scope

This Privacy Policy explains how TRANZA L.L.C-FZ (“TRANZA”, the “Company” or “we”) collects, uses, retains and shares personal data in connection with tranza.io, its platform, dashboards, APIs and related services, merchant onboarding and servicing, and cooperation with banks and payment partners.

TRANZA is incorporated in Meydan Free Zone, Dubai, UAE. Meydan Free Zone Business Licence No. 2649230.01 includes the activity Payment Services Provider, code 8291.98. The Company provides legal entities with technology, operational and settlement-information infrastructure. This business licence does not, by itself, evidence separate authorisation from the Central Bank of the UAE to provide regulated financial services.

This Policy covers website visitors, platform users, representatives, directors, signatories and beneficial owners of merchants and counterparties, and payers and beneficiaries to the extent their information is available to TRANZA. Making a payment to a merchant does not, by itself, make the payer a TRANZA client. Read this Policy together with the applicable terms of service, AML/CFT/CPF Policy and Cookie Policy.

2. TRANZA’s Role in Processing

TRANZA acts as a personal data controller for processing whose purposes and means it determines, including website and platform operation, communications, merchant onboarding, its own checks and risk assessment, security, monitoring of available payment information and record keeping. This data protection role does not imply status as a regulated financial institution.

Where TRANZA processes data solely on another party’s documented instructions, its role and obligations are governed by the relevant agreement and applicable law. Banks, acquirers, payment and verification providers may act as independent controllers or processors depending on the particular processing. Their independent processing is governed by their own privacy notices; this Policy describes processing performed by TRANZA.

3. Data Categories and Sources

Depending on the relationship, service, risk level and available information, we may process names, contact details, positions and authority; account data and correspondence; identification documents and information concerning representatives, directors, signatories and beneficial owners; ownership and control information; sanctions, PEP and other compliance check results; source of funds and, where necessary, source of wealth information; available payment details, identifiers, amounts, dates, statuses and purposes; and documents concerning payments, refunds, complaints and disputes.

Use of the website and platform may involve processing IP addresses, device, browser and operating system information, access and activity logs, and data from cookies and similar technologies as described in the Cookie Policy.

Data may come from you, merchants and their representatives, banks, payment and settlement partners, verification and technical service providers, and lawfully accessible public sources, registers and sanctions lists. Collection and use are limited to what is necessary. This list does not mean that TRANZA receives every category for every person or payment.

4. Purposes of Processing

We use data to operate and support the website, platform and accounts; handle enquiries and establish business relationships; verify merchants, beneficial owners and representatives’ authority; perform agreements and coordinate settlements; conduct reconciliation and reporting and handle refunds, complaints and disputes; protect infrastructure and prevent misuse; assess AML/CFT/CPF, sanctions and fraud risks; monitor available payment information; and internally review unusual transactions.

Data may also be used to respond to justified bank and partner requests, comply with applicable legal obligations, and establish, exercise or defend legal claims. Information and marketing communications are sent subject to applicable requirements and any necessary consent; you may opt out of optional communications.

5. Legal Grounds

TRANZA determines the legal ground for each processing purpose under applicable data protection law. Depending on the circumstances, this may be consent; necessity to perform a contract with the data subject or take steps at their request before entering into a contract; an applicable legal obligation; establishment, exercise or defence of legal claims; or another expressly permitted ground. Legitimate interests are used only where and to the extent that the applicable legal regime permits that ground, taking account of the data subject’s rights and interests.

A merchant agreement does not automatically provide a ground for every processing activity concerning its representatives, beneficial owners or customers. Internal AML policies and partner requirements describe purposes and controls but do not replace a necessary legal ground. Where consent is required, it is requested separately. Withdrawal does not affect the lawfulness of earlier processing or stop processing lawfully undertaken on another ground.

Certain information may be necessary for verification or servicing. Without necessary information, TRANZA may be unable to onboard a merchant, provide a particular service or continue servicing.

6. Sharing Personal Data

Where there is an applicable legal ground and to the extent necessary, we may share data with servicing banks, acquirers, payment and settlement partners; providers of identification, compliance checks, hosting, communications, security and technical support; professional advisers and auditors; and competent authorities where disclosure is required or permitted by law.

Disclosure takes account of its purpose, confidentiality, contractual terms and the recipient’s role. Recipients processing on our behalf must act within agreed instructions and data protection requirements. Independent controllers are responsible for their own processing. TRANZA does not sell personal data.

7. International Processing and Transfers

Because services are international, data may be processed in the UAE and other countries where relevant banks, partners or services are located; access from another country may also be relevant to international transfer rules. Applicable transfer requirements are assessed in light of the data, recipient and jurisdictions involved.

Where necessary, TRANZA applies the mechanisms and safeguards required by the applicable law for international transfers. Information about recipients, countries and safeguards relevant to your data may be requested using the contact details below, subject to permitted disclosure restrictions.

8. Retention

Data is retained to the extent and for the period necessary for the relevant purposes and permitted by applicable law. For KYB/CDD and EDD documents and records, check results, available payment information and material compliance correspondence, the baseline internal retention period is at least five years after the end of the business relationship or the relevant transaction, whichever occurs later, subject to a proper ground for retention.

Longer retention may apply in connection with a mandatory requirement, investigation, dispute or defence of legal claims where there is an appropriate ground. Retention of website enquiries, account information, technical logs and optional communications is determined by their purpose, necessity, the relationship and applicable requirements; the five-year period does not automatically apply to all data.

Once retention is no longer necessary or supported by a legal ground, data is deleted or anonymised, taking account of applicable rules and the technical backup cycle.

9. Security and Confidentiality

TRANZA applies reasonable organisational and technical safeguards appropriate to the data and risks, including need-to-know access restrictions and controls on information sharing. Measures are reviewed as processes and risks change. Users must keep their account credentials confidential. Absolute security of transmission and storage cannot be guaranteed.

If a personal data breach is identified, the Company assesses the circumstances and takes necessary action, including notifying competent authorities and affected individuals where required by applicable law.

10. Verification Tools and Automation

Depending on the systems used, checks and monitoring may include automated matching, alerts and assessment of risk indicators. These activities do not, by themselves, mean that a decision is made solely by automated means without human involvement.

If particular processing involves a solely automated decision producing legal or similarly significant effects on an individual, TRANZA provides the necessary information and implements safeguards and challenge procedures required by applicable law. You may request information about the processing of your data and applicable review options from the Company.

11. Your Rights and Requests

Depending on applicable law, you may have rights to information about processing and access to data, correction, deletion or restriction, objection, data portability, withdrawal of consent, and complaint to a competent authority. The scope and conditions of those rights depend on the relevant legal regime.

Requests concerning TRANZA’s processing should be sent to info@tranza.io. We may request information reasonably necessary to verify the applicant’s identity and authority and respond within applicable legal time limits. Requests concerning a bank’s or partner’s independent processing should be directed to that party; where necessary, we explain how to contact the relevant party.

Rights may be restricted in circumstances permitted by law, including lawful record retention, protection of legal claims, other persons’ rights, investigation confidentiality and applicable tipping-off restrictions. Refusal or restriction is not applied automatically to all compliance data; the grounds are assessed for the particular request.

12. Updates and Contact Details

Updated versions are published on the website with a revised date. Material changes are communicated in a manner appropriate to their nature and applicable requirements. Where a change requires new consent, it is requested separately; continued use of the website does not, by itself, replace that consent. For personal data protection enquiries: info@tranza.io. TRANZA L.L.C-FZ, Meydan Grandstand, 6th floor, Meydan Road, Nad Al Sheba, Dubai, U.A.E.