Privacy Policy
How Pay it Today collects, uses and protects your personal data, in compliance with Regulation (EU) 2016/679 (GDPR) and the French Data Protection Act of 6 January 1978 as amended.
Last updated: 2026-05-15
1. Data controllers
Two entities act as data controllers, each within the scope of the processing operations that fall under their own responsibility.
Sell it Today SAS, registered with the Paris Trade and Companies Register under [SIT-SIREN], is the data controller for processing related to the platform layer: account creation, in-app interactions, customer support, marketing communications, security of the applications.
Treezor SAS, EMI licensed by the ACPR under number 16798, is the data controller for processing related to the regulated banking layer: identity verification under AML/CFT, IBAN allocation, execution of payment transactions, card issuance, fraud monitoring, regulatory reporting. The two entities cooperate as joint controllers within the meaning of Article 26 of the GDPR for the on-boarding flow; the essence of their arrangement is described below and a copy may be obtained on request.
2. Categories of personal data
We process the following categories of data:
- identification data: name, first names, date and place of birth, nationality, identity-document number, copy of the identity document, selfie / liveness video, signature; - contact data: postal address, email address, mobile phone number; - professional data: position held within the legal person, SIREN, SIRET, KBIS, beneficial-ownership declarations; - financial data: account balance, payment transactions, card transactions, beneficiary IBANs, source-of-funds declarations; - device and connection data: IP address, device identifier, operating system version, browser fingerprint, login timestamps, language preference; - biometric data: liveness-detection result returned by Ubble (processed by Ubble for the strict purpose of identity verification; we receive only the binary outcome and the underlying scoring features used for AML risk-rating).
We do not process the special categories of data listed in Article 9 of the GDPR for any purpose other than identity verification.
3. Purposes and legal basis
The purposes of processing and the corresponding legal basis under Article 6 of the GDPR are the following:
- provision and management of the Account: performance of the contract (Art. 6.1.b); - execution of payment transactions and card issuance: performance of the contract and compliance with a legal obligation under PSD2 (Art. 6.1.b and 6.1.c); - KYC/KYB identity verification: compliance with a legal obligation under Article L. 561-5 of the Code monétaire et financier (Art. 6.1.c); - AML/CFT monitoring, sanctions screening, suspicious-activity reporting to Tracfin: compliance with a legal obligation (Art. 6.1.c); - fraud prevention and security of the Services: legitimate interest of the controller and of the user (Art. 6.1.f); - customer support and complaints handling: performance of the contract and legitimate interest (Art. 6.1.b and 6.1.f); - direct marketing of similar products and services to existing clients: legitimate interest (Art. 6.1.f), with an opt-out at any time; - accounting, tax and regulatory record-keeping: compliance with a legal obligation (Art. 6.1.c).
4. Recipients
Your data is shared, on a need-to-know basis, with:
- Treezor SAS, in its capacity as licensed EMI; - Ubble SAS, identity-verification provider, for the sole purpose of KYC liveness; - SES Imagotag and Octopush, telecommunications providers, for transactional SMS; - our cloud-infrastructure providers operating within the European Economic Area (Microsoft Azure, Scaleway); - our regulators (ACPR, AMF, CNIL, Tracfin), the tax administration and any judicial authority entitled to access the data by law; - the Mastercard scheme, for the routing and clearing of card transactions; - external auditors and counsel, bound by a duty of professional secrecy.
We never sell your data to third parties for advertising purposes.
5. International transfers
Personal data are hosted within the European Economic Area. A limited number of sub-processors are located in the United States (in particular for the Mastercard authorisation network and certain anti-fraud telemetry); transfers to these sub-processors take place on the basis of the Standard Contractual Clauses adopted by the European Commission (decision 2021/914), supplemented where necessary by technical and organisational measures (encryption in transit and at rest, pseudonymisation) in line with the recommendations of the European Data Protection Board (EDPB Recommendations 01/2020). A copy of the safeguards may be obtained from our DPO.
6. Retention periods
Identification and KYC data are retained for the duration of the contractual relationship and for five (5) years after its termination, in compliance with Article L. 561-12 of the Code monétaire et financier.
Payment-transaction records are retained for five (5) years from the date of execution, in compliance with Article L. 123-22 of the Code de commerce.
Logs used for fraud-monitoring and security are retained for thirteen (13) months after collection, in compliance with the CNIL deliberation 2020-091.
Customer-support exchanges are retained for three (3) years after the end of the contractual relationship.
Prospect data are retained for three (3) years from the last interaction. Cookies are retained for the periods set out in our Cookie Policy.
8. Your rights
In accordance with Chapter III of the GDPR (Articles 15 to 22), you have the right to access your data, to obtain rectification of inaccurate data, to obtain erasure within the limits of our legal-retention obligations, to obtain restriction of processing, to data portability for data provided by yourself and processed on the basis of consent or the performance of a contract, to object to processing carried out on the basis of legitimate interest, and to give instructions on the fate of your data after your death.
These rights may be exercised, free of charge, by writing to our DPO (see below). We reply within one (1) month from the date of receipt of a valid request; this period may be extended by two (2) months for complex requests. Where there is reasonable doubt as to your identity, we may ask for additional information to verify it.
9. Data Protection Officer
We have appointed a Data Protection Officer (DPO). The DPO may be contacted by post at Sell it Today - DPO, Paris, France, or by email at dpo@payittoday.fr. The DPO of Treezor SAS may be reached at dpo@treezor.com for any question relating to the regulated banking processing.
10. Right to lodge a complaint with the CNIL
Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with the Commission nationale de l'informatique et des libertés (CNIL), 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, or online at www.cnil.fr, if you consider that the processing of your personal data infringes the GDPR.
11. Security measures
We implement technical and organisational measures appropriate to the risk, as required by Article 32 of the GDPR: encryption in transit (TLS 1.3) and at rest (AES-256), pseudonymisation of identifiers used in analytics, hardware-isolated key custody for cryptographic material, role-based access control with audit logs, segregation of environments, monthly vulnerability scans, annual third-party penetration tests, incident-response runbooks aligned with the ANSSI good-practice guide, and a personal-data breach notification procedure aligned with Articles 33 and 34 of the GDPR.
12. Automated decision-making
Two processes involve automated decision-making within the meaning of Article 22 of the GDPR.
KYB risk scoring at on-boarding combines public-register data, sanctions-screening results and Ubble's liveness scoring to assign your file to a risk band; a high-risk band triggers a manual review by a compliance officer before any decision to refuse the relationship is taken. A pure refusal solely based on the algorithm never occurs without human review.
Real-time card and SEPA transaction anti-fraud scoring may, in case of a high score, lead to the temporary blocking of a single transaction; you are notified inside the application and may request human review.
In both cases, you have the right to obtain human intervention, to express your point of view, and to contest the decision.
13. Behavioural tracking and advertising
We do not carry out any cross-site advertising tracking. No data are sold or rented to advertising networks. Product-analytics, where activated with your consent, are performed on pseudonymised aggregates and are never used for individual targeting.
14. Updates to this Policy
We may amend the present Privacy Policy to reflect changes in the regulations, in the Services or in our processing operations. Substantial changes are notified to you on a durable medium with reasonable notice. The current version is permanently accessible at /legal/privacy.