1. Who we are and what this is
Elaris is a payment service: we help companies accept payments on a website, in an app, in a messenger and through a payment link, and make payouts. The website and the service are operated by Elaris Payments L.L.C-FZ.
This document explains what data we receive from website visitors, from companies that submit an application for onboarding, and from active merchant clients. It also covers why we need that data, who we share it with, how long we keep it and how you can influence this.
The policy applies to the Elaris website and to the services we provide under contract. It does not apply to merchant websites or to third-party services that may be linked from our website: they have their own data practices.
Elaris Payments L.L.C-FZ
Legal form: Limited Liability Company
Licence 2654048.01, registration number 2654048, issued by Meydan Free Zone, Dubai, U.A.E.
Licensed activities: Payment Services Provider, Digital content services
Address: Meydan Grandstand, 6th floor, Meydan Road, Nad Al Sheba, Dubai, U.A.E.
2. What data we collect
We collect only what is needed to reply to an enquiry, to onboard a client and to keep the service running. We do not collect data about race, health, religious or political views, and we do not ask you to send it.
| What data | Why |
|---|---|
| Application data: name, phone number, company name, website address, the comment you leave in the form, email address if you provide one | To contact you, understand the task, suggest suitable payment methods and terms, answer your question |
| Technical data: IP address, device type, operating system, browser, language, pages viewed, date and time of the visit, referring source | To serve the website correctly, measure traffic, find errors, protect forms from automated attacks and spam |
| Merchant onboarding data: company details, registration and tax numbers, licences and permits, description of the business and its products, contacts of responsible staff, bank details for payouts, documents we request during the check | To conclude and perform the contract, verify the business before onboarding, meet the requirements of acquiring banks, payment systems and anti-money-laundering legislation |
| Transaction data: amount, currency, date and time, payment method, status, order reference and technical payment identifier, masked card number in the first and last digits format | To process payments and payouts, display transactions in the merchant dashboard, handle disputes, refunds and chargebacks, keep accounting records |
| Correspondence: support messages, email enquiries, records of onboarding arrangements | To handle the request, keep the history of the case, confirm the terms agreed |
Part of the technical data is collected through cookies and similar technologies. Which cookies we set and how to refuse the optional ones is described in the Cookie policy.
3. Why we collect it and on what basis
We process data only for specific purposes and only while a legal basis for the processing exists. The bases are:
- Conclusion and performance of a contract. Handling the application, verifying the company before onboarding, configuring the service, processing payments and payouts, support, invoicing and reporting to the client.
- Legal requirements and payment industry rules. Client identification, checks on the source of transactions, retention of documents and transaction records, responses to lawful requests from competent authorities, compliance with the requirements of acquiring banks and international payment systems.
- Our legitimate interest. Protecting the service from fraud and automated attacks, quality control in support, basic traffic analytics, defending our rights in disputes. We make sure such processing does not override your rights and we keep its scope limited.
- Consent. Optional cookies, newsletters and product updates. Consent can be withdrawn at any time, which does not affect the lawfulness of processing carried out before the withdrawal.
We do not sell personal data and do not pass it to third parties for their own advertising.
4. Cardholder payment data
This section covers the most sensitive part. When a customer pays on a merchant website through Elaris, the full card details are entered on a secure payment form or in a banking app, not on the merchant side.
- Elaris does not store the full card number, the expiry date or the card verification code.
- Elaris does not pass full card details to the merchant. The merchant only sees the transaction status, amount, currency, order reference and the masked card number in the first and last digits format.
- Card data is handled inside a secure processing environment that follows the PCI DSS industry security standard, with encryption in transit and restricted access.
- Transactions are confirmed using 3-D Secure, that is an additional check of the payer on the issuing bank side.
When a customer pays on a merchant website, the merchant decides what order data it collects and how it uses it. In that part the merchant is responsible for its own data and publishes its own policy. Elaris processes such data only to the extent needed to execute the payment.
6. Cross-border transfer and storage
Elaris Payments L.L.C-FZ is registered in Meydan Free Zone, Dubai, U.A.E. The main systems and servers holding client data and service records are located in the U.A.E.
The service operates across several countries, so data may be transferred outside the country where you are located: for example to acquiring banks, payment systems and infrastructure providers in other jurisdictions. In such cases we:
- transfer only the volume of data the recipient needs for its role;
- sign agreements with recipients that include confidentiality and data protection obligations;
- use encrypted transmission channels and access control;
- comply with the applicable legislation on cross-border data transfer.
Where a specific transfer requires your consent, we request it separately.
7. Retention periods
We keep data exactly as long as the purpose it was collected for requires, and then delete or anonymise it.
- Application data where onboarding did not follow. Up to 12 months from the last contact, so that we can pick up the conversation if you write again. Sooner if you ask us to delete it.
- Merchant data and verification documents. For the term of the contract and then for the period prescribed by legislation and payment industry rules for keeping such documents.
- Transaction and accounting records. For the period set by financial reporting and primary document retention requirements.
- Support correspondence. Up to 3 years, to keep the history of the case and confirm what was agreed.
- Technical logs and web analytics data. As a rule up to 12 months; security logs may be kept longer where this is needed to investigate an incident.
If data is needed to defend our rights in a pending dispute or to comply with an order of a competent authority, the retention period is extended until that procedure is completed.
8. Your rights
In relation to your data you can:
- find out whether we process your data and obtain a copy of it;
- ask us to correct inaccurate or incomplete data;
- ask us to delete data where we no longer have a basis to keep it;
- restrict processing or object to processing based on our legitimate interest;
- withdraw consent where the processing was based on it, including unsubscribing from mailings;
- receive your data in a machine-readable format where this applies to your case;
- lodge a complaint with a competent data protection authority.
To exercise a right, write to the address in section 10 and describe your request. We reply within a reasonable time, as a rule within 30 days. To avoid disclosing data to the wrong person, we may ask you to confirm your identity or your connection to a client company.
In some cases we may refuse in full or in part: for example, where the law requires us to keep the data or where the request affects the rights of other people. We will explain the reason for any refusal.
If you are a customer and your question concerns an order with a particular merchant, contact that merchant first: it is the merchant that decides what order data is collected and how it is used.
9. Security
We protect data with organisational and technical measures, including:
- encryption of data transmitted over public networks;
- role-based access control and the principle of least privilege;
- logging of access to sensitive data and regular review of those logs;
- separation of development and production environments, change control;
- card data handled in an environment that follows the PCI DSS industry standard;
- anti-fraud transaction monitoring and protection of forms and APIs from automated attacks;
- backups and tested recovery procedures;
- confidentiality obligations for employees and contractors.
No service can guarantee absolute security. If an incident occurs that may create a risk to your rights, we will notify the affected clients and the competent authorities in the manner required by applicable law. On your side, keep dashboard credentials and API keys secret and tell us if you believe they have been compromised.
10. Changes and contacts
We may update this policy: for example when our processes, our vendors or legal requirements change. The current version is always available on this page, and the version date is shown in the document header. If the changes are material, we will notify you separately by email or through the dashboard.
For any question about data processing, and to exercise the rights listed in section 8, write to us:
Postal address: Elaris Payments L.L.C-FZ, Meydan Grandstand, 6th floor, Meydan Road, Nad Al Sheba, Dubai, U.A.E.
See also the Terms of use, the Public offer and the Cookie policy.